The legal framework
Protection rests on the Protection of Personal Information Act (POPIA), fully in force since July 2021 and enforced by the Information Regulator. POPIA is unusual in also protecting the personal information of companies, and the Regulator handles both privacy and access-to-information complaints. These statutes follow the familiar pattern: lawful basis, purpose limitation, security, and rights of access, correction and objection.
Key points
| Rights | Access, correction, objection, and erasure under the more recent statutes |
|---|---|
| Registration | Data controllers must often register with the regulator |
| Breach notification | Required under most of these Acts |
| Cross-border transfers | Permitted subject to adequacy or safeguards |
| Regulator | Information Regulator of South Africa |
| Sectoral rules | Telecommunications and financial regulators impose additional confidentiality duties |
| Direct marketing opt-in | Electronic direct marketing requires prior consent |
| Information officer | Every organisation must register one with the Regulator |
| Enforcement notices | Failure to comply is an offence with substantial penalties |
| PAIA | Access to information is administered by the same Regulator |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Complain first to the organisation's information officer, then to the Regulator.
- Use PAIA where the problem is obtaining records rather than stopping processing.
Cost and coverage
Complaints to the regulator are free.
Recent changes
Digital lending applications that harvest contact lists have become the most common subject of enforcement across the region, alongside unsolicited marketing.
Where to go
- Information Regulator of South Africa — complaints and guidance.
- Telecommunications regulator for mobile and SMS abuse.
- Consumer protection body for related commercial disputes.
Worth knowing
Where a foreign platform is involved, the GDPR often applies in parallel if the company operates in Europe. Complaining in both places at once is legitimate and frequently faster. South Africa requires opt-in consent for electronic direct marketing, which is stricter than many regimes. Unsolicited messages are usually unlawful from the first one.
Official sources and links
- gov.za — official government portal
- South African Human Rights Commission — constitutional rights body
