Skip to content
← Services

POPIA

Protection of Personal Information Act 2013 (South Africa)

Data ProtectionSouth AfricaIn force: July 1, 2021

What it is

POPIA is South Africa's primary data protection statute, fully effective since July 2021. It aligns with GDPR principles while accommodating South African enforcement realities and the Information Regulator's mandate, which also covers PAIA access-to-information requests.

What it requires

All responsible parties processing personal information of South African residents. Eight conditions for lawful processing, data subject rights, breach notification to the Information Regulator and affected parties, prior authorisation for certain processing, and registration of Information Officers.

Key facts

Supervisor
Information Regulator (South Africa)
Maximum fine
Up to ZAR 10 million administrative fine; criminal liability for certain offences

Related briefings

The Credential You Can't Change
Chokepoint DoctrineJuly 7, 2026
The Credential You Can't Change

Your voiceprint is not a password. A password can be changed; your voice cannot. In January 2021 Walmart settled for $10M over palm scans of 22,000 Illinois employees; by July it was sued over warehouse-headset voiceprints, then over uploading shoppers' faces to a Clearview AI database - three biometric systems, one company, all under Illinois's Biometric Information Privacy Act, the only US law that lets individuals sue. McDonald's, Chipotle, Verizon, Microsoft Teams face the same claims; 107 BIPA class actions were filed in Illinois in 2025 alone. In 47 of 50 states, collecting your fingerprint, face, or voiceprint needs no consent, no disclosure, and carries no consequence. Under GDPR Article 9 it is special-category data requiring explicit consent, with fines to EUR 20M or 4% of turnover - and the EU AI Act bans workplace emotion inference from 2 August 2026. My assessment: this is not a regulatory gap but a policy choice, applied to the one category of data that is permanent. If the database holding your voiceprint is breached, the credential is compromised for life - and in 47 states no one is obliged to tell you.

Free tier8 min read
If You Put Data in a US Cloud, You Share It With US Intelligence
Chokepoint DoctrineJune 29, 2026
If You Put Data in a US Cloud, You Share It With US Intelligence

From a conference stage, Claus Balslev, head of digitalisation at Denmark's STAR labour-market agency, said the sentence everyone hedges around: if you put data in a US cloud, you share it directly with the US intelligence service. Then he acted on it, migrating STAR's systems off Microsoft and onto European cloud in roughly nine months, and saving money doing it. My assessment: the statement is not rhetoric, it is the precise legal architecture. The CLOUD Act attaches jurisdiction to the US entity, not the data; FISA 702 authorises bulk collection from US providers with no warrant and a gag order; RISAA (2024) extends reach toward the silicon itself; and the 12 June 2026 Fable/Mythos AI suspension proved Washington can switch off the capability globally by letter. Asked under oath before the French Senate in 2025 whether Microsoft could guarantee EU data is never sent to US authorities, Microsoft France's legal-affairs director answered: no. This is not a governance gap but a governance collision, two irreconcilable legal systems applied to the same data, which is why Safe Harbor, Privacy Shield, and soon the current framework all fall. Residency is where the bits sit; sovereignty is who controls access. STAR removed the last excuse, and the AI layer is the next Schrems ruling.

Free tier9 min read
The Root of Trust That Already Leaked
Chokepoint DoctrineJune 28, 2026
The Root of Trust That Already Leaked

In June 2024, Paradigm Initiative proved the largest data leak in Nigerian history by buying it: for 100 naira a record, rogue sites were selling the NIN, BVN, passport, and phone number of 104 million Nigerians from NIMC's database, including the slips of the digital-economy minister and the national data regulator. On 27 June 2026, President Tinubu signed the NIMC Act 2026, replacing a 19-year-old law, and named that same commission the Root Certification Authority for Nigeria's national PKI. My assessment: the Act hardens the cryptography, but the 2024 breach was never cryptographic. It leaked through custody and access, third-party agents with legitimate credentials, the exact layer a certificate hierarchy does not fix. The new 14-agency board (INEC, DSS, EFCC, CBN, the population commission, the national security adviser) concentrates the state's coercive machinery around one dataset. For every Nigerian fintech, identity verification now chains to a single sovereign root you cannot switch away from, held by a custodian with a demonstrated breach history. The law is overdue and much of it is sound. But a root of trust is the one credential that cannot be reissued, and it now sits on the custody layer that already failed once, at the scale of a nation. What to watch: the secondary regulations, the data regulator's enforcement teeth, the access-governance layer, and whether any redress ever reaches the 104 million.

Free tier9 min read
The Weakest Custodian in the Chain
Chokepoint DoctrineJune 22, 2026
The Weakest Custodian in the Chain

985,000 passports and driver's licences sat on public URLs with no password, no access control, nothing. No hack, no exploit chain. The custodian was not a government agency or a bank but Nefos Solutions, a two-person Irish startup that built membership software for Spanish cannabis clubs, with a Stripe key in plain text inside its app. My assessment: this is not one breach. France Titres (national identity agency, IDOR found by a 15-year-old, 11.7M records), the UK Visa Portal (guessable URL, 100,000+ passports), the Texas hunting-licence vendor (third-party breach, 3.09M Texans), and Nefos (public URL, 985,000 passports) are four expressions of one structural reality. From the most capable national agency to a two-person startup, the security outcome is identical: government identity documents on the open internet. The EU's age-verification mandate will create thousands more Nefos-scale custodians collecting the one category of data that cannot be reset. Identity documents are only as secure as the weakest custodian in the chain that now holds them. Extends the DSI EU regulatory series: France Titres, the EUDI Wallet, and the age-verification oxymoron.

Free tier10 min read
Nigerian Oil and Gas at the Cyber-Physical Frontier: What the 2026 Pattern Tells Operators
Threat AssessmentMay 22, 2026
Nigerian Oil and Gas at the Cyber-Physical Frontier: What the 2026 Pattern Tells Operators

Berlin, January 2022. Hackers took the IT systems of Oiltanking and Mabanaft offline. Tank-loading scheduling went dark for two weeks. The OT held — but the IT system that scheduled the loading did not. That is the incident pattern now migrating into the Nigerian operational reality. This briefing examines what the global oil and gas pattern is telling operators in the post-PIA Nigerian context — and why single-operator defence has reached its structural ceiling.

Free tier25 min read
The Nigerian Banking Sector Under Siege: What the 2026 Incident Pattern Tells Security Leaders
Threat AssessmentMay 21, 2026
The Nigerian Banking Sector Under Siege: What the 2026 Incident Pattern Tells Security Leaders

A Tier 1 Nigerian bank lost billions on a Friday evening. The institution did not report the breach to its peers. Within 48 hours, two other banks were compromised by the same group. This briefing examines what the 2026 incident pattern is telling CISOs in the Nigerian banking sector — and why individual-bank defence has stopped working.

Free tier7 min read

Read more on this

Other data protection frameworks in the DSI registry: