Jurisdiction Guide
South Africa Privacy & Data Protection Laws
Every regime below can apply to a business handling South Africa residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
POPIA does not use the GDPR Article 3 model. Section 3(1) instead applies the Act wherever the responsible party is domiciled in South Africa, OR — if not domiciled there — 'makes use of automated or non-automated means in the Republic' (unless those means are used only to forward information through the country) — closer to the old pre-GDPR EU Directive 95/46/EC 'means/equipment' test than to a targeting test. Modeled here as an established-presence trigger since 'uses processing means located there' is the closest fit. Section 6 excludes purely personal/household activity, properly de-identified data, and processing by public bodies for national security/defense/law enforcement (with safeguards, not a blanket carve-out). No small-business, nonprofit, or sector-specific exemption.