Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

South Africa · POPIA

Processing documentation & security compromises.

Applies to: Responsible parties under POPIA. Built · enforced since 1 Jul 2021

What the signed record shows

Documentation of processing, security signals, and security-compromise detail for Regulator notification.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: POPIA (Act 4 of 2013) s.17/19/21/22

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Protection of Personal Information Act 4 of 2013 (POPIA). Provisions addressed:

s. 17
Documentation: maintain documentation of all processing operations (as referred to in s. 14 or s. 15 of PAIA).
s. 19
Security measures on integrity and confidentiality of personal information (appropriate, reasonable technical/organisational measures).
s. 21
Information processed by an operator (written contract; operator must notify the responsible party of unauthorised access/acquisition).
s. 22
Notification of security compromises to the Information Regulator and the affected data subject as soon as reasonably possible. Condition 7 (Security Safeguards) and Condition 1 (Accountability). Enforcement from 1 July 2021.

Taken from the Regulayer entry for this instrument, which is built against the primary text.