POPIA is routinely called South Africa’s GDPR, which flatters both laws into blandness. POPIA drafted its own answers: companies get privacy rights, the CEO is the default compliance officer, electronic marketing is opt-in with a single carefully fenced exception, and some processing waits for regulator sign-off before it may begin. A GDPR program covers perhaps eighty percent of POPIA; the remaining twenty percent is precisely the part no EU checklist will surface, and it is where the Information Regulator has chosen to enforce.
| Dimension | GDPR | POPIA |
|---|---|---|
| Legal persons | Excluded | Protected (juristic persons) |
| Compliance officer | DPO (conditional, independent) | Information officer (CEO default, registered) |
| E-marketing | Basis-neutral + ePrivacy | Opt-in, narrow existing-customer relief |
| Prior authorization | None | Section 57 listed processing |
| Breach clock | 72 hours | As soon as reasonably possible |
| Max fine | 4% worldwide turnover | R10M + criminal exposure |
Bridging the two regimes
Annex, don’t fork. Run the GDPR core and add the South African gateways; the full POPIA guide sequences the annex.
Start with marketing and scope. Opt-in conversion and juristic-person inventory are the two changes with immediate legal effect, and marketing is the Regulator’s enforcement theme.
Institutionalize the information officer. Executive accountability with delegated deputies, registered and documented; details in the information officer guide.
Harmonize continentally with care. Nigeria’s NDPA and Kenya’s DPA sit closer to GDPR; the NDPA vs POPIA comparison maps the pan-African deltas.
Your South African pages’ marketing consent behavior is Section 69 evidence: verify it with a free scan.