The POPIA regulations are subordinate legislation to the POPI Act that the Information Regulator in South Africa publishes. The regulations are largely administrative in nature and do not help organisations to interpret the POPI Act or make it easier for them to comply. There are no clear controls, and the duty to comply is still left to the responsible party to apply the conditions to their circumstances. The regulations contain very few compliance requirements, except for the impact that the forms might have.
On this page, you will find practical guidance on them, a timeline of posts explaining the POPI regulations and all related updates from the regulator, their history, and a summary of the most important regulations.
Commencement of the POPIA Regulations
The POPIA regulations came in two waves. The 2018 POPIA Regulations came into operation in different parts.
- Application for issuing code of conduct on 1 March 2021.
- Responsibilities of information officers on 1 May 2021.
- All other provisions took effect on 1 July 2021.
In September 2021, the Information Regulator invited comments on draft regulations to amend the POPIA Regulations, 2018. On 17 April 2025, the information regulator published these regulations (which are referred to as the POPIA Amendment Regulations 2025) in the Government Gazette (GG52523 No6126) and they take immediate effect as of 17 April 2025.
Actions you could take
- You can download the POPIA Regulations 2018 and download the POPIA Amendment Regulations 2025 and read them together.
- Meet your responsibilities as an Information Officer by joining the Michalsons data protection programme or outsource the responsibilities to Michalsons.
- Assess the impact of the regulations on your specific organisation by doing an impact assessment.
- Comply with the conditions for lawful processing in South Africa by asking Michalsons to do a personal information impact assessment (PIA) for you or by joining the Michalsons Data Protection programme and doing a PIA yourself.
- Obtain consent for direct marketing lawfully by asking us to advise you on how to obtain consent in accordance with the POPIA regulations.
- Be alerted to future developments regards data protection compliance by subscribing to our newsletter.
- Keep abreast of any updates to the POPIA regulations by visiting this page.
- Comply with data protection laws by finding out how to get expert assistance.
What do the POPIA regulations deal with?
- Definitions of words in the POPIA regulations
- How a data subject can object to the processing of their personal information. (Important!)
- How a data subject can request the correction or deletion of information.
- The responsibilities of an information officer. (Important!)
- How to apply for the regulator to issue a code of conduct.
- How to request marketing consent. (Important!)
- How to submit a complaint to the regulator.
- How the regulator will act as a conciliator in investigations.
- What the regulator must do before it investigates you.
- How the regulator will try to settle complaints.
- How the regulator will conduct assessments.
- How the regulator will notify people during investigations.
- Administrative fines
To save you time, we summarise the ones we think are important.
Objection to the processing of personal information
Regulation 2 relates to objection of processing personal information. A data subject may object at any time during a responsible party’s office hours, free of charge. The objection must be lodged on a form “substantially similar” to Form 1, and the responsible party must make this form easily accessible – whether by hand, post, e-mail, SMS, or any other convenient channel. Responsible parties must also alert data subjects of their right to object when collecting personal information. If an objection is made over the phone, the responsible party must record it electronically, and ensure that the recording (or transcription) is made available to the data subject on his or her request.
Requests for correction or deletion of personal information
A data subject has the right to request that a responsible party correct, destroy, or delete their personal information, free of charge, at any time. Regulation 3 follows the same channel of communication as Regulation 2 above. The request must be made on a form “substantially similar” to Form 2. Once a correction or deletion request is received, the responsible party has 30 days to inform the data subject of the action taken.
The responsibilities of information officers
Regulation 4 of the POPIA regulations is interesting because the duties or responsibilities of an information officer have been trimmed. The information officer has a duty to continually improve its organisation’s compliance framework. The responsibility to develop and maintain a PAIA manual and provide copies thereof upon request has been removed. This does not mean that an organisation is no longer required to have a PAIA manual, but rather, this responsibility now falls under the provisions of PAIA.
Request for data subject’s consent to direct market
Regulation 6 and Form 4
The POPIA regulations have an impact on direct marketing consents. Regulation 6 says “A responsible party who wishes to process personal information of a data subject for the purpose of direct marketing through unsolicited electronic communication must in terms of section 69(2) of the Act must obtain written consent to that data subject on a form substantially similar to Form 4 or in any manner that may be expedient, free of charge and reasonably accessible to a data subject.” Terms in bold are defined in the POPIA Regulations or in the ECT Act. Form 4 sets out how to get consent to direct market to a data subject. Essentially, you must:
- identify the data subject,
- identify the responsible party and provide their contact details,
- identify the person designated to sign for the responsible party,
- enable the data subject to consent to receive direct marketing for specified goods or services by specified methods of electronic communication, and
- get both the person designated by the responsible party and the data subject to sign.
Regulation 6 also broadens how you may obtain consent and clarifies that an “opt-out” checkbox on its own is insufficient. Any data message that captures intent and is “accessible for subsequent reference” will qualify as “written” and “signed”, for example, a click-wrap, a recorded “yes” on a call, or a WhatsApp reply will suffice. Consent provided via a telephone call or an automated calling machine, must be recorded (and transcribed) and be made available to the data subject upon their request.
Many people (especially direct marketers) will read Regulation 6 and Form 4 with concern, especially the requirements that the consent must be written and signed by both a person designated by the responsible party and the data subject. But when you unpack the regulation, it is not as prescriptive as you might fear.
Relevant definitions
The regulation is hard to unpack because it contains many definitions which themselves contain definitions. For example:
- “Complainant” means any person who lodges a complaint with the information regulator.
- “Complaint” means:
- a matter reported to the information regulator in terms of Section 74 of the Act;
- complaints referred to the information regulator or referred to the enforcement committee; and
- a matter reported or referred to the information regulator in terms of other legislation that regulates the mandate of the regulator.
- “Submit” means submit by data message, electronic communication, registered post, electronic mail, facsimile, and personal delivery.
- “Written” means any form of writing, including in the form of a data message that is accessible in a manner usable for subsequent reference.
- “Form” includes “any form which is substantially similar to” Form 4.
- A “data message” means “data generated, sent, received, or stored by electronic means and includes:
- voice, where the voice is used in an automated transaction; and
- a stored record.”
- “Day” means a calendar day, unless the last day of a specified period happens to fall on a Sunday or a public holiday.
- “Office hours” means:
- in respect of offices of the information regulator, means the hours between 08:00 and 16:00 on Monday to Friday (excluding public holidays); and
- in respect of offices designated by the information regulator, means the hours during which the offices are operating.
- “Sign” or “signature” includes an electronic signature which means “data attached to, incorporated in, or logically associated with other data and which is intended by the user to serve as a signature”.
- “Relevant body(ies)” refers to “any specific body or class of bodies, any specified industry, profession, vocation or class of industries or professions, or professions that in the opinion of the regulator have sufficient representation”.
Submitting complaints with the information regulator
Regulation 7 sets out an expanded, user-friendly framework for submitting complaints with the regulator. Complaints may be brought not only by a data subject whose personal information has been interfered with, but also by representatives acting on their behalf, anyone with sufficient personal interest, aggrieved responsible parties, data subjects contesting an adjudicator’s decision, or individuals acting in the public interest. Every complaint must be reduced to writing, either by completing the online Form 5 or using a paper Form 5 obtained from the regulator’s office.
The regulator will acknowledge receipt of the complaint and provide a reference number to the complainant within 14 days. A valid complaint must include the complainant’s and responsible party’s details and contact information and any additional contextual information. If the complaint involves whistle-blowing or the complainant seeks anonymity, the regulator will evaluate the request for non-disclosure under the Protected Disclosures Act before the complainant decides whether to proceed. Designated staff must offer whatever help is needed to keep the complaints process accessible and free of charge.
Administrative Fines
Regulation 13 is a new addition to the POPIA Regulations. Responsible parties that have been served with an infringement notice and are unable to pay the administrative fine in a lump sum may make arrangements with the regulator to pay the fine in instalments. The regulator will handle these requests on a case-by-case basis and will consider the financial circumstances of the responsible party and any other relevant compelling reasons that may affect the responsible party’s affordability.
Forms streamlined
Lastly, Forms 17 to 19, which deal with appeals lodged against enforcement notices in terms of section 97 and 98 of POPIA, have been deleted. Responsible parties must ensure that they update links related to these Forms as well as replace the legacy Forms 1 to 5 with the updated Forms found in the 2021 POPI Regulations.
The practical impact of the POPIA Regulations
Consent and direct marketing
At the outset, it is important to remember that consent is only necessary for direct marketing by electronic communications – if you direct market by physical communication, you do not need consent. For example, you do not need someone’s consent to phone them. Also, you only need consent from prospects, you do not need consent from your customers. If you are going to direct electronic market to someone you don’t know, you must get their consent in the form prescribed by these regulations. Don’t fall into the trap of thinking you have to get this written signed consent from everyone.
Written consent requirements
The written requirement means that the consent must be made up of data that can be referred to after the consent is given. In other words, there must be some form of record of the consent. Data is very broad and includes voice. So, if a data subject consents on a call, that is written consent. We can’t think of a way that the regulation stops you from requesting consent.
You can submit a request for consent in any way you choose. You can send customers an SMS, email them, talk to them, ask on a website, ask on an app, and ask over the phone. We can’t think of a way that the regulation stops you from requesting consent. Can you?
Both parties must sign the consent, but you can use any kind of signature. All that is required is that some data (which the person signing intends to serve as a signature) must be associated with the data which makes up the consent. For example, a signature could be data recording that a data subject clicked on a button, or ticked a box, or agreed to terms, or even says “I agree” over the phone.
The form of the request does not need to be in the form of Form 4!
The word “form” has two meanings.
Form means “a particular way in which a thing exists or appears” or it means a Form that you fill in. You’ll be fine as long as the request contains the essence of what is in Form 4 (See the five things we set out above). The request (or consent) must just be substantially similar to Form 4. One could argue that this means that the consent does not need to be on an actual Form. It can basically take any form, like a pop-up notice on a website, or an SMS or an email.
The bottom line
You can get consent however you like and the POPIA Regulations do not prescribe any particular method. There might be some practical challenges, but most will be overcome. This is good news for anyone who must get consents from data subjects to direct electronic market to them.
Minster’s POPIA Regulations
There are two people who have the power to make regulations. The regulator is one – the other is the Minister of Justice and Constitutional Development who has the limited power to make POPIA Regulations (under section 112(1)) about:
- establishing the Information Regulator, and
- fees that data subjects must pay to:
- a responsible party for accessing the personal information it processes, and
- the Regulator when complaining to the Regulator.
That is it – the Minister has quite limited powers to make regulations.
The history and timeline of the POPIA regulations
Below, you will find a timeline of posts explaining the POPIA regulations and all related updates from the regulator. It is useful to see the history of how the regulations evolved over time. We are continuing to monitor developments.

