South Africa

POPIA

43 controls. 132 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

43 controls 132 frameworks share controls with it South Africa verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
POPIASA-1Accountability, Processing Limitation, Lawful Basis, Codes0
POPIASA-2Purpose Specification, Collection Limitation, Further Processing Limitation0
POPIASA-3Data Subject Rights (Access, Correction, Objection), Automated Decisions50
POPIASA-4Special Personal Information, Children, Information Quality, Documentation94
POPIASA-5Security Safeguards, Encryption, Access Control, Operator Obligations87
POPIASA-6Transborder Information Flows, Direct Marketing21
POPIASA-7Information Officer, Records of Processing, Notification, Training42
POPIASA-8Information Regulator Cooperation, Complaints, Enforcement20
1-2Definitions and purpose0
10Condition 2, processing limitation: minimality0
100-109Offences, penalties and administrative fines0
11Condition 2, processing limitation: consent, justification and objection0
110-115Regulations, amendment of laws, transitional arrangements and commencement0
12Condition 2, processing limitation: collection directly from the data subject0
13Condition 3, purpose specification: collection for a specific purpose0
14Condition 3, purpose specification: retention, destruction and restriction of records0
15Condition 4, further processing limitation0
16Condition 5, information quality0
17Condition 6, openness: documentation of processing operations0
18Condition 6, openness: notification to the data subject when collecting0
19Condition 7, security safeguards: integrity and confidentiality0
20Condition 7, security safeguards: operators and persons acting under authority0
21Condition 7, security safeguards: written operator contracts and operator breach notification0
22Condition 7, security safeguards: notification of security compromises0
23Condition 8, data subject participation: access to personal information0
24Condition 8, data subject participation: correction and deletion0
25Manner of access0
26-27Special personal information: prohibition and authorisations0
3-7Application, lawful processing, rights of data subjects and exclusions0
34-35Personal information of children: prohibition and authorisations0
36-38Exemptions from the conditions0
39-54The Information Regulator0
55-56Information officer and deputy information officers0
57-58Prior authorisation by the Regulator0
60-68Codes of conduct0
69Direct marketing by unsolicited electronic communications0
70Directories of subscribers0
71Automated decision making0
72Transfers of personal information outside the Republic0
73-99Enforcement: complaints, investigation, assessments, enforcement notices, appeals and civil remedies0
8Condition 1, accountability: responsible party ensures the conditions are met0
9Condition 2, processing limitation: lawfulness and reasonableness0
REGSRegulations relating to the Protection of Personal Information, 2018 (amended 2025), and Regulator guidance0

Tell me when POPIA files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Retention schedule
  • Retention schedule with the section 14(1) ground per record class
  • Destruction and de-identification records showing irreversibility
  • Restriction procedure and log with pre-lifting notices
  • Purpose specification
  • Retention schedule by data category
  • Data quality procedures proportionate to the purpose
  • Update and correction workflows
  • Data inventory mapping each data element to a lawful purpose
  • Accuracy maintenance and update procedures

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for POPIA, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition