South Africa
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in South Africa — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of South Africa, but you need a reason the law allows. The usual one is a contract with the receiving company that gives people the same level of protection they had at home. There is no government list of approved or banned countries. There is no form to file. The privacy regulator is real, staffed and issuing orders. Its fines are small by world standards.
Data governance in South Africa
The eight things that decide how you handle data about people in South Africa. Same eight on every country page, so you can compare.
Who has to follow these rules
It can reach you without an office in South Africa, but not automatically. The law covers you if your organisation is based in South Africa. It also covers you if you are based elsewhere but use equipment or people inside South Africa to handle the data. Simply having South African customers, with everything handled abroad, is arguably outside the law. That is a narrower reach than Europe's. There is no size or revenue threshold. You do not have to appoint a local representative.
- What you have to do here:
- Register or notify
The Protection of Personal Information Act 4 of 2013, section 3(1)(b), sets the reach. The Act applies where the organisation deciding why data is used is based in the Republic. It also applies where that organisation is not based there but 'makes use of automated or non-automated means in the Republic'. There is an exception where those means are used only to forward personal information through the Republic. The Regulator has been willing to act against very large foreign platforms. It served an enforcement notice on WhatsApp on 16 April 2025 under section 95 of the Act. Every organisation also has an 'information officer'. By default that is the head of the organisation, not a specialist. That person must be registered with the Regulator before taking up those duties (section 55(2)).
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, sections 3 and 55
gov.za
“This Act applies to the processing of personal information ... where the responsible party is (i) domiciled in the Republic; or (ii) not domiciled in the Republic, but makes use of automated or non-automated means in the Republic, unless those means are used only to forward personal information through the Republic.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Enforcement Notices — including WhatsApp, 16 April 2025
inforegulator.org.za
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. The general rule is simple. You may send personal data abroad if the receiver is bound by a law, a group-wide policy or a contract. That must protect the data about as well as South African law does. There is no list of approved countries and no permission slip to collect. But several industries override this, and so does one rule that applies to every company. In those areas data either stays in the country, or needs a regulator's blessing first.
- Ways to send data out:
- Official 'this country is safe' decision · Approved group rules · Explicit consent · Needed for a contract
Industry by industry, checked on 18 August 2026. TAX RECORDS, ALL COMPANIES. Electronic records kept outside South Africa need prior written authorisation from a senior official of the South African Revenue Service. Rated conditional. BANKS AND FOREIGN-EXCHANGE DEALERS. The central bank's Financial Surveillance Department considers offshoring and cloud use only case by case, on formal application. Moving the business processes themselves offshore, rather than the data, is refused outright. Storage in sanctioned countries is refused. So is storage anywhere that would block regulator access. Rated conditional. BANKS GENERALLY. The Prudential Authority's Directive 3 of 2018 and Guidance Note 5 of 2018 allow cloud use and offshoring, subject to its requirements. The board carries ultimate responsibility. Rated conditional. PAYMENTS. No rule today says where the data must sit. But in March 2025 the central bank proposed keeping clearing and settlement data of payment market infrastructures inside South Africa. Rated open today, closed if the proposal is issued. INSURANCE. No rule says where the data must sit. The joint insurance outsourcing standard requires 30 days' notice to the regulators before a material outsourcing, plus contractual access rights. Rated open. GOVERNMENT. Government data touching national security must be stored only on infrastructure inside South Africa, under the National Data and Cloud Policy. The State Information Technology Agency is the buying channel for government cloud. Rated closed for that category. HEALTH, TELECOM, EDUCATION, GAMBLING, MAPPING. We found no rule on official sources about where data must sit, checked 18 August 2026. Telecoms must keep call and connection records for between three and five years, but the law does not say where.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, section 72 (transfers of personal information outside the Republic)
gov.za
“A responsible party in the Republic may not transfer personal information about a data subject to a third party who is in a foreign country unless ... the third party who is the recipient of the information is subject to a law, binding corporate rules or binding agreement which provide an adequate level of protection.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServiceRecord keeping — authorisation required to keep electronic records outside South Africa
sars.gov.za
“Where the electronic records are kept at a place physically located outside of South Africa ... a senior SARS official may, subject to conditions, in accordance with section 30(2) of Tax Administration Act, authorise such location outside of South Africa, if acceptable.”
Link checked 18 August 2026
- Official sourceSouth African Reserve Bank, Financial Surveillance DepartmentCurrency and Exchanges Manual for Authorised Dealers, section J(D) — Offshoring and cloud computing
resbank.co.za
“Requests for utilising offshoring and cloud computing will only be considered, on a case-by-case basis, upon the submission of a formal application to the Financial Surveillance Department.”
Link checked 18 August 2026
- Official sourceDepartment of Communications and Digital TechnologiesNational Data and Cloud Policy, Government Gazette 50741, 31 May 2024, paragraph 15.4.2
gov.za
“Government data that incorporates content pertaining to the protection and preservation of national security and sovereignty of the Republic shall be stored only in digital infrastructure located within the borders of South Africa.”
Link checked 18 August 2026
- Official sourceSouth African Reserve Bank, National Payment System DepartmentCloud computing and data offshoring in the national payment system — consultation paper, March 2025
resbank.co.za
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves South Africa.
Sending data out of the country
You need a legal reason before the data goes, and you decide for yourself whether you have one. The usual route is a contract with the receiving company that carries the same protections forward. That includes to anyone they pass it on to. Group-wide internal rules also work. So does the person's own consent, or the transfer being necessary for their contract. Nobody approves it, nothing is filed, and no country is banned. Sensitive data and children's data are the exception, and do need approval.
- Ways to send data out:
- Official 'this country is safe' decision · Approved group rules · Explicit consent · Needed for a contract · Government sign-off needed
Section 72 of the Protection of Personal Information Act lists five grounds. An adequate law, binding corporate rules, or a binding agreement covering the recipient and onward transfers. The person's consent. Necessity for their contract. Necessity for a contract made in their interest. Or benefit to them where consent is impractical. There is no official standard contract template. There is no list of approved countries, and no registration step. So 'adequate protection' here is something you decide yourself and must be able to defend. Separately, section 57(1)(d) requires prior authorisation from the Regulator in some cases. That is before sending special personal information, or children's personal information, to a recipient in a country without adequate protection. Special personal information covers race, health, sex life, biometrics, religion, politics, trade union membership and criminal behaviour. Under section 58 you may not start until the Regulator says it will not investigate further, or finishes investigating. It has four weeks for the initial answer, and up to thirteen weeks more. That is a real case-by-case approval layer on top of an otherwise self-service system. Approvals for particular industries from the central bank and the revenue service run in parallel. Section 72 does not replace them.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, sections 57, 58 and 72
gov.za
“The responsible party must obtain prior authorisation from the Regulator ... prior to any processing if that responsible party plans to ... transfer special personal information ... or the personal information of children ... to a third party in a foreign country that does not provide an adequate level of protection.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Prior Authorisation — application form and guidance note (revised)
inforegulator.org.za
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
The Information Regulator enforces the law, and it is working. It has a chairperson and two other members, with two seats vacant. It issued enforcement orders against a college, a mining company and a provincial health department in May and June 2026 alone. In April 2026 it went to the High Court and got a fine against a municipality confirmed. The judge cut the fine from about 28,000 US dollars to about 14,000. Banking, insurance and tax regulators enforce their own rules separately, and are far better resourced.
The Information Regulator (South Africa) was set up under section 39 of the Protection of Personal Information Act. It has been operational since 2016 and took over privacy enforcement on 1 July 2021. Members as at 18 August 2026 are Adv Pansy Tlakula (Chairperson), Adv Lebogang Stroom (full-time) and Mr Mfana Gwala (part-time). One full-time and one part-time seat are shown as vacant on the Regulator's own members page. Enforcement notices published for 2026 follow. Central Johannesburg TVET College on 20 May 2026, for unlawful sharing of special personal information and failure to report a security compromise. Sibanye Stillwater on 2 June 2026, on access to information. Gauteng Department of Health on 10 June 2026. The Blouberg Local Municipality matter shows most clearly how enforcement works. It ran from complaint, to investigation, to enforcement notice, to infringement notice. Then came a court application under section 109(5) to turn the administrative fine into a court order. The Regulator imposed 500,000 rand. The Polokwane High Court reduced it to 250,000 rand in early April 2026, because only one person was affected and it was a first offence. The other enforcers are the Prudential Authority and Financial Sector Conduct Authority for financial institutions. The central bank's Financial Surveillance Department handles exchange control. The South African Revenue Service handles tax records.
Sources
- Official sourceInformation Regulator (South Africa)Members of the Information Regulator — two seats shown vacant
inforegulator.org.za
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Media statement: Information Regulator turns to the courts to fine Blouberg Local Municipality, 29 April 2026
inforegulator.org.za
“The infringement fine imposed on the Blouberg Local Municipality by the Regulator amounted to R500,000, however, the Judge who considered the section 109(5) statement was of the view that the fine was excessive in the circumstances.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Media statement: Information Regulator issues enforcement notices, 2 June 2026
inforegulator.org.za
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both directions apply, and they pull against each other. The privacy law says delete personal data once you no longer need it. Other laws say keep it. Tax records run five years. Money-laundering checks run five years. Cross-border payment records at banks run five years. Phone and internet connection records run between three and five years. Where they clash, the keeping rule wins. The privacy law lets you hold data longer when another law requires it.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period
The limit is section 14 of the Protection of Personal Information Act. You must not keep records longer than you need them for the purpose. You must destroy, delete or de-identify them as soon as reasonably practicable after that. The destruction must prevent reconstruction. Section 14(1)(a) is the way out. You may keep data where that is 'required or authorised by law'. Now the minimums. Tax records: five years from filing, and longer if a return is outstanding or an audit is running. Records under the Financial Intelligence Centre Act: five years from the end of the business relationship or the transaction. Exchange-control data at authorised dealers: five years, retrievable within 48 hours. When an offshore arrangement ends, the previous five years of data must be copied back to South Africa. Telecommunications connection records: a period fixed by ministerial directive, which may 'not be less than three years and not more than five years'. The sharpest conflict is in the public sector. Under the National Archives and Records Service of South Africa Act, no public record may be destroyed or erased without the National Archivist's written authorisation. So a government body cannot simply honour a deletion request the way a company can.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, section 14
gov.za
“records of personal information must not be retained any longer than is necessary for achieving the purpose for which the information was collected or subsequently processed, unless retention of the record is required or authorised by law.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServiceRecord keeping — five-year retention periods
sars.gov.za
Link checked 18 August 2026
- Official sourceGovernment of South AfricaRegulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002, section 30
gov.za
“the period for which such information must be stored, which period may ... not be less than three years and not more than five years from the date of the transmission of the indirect communication.”
Link checked 18 August 2026
- Official sourceGovernment of South AfricaNational Archives and Record Service of South Africa Act 43 of 1996, section 13(2)(a)
gov.za
“no public record under the control of a governmental body shall be transferred to an archives repository, destroyed, erased or otherwise disposed of without the written authorisation of the National Archivist.”
Link checked 18 August 2026
- Official sourceGovernment of South AfricaFinancial Intelligence Centre Act 38 of 2001, sections 22 to 24 (as amended)
gov.za
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Only one deadline actually runs, and it has no number on it. If someone accesses personal data who should not have it, you must tell the regulator and the affected people. The law says 'as soon as reasonably possible'. There are no fixed hours. A separate 72-hour reporting duty to the police is printed in the cybercrime law. It has never been switched on, so it does not apply. Financial firms have a third duty. They must report serious technology and cyber incidents to their regulators.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Section 22 of the Protection of Personal Information Act sets the duty. You must notify the Regulator and each identifiable affected person as soon as reasonably possible after discovery. You may allow for the needs of law enforcement, and for work to determine the scope and restore the system. You may only delay notice if the police or the Regulator say it would impede a criminal investigation. The notice must describe the likely consequences and what you are doing about it. It must say what the person should do. And it must identify the intruder if you know who it is. Since April 2025 you report breaches through the Regulator's online services portal. Section 54 of the Cybercrimes Act 19 of 2020 carries a 72-hour deadline. It would require communications providers and financial institutions to report to the police. It was expressly left out of the commencement proclamation of 30 November 2021 and is still not in force. It also depends on the Minister of Police first listing the categories of offence by notice, which we have not found. For financial institutions, Joint Standard 1 of 2023 on information technology governance took effect on 15 November 2024. Joint Standard 2 of 2024 on cybersecurity and cyber resilience took effect on 1 June 2025. The notification template for material technology and cyber incidents was still out for consultation in September 2025. So the precise deadline is not settled.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, section 22
gov.za
“The notification referred to in subsection (1) must be made as soon as reasonably possible after the discovery of the compromise.”
Link checked 18 August 2026
- Official sourcePresidency / Department of Justice and Constitutional DevelopmentProclamation R42 of 30 November 2021 — commencement of certain sections of the Cybercrimes Act, excluding section 54
gov.za
“Chapter 8, with the exclusion of section 54”
Link checked 18 August 2026
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Communication 3 of 2025 — draft notification template for material IT and cyber incidents
resbank.co.za
“Joint Standard 1 of 2023 ... Effective 15 November 2024. Joint Standard 2 of 2024 ... Effective 1 June 2025.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Guidelines on completing a security compromise notification under section 22
inforegulator.org.za
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. First, the regulator cannot fine you for the breach itself. It must order you to fix it. Only ignoring that order becomes a crime, carrying a fine of up to 10 million rand, roughly half a million US dollars. Second, sending sensitive or children's data to a weakly protected country needs approval before you start, and you must wait. Third, letting people opt out is not consent for marketing emails or texts. Fourth, plugging a computer holding patient records into another system without permission is a criminal offence. Fifth, your accounting system in a foreign cloud probably needs the tax authority's written permission.
- What you have to do here:
- Get a parent's consent for children · Get consent
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
(1) The enforcement chain runs in steps. First an investigation. Then an enforcement notice. Then an infringement notice with an administrative fine capped at 10 million rand. Then a court application to make it an order. Failing to comply with an enforcement notice is an offence carrying up to ten years' imprisonment. Courts will reduce fines they consider excessive, as in the Blouberg municipality matter in April 2026. (2) Prior authorisation under sections 57 and 58 covers more than transfers. It also covers linking unique identifiers across organisations, handling information about criminal behaviour for third parties, and credit reporting. You must stop until the Regulator responds. (3) The Regulations were amended with immediate effect on 17 April 2025. They now say plainly that opt-out is not consent for unsolicited electronic marketing. Consent requested by telephone or automated calling machine must be electronically recorded. You must give that recording to the person free of charge on request. (4) Section 17 of the National Health Act creates a criminal offence. You may not connect a computer holding patient records to another computer or terminal without authority. That is a live risk for any health system integration or cloud migration. (5) Tax records in electronic form kept outside South Africa need authorisation from a senior revenue service official. (6) A sixth applies to public bodies. They cannot delete public records without the National Archivist's written authorisation. So honouring a deletion request may itself be unlawful.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, sections 57, 58, 103, 107 and 109
gov.za
“specify the amount of the administrative fine payable, which amount may, subject to subsection (10), not exceed R10 million”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Amended Regulations relating to the Protection of Personal Information, regulation 6
inforegulator.org.za
“For the purposes of direct marketing through unsolicited electronic communications, opt-out shall not constitute consent as referred to in section 69 (2) of the Act.”
Link checked 18 August 2026
- Official sourceGovernment of South AfricaNational Health Act 61 of 2003, section 17
gov.za
“without authority, connects any part of a computer or other electronic system on which records are kept to any other computer or other electronic system ... commits an offence.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServiceRecord keeping — authorisation to keep electronic records outside South Africa
sars.gov.za
Link checked 18 August 2026
What's changing next
Four things are in the pipeline, and none of them is law yet. The banking and insurance regulators say they are writing a binding standard on cloud use and sending data offshore. The central bank has proposed that payment clearing and settlement data stay inside South Africa. The privacy regulator has draft rules for health and sex-life data. It also has a binding code for security gates and cameras at estates and office parks. Separately, a 72-hour police reporting duty already sits in law and can be switched on overnight.
Dated items. March 2025: the central bank's payments department proposed a directive under section 12 of the National Payment System Act. It would require prior approval before payment institutions use cloud or offshore data. It would also require clearing and settlement data, systems and infrastructure of payment market infrastructures to sit inside South Africa. Cross-border settlement systems would be excluded. No directive had been issued as at 18 August 2026. May 2025: Joint Communication 2 of 2025 named two bodies, the Financial Sector Conduct Authority and the Prudential Authority. They are developing a cloud computing and data offshoring Joint Standard. It is to be published for consultation. Nothing was published as at 18 August 2026. 26 September 2025: draft regulations on handling health or sex-life data. Comments closed on 10 October 2025 and they are not yet final. 30 April 2026: the Regulator gazetted its own code of conduct on handling personal information at gated accesses. It covers closed-circuit television and biometric access control, and the comment period was extended in May 2026. Once issued, breaching a code of conduct counts as interference with the protection of personal information. POWERS THAT CAN BE USED WITHOUT NEW LEGISLATION. Section 54 of the Cybercrimes Act, the 72-hour police reporting duty, needs only a presidential proclamation plus a ministerial notice listing offence categories. Chapter 9 of the Electronic Communications and Transactions Act lets the Minister declare classes of information to be 'critical data'. The Minister can then set binding rules on storing, archiving, transferring and controlling the databases holding it. We found no such notice as at 18 August 2026. The telecommunications retention period is set by ministerial directive, within a three-to-five-year band. And the 10 million rand fine ceiling can be raised for inflation by ministerial notice.
Sources
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Communication 2 of 2025 — Cloud computing and data offshoring
resbank.co.za
“The Authorities are in the process of developing a cloud computing and/or data offshoring Joint Standard. ... The Joint Standard will be published for public consultation in due course.”
Link checked 18 August 2026
- Official sourceSouth African Reserve Bank, National Payment System DepartmentCloud computing and data offshoring in the national payment system — consultation paper, March 2025, paragraph 9.2
resbank.co.za
“clearing and settlement data and systems for payment system FMIs must be processed, stored and/or located within the borders of South Africa.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Government Gazette 54594 — own-initiative code of conduct on processing personal information at gated accesses, 30 April 2026
inforegulator.org.za
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Government Gazette 53426 Notice 6673 — draft regulations on processing health or sex life data, 26 September 2025
inforegulator.org.za
Link checked 18 August 2026
- Official sourceGovernment of South AfricaElectronic Communications and Transactions Act 25 of 2002, sections 53 and 55 (protection of critical databases)
gov.za
“The Minister may prescribe minimum standards or prohibitions in respect of ... access to, transfer and control of critical databases ... procedures and technological methods to be used in the storage or archiving of critical databases.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking data must stay in the country
Official name: Currency and Exchanges Manual for Authorised Dealers, section J(D) — Offshoring and cloud computing · Issued under the Exchange Control Regulations, 1961; current edition 2026 · Regulator directive
Banks and licensed foreign-exchange dealers must apply to the central bank's Financial Surveillance Department first. They apply case by case, before moving cross-border transaction data, customer records or systems offshore or into the cloud. Storage in sanctioned countries is refused outright. So is storage anywhere that would block the regulator's access to the data.
Enforced by Financial Surveillance Department, South African Reserve Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryMoving the business processes themselves offshore is refused. Only data, systems and infrastructure may go offshore, and only with approval. When an approved arrangement ends, the previous five years of data must be copied back to South Africa.
- Keep data for a minimum period — 5 yearsData must be retrievable immediately and in any event within 48 hours.
- Assess high-risk projectsA documented risk assessment is required before the arrangement starts.
- Written vendor contractA binding agreement must ring-fence the reporting entity's data inside the data centre.
Sources
- Official sourceSouth African Reserve BankCurrency and Exchanges Manual for Authorised Dealers, section J(D)
resbank.co.za
“The Financial Surveillance Department is not agreeable to ... any form of offshoring and cloud computing models where data is stored in a sanctioned country or in jurisdictions that may inhibit effective access to data.”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Directive 3 of 2018 and Guidance Note 5 of 2018 — Cloud computing and the offshoring of data · D3/2018 and G5/2018, Prudential Authority · Regulator directive
Banks, controlling companies and branches of foreign banks may use cloud services and send data offshore. They must meet the Prudential Authority's requirements, and their board takes ultimate responsibility for the risk. This is a permission with conditions, not a rule about where data must sit.
Enforced by Prudential Authority
How this country controls where data goes: No restriction
What you have to do
- Secure the data
- Assess high-risk projectsA risk-based approach aligned to the bank's risk appetite, with the board of directors carrying ultimate responsibility.
Sources
- Official sourcePrudential Authority, South African Reserve BankD3/2018: Cloud computing and the offshoring of data
resbank.co.za
Link checked 18 August 2026
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Communication 2 of 2025, paragraph 3.3 — confirming Directive 3 of 2018 and Guidance Note 5 of 2018 are the only cloud instruments in force
resbank.co.za
“To date, the only regulatory framework-related instruments/documents focused on cloud computing that have been published were issued by the PA and relate to banks.”
Link checked 18 August 2026
Cloud and outsourcing rules (Insurance)
Official name: Joint Standard 1 of 2024 — Outsourcing by Insurers · Joint Standard 1 of 2024, issued under the Financial Sector Regulation Act 9 of 2017 · Government rules
No rule tells insurers where to keep data. But any material outsourcing must be notified to the regulators at least 30 days in advance. That includes moving policyholder data to a cloud provider. The contract must give both the insurer and the regulators access rights. Arrangements signed before 1 December 2024 have until 1 December 2026, or their next renewal, to comply.
That is a long gap: the duty is real law today, but no penalty can follow until 1 December 2026. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by Financial Sector Conduct Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractThe contract must address confidentiality, privacy and security, and must let the insurer and the regulators inspect the supplier's premises and documents.
- Register or notify — within 720 hoursThe regulators must be notified at least 30 days before entering a material outsourcing arrangement.
Sources
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Standard 1 of 2024 — Outsourcing by Insurers
resbank.co.za
“This Joint Standard comes into operation on 1 December 2024.”
Link checked 18 August 2026
Payments data must stay in the country
Official name: Cloud computing and data offshoring in the national payment system — proposed directive under section 12 of the National Payment System Act 78 of 1998 · Consultation paper, National Payment System Department, March 2025 · Draft law
This is a proposal, not law. The central bank consulted in March 2025 on a directive. It would require payment institutions to get its approval before using cloud services or sending data abroad. It would also keep clearing and settlement data of payment market infrastructures inside South Africa. No directive had been issued as at 18 August 2026.
Enforced by South African Reserve Bank
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryProposed only. Clearing and settlement data, systems and infrastructure of payment market infrastructures would have to stay inside South Africa. Cross-border settlement systems would be excluded, such as the regional and continuous linked settlement systems.
- Register or notifyProposed prior approval from the central bank before any payment institution uses cloud services or offshores data.
Sources
- Official sourceSouth African Reserve Bank, National Payment System DepartmentCloud computing and data offshoring in the national payment system — consultation paper, March 2025
resbank.co.za
“The offshoring of clearing and settlement services and activities, data, mechanisms, processes, infrastructures and systems should be prohibited for PCH SOs and RTGS operators as payment system FMIs.”
Link checked 18 August 2026
Government data must stay in the country
Official name: National Data and Cloud Policy · General Notice 2533, Government Gazette 50741, 31 May 2024, issued under section 3(5) of the Electronic Communications Act 36 of 2005 · Government policy document
Government data about national security and sovereignty must be stored only on infrastructure inside South Africa. Government cloud is bought through the State Information Technology Agency. This is a policy. So it directs government bodies and their suppliers, rather than binding the private sector directly.
Enforced by Department of Communications and Digital Technologies
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countryApplies to government data about national security and sovereignty. The policy does not restrict where other government data sits.
- Register or notifyThe State Information Technology Agency is the responsible authority for sourcing data infrastructure and cloud services for government.
Sources
- Official sourceDepartment of Communications and Digital TechnologiesNational Data and Cloud Policy, Government Gazette 50741, 31 May 2024
gov.za
“The State Information Technology Agency (SITA) shall be the responsible authority, by virtue of its legislative mandate, to source data infrastructure and cloud services for the government.”
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Protection of Personal Information Act, 2013 · Act No. 4 of 2013 · Act of parliament
This is South Africa's general privacy law. Data may go abroad if the recipient is covered by a law, group-wide rules or a contract giving substantially similar protection. Narrow grounds such as consent also work. There is no list of approved countries and no filing step. But sensitive and children's data going to a weakly protected country needs the Regulator's approval first. Fines are capped at 10 million rand and generally need a court to confirm them.
Enforced by Information Regulator (South Africa)
How this country controls where data goes: No restriction · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Government sign-off needed
What you have to do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Report breaches to the regulatorAs soon as reasonably possible after discovery. No fixed number of hours.
- Tell affected people
- Written vendor contractYou need a written contract with any supplier that handles data on your behalf.
- Register or notifyThe information officer, by default the head of the organisation, must be registered with the Regulator before taking up those duties.
- Assess high-risk projectsA personal information impact assessment is required of information officers under the Regulations.
- Put a transfer safeguard in place
- Get a parent's consent for children — applies at: under 18
- Delete data after a period
What it costs if you get it wrong
- Fixed maximum fine: ZAR 10 million — about $560 thousandAdministrative fine by infringement notice, available only where an offence under the Act has been committed
- Criminal liability: Up to 10 years imprisonmentFailure to comply with an enforcement notice, obstruction of the Regulator, or unlawful acts involving account numbers
- Order to stopAn enforcement notice may require the responsible party to stop processing
- Claims by individualsCivil action for damages by a data subject, with or without fault on the part of the responsible party
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013
gov.za
Link checked 18 August 2026
- Official sourcePresidency of the Republic of South AfricaProclamation R21 of 2020 — commencement of sections 2 to 38, 55 to 109, 111 and 114(1)-(3) on 1 July 2020
gov.za
“1 July 2020 as the date on which (i) sections 2 to 38; (ii) sections 55 to 109; (iii) section 111; and (iv) section 114(1), (2) and (3) ... shall commence.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Amended Regulations relating to the Protection of Personal Information (published for implementation 17 April 2025)
inforegulator.org.za
Link checked 18 August 2026
Personal data must stay in the country
Official name: Tax Administration Act, 2011 section 30 read with Public Notice 787 of 1 October 2012 (electronic form of record-keeping) · Act No. 28 of 2011, s 30; GG 35733 Notice 787 · Government rules
If you keep tax records electronically, they must stay inside South Africa. The exception is written permission from the revenue service to keep them abroad. This applies to every industry. It is the most commonly missed data-location rule in the country, because it catches ordinary foreign-hosted accounting and business software.
Enforced by South African Revenue Service
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryElectronic tax records must be kept in South Africa unless a senior revenue service official authorises a location outside the country.
- Keep data for a minimum period — 5 yearsFive years from submission of the return, or until an audit or investigation is concluded.
What it costs if you get it wrong
- Fixed maximum fineNon-compliance penalties under the Tax Administration Act; amount depends on the taxpayer's assessed income
Sources
- Official sourceSouth African Revenue ServiceRecord keeping
sars.gov.za
“In the following instances you must request SARS for authorisation to deviate from the above-mentioned requirements: Where records are to be kept in a different form; and/or Where the electronic records are kept at a place physically located outside of South Africa.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServicePublic Notices — Notice 787, GG 35733, Electronic form of record-keeping in terms of section 30(1)(b), 1 October 2012
sars.gov.za
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact wording and current text of Public Notice 787 of 2012 on electronic record-keeping
The revenue service serves the notice as a scanned image with no text layer. So we rely on the revenue service's own plain-language record-keeping page. That page states the authorisation requirement clearly. We rate the rule medium confidence.
The detailed content of Prudential Authority Directive 3 of 2018 and Guidance Note 5 of 2018 on cloud computing and offshoring
Both are scanned documents with no readable text. What we say here comes from the central bank's own March 2025 consultation paper and Joint Communication 2 of 2025, which describe them. Rated medium confidence.
The incident notification deadline in Joint Standard 2 of 2024 on cybersecurity and cyber resilience
An official joint communication confirms the standard took effect on 1 June 2025. We could not open the standard's own text on either regulator's site. The notification template was still in consultation in September 2025.
Whether any Minister has ever declared classes of 'critical data' or registered critical databases under Chapter 9 of the Electronic Communications and Transactions Act
We found no such notice on government sources, checked 18 August 2026. We cannot prove that none exists. The power itself is confirmed from the Act.
Whether the Regulation of Interception of Communications Amendment Bill of 2023 has been enacted, and the current ministerial directive setting the telecoms retention period
The government's document library shows only bill versions. We found no amendment act and no published directive. The three-to-five-year period is confirmed from the Act itself.
Data-location or server-location conditions in provincial gambling licences, and any rule for mapping or geospatial data
Gambling is licensed province by province, and licence conditions are not published centrally. We found no official source, and no rule, checked 18 August 2026. Confidence is low. If you work in this industry, check before you rely on it.
Health record retention periods
The National Health Act sets protections and criminal offences, but no retention period. The commonly cited six-year period comes from professional council guidance we could not open on an official site. The draft regulations on health and sex-life data were still not final on 18 August 2026.
Whether section 54 of the Cybercrimes Act has been brought into force by any proclamation after 30 November 2021
The government document library shows only the 2021 commencement proclamation, which leaves out section 54. A later proclamation could exist and not be indexed.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.