The POPI Act the Act, section by section, free PAIA Guide ↗

Frequently asked questions about POPIA.

Straight answers to the questions estates, boards, and compliance teams actually ask, each one grounded in, and linked to, the specific section of the Act it comes from.

This is a reference for general information. It is not the Information Regulator and does not constitute legal advice.

About POPIA

What is POPIA and how big is the Act? ▾

The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's data protection law, 12 chapters and 115 sections in total, covering how personal information may be collected, used, secured, and shared.

When did POPIA actually come into force? ▾

Most sections commenced on 1 July 2020, a one-year grace period for compliance ended 30 June 2021, and POPIA has been fully enforceable since 1 July 2021.

Have the POPIA Regulations changed recently? ▾

Yes, the Information Regulator gazetted amended Regulations (GN 6126) on 17 April 2025, widening the channels for objections and correction requests and tightening direct-marketing consent rules, among other changes. See our full summary of the 2025 amendments.

Who enforces POPIA? ▾

The Information Regulator, established under section 39 (Chapter 5, Supervision), which also has its own Enforcement Committee for investigating complaints under Chapter 10.

The 8 conditions for lawful processing

What are the 8 conditions for lawful processing under POPIA? ▾

Chapter 3 sets out eight conditions: Accountability, Processing Limitation, Purpose Specification, Further Processing Limitation, Information Quality, Openness, Security Safeguards, and Data Subject Participation, every section in ss.8-35 falls under one of these eight.

Does POPIA require consent for all processing? ▾

No, section 11 sets out six separate lawful grounds, and consent is only one of them; the others include contractual necessity, a legal obligation, protecting the data subject's own interest, a public-law duty, or a legitimate interest of the responsible party or a third party.

What security measures does POPIA require? ▾

Section 19 requires “appropriate, reasonable technical and organisational measures,” broken into four ongoing duties: identify risks, establish safeguards, verify they work, and keep updating them as risks change.

For estates, sectional title schemes & HOAs

Does POPIA apply to sectional title schemes, HOAs, and body corporates? ▾

Yes, a body corporate or HOA is almost always the “responsible party” for resident, visitor, and staff data (CCTV footage, visitor logs, and biometric access records included), which places the full set of Chapter 3 conditions on the scheme itself, not just its managing agent.

Does our estate need to appoint an Information Officer? ▾

Yes, and section 55(2) requires that person to be registered with the Information Regulator before they may take up their duties; a title on an org chart isn't sufficient on its own.

What has to happen if our estate has a data breach? ▾

Section 22 requires notifying both the Information Regulator and the affected data subjects (unless their identity can't be established), as soon as reasonably possible after discovering the compromise.

For boards & governance

Is POPIA compliance a board-level responsibility? ▾

Section 8 (Accountability) puts compliance squarely on the responsible party at the time it determines the purpose and means of processing, for a governed body, that traces back to the board or trustees, not just whoever administers IT.

What's the difference between an Information Officer and the board's own governance role? ▾

The Information Officer (s.55) handles the Act's day-to-day duties, requests, Regulator liaison, encouraging compliance, while accountability for whether those conditions are actually met in the first place (s.8) sits with the responsible party's own governing body.

Enforcement & penalties

What's the maximum fine under POPIA? ▾

Section 109(2)(c) caps administrative fines at R10 million per infringement notice, a per-notice ceiling, not a lifetime limit, and the Minister may adjust this figure over time under subsection (10).

Can the Information Regulator both fine and criminally prosecute for the same incident? ▾

No, sections 109(6) and (7) mean the Regulator can't pursue an administrative fine after a criminal charge has been laid for the same facts, and can't prosecute after a fine under that section has already been paid.

What counts as “interference” with someone's personal information under POPIA? ▾

Section 73 defines it as any breach of the Chapter 3 conditions, non-compliance with specific sections (22, 54, 69, 70, 71 or 72), or a breach of a registered code of conduct, this definition is what triggers the Chapter 10 complaints and enforcement process.

Still have a question specific to your estate or board?

Start with the free POPIA Compliance Status Assessment for a personalised view of where you actually stand, reviewed by Celagenix data-privacy specialists, with no obligation. PopiGuard then turns it into a guided compliance programme for South African estates.