Skip to the content
Global Data RulesData governance rules, country by country

South Africa

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: MediumEnforcement: Active

Personal data may leave South Africa, but only if you can point to a reason the law allows — usually a contract with the receiving company that gives people the same level of protection they had at home. There is no government list of approved or banned countries, and no form to file. The privacy regulator is real, staffed and issuing orders, though its fines are small by world standards.

Data governance in South Africa

The eight things that decide how you handle data about people in South Africa. Same eight on every country page, so you can compare.

Who has to follow these rules

It can reach you without an office in South Africa, but not automatically. The law covers you if your organisation is based in South Africa, or if it is based elsewhere but uses equipment or people inside South Africa to handle the data. Simply having South African customers, with everything processed abroad, is arguably outside the law — which is a narrower reach than Europe's. There is no size or revenue threshold, and no requirement to appoint a local representative.

High confidenceNational rulesControllerRegister or notify

Where the data is allowed to live

Yes, with paperwork. The general rule is that you may send personal data abroad if the receiver is bound by a law, a group-wide policy or a contract that protects it about as well as South African law does. There is no list of approved countries and no permission slip to collect. But several industries and one rule that applies to every company override this, and in those areas data either stays in the country or needs a regulator's blessing first.

High confidenceYes, with paperworkNo restrictionOfficial 'this country is safe' decisionApproved group rulesExplicit consentNeeded for a contract

Sending data out of the country

You need a legal reason before the data goes, and you decide for yourself whether you have one. The usual route is a contract with the receiving company that carries the same protections forward, including to anyone they pass it on to. Group-wide internal rules, the person's own consent, or the transfer being necessary for their contract also work. Nobody approves it, nothing is filed, and no country is banned — but sensitive data and children's data are the exception and do need approval.

High confidenceNo restrictionOfficial 'this country is safe' decisionApproved group rulesExplicit consentNeeded for a contractGovernment sign-off needed

The regulator, and whether it actually acts

The Information Regulator, and it is genuinely working. It has a chairperson and two other members, with two seats vacant, and it issued enforcement orders against a college, a mining company and a provincial health department in May and June 2026 alone. In April 2026 it went to the High Court and got a fine against a municipality confirmed — though the judge cut it from about 28,000 US dollars to about 14,000. Banking, insurance and tax regulators enforce their own rules separately and are far better resourced.

High confidenceActiveRegulator

How long you must keep it — and when to delete it

Both directions apply and they pull against each other. The privacy law says delete personal data once you no longer need it. Other laws say keep it: five years for tax records, five years for money-laundering checks, five years for cross-border payment records at banks, and between three and five years for phone and internet connection records. Where they clash, the keeping rule wins, because the privacy law allows you to hold data longer when another law requires it.

High confidenceDelete data after a periodKeep data for a minimum periodKeep logs

If something goes wrong

There is only one clock that actually runs, and it has no number on it. If personal data is accessed by someone who should not have it, you must tell the regulator and the affected people 'as soon as reasonably possible' — no fixed hours. A separate 72-hour reporting duty to the police is printed in the cybercrime law but has never been switched on, so it does not apply. Financial firms have a third duty to report serious technology and cyber incidents to their regulators.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things catch people out. First, the regulator cannot fine you for the breach itself — it must order you to fix it, and only ignoring that order becomes a crime that carries a fine of up to 10 million rand, roughly half a million US dollars. Second, sending sensitive or children's data to a weakly protected country needs approval before you start, and you must wait. Third, letting people opt out is not consent for marketing emails or texts. Fourth, plugging a computer holding patient records into another system without permission is a criminal offence. Fifth, your accounting system in a foreign cloud probably needs the tax authority's written permission.

High confidenceCriminal liabilityFixed maximum fineGet a parent's consent for childrenGet consentKeep the data in the country

What's changing next

Four things are in the pipeline and none of them is law yet. The banking and insurance regulators say they are writing a binding standard on cloud use and sending data offshore. The central bank has proposed that payment clearing and settlement data stay inside South Africa. The privacy regulator has draft rules for health and sex-life data, and a binding code for security gates and cameras at estates and office parks. Separately, a 72-hour police reporting duty already sits in law and can be switched on overnight.

High confidenceProposedGovernment policy documentStatutory code of practice

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Currency and Exchanges Manual for Authorised Dealers, section J(D) — Offshoring and cloud computing

Regulator directive · Issued under the Exchange Control Regulations, 1961; current edition 2026

In forceYes, with paperwork

Banks and licensed foreign-exchange dealers must apply to the central bank's Financial Surveillance Department, case by case, before moving cross-border transaction data, customer records or systems offshore or into the cloud. Storage in sanctioned countries, or anywhere that would block the regulator's access to the data, is refused outright.

In force since 1 January 2022

Enforced by Financial Surveillance Department, South African Reserve Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Banking

Directive 3 of 2018 and Guidance Note 5 of 2018 — Cloud computing and the offshoring of data

Regulator directive · D3/2018 and G5/2018, Prudential Authority

In forceYes, with paperwork

Banks, controlling companies and branches of foreign banks may use cloud services and send data offshore, provided they meet the Prudential Authority's requirements and their board takes ultimate responsibility for the risk. This is a permission with conditions, not a location rule.

In force since 17 September 2018

Enforced by Prudential Authority

Transfer model: No restriction

Medium confidence
Insurance

Joint Standard 1 of 2024 — Outsourcing by Insurers

Government rules · Joint Standard 1 of 2024, issued under the Financial Sector Regulation Act 9 of 2017

In forceYes — store it anywhere

Insurers face no data-location rule, but any material outsourcing — which includes moving policyholder data to a cloud provider — must be notified to the regulators at least 30 days in advance, and the contract must give both the insurer and the regulators access rights. Arrangements signed before 1 December 2024 have until 1 December 2026, or their next renewal, to comply.

In force since 1 December 2024But only enforceable from 1 December 2026

Enforced by Financial Sector Conduct Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Protection of Personal Information Act, 2013

Act of parliament · Act No. 4 of 2013

In forceYes, with paperwork

South Africa's general privacy law. Data may go abroad if the recipient is covered by a law, group-wide rules or a contract giving substantially similar protection, or on narrow grounds such as consent. There is no list of approved countries and no filing step, but sensitive and children's data going to a weakly protected country needs the Regulator's prior approval. Fines are capped at 10 million rand and generally require a court to confirm them.

In force since 1 July 2020But only enforceable from 1 July 2021

Enforced by Information Regulator (South Africa)

Transfer model: No restriction · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Government sign-off needed

High confidence

Tax Administration Act, 2011 section 30 read with Public Notice 787 of 1 October 2012 (electronic form of record-keeping)

Government rules · Act No. 28 of 2011, s 30; GG 35733 Notice 787

In forceYes, with paperwork

Every business keeping tax records electronically must keep them inside South Africa unless the revenue service gives written permission to keep them abroad. This applies to all industries and is the single most commonly missed data-location rule in the country, because it catches ordinary foreign-hosted accounting and enterprise software.

In force since 1 October 2012

Enforced by South African Revenue Service

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact wording and current text of Public Notice 787 of 2012 on electronic record-keeping

    The revenue service serves the notice as a scanned image with no text layer, so we rely on the revenue service's own plain-language record-keeping page, which states the authorisation requirement clearly. The rule is therefore rated medium confidence.

  • The detailed content of Prudential Authority Directive 3 of 2018 and Guidance Note 5 of 2018 on cloud computing and offshoring

    Both are scanned documents with no extractable text. What we assert comes from the central bank's own March 2025 consultation paper and Joint Communication 2 of 2025, which describe them. Rated medium confidence.

  • The incident notification deadline in Joint Standard 2 of 2024 on cybersecurity and cyber resilience

    We confirmed from an official joint communication that the standard took effect on 1 June 2025, but could not open the standard's own text on either regulator's site, and the notification template was still in consultation in September 2025.

  • Whether any Minister has ever declared classes of 'critical data' or registered critical databases under Chapter 9 of the Electronic Communications and Transactions Act

    No such notice was found on government sources, checked 18 August 2026. We cannot prove a negative; the power itself is verified from the Act.

  • Whether the Regulation of Interception of Communications Amendment Bill of 2023 has been enacted, and the current ministerial directive setting the telecoms retention period

    Only bill versions appear in the government's document library; no amendment act and no published directive were located. The three-to-five-year statutory band is verified from the Act itself.

  • Data-location or server-location conditions in provincial gambling licences, and any rule for mapping or geospatial data

    Gambling is licensed province by province and licence conditions are not published centrally; no official source was located. No rule found, checked 18 August 2026, low confidence.

  • Health record retention periods

    The National Health Act sets protection and criminal offences but no retention period; the commonly cited six-year period comes from professional council guidance we could not open on an official domain. The draft regulations on health and sex-life data were still not final on 18 August 2026.

  • Whether section 54 of the Cybercrimes Act has been brought into force by any proclamation after 30 November 2021

    The government document library shows only the 2021 commencement proclamation, which excludes section 54. A later proclamation could exist and not be indexed.

60-day cadence. Two binding financial-sector instruments on cloud and offshoring are in the pipeline, either of which would change the sector ratings, and three dormant switches (the uncommenced 72-hour reporting duty, the critical-database powers, and the telecoms retention directive) can each be flipped by proclamation or gazette notice without consultation.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

South Africa versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.