Skip to main content
Category: Laws and Regulations

Protection of Personal Information Act, 2013

Also known as: POPIA, Protection of Personal Information Act, POPI Act
Simply put

POPIA is South Africa's data protection law. It sets out rules for how organizations collect, use, store, and share people's personal information. It is South Africa's counterpart to broader privacy and data protection regimes found in other jurisdictions.

Formal definition

The Protection of Personal Information Act, 2013 (POPIA) is the South African statute governing data protection and privacy, regulating how responsible parties collect, process, store, and share personal information. Its scope is national to South Africa, and it stands as a distinct legal regime; obligations under POPIA should not be assumed to mirror those of EU frameworks such as the GDPR or ePrivacy Directive, nor should compliance with one be treated as satisfying another. The evidence provided does not detail POPIA's specific provisions on cookies, consent standards, or how it applies to tracking technologies, so those aspects fall outside the scope of this definition.

Why it matters

POPIA is South Africa's principal data protection statute, governing how organizations collect, process, store, and share personal information within the country. For privacy officers, legal counsel, and compliance teams operating in or serving South African markets, it establishes a distinct legal regime that must be assessed on its own terms rather than assumed to mirror frameworks such as the EU's GDPR or ePrivacy Directive. Compliance with one regime does not automatically satisfy the other.

For organizations that operate across multiple jurisdictions, POPIA matters because it is a separate obligation that may apply alongside other privacy laws. Teams managing cookie consent and tracking technologies for South African audiences should treat POPIA as its own compliance workstream, drawing on qualified local guidance rather than transposing rules developed for the EU, UK, or US state regimes.

The evidence available here describes POPIA at a high level as a law regulating the handling of personal information, but does not detail its specific provisions on cookies, consent standards, or how it applies to tracking technologies. Organizations should therefore consult the text of the Act and current guidance from the relevant South African regulator before drawing conclusions about how POPIA treats cookie consent or online tracking.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for organizations that handle the personal information of individuals in South Africa need to treat POPIA as a distinct compliance obligation. Because the available evidence does not detail POPIA's cookie or consent provisions, professionals should verify specific requirements against the Act and local regulatory guidance rather than assuming they mirror the GDPR.
Legal counsel advising on multi-jurisdictional operations
Counsel supporting organizations that operate across borders should recognize POPIA as a separate legal regime whose obligations should not be assumed to align with EU or US frameworks. Advice on cookie consent for South African audiences should be grounded in POPIA's own text and South African regulatory positions.
Marketing and compliance teams serving South African audiences
Teams deploying tracking technologies or cookie consent mechanisms for users in South Africa should confirm how POPIA applies before relying on consent flows designed for other jurisdictions. The scope of POPIA's treatment of cookies and tracking is not covered by the evidence here and requires separate assessment.

Inside POPIA

Protection of Personal Information Act (POPIA)
South Africa's comprehensive data protection law, which governs the processing of personal information and gives effect to the constitutional right to privacy. It sets conditions for lawful processing that apply to personal data collected through cookies and similar technologies where such data relates to an identifiable person.
Lawful processing conditions
POPIA establishes a set of conditions for the lawful processing of personal information, including accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Where cookies process personal information, these conditions generally apply.
Information Regulator
The supervisory authority responsible for overseeing and enforcing POPIA in South Africa. Practitioners should look to its guidance for enforcement positions, though such guidance continues to evolve and specific interpretations regarding cookies may not be fully settled.
Consent and alternative lawful bases
POPIA permits processing on the basis of consent as well as other justifications, such as where processing is necessary for a legitimate interest or the performance of a contract. Consent under POPIA is defined as a voluntary, specific, and informed expression of will, which is broadly comparable in spirit to standards under other regimes but is a distinct legal requirement.
Scope relative to cookies and tracking technologies
POPIA is a general data protection statute rather than a cookie-specific rule. It applies to cookies, pixels, SDKs, local storage, and similar technologies to the extent they involve processing personal information, but it does not replicate the specific device-access consent mechanism found in the EU ePrivacy Directive.

Common questions

Answers to the questions practitioners most commonly ask about POPIA.

Is POPIA basically South Africa's version of the GDPR, so GDPR compliance automatically covers it?
No. While POPIA (the Protection of Personal Information Act) shares broad principles with the GDPR, such as lawful processing and data subject rights, it is a distinct South African statute with its own definitions, conditions for lawful processing, and regulator (the Information Regulator). GDPR compliance may help you meet some overlapping obligations, but it does not automatically satisfy POPIA. You should assess POPIA's specific requirements separately, and where facts about a particular processing activity determine the outcome, seek local legal advice.
Does POPIA contain detailed cookie consent rules like the EU's ePrivacy Directive?
POPIA is a general data protection law rather than a dedicated ePrivacy-style instrument governing the placing of or access to information on a user's device. In the EU, the ePrivacy Directive specifically regulates cookies and similar technologies, while the GDPR governs any resulting personal data processing. POPIA does not replicate that ePrivacy-specific layer, so cookie practices under POPIA are generally analyzed through its broader personal information processing conditions rather than a cookie-specific consent rule. The precise treatment of cookies under South African law can depend on facts and evolving regulatory interpretation.
When does POPIA apply to a website's use of cookies and similar technologies?
POPIA generally applies where personal information is processed and the relevant jurisdictional conditions are met. If cookies, pixels, SDKs, or similar technologies collect or process personal information, that processing may fall within POPIA's scope even though these technologies are not literally cookies. Whether a specific implementation triggers POPIA depends on facts such as what data is collected and how it is used, which are outside the scope of a general definition. Confirm applicability against POPIA's own scope provisions for your circumstances.
How should organizations handle consent for cookies under POPIA compared with the EU approach?
POPIA sets out its own conditions for lawful processing, which may include consent as well as other bases, rather than mirroring the EU's prior opt-in model for non-essential cookies. This differs from most EU jurisdictions, where analytics and advertising cookies typically require prior affirmative consent and practices such as pre-ticked boxes or implied consent are widely considered non-compliant. Because requirements and enforcement positions differ by jurisdiction, you should not assume an EU-style consent banner automatically meets POPIA, and should map each technology to the appropriate lawful basis under South African law.
Can a consent management platform (CMP) make a website POPIA-compliant?
A CMP can support POPIA-related efforts by presenting notices, capturing user choices, and maintaining records, but no tool guarantees compliance. Technical measures such as CMPs and consent logging support compliance but do not replace the legal judgment needed to determine the correct lawful basis, notice content, and record-keeping approach under POPIA. Configuration should reflect POPIA's requirements rather than defaults built for other regimes, and legal review remains necessary.
What records or accountability measures should organizations consider for cookie-related processing under POPIA?
As a general matter, organizations subject to POPIA should be able to demonstrate that their processing meets the Act's conditions, which typically involves maintaining appropriate documentation of processing activities and, where consent is relied upon, evidence of the choices made. The specific form and retention of such records can depend on facts and on guidance from the Information Regulator, which may evolve. This definition does not prescribe exact record-keeping formats; confirm current expectations against POPIA and applicable regulatory guidance.

Common misconceptions

POPIA imposes the same cookie consent regime as the EU ePrivacy Directive.
POPIA is a general data protection law governing the processing of personal information; it does not contain the specific rule on placing and accessing information on a user's device that characterizes the EU ePrivacy Directive. Cookie practices designed solely for EU ePrivacy compliance should not be assumed to satisfy POPIA, and vice versa.
If a cookie banner is compliant with the GDPR, it is automatically compliant with POPIA.
POPIA is a separate South African regime with its own conditions for lawful processing and its own definition of consent. While there are conceptual similarities, compliance under one framework does not automatically establish compliance under the other, and organizations operating in South Africa should assess POPIA's requirements independently.
POPIA requires opt-in consent for all cookies.
POPIA permits processing on several lawful bases, not consent alone, so consent is not necessarily required for every cookie. Whether consent or another basis applies depends on the nature of the processing and the personal information involved, and the position may differ from strictly consent-driven interpretations under EU law.

Best practices

Assess whether your cookies and similar technologies (pixels, SDKs, local storage) process personal information relating to an identifiable person, since POPIA's conditions apply on that basis rather than to cookies as such.
Treat POPIA as a distinct framework and evaluate it independently rather than assuming that GDPR or EU ePrivacy compliance transfers over automatically.
Identify and document the appropriate lawful basis for each category of cookie-based processing, considering that POPIA allows justifications beyond consent alone.
Where you rely on consent, ensure it is voluntary, specific, and informed as required under POPIA, and keep records that demonstrate how consent was obtained.
Monitor guidance from the Information Regulator, recognizing that enforcement positions and interpretations relevant to cookies continue to evolve.
Use consent management tools to support compliance but do not treat them as a substitute for legal judgment or a POPIA-specific assessment of your processing.