Frequently asked questions about POPIA.
Straight answers to the questions estates, boards, and compliance teams actually ask, each one grounded in, and linked to, the specific section of the Act it comes from.
This is a reference for general information. It is not the Information Regulator and does not constitute legal advice.
About POPIA
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's data protection law, 12 chapters and 115 sections in total, covering how personal information may be collected, used, secured, and shared.
Most sections commenced on 1 July 2020, a one-year grace period for compliance ended 30 June 2021, and POPIA has been fully enforceable since 1 July 2021.
Yes, the Information Regulator gazetted amended Regulations (GN 6126) on 17 April 2025, widening the channels for objections and correction requests and tightening direct-marketing consent rules, among other changes. See our full summary of the 2025 amendments.
The Information Regulator, established under section 39 (Chapter 5, Supervision), which also has its own Enforcement Committee for investigating complaints under Chapter 10.
The 8 conditions for lawful processing
Chapter 3 sets out eight conditions: Accountability, Processing Limitation, Purpose Specification, Further Processing Limitation, Information Quality, Openness, Security Safeguards, and Data Subject Participation, every section in ss.8-35 falls under one of these eight.
No, section 11 sets out six separate lawful grounds, and consent is only one of them; the others include contractual necessity, a legal obligation, protecting the data subject's own interest, a public-law duty, or a legitimate interest of the responsible party or a third party.
Section 19 requires “appropriate, reasonable technical and organisational measures,” broken into four ongoing duties: identify risks, establish safeguards, verify they work, and keep updating them as risks change.
For estates, sectional title schemes & HOAs
Yes, a body corporate or HOA is almost always the “responsible party” for resident, visitor, and staff data (CCTV footage, visitor logs, and biometric access records included), which places the full set of Chapter 3 conditions on the scheme itself, not just its managing agent.
Yes, and section 55(2) requires that person to be registered with the Information Regulator before they may take up their duties; a title on an org chart isn't sufficient on its own.
Section 22 requires notifying both the Information Regulator and the affected data subjects (unless their identity can't be established), as soon as reasonably possible after discovering the compromise.
For boards & governance
Section 8 (Accountability) puts compliance squarely on the responsible party at the time it determines the purpose and means of processing, for a governed body, that traces back to the board or trustees, not just whoever administers IT.
Enforcement & penalties
Section 109(2)(c) caps administrative fines at R10 million per infringement notice, a per-notice ceiling, not a lifetime limit, and the Minister may adjust this figure over time under subsection (10).
No, sections 109(6) and (7) mean the Regulator can't pursue an administrative fine after a criminal charge has been laid for the same facts, and can't prosecute after a fine under that section has already been paid.
Section 73 defines it as any breach of the Chapter 3 conditions, non-compliance with specific sections (22, 54, 69, 70, 71 or 72), or a breach of a registered code of conduct, this definition is what triggers the Chapter 10 complaints and enforcement process.
Still have a question specific to your estate or board?
Start with the free POPIA Compliance Status Assessment for a personalised view of where you actually stand, reviewed by Celagenix data-privacy specialists, with no obligation. PopiGuard then turns it into a guided compliance programme for South African estates.