South Africa - Personal Information Protection (R1383/2018)

Regulations relating to the Protection of Personal Information, 2018 (Government Notice R1383 of 2018)

South Africa

RAI-ZA-NA-RRPPIXX-2018
Effective: March 1, 2021
In Force (Amended)(In Force (Amended))
RegulationData Protection and PrivacyGovernance and Oversight
Export PDF

The Regulations relating to the Protection of Personal Information, 2018 (GoN R1383) were made by the Information Regulator under POPIA to prescribe forms, procedural rules, and minimum administrative requirements to operationalise data subject rights, complaints and enforcement processes under the Protection of Personal Information Act (POPIA). They set out duties for information officers, standardized forms for objections, corrections, codes of conduct, complaints, assessments and enforcement notices, and specify procedural timelines and remediation steps.

Summary

The Regulations relating to the Protection of Personal Information, 2018 (Government Notice R1383 of 2018) were promulgated by the Information Regulator under section 112(2) of the Protection of Personal Information Act, 2013 (POPIA). Published in Government Gazette No. 42110 on 14 December 2018, the Regulations provide mandatory procedural and administrative detail to support the implementation and enforcement of POPIA. They supply prescribed forms (Forms 1–19) for interactions between data subjects, responsible parties and the Regulator — including forms for objections to processing, requests for correction or deletion, consent for direct marketing, complaints, notices of conciliation and settlement, assessment requests, enforcement notices and appeals. The Regulations also specify how objections and requests may be submitted (data message, electronic mail, registered post, facsimile, or personal delivery), require responsible parties to provide reasonable assistance free of charge for completion of forms, and require responsible parties to notify data subjects of their objection rights at the point of collection.

Crucially, the Regulations expand the obligations of Information Officers by requiring them to develop, implement and continuously improve a compliance framework, to conduct personal information impact assessments (PIAs), to maintain and make available PAIA manuals as required by the Promotion of Access to Information Act, and to build internal procedures to process information requests. The Regulations set out the Regulator’s procedural approach to complaints and investigations, including pre-investigation notification, conciliation and settlement processes (with prescribed notices/forms), assessment procedures, and obligations to keep parties informed. They also prescribe how the Regulator must notify parties about enforcement and appeal developments using standardized forms.

The Regulations were implemented in stages: parts of them were commenced by General Notice 75 of 2021 (with effective dates in March, May and July 2021), and other provisions were commenced or amended in later notices (including amendments and subsequent commencement notices in 2025). The Regulations operate together with POPIA (which provides substantive offences, administrative fines and criminal sanctions) and with related instruments such as Codes of Conduct issued under section 61, guidance published by the Information Regulator, and PAIA obligations. The Regulations are a practical compliance toolkit for responsible parties and operators processing personal information in South Africa; they strengthen accountability, standardise access and remediation processes, and provide the Information Regulator with the procedural machinery required to investigate, assess and enforce compliance under POPIA.

Full article

Read full text ↗

Overview

The Regulations relating to the Protection of Personal Information, 2018 (GoN R1383) were promulgated by the Information Regulator pursuant to section 112(2) of the Protection of Personal Information Act, 2013 (POPIA). Published in Government Gazette No. 42110 on 14 December 2018, the Regulations operationalise many procedural elements of POPIA by prescribing mandatory forms, submission methods and internal administrative duties for responsible parties and information officers. The authoritative consolidated text of the Regulations (including annexed Forms 1–19) is available from the Information Regulator’s published Gazette PDF and related governmental listings, for example Regulations PDF (GG 42110) and governmental notices on gov.za. The Regulations set out clear workflows for objections to processing, rectification and deletion requests, complaint lodging and handling, assessment requests and enforcement procedures. They therefore form an essential part of the compliance architecture for organisations processing personal information in South Africa.

Definitions

The Regulations adopt definitions from POPIA and related statutes. Key defined terms include: "data message" (as in the Electronic Communications and Transactions Act), "form(s)" (the annexed prescribed forms or substantially similar forms), "signature" (including electronic signatures), "submit" (a set of accepted submission channels including data messages, registered post and personal delivery), "day" (calendar day with interpretation rules for holidays), and references to "the Act" meaning POPIA. The Regulations also clarify practical terms such as "office hours" for the Regulator and designated offices, and define "Relevant body/bodies" when referring to representative entities applying for codes of conduct. These definitions ensure alignment across POPIA, the Regulations and related instruments to avoid ambiguity in procedure or timing.

Governance and Institutional Framework

The Regulations assign procedural responsibilities mainly to two institutional actors: the Information Regulator (the independent supervisory authority under POPIA) and Information Officers within responsible parties. The Regulator is empowered to receive complaints, conduct investigations, act as conciliator or convene settlement meetings, perform assessments and issue enforcement notices — all via prescribed forms and timelines. The Regulations require the Regulator to acknowledge receipt of complaints, provide reference numbers and keep complainants and affected parties informed throughout investigative and enforcement actions. The duties of Information Officers are significantly expanded; they must implement, monitor and maintain a compliance framework, conduct personal information impact assessments (PIAs), develop internal measures and systems to process information requests and maintain PAIA manuals as required by the Promotion of Access to Information Act. The Regulations also provide for representative bodies and industry codes of conduct, with an application process to the Regulator (Form 3), facilitating sectoral self-regulation while preserving oversight by the Regulator. See the full regulatory text at Regulations PDF (GG 42110) and the Regulator’s guidance pages on inforegulator.org.za for notices and implementation updates.

Key Focus Areas

The Regulations focus on a set of operational priorities to make POPIA enforceable: (1) Standardised data subject interactions — mandatory forms for objections (Form 1), corrections/deletions (Form 2), direct-marketing consent (Form 4), and formal complaints (Form 5) ensure consistent records and easier dispute resolution. (2) Complaint handling and dispute resolution — the Regulator’s role as conciliator and the use of Forms 6–10 for conciliation and settlement formalise alternative dispute resolution steps prior to formal enforcement. (3) Investigations and assessments — Forms 8, 11 and 12 govern pre-investigation notices and assessment requests and outcomes, bringing transparency and procedural fairness to regulator-led assessments. (4) Enforcement and appeals — the Regulations prescribe the content and service of enforcement-related notices (Forms 13–19), establishing a predictable pathway from investigation to enforcement and appeal. (5) Institutional accountability — obligations on Information Officers to establish compliance frameworks, perform PIAs and make PAIA manuals available strengthen internal governance. Collectively, these measures emphasise documentation, evidence, and process integrity, supporting both enforcement by the Regulator and defensibility by responsible parties.

Implementation Framework

Implementation is staged and coordinated between the Regulator and responsible parties. The Regulations were published in December 2018 but many provisions required commencement notices; General Notice 75 of 2021 and related commencements put several sections into effect on dates in 2021 (1 March, 1 May and 1 July 2021), with further commencement and amendment activity recorded in subsequent Government Gazettes and Regulator notices (e.g., notices and amendments published on the Regulator’s site and gov.za). Responsible parties must adopt the prescribed forms (or substantially similar equivalents), integrate submission channels (email, data messages, mail and in-person delivery), and ensure that Information Officers and deputies are registered and trained to implement compliance frameworks and PIAs. Organisations should also align their PAIA manuals with the requirements referenced in the Regulations and make these available as required by law. Practical implementation resources and the authoritative Gazetted text are available from the Regulator’s PDF archive: Regulations PDF (GG 42110).

Monitoring and Evaluation

The Regulations require process transparency and periodic communication from the Regulator during investigations and enforcement activities. The Regulator must: acknowledge and reference complaints, inform participants of conciliation/settlement meetings and outcomes, notify parties about decisions to conduct assessments, and provide updates on enforcement notices and appeals using prescribed forms. These procedural requirements enable tracking of case progress and encourage record-based monitoring. Additionally, the Information Officer’s duty to maintain and continuously improve a compliance framework and to conduct PIAs provides internal monitoring mechanisms within organisations. The Regulator’s eServices and public notices (hosted on inforegulator.org.za) also facilitate oversight, public reporting and evaluation of how the Regulations are being applied in practice.

Penalties, Liability, and Appeals

While the Regulations mainly prescribe procedures and forms, enforcement and sanctions are governed principally by POPIA itself. POPIA provides for administrative fines (issued via infringement notices) and criminal penalties for certain offences. Administrative fines may be imposed by the Regulator (section 109 of POPIA) and are subject to a statutory cap (commonly cited in guidance and legal commentary as up to R10,000,000 per incident). Criminal penalties and imprisonment apply to specified offences under POPIA (sections 100–107), with more serious offences carrying the possibility of sentencing up to 10 years in certain cases. The Regulations implement procedural steps for issuing enforcement notices (Forms 13–19), and they ensure that parties receive notice and that appeals processes are recorded. For authoritative text on sanctions and enforcement consult POPIA and the Regulations PDF; see POPIA chapters on offences, fines and enforcement and the Regulations’ enforcement forms in the Annex: Regulations PDF (GG 42110).

Relationship to Other Instruments

The Regulations operate alongside POPIA and intersect with other South African laws and instruments, notably the Promotion of Access to Information Act (PAIA) — the Regulations explicitly require Information Officers to develop and make available PAIA manuals where applicable. The Regulations also support the issuance and operation of Codes of Conduct under section 61 of POPIA (application on Form 3). They complement other sector-specific codes and rules (for example banking or credit bureau codes) and work in tandem with commencement notices and amendment Gazettes published on gov.za and the Regulator’s site. Where sectoral or international instruments apply (such as obligations under financial-sector regulation or cross-border data transfer guidance), organisations must ensure compliance with both the Regulations and the applicable external requirements.

International Alignment

The Regulations reflect internationally-recognised data-protection practices — documenting data subject rights, mandating impact assessments, requiring documented consent for direct marketing, and prescribing breach/complaint/enforcement procedures. These features enhance comparability with instruments such as the EU GDPR in terms of rights, documentation and PIAs, while retaining South Africa-specific processes (Gazetted forms, Regulator-led conciliation and prescribed submission channels). The Regulations and POPIA together make South Africa’s framework more interoperable with international standards, assisting cross-border data flow assessments and corporate compliance programs that must meet both domestic and international expectations. See the Regulator’s guidance and international comparative commentary on the Regulator site: inforegulator.org.za.

Implementation Timeline

EventDate
Publication in Government Gazette (GG 42110)2018-12-14
Commencement: Section 52021-03-01
Commencement: Section 42021-05-01
Commencement: Sections 1–3 & 6–132021-07-01
Amendment / Further commencement of selected provisions2025-04-17

Sources and References

SourceType
Regulations relating to the Protection of Personal Information, 2018 (GG 42110) — PDFPrimary Source
South African Government Notices (gov.za)Primary Source
LawLibrary consolidated text (amendment history)Secondary/Reference

Requirements for a company

What an organisation has to do under South Africa - Personal Information Protection (R1383/2018), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

8
  • Register and train an Information Officer and any deputies.Responsible parties processing personal information.
  • Develop, implement, monitor, and maintain a personal information compliance framework.Information Officers within responsible parties.
  • Conduct personal information impact assessments (PIAs) for processing activities.Information Officers within responsible parties.
  • Comply with prescribed forms and timelines for Regulator investigations, assessments, and enforcement notices.Responsible parties subject to Regulator actions.
  • Use prescribed forms for data subject objections, corrections, deletions, and direct marketing consent.Responsible parties processing personal information.
  • Develop internal measures and systems to process information requests.Information Officers within responsible parties.
  • +2 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under South Africa - Personal Information Protection (R1383/2018), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Responsible parties processing personal information.Register and train an Information Officer and any deputies.
Information Officers and deputies are registered and trained to implement compliance frameworks.
Critical
2Information Officers within responsible parties.Develop, implement, monitor, and maintain a personal information compliance framework.
Information Officers... must implement, monitor and maintain a compliance framework
Critical
3Information Officers within responsible parties.Conduct personal information impact assessments (PIAs) for processing activities.
Information Officers... must... conduct personal information impact assessments (PIAs)
Critical
4Responsible parties subject to Regulator actions.Comply with prescribed forms and timelines for Regulator investigations, assessments, and enforcement notices.
Forms 8, 11 and 12 govern pre-investigation notices and assessment requests and outcomes.
Critical
5Responsible parties processing personal information.Use prescribed forms for data subject objections, corrections, deletions, and direct marketing consent.
mandatory forms for objections (Form 1), corrections/deletions (Form 2), direct-marketing consent (Form 4)
Important
6Information Officers within responsible parties.Develop internal measures and systems to process information requests.
Information Officers... must... develop internal measures and systems to process information requests
Important
7Responsible parties processing personal information.Handle formal complaints using the prescribed Form 5 and follow dispute resolution steps.
formal complaints (Form 5) ensure consistent records and easier dispute resolution.
Important
8Responsible parties processing personal information.Publish and maintain a PAIA manual as required by law.
Organisations should also align their PAIA manuals with the requirements referenced in the Regulations.
Important

© Regulations.AI · updated on 13-Jun-2026