POPIA reads like the GDPR redrafted by someone who wanted executives personally on the hook: the information officer is the CEO by default, the first administrative fine landed on a government department, and the statute protects companies’ information alongside individuals’, which quietly expands scope beyond anything in the EU. Fully effective since July 2021, it has moved from education to enforcement, with direct marketing, breach response, and public-sector negligence as the Regulator’s running themes.
| Law | POPIA, Act 4 of 2013 |
|---|---|
| Fully effective | July 1, 2021 |
| Regulator | Information Regulator |
| Scope quirk | Protects juristic persons (companies) too |
| Marketing | Opt-in for electronic direct marketing (s 69) |
| Max penalty | R10M administrative; criminal to 10 years |
Building POPIA compliance
Register the information officer and mean it. The role’s executive default is the Regulator’s chosen pressure point; delegate operations to deputies but document the framework the officer owns. The information officer guide details the duties.
Run the gap analysis by condition. The eight conditions are the statute’s own audit structure; map systems, justifications, retention, and security against each, including juristic-person data your global program ignores.
Fix electronic marketing first. Section 69’s opt-in rule is the live enforcement theme and is externally visible; the POPIA vs GDPR comparison covers how it differs from EU soft opt-in.
Paper Section 72 transfers. Recipient-country law or binding agreements, consent, or contract necessity, documented per flow; the Nigeria comparison helps pan-African programs harmonize.
Marketing consent and trackers on your South African pages are exactly what Section 69 complaints cite: check them with a free scan.