South Africa - Personal Information Protection (GN 6126/2025)

Amendment to the Regulations relating to the Protection of Personal Information (POPIA Amendment Regulations) (Government Notice GN 6126 of 2025)

South Africa

RAI-ZA-NA-ARRPPXX-2025
Effective: April 17, 2025
In Force(In Force)
RegulationData Protection and PrivacyAccountability and DocumentationGovernance and Oversight
Export PDF

The POPIA Amendment Regulations (GN 6126 of 2025), adopted by South Africa's Information Regulator, bind responsible parties processing personal data by updating compliance and consent rules. The instrument came into force on 17 April 2025. It mandates explicit direct marketing consent and expands options for data subject requests.

Summary

The Amendment to the Regulations relating to the Protection of Personal Information (POPIA Amendment Regulations), published under Government Notice 6126 in Government Gazette No. 52523 on 17 April 2025, is currently In Force. The amendments took effect immediately upon publication on 17 April 2025. The Information Regulator (South Africa) enforces and oversees compliance with POPIA and these Regulations, possessing statutory authority to receive and investigate complaints, audit responsible parties, issue compliance notices, impose administrative fines, negotiate fine payment instalment arrangements, and approve sectoral codes of conduct.

The instrument updates and clarifies key terms in Regulation 1, including complainant, complaint, day, office hours, and writing, aligning procedural timelines with the Interpretation Act and recognizing electronic documentation under the Electronic Communications and Transactions Act. It expands access for data subjects to exercise rights such as objecting to processing or requesting correction and deletion of personal data free of charge across multiple digital and oral channels, including email, SMS, WhatsApp, and telephone. Telephonic requests must be recorded electronically by responsible parties and made available as recordings or transcriptions upon request.

Regarding direct marketing, the amended Regulations require responsible parties engaging in unsolicited electronic communications with non-customers to obtain explicit written consent through accessible channels or expedient methods. The amendment explicitly confirms that opt-out mechanisms do not constitute valid consent for direct marketing under section 69(2) of POPIA. Any consent requested telephonically or via automated calling machines must be electronically recorded and provided to the data subject on request.

The Regulations expand standing to lodge complaints with the Information Regulator to include any person acting in the public interest or with a sufficient personal interest. They mandate regulatory assistance for complainants who require help reducing complaints to writing or using languages other than English, and allow requests for complainant anonymity. For enforcement, responsible parties unable to pay administrative fines in a lump sum may arrange instalment payments with the Regulator, while transitional provisions ensure that prior valid actions taken under earlier regulations remain recognized.

Full article

Read full text ↗

Overview

The Amendment to the Regulations relating to the Protection of Personal Information (POPIA Amendment Regulations), published by the Information Regulator under Government Notice 6126 in Government Gazette No. 52523 on 17 April 2025, updates the Regulations Relating to the Protection of Personal Information, 2018. The amendment is published for immediate implementation and is intended to clarify definitions, improve accessibility and procedural certainty for data subjects, strengthen administrative and enforcement processes, and align certain procedural definitions with existing statutes such as the Protection of Personal Information Act, 2013 and the Electronic Communications and Transactions Act. The full Government Gazette notice is available from the official Gazette: GG 52523 GoN 6126 (17 April 2025), and the finalized Regulations file is published on the Information Regulator website: POPIA-2021-Regulations-FINAL-21-Jan-2025.pdf.

Definitions

The amendment revises and adds definitions in Regulation 1 to reduce uncertainty in interpretation. New or clarified entries include: "complainant" (any person who lodges a complaint with the Information Regulator); "complaint" (explicitly covering matters reported under sections 74, 76(1)(e) and 92(1) of POPIA and matters referred under other legislation within the Regulator’s mandate); "day" (calendar day with rules when the period ends on a Sunday or public holiday aligned with the Interpretation Act); "office hours" (default hours for the Information Regulator’s offices); "relevant bodies" (for the purposes of industry/profession codes of conduct applications); and "writing" (expanded to include electronic documentation consistent with the Electronic Communications and Transactions Act). These definitional updates standardize timing rules, modes of submission and the actors able to initiate regulatory processes.

Governance and Institutional Framework

The amended Regulations reaffirm the central role of the Information Regulator as the enforcement and oversight body under POPIA. They direct that the final consolidated Regulations are published and made available for implementation and operational use by stakeholders and the public. The instrument removes a specific requirement in the Regulations that information officers compile and keep PAIA manuals (while noting the PAIA obligation continues to exist under PAIA itself) and simultaneously strengthens the compliance framework duty: responsible parties must develop, implement and continuously improve POPIA compliance frameworks in line with operational developments. The amendment also creates a procedural pathway for industry or profession bodies ("relevant bodies") to develop or apply for codes of conduct, subject to the Regulator’s approval and oversight. For source documents and the official notice, see the Government Gazette entry (GG 52523 GoN 6126) and the Regulator’s published text (Information Regulator: POPIA Regulations (final)).

Key Focus Areas

The amendments concentrate on practical, compliance-oriented reforms. First, there is an express focus on accessibility of data-subject rights: multi-channel submission and response options (including communication by SMS, WhatsApp and telephonic requests) are explicitly permitted. Telephonic requests must be recorded electronically, and the recording or a transcription must be made available to the data subject upon request, strengthening evidentiary records and transparency. Second, consent, particularly for direct marketing to non-customers, is clarified: consent must be obtained in an expedient, free and reasonably accessible manner and must involve a positive action; telephone or automated consents must be recorded and producible. Third, complaint processes are enhanced — standing to lodge complaints is broadened (to persons with sufficient personal interest and persons acting in the public interest), forms and submission channels are standardized, assistance must be provided for reducing complaints to writing or when complaints are made in languages other than English, and requests for complainant anonymity must be considered by the Regulator. Fourth, the compliance framework obligation has been enlarged, with an express requirement for continuous improvement and demonstrable documentation, aligning institutional governance expectations with evolving operational and legal risks. Finally, enforcement mechanics were addressed — for example administrative fines and the possibility of installment payment arrangements.

Implementation Framework

Responsible parties and information officers must take immediate steps to align internal processes with the amended Regulations. Key implementation actions include: update complaint handling procedures; enable multi-channel request intake (including secure telephonic recording and transcription capability); revise consent-gathering workflows for direct marketing to ensure recorded positive opt-in where required; document and evidence continuous improvement of POPIA compliance frameworks; prepare forms and templates that reflect the amended Regulations; and update staff training and public-facing privacy notices to reflect new multi-channel rights and timeframes (for example, responding to correction/deletion requests within existing statutory or prescribed periods). The Regulator also invites relevant industry bodies to pursue codes of conduct (subject to approval) and will oversee such processes. Implementation resources and the final consolidated Regulations are available from the Information Regulator site: Regulator - Final Regulations (PDF).

Monitoring and Evaluation

Monitoring mechanisms remain under the Information Regulator’s authority. The amended Regulations reinforce the Regulator’s capacity to receive complaints, investigate matters, and apply enforcement measures. Responsible parties should document compliance steps and maintain records (including recordings/transcriptions of telephonic consents or requests) to provide evidence in the event of inquiries. The expanded complaint framework and improved avenues for submission are also intended to increase regulatory visibility into non-compliance patterns, enabling targeted supervisory and outreach activity by the Regulator. The transitional provisions allow prior-compliant actions to be treated as compliant under the amended Regulations to facilitate continuity during the shift to the revised requirements.

Penalties, Liability, and Appeals

The amendment preserves the Information Regulator’s enforcement toolkit under POPIA (investigations, administrative fines and other corrective measures). It clarifies administrative practice for fines by allowing an entity that cannot pay a fine in a lump sum to engage the Regulator for instalment arrangements. Liability under the Act (including civil claims and other remedies) remains governed by POPIA and related law; appeals and review mechanisms will continue to operate through the administrative and judicial processes described in POPIA and the Regulations. Responsible parties should be mindful that failure to comply with obligations (for example, in relation to access, consent recording or complaint handling) can be material in an enforcement action.

Relationship to Other Instruments

The amended Regulations operate under and to give effect to the Protection of Personal Information Act, 2013. They align certain definitions and procedural elements with the Interpretation Act and the Electronic Communications and Transactions Act (for example in relation to "writing" and electronic signatures/data messages). The amendment also cross-references the Promotion of Access to Information Act (PAIA): although the Regulations remove an internal obligations cross-reference requiring an information officer to maintain a PAIA manual, the PAIA obligations on public bodies remain intact under PAIA. Transitional provisions confirm that acts taken under the prior Regulations (GoN 1383 of 2018) are to be regarded as done under the amended Regulations where applicable, reducing legal uncertainty and administrative duplication.

International Alignment

While the amendment is domestic in scope, several changes improve alignment with international good practice for data protection and rights of access. For example the multi-channel access and clear recorded-consent requirements echo modern requirements for verifiable consent and practical access mechanisms in other data protection frameworks. The focus on continuous improvement of compliance frameworks aligns with international regulatory expectations (demonstrable privacy governance, documentation and accountability). The Information Regulator also continues to consider cross-border transfer rules and other POPIA provisions when providing guidance and decisions, maintaining South Africa’s legal interoperability with international privacy regimes.

Implementation Timeline

EventDate
Signatory date (Information Regulator CEO signed)2025-04-10
Publication in Government Gazette (GG 52523)2025-04-17
Effective date (immediate on publication)2025-04-17
Recommended immediate steps by responsible parties (update policies/forms/training)Within 30–90 days of publication

Sources and References

SourceType
Protection of Personal Information Act: Regulations: Amendment (GG 52523, GoN 6126, 17 April 2025)Primary Source
Information Regulator - POPIA Regulations (Final consolidated text)Primary Source
Regulations relating to the Protection of Personal Information, 2018 — LawLibrary (amended version dated 17 April 2025)Secondary/Consolidated

Requirements for a company

What an organisation has to do under South Africa - Personal Information Protection (GN 6126/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

5
  • Develop, implement, and continuously improve a POPIA compliance framework that aligns with evolving operational developments.Responsible parties processing personal information
  • Record and maintain all telephone and automated direct marketing consents so they can be produced upon request.Responsible parties conducting direct marketing
  • Record all telephonic data subject requests electronically and provide the recording or transcription upon request.Responsible parties receiving telephonic data subject requests
  • Obtain direct marketing consent through an explicit positive action in an expedient, free, and accessible manner.Responsible parties sending direct marketing communications
  • Document compliance actions and maintain recordings or transcriptions of requests and consents to present during regulatory inquiries.Responsible parties subject to POPIA oversight

Must not do

1
  • Do not send direct marketing communications to non-customers without securing and recording positive opt-in consent.Responsible parties sending direct marketing communications

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under South Africa - Personal Information Protection (GN 6126/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Responsible parties processing personal informationDevelop, implement, and continuously improve a POPIA compliance framework that aligns with evolving operational developments.
responsible parties must develop, implement and continuously improve POPIA compliance frameworks in line with operational developments.
Apr 17, 2025Critical
2Responsible parties conducting direct marketingRecord and maintain all telephone and automated direct marketing consents so they can be produced upon request.
telephone or automated consents must be recorded and producible.
Apr 17, 2025Critical
3Responsible parties receiving telephonic data subject requestsRecord all telephonic data subject requests electronically and provide the recording or transcription upon request.
Telephonic requests must be recorded electronically, and the recording or a transcription must be made available to the data subject upon request
Apr 17, 2025Critical
4Responsible parties sending direct marketing communicationsObtain direct marketing consent through an explicit positive action in an expedient, free, and accessible manner.
consent must be obtained in an expedient, free and reasonably accessible manner and must involve a positive action
Apr 17, 2025Critical
5Responsible parties sending direct marketing communicationsDo not send direct marketing communications to non-customers without securing and recording positive opt-in consent.
consent, particularly for direct marketing to non-customers, is clarified: consent must be obtained in an expedient, free and reasonably accessible manner and must involve a positive action
Apr 17, 2025Critical
6Responsible parties subject to POPIA oversightDocument compliance actions and maintain recordings or transcriptions of requests and consents to present during regulatory inquiries.
Responsible parties should document compliance steps and maintain records (including recordings/transcriptions of telephonic consents or requests) to provide evidence in the event of inquiries.
Apr 17, 2025Important

© Regulations.AI · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash