Back to Frameworks

South African POPIA

South Africa
18 domains
32 controls

South Africa Protection of Personal Information Act 4 of 2013.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (18)

Automated Decisions

1 controls
Controls in the Automated Decisions domain of South African POPIA1 controls
CodeTitle
s.71Automated Decision Making

Children's Data

1 controls
Controls in the Children's Data domain of South African POPIA1 controls
CodeTitle
s.34-35Personal Information of Children

Condition 1 Accountability

1 controls
Controls in the Condition 1 Accountability domain of South African POPIA1 controls
CodeTitle
s.8Accountability

Condition 2 Processing Limitation

4 controls
Controls in the Condition 2 Processing Limitation domain of South African POPIA4 controls
CodeTitle
s.10Minimality
s.11Consent, Justification and Objection
s.12Collection Directly from Data Subject
s.9Lawfulness of Processing

Condition 3 Purpose Specification

2 controls
Controls in the Condition 3 Purpose Specification domain of South African POPIA2 controls
CodeTitle
s.13Collection for Specific Purpose
s.14Retention and Restriction of Records

Condition 4 Further Processing Limitation

1 controls
Controls in the Condition 4 Further Processing Limitation domain of South African POPIA1 controls
CodeTitle
s.15Further Processing to be Compatible with Purpose of Collection

Condition 5 Information Quality

1 controls
Controls in the Condition 5 Information Quality domain of South African POPIA1 controls
CodeTitle
s.16Quality of Information

Condition 6 Openness

2 controls
Controls in the Condition 6 Openness domain of South African POPIA2 controls
CodeTitle
s.17Documentation
s.18Notification to Data Subject When Collecting Personal Information

Condition 7 Security Safeguards

4 controls
Controls in the Condition 7 Security Safeguards domain of South African POPIA4 controls
CodeTitle
s.19Security Measures on Integrity and Confidentiality
s.20Information Processed by Operator or Person Acting Under Authority
s.21Security Measures Regarding Information Processed by Operator
s.22Notification of Security Compromises

Condition 8 Data Subject Participation

3 controls
Controls in the Condition 8 Data Subject Participation domain of South African POPIA3 controls
CodeTitle
s.23Access to Personal Information
s.24Correction of Personal Information
s.25Manner of Access

Cross-Border Transfers

1 controls
Controls in the Cross-Border Transfers domain of South African POPIA1 controls
CodeTitle
s.72Transfers of Personal Information Outside Republic

Data Subject Participation

1 controls
Controls in the Data Subject Participation domain of South African POPIA1 controls
CodeTitle
Reg.5Request for Access, Correction and Objection Forms

Direct Marketing

2 controls
Controls in the Direct Marketing domain of South African POPIA2 controls
CodeTitle
s.69Direct Marketing by Means of Unsolicited Electronic Communications
s.70Directories

Enforcement

1 controls
Controls in the Enforcement domain of South African POPIA1 controls
CodeTitle
s.99-100Civil Remedies and Offences

Implementation

1 controls
Controls in the Implementation domain of South African POPIA1 controls
CodeTitle
Effective.July2021Commencement and Transitional Period

Information Officer

2 controls
Controls in the Information Officer domain of South African POPIA2 controls
CodeTitle
Reg.4Responsibilities of Information Officer (Regulations)
s.55-56Information Officer Duties and Registration

Prior Authorisation

2 controls
Controls in the Prior Authorisation domain of South African POPIA2 controls
CodeTitle
s.57Prior Authorisation by Information Regulator
s.58Notification to Regulator

Special Personal Information

2 controls
Controls in the Special Personal Information domain of South African POPIA2 controls
CodeTitle
s.26-27Special Personal Information Prohibition and Exemptions
s.28-33Authorisation for Specific Categories of Special Information

Frequently Asked Questions

What is South African POPIA?

South African POPIA is a compliance framework from South Africa with 18 domains and 32 controls. South Africa Protection of Personal Information Act 4 of 2013. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does South African POPIA have?

South African POPIA has 32 controls organised across 18 domains. The largest domains are Condition 2 Processing Limitation (4 controls), Condition 7 Security Safeguards (4 controls), Condition 8 Data Subject Participation (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does South African POPIA map to?

South African POPIA does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with South African POPIA compliance?

Start your South African POPIA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about South African POPIA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required