Protection of Personal Information Act, 2013
POPIA is South Africa's data protection law. It sets out rules for how organizations collect, use, store, and share people's personal information. It is South Africa's counterpart to broader privacy and data protection regimes found in other jurisdictions.
The Protection of Personal Information Act, 2013 (POPIA) is the South African statute governing data protection and privacy, regulating how responsible parties collect, process, store, and share personal information. Its scope is national to South Africa, and it stands as a distinct legal regime; obligations under POPIA should not be assumed to mirror those of EU frameworks such as the GDPR or ePrivacy Directive, nor should compliance with one be treated as satisfying another. The evidence provided does not detail POPIA's specific provisions on cookies, consent standards, or how it applies to tracking technologies, so those aspects fall outside the scope of this definition.
Why it matters
POPIA is South Africa's principal data protection statute, governing how organizations collect, process, store, and share personal information within the country. For privacy officers, legal counsel, and compliance teams operating in or serving South African markets, it establishes a distinct legal regime that must be assessed on its own terms rather than assumed to mirror frameworks such as the EU's GDPR or ePrivacy Directive. Compliance with one regime does not automatically satisfy the other.
For organizations that operate across multiple jurisdictions, POPIA matters because it is a separate obligation that may apply alongside other privacy laws. Teams managing cookie consent and tracking technologies for South African audiences should treat POPIA as its own compliance workstream, drawing on qualified local guidance rather than transposing rules developed for the EU, UK, or US state regimes.
The evidence available here describes POPIA at a high level as a law regulating the handling of personal information, but does not detail its specific provisions on cookies, consent standards, or how it applies to tracking technologies. Organizations should therefore consult the text of the Act and current guidance from the relevant South African regulator before drawing conclusions about how POPIA treats cookie consent or online tracking.
Who it's relevant to
Inside POPIA
Common questions
Answers to the questions practitioners most commonly ask about POPIA.