What POPIA actually requires
South Africa's data protection law, structured around eight conditions for lawful processing. POPIA requires consent for processing many categories of personal information, including the use of cookies to track or profile users. It is enforced by the Information Regulator.
Key requirements
- Identify a lawful condition (usually consent) before processing personal information
- Be transparent about what you collect and why, in plain language
- Allow data subjects to access, correct and delete their information
- Implement reasonable technical and organisational security measures
- Notify the Information Regulator and affected users of security compromises
- Appoint an Information Officer responsible for compliance
At a glance
Full name
Protection of Personal Information Act
Region
South Africa
Status
Fully enforceable since July 2021
Who it affects
Any public or private body that processes personal information of South African data subjects, regardless of whether the organisation is based in South Africa.
Penalties
Administrative fines up to ZAR 10 million per offence, plus criminal penalties of up to ten years' imprisonment for the most serious offences.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
