The POPI Act the Act, section by section, free PAIA Guide ↗
The POPI Act / Sections / Section 72
Section 72

Transfers of personal information outside Republic

Chapter 9 · Transborder Information Flows

(1) A responsible party in the Republic may not transfer personal information about a data subject to a third party who is in a foreign country unless— (a) the third party who is the recipient of the information is subject to a law, binding corporate rules or binding agreement which provide an adequate level of protection that— (i) effectively upholds principles for reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information relating to a data subject who is a natural person and, where applicable, a juristic person; and (ii) includes provisions, that are substantially similar to this section, relating to the further transfer of personal information from the recipient to third parties who are in a foreign country; (b) the data subject consents to the transfer; (c) the transfer is necessary for the performance of a contract between the data subject and the responsible party, or for the implementation of pre-contractual measures taken in response to the data subject's request; (d) the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject between the responsible party and a third party; or (e) the transfer is for the benefit of the data subject, and— (i) it is not reasonably practicable to obtain the consent of the data subject to that transfer; and (ii) if it were reasonably practicable to obtain such consent, the data subject would be likely to give it.

(2) For the purpose of this section— (a) "binding corporate rules" means personal information processing policies, within a group of undertakings, which are adhered to by a responsible party or operator within that group of undertakings when transferring personal information to a responsible party or operator within that same group of undertakings in a foreign country; and (b) "group of undertakings" means a controlling undertaking and its controlled undertakings.

transborder flowschapter 9cross-border transfercloud hostingbinding corporate rules
Beyond the text

What this means for your estate

  • This is the section that governs cloud services, CCTV/access-control vendors, or software hosted outside South Africa, subsection (1) blocks a transfer to a foreign third party unless one of five gateways in (a)-(e) applies, most commonly (a) an adequate-protection law/binding corporate rules/binding agreement, or (b) the data subject's consent.
  • Subsection (1)(a)(ii) matters for due diligence on vendors specifically: the adequacy test also requires the foreign recipient's own onward-transfer terms to be substantially similar to this section, so “our vendor is compliant” isn't enough if that vendor can freely pass the data on again without equivalent protection.
  • Subsections (1)(c)-(e) are the practical gateways for routine SaaS use, a transfer necessary to perform a contract with the data subject, or for their benefit where getting consent isn't reasonably practicable, without needing a full binding-corporate-rules arrangement for every vendor.
Relevant tool

PopiGuard's vendor register checks every offshore-hosted tool your estate uses against s.72's adequacy gateways, so a CCTV platform or accounting SaaS doesn't quietly put you in breach.

See PopiGuard for estates →