South Africa
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Personal data may leave South Africa, but only if you can point to a reason the law allows — usually a contract with the receiving company that gives people the same level of protection they had at home. There is no government list of approved or banned countries, and no form to file. The privacy regulator is real, staffed and issuing orders, though its fines are small by world standards.
Data governance in South Africa
The eight things that decide how you handle data about people in South Africa. Same eight on every country page, so you can compare.
Who has to follow these rules
It can reach you without an office in South Africa, but not automatically. The law covers you if your organisation is based in South Africa, or if it is based elsewhere but uses equipment or people inside South Africa to handle the data. Simply having South African customers, with everything processed abroad, is arguably outside the law — which is a narrower reach than Europe's. There is no size or revenue threshold, and no requirement to appoint a local representative.
The Protection of Personal Information Act 4 of 2013, section 3(1)(b), applies the Act where the responsible party (the organisation deciding why data is used) is domiciled in the Republic, or is not domiciled there but 'makes use of automated or non-automated means in the Republic, unless those means are used only to forward personal information through the Republic'. In practice the Regulator has been willing to act against very large foreign platforms: it served an enforcement notice on WhatsApp on 16 April 2025 under section 95 of the Act. Every organisation also has an 'information officer' — by default the head of the organisation, not a specialist — who must be registered with the Regulator before taking up those duties (section 55(2)).
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, sections 3 and 55
gov.za
“This Act applies to the processing of personal information ... where the responsible party is (i) domiciled in the Republic; or (ii) not domiciled in the Republic, but makes use of automated or non-automated means in the Republic, unless those means are used only to forward personal information through the Republic.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Enforcement Notices — including WhatsApp, 16 April 2025
inforegulator.org.za
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. The general rule is that you may send personal data abroad if the receiver is bound by a law, a group-wide policy or a contract that protects it about as well as South African law does. There is no list of approved countries and no permission slip to collect. But several industries and one rule that applies to every company override this, and in those areas data either stays in the country or needs a regulator's blessing first.
Sector by sector, checked on 18 August 2026. TAX RECORDS, ALL COMPANIES: electronic records kept outside South Africa need prior written authorisation from a senior official of the South African Revenue Service — rated conditional. BANKS AND FOREIGN-EXCHANGE DEALERS: the central bank's Financial Surveillance Department considers offshoring and cloud use only case by case on formal application; offshoring the business processes themselves (as opposed to the data) is refused outright, and storage in sanctioned countries or in places that would block regulator access is refused — rated conditional. BANKS GENERALLY: the Prudential Authority's Directive 3 of 2018 and Guidance Note 5 of 2018 permit cloud use and offshoring subject to its requirements, with the board carrying ultimate responsibility — rated conditional. PAYMENTS: no localisation rule in force today, but the central bank proposed in March 2025 that clearing and settlement data of payment market infrastructures be kept inside South Africa — rated open today, closed if the proposal is issued. INSURANCE: no localisation; the joint insurance outsourcing standard requires 30 days' notice to the regulators before a material outsourcing and contractual access rights — rated open. GOVERNMENT: government data touching national security must be stored only on infrastructure inside South Africa under the National Data and Cloud Policy, and the State Information Technology Agency is the buying channel for government cloud — rated closed for that category. HEALTH, TELECOM, EDUCATION, GAMBLING, MAPPING: no data-location rule found on official sources, checked 18 August 2026; telecoms must keep call and connection records for between three and five years but the law does not say where.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, section 72 (transfers of personal information outside the Republic)
gov.za
“A responsible party in the Republic may not transfer personal information about a data subject to a third party who is in a foreign country unless ... the third party who is the recipient of the information is subject to a law, binding corporate rules or binding agreement which provide an adequate level of protection.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServiceRecord keeping — authorisation required to keep electronic records outside South Africa
sars.gov.za
“Where the electronic records are kept at a place physically located outside of South Africa ... a senior SARS official may, subject to conditions, in accordance with section 30(2) of Tax Administration Act, authorise such location outside of South Africa, if acceptable.”
Link checked 18 August 2026
- Official sourceSouth African Reserve Bank, Financial Surveillance DepartmentCurrency and Exchanges Manual for Authorised Dealers, section J(D) — Offshoring and cloud computing
resbank.co.za
“Requests for utilising offshoring and cloud computing will only be considered, on a case-by-case basis, upon the submission of a formal application to the Financial Surveillance Department.”
Link checked 18 August 2026
- Official sourceDepartment of Communications and Digital TechnologiesNational Data and Cloud Policy, Government Gazette 50741, 31 May 2024, paragraph 15.4.2
gov.za
“Government data that incorporates content pertaining to the protection and preservation of national security and sovereignty of the Republic shall be stored only in digital infrastructure located within the borders of South Africa.”
Link checked 18 August 2026
- Official sourceSouth African Reserve Bank, National Payment System DepartmentCloud computing and data offshoring in the national payment system — consultation paper, March 2025
resbank.co.za
Link checked 18 August 2026
Sending data out of the country
You need a legal reason before the data goes, and you decide for yourself whether you have one. The usual route is a contract with the receiving company that carries the same protections forward, including to anyone they pass it on to. Group-wide internal rules, the person's own consent, or the transfer being necessary for their contract also work. Nobody approves it, nothing is filed, and no country is banned — but sensitive data and children's data are the exception and do need approval.
Section 72 of the Protection of Personal Information Act lists five grounds: an adequate law, binding corporate rules or a binding agreement covering the recipient and onward transfers; the person's consent; necessity for their contract; necessity for a contract made in their interest; or benefit to them where consent is impractical. There is no official standard contract template, no adequacy list, and no registration step, so 'adequacy' here is a self-assessment the organisation must be able to defend. Separately, section 57(1)(d) requires prior authorisation from the Regulator before transferring special personal information (race, health, sex life, biometrics, religion, politics, trade union membership, criminal behaviour) or children's personal information to a recipient in a country that does not provide adequate protection. Under section 58 the processing may not start until the Regulator says it will not investigate further, or finishes investigating: four weeks for the initial answer and up to thirteen weeks more. That is a genuine case-by-case approval layer sitting on top of an otherwise self-service regime. Sector-specific approvals from the central bank and the revenue service run in parallel and are not replaced by section 72.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, sections 57, 58 and 72
gov.za
“The responsible party must obtain prior authorisation from the Regulator ... prior to any processing if that responsible party plans to ... transfer special personal information ... or the personal information of children ... to a third party in a foreign country that does not provide an adequate level of protection.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Prior Authorisation — application form and guidance note (revised)
inforegulator.org.za
Link checked 18 August 2026
The regulator, and whether it actually acts
The Information Regulator, and it is genuinely working. It has a chairperson and two other members, with two seats vacant, and it issued enforcement orders against a college, a mining company and a provincial health department in May and June 2026 alone. In April 2026 it went to the High Court and got a fine against a municipality confirmed — though the judge cut it from about 28,000 US dollars to about 14,000. Banking, insurance and tax regulators enforce their own rules separately and are far better resourced.
The Information Regulator (South Africa) was established under section 39 of the Protection of Personal Information Act and has been operational since 2016, taking over privacy enforcement on 1 July 2021. Members as at 18 August 2026: Adv Pansy Tlakula (Chairperson), Adv Lebogang Stroom (full-time), Mr Mfana Gwala (part-time), with one full-time and one part-time seat shown as vacant on the Regulator's own members page. Enforcement notices published for 2026: Central Johannesburg TVET College (20 May 2026, unlawful sharing of special personal information and failure to report a security compromise), Sibanye Stillwater (2 June 2026, access to information), Gauteng Department of Health (10 June 2026). The Blouberg Local Municipality matter is the clearest picture of how enforcement actually works: complaint, investigation, enforcement notice, infringement notice, then a court application under section 109(5) to turn the administrative fine into a court order. The Regulator imposed 500,000 rand; the Polokwane High Court reduced it to 250,000 rand in early April 2026 because only one person was affected and it was a first offence. The other enforcers are the Prudential Authority and Financial Sector Conduct Authority (financial institutions), the central bank's Financial Surveillance Department (exchange control), and the South African Revenue Service (tax records).
Sources
- Official sourceInformation Regulator (South Africa)Members of the Information Regulator — two seats shown vacant
inforegulator.org.za
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Media statement: Information Regulator turns to the courts to fine Blouberg Local Municipality, 29 April 2026
inforegulator.org.za
“The infringement fine imposed on the Blouberg Local Municipality by the Regulator amounted to R500,000, however, the Judge who considered the section 109(5) statement was of the view that the fine was excessive in the circumstances.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Media statement: Information Regulator issues enforcement notices, 2 June 2026
inforegulator.org.za
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both directions apply and they pull against each other. The privacy law says delete personal data once you no longer need it. Other laws say keep it: five years for tax records, five years for money-laundering checks, five years for cross-border payment records at banks, and between three and five years for phone and internet connection records. Where they clash, the keeping rule wins, because the privacy law allows you to hold data longer when another law requires it.
The ceiling is section 14 of the Protection of Personal Information Act: records must not be kept longer than necessary for the purpose, must be destroyed, deleted or de-identified as soon as reasonably practicable after that, and the destruction must prevent reconstruction. Section 14(1)(a) is the escape hatch — retention is allowed where 'required or authorised by law'. The floors: tax records five years from filing (longer if a return is outstanding or an audit is running); records under the Financial Intelligence Centre Act five years from the end of the business relationship or the transaction; exchange-control data at authorised dealers five years, retrievable within 48 hours, and on termination of an offshore arrangement the previous five years of data must be replicated back to South Africa; telecommunications connection records for a period fixed by ministerial directive that may 'not be less than three years and not more than five years'. The sharpest conflict is in the public sector: under the National Archives and Records Service of South Africa Act no public record may be destroyed or erased without the written authorisation of the National Archivist, so a government body cannot simply honour a deletion request the way a company can.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, section 14
gov.za
“records of personal information must not be retained any longer than is necessary for achieving the purpose for which the information was collected or subsequently processed, unless retention of the record is required or authorised by law.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServiceRecord keeping — five-year retention periods
sars.gov.za
Link checked 18 August 2026
- Official sourceGovernment of South AfricaRegulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002, section 30
gov.za
“the period for which such information must be stored, which period may ... not be less than three years and not more than five years from the date of the transmission of the indirect communication.”
Link checked 18 August 2026
- Official sourceGovernment of South AfricaNational Archives and Record Service of South Africa Act 43 of 1996, section 13(2)(a)
gov.za
“no public record under the control of a governmental body shall be transferred to an archives repository, destroyed, erased or otherwise disposed of without the written authorisation of the National Archivist.”
Link checked 18 August 2026
- Official sourceGovernment of South AfricaFinancial Intelligence Centre Act 38 of 2001, sections 22 to 24 (as amended)
gov.za
Link checked 18 August 2026
If something goes wrong
There is only one clock that actually runs, and it has no number on it. If personal data is accessed by someone who should not have it, you must tell the regulator and the affected people 'as soon as reasonably possible' — no fixed hours. A separate 72-hour reporting duty to the police is printed in the cybercrime law but has never been switched on, so it does not apply. Financial firms have a third duty to report serious technology and cyber incidents to their regulators.
Section 22 of the Protection of Personal Information Act requires notification to the Regulator and to each identifiable affected person as soon as reasonably possible after discovery, allowing only for the needs of law enforcement and for work to determine the scope and restore the system. Notification may be delayed only if the police or the Regulator say it would impede a criminal investigation. The notice must describe likely consequences, what you are doing about it, what the person should do, and the identity of the intruder if known. Since April 2025 breaches are reported through the Regulator's online services portal. The 72-hour clock in section 54 of the Cybercrimes Act 19 of 2020 — which would oblige communications providers and financial institutions to report to the police — was expressly excluded from the commencement proclamation of 30 November 2021 and remains uncommenced; it also depends on the Minister of Police first listing the categories of offence by notice, which has not been found. For financial institutions, Joint Standard 1 of 2023 on information technology governance took effect on 15 November 2024 and Joint Standard 2 of 2024 on cybersecurity and cyber resilience took effect on 1 June 2025; the notification template for material technology and cyber incidents was still out for consultation in September 2025, so the precise deadline is not settled.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, section 22
gov.za
“The notification referred to in subsection (1) must be made as soon as reasonably possible after the discovery of the compromise.”
Link checked 18 August 2026
- Official sourcePresidency / Department of Justice and Constitutional DevelopmentProclamation R42 of 30 November 2021 — commencement of certain sections of the Cybercrimes Act, excluding section 54
gov.za
“Chapter 8, with the exclusion of section 54”
Link checked 18 August 2026
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Communication 3 of 2025 — draft notification template for material IT and cyber incidents
resbank.co.za
“Joint Standard 1 of 2023 ... Effective 15 November 2024. Joint Standard 2 of 2024 ... Effective 1 June 2025.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Guidelines on completing a security compromise notification under section 22
inforegulator.org.za
Link checked 18 August 2026
What catches people out
Five things catch people out. First, the regulator cannot fine you for the breach itself — it must order you to fix it, and only ignoring that order becomes a crime that carries a fine of up to 10 million rand, roughly half a million US dollars. Second, sending sensitive or children's data to a weakly protected country needs approval before you start, and you must wait. Third, letting people opt out is not consent for marketing emails or texts. Fourth, plugging a computer holding patient records into another system without permission is a criminal offence. Fifth, your accounting system in a foreign cloud probably needs the tax authority's written permission.
(1) The enforcement chain is procedural: investigation, then an enforcement notice, then an infringement notice with an administrative fine capped at 10 million rand, then a court application to make it an order. Failing to comply with an enforcement notice is an offence carrying up to ten years' imprisonment. Courts will reduce fines they consider excessive, as in the Blouberg municipality matter in April 2026. (2) Prior authorisation under sections 57 and 58 also covers linking unique identifiers across organisations, processing information about criminal behaviour for third parties, and credit reporting — and processing must stop until the Regulator responds. (3) The Regulations were amended with immediate effect on 17 April 2025 and now state plainly that opt-out does not constitute consent for unsolicited electronic marketing, and that consent requested by telephone or automated calling machine must be electronically recorded and given to the person free of charge on request. (4) Section 17 of the National Health Act makes it a criminal offence to connect a computer holding patient records to another computer or terminal without authority — a live risk for any health system integration or cloud migration. (5) Tax records in electronic form kept outside South Africa need authorisation from a senior revenue service official. (6) A sixth for public bodies: they cannot delete public records without the National Archivist's written authorisation, so honouring a deletion request may itself be unlawful.
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013, sections 57, 58, 103, 107 and 109
gov.za
“specify the amount of the administrative fine payable, which amount may, subject to subsection (10), not exceed R10 million”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Amended Regulations relating to the Protection of Personal Information, regulation 6
inforegulator.org.za
“For the purposes of direct marketing through unsolicited electronic communications, opt-out shall not constitute consent as referred to in section 69 (2) of the Act.”
Link checked 18 August 2026
- Official sourceGovernment of South AfricaNational Health Act 61 of 2003, section 17
gov.za
“without authority, connects any part of a computer or other electronic system on which records are kept to any other computer or other electronic system ... commits an offence.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServiceRecord keeping — authorisation to keep electronic records outside South Africa
sars.gov.za
Link checked 18 August 2026
What's changing next
Four things are in the pipeline and none of them is law yet. The banking and insurance regulators say they are writing a binding standard on cloud use and sending data offshore. The central bank has proposed that payment clearing and settlement data stay inside South Africa. The privacy regulator has draft rules for health and sex-life data, and a binding code for security gates and cameras at estates and office parks. Separately, a 72-hour police reporting duty already sits in law and can be switched on overnight.
Dated items. March 2025: the central bank's payments department proposed a directive under section 12 of the National Payment System Act requiring prior approval before payment institutions use cloud or offshore data, and requiring clearing and settlement data, systems and infrastructure of payment market infrastructures to be located inside South Africa, with cross-border settlement systems excluded; no directive had been issued as at 18 August 2026. May 2025: Joint Communication 2 of 2025 confirmed the Financial Sector Conduct Authority and Prudential Authority are developing a cloud computing and data offshoring Joint Standard, to be published for consultation; nothing published as at 18 August 2026. 26 September 2025: draft regulations on processing health or sex-life data, comments closed 10 October 2025, not yet final. 30 April 2026: the Regulator gazetted its own-initiative code of conduct on processing personal information at gated accesses, covering closed-circuit television and biometric access control, with the comment period extended in May 2026; once issued, breaching a code of conduct counts as interference with the protection of personal information. DORMANT SWITCHES, each flippable without new legislation: section 54 of the Cybercrimes Act, the 72-hour police reporting duty, needs only a presidential proclamation plus a ministerial notice listing offence categories; Chapter 9 of the Electronic Communications and Transactions Act lets the Minister declare classes of information to be 'critical data' and then prescribe binding rules on the storage, archiving, transfer and control of the databases holding it, with no such notice found as at 18 August 2026; the telecommunications retention period is set by ministerial directive within a three-to-five-year band; and the 10 million rand fine ceiling can be raised for inflation by ministerial notice.
Sources
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Communication 2 of 2025 — Cloud computing and data offshoring
resbank.co.za
“The Authorities are in the process of developing a cloud computing and/or data offshoring Joint Standard. ... The Joint Standard will be published for public consultation in due course.”
Link checked 18 August 2026
- Official sourceSouth African Reserve Bank, National Payment System DepartmentCloud computing and data offshoring in the national payment system — consultation paper, March 2025, paragraph 9.2
resbank.co.za
“clearing and settlement data and systems for payment system FMIs must be processed, stored and/or located within the borders of South Africa.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Government Gazette 54594 — own-initiative code of conduct on processing personal information at gated accesses, 30 April 2026
inforegulator.org.za
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Government Gazette 53426 Notice 6673 — draft regulations on processing health or sex life data, 26 September 2025
inforegulator.org.za
Link checked 18 August 2026
- Official sourceGovernment of South AfricaElectronic Communications and Transactions Act 25 of 2002, sections 53 and 55 (protection of critical databases)
gov.za
“The Minister may prescribe minimum standards or prohibitions in respect of ... access to, transfer and control of critical databases ... procedures and technological methods to be used in the storage or archiving of critical databases.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Currency and Exchanges Manual for Authorised Dealers, section J(D) — Offshoring and cloud computing
Regulator directive · Issued under the Exchange Control Regulations, 1961; current edition 2026
Banks and licensed foreign-exchange dealers must apply to the central bank's Financial Surveillance Department, case by case, before moving cross-border transaction data, customer records or systems offshore or into the cloud. Storage in sanctioned countries, or anywhere that would block the regulator's access to the data, is refused outright.
Enforced by Financial Surveillance Department, South African Reserve Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryOffshoring of the business processes themselves is refused; only data, systems and infrastructure may be offshored, and only with approval. On termination of an approved arrangement the previous five years of data must be replicated back to South Africa.
- Keep data for a minimum period — 5 yearsData must be retrievable immediately and in any event within 48 hours.
- Assess high-risk projectsA documented risk assessment is required before the arrangement starts.
- Written vendor contractA binding agreement must ring-fence the reporting entity's data inside the data centre.
Sources
- Official sourceSouth African Reserve BankCurrency and Exchanges Manual for Authorised Dealers, section J(D)
resbank.co.za
“The Financial Surveillance Department is not agreeable to ... any form of offshoring and cloud computing models where data is stored in a sanctioned country or in jurisdictions that may inhibit effective access to data.”
Link checked 18 August 2026
Directive 3 of 2018 and Guidance Note 5 of 2018 — Cloud computing and the offshoring of data
Regulator directive · D3/2018 and G5/2018, Prudential Authority
Banks, controlling companies and branches of foreign banks may use cloud services and send data offshore, provided they meet the Prudential Authority's requirements and their board takes ultimate responsibility for the risk. This is a permission with conditions, not a location rule.
Enforced by Prudential Authority
Transfer model: No restriction
What it makes you do
- Secure the data
- Assess high-risk projectsA risk-based approach aligned to the bank's risk appetite, with the board of directors carrying ultimate responsibility.
Sources
- Official sourcePrudential Authority, South African Reserve BankD3/2018: Cloud computing and the offshoring of data
resbank.co.za
Link checked 18 August 2026
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Communication 2 of 2025, paragraph 3.3 — confirming Directive 3 of 2018 and Guidance Note 5 of 2018 are the only cloud instruments in force
resbank.co.za
“To date, the only regulatory framework-related instruments/documents focused on cloud computing that have been published were issued by the PA and relate to banks.”
Link checked 18 August 2026
Joint Standard 1 of 2024 — Outsourcing by Insurers
Government rules · Joint Standard 1 of 2024, issued under the Financial Sector Regulation Act 9 of 2017
Insurers face no data-location rule, but any material outsourcing — which includes moving policyholder data to a cloud provider — must be notified to the regulators at least 30 days in advance, and the contract must give both the insurer and the regulators access rights. Arrangements signed before 1 December 2024 have until 1 December 2026, or their next renewal, to comply.
Enforced by Financial Sector Conduct Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractThe contract must address confidentiality, privacy and security, and must let the insurer and the regulators inspect the supplier's premises and documents.
- Register or notify — within 720 hoursThe regulators must be notified at least 30 days before entering a material outsourcing arrangement.
Sources
- Official sourcePrudential Authority and Financial Sector Conduct AuthorityJoint Standard 1 of 2024 — Outsourcing by Insurers
resbank.co.za
“This Joint Standard comes into operation on 1 December 2024.”
Link checked 18 August 2026
Cloud computing and data offshoring in the national payment system — proposed directive under section 12 of the National Payment System Act 78 of 1998
Draft law · Consultation paper, National Payment System Department, March 2025
A proposal, not law. The central bank consulted in March 2025 on a directive that would require payment institutions to get its approval before using cloud services or sending data abroad, and would keep clearing and settlement data of payment market infrastructures inside South Africa. No directive had been issued as at 18 August 2026.
Enforced by South African Reserve Bank
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryProposed only. Clearing and settlement data, systems and infrastructure of payment market infrastructures would have to stay inside South Africa; cross-border settlement systems such as the regional and continuous linked settlement systems would be excluded.
- Register or notifyProposed prior approval from the central bank before any payment institution uses cloud services or offshores data.
Sources
- Official sourceSouth African Reserve Bank, National Payment System DepartmentCloud computing and data offshoring in the national payment system — consultation paper, March 2025
resbank.co.za
“The offshoring of clearing and settlement services and activities, data, mechanisms, processes, infrastructures and systems should be prohibited for PCH SOs and RTGS operators as payment system FMIs.”
Link checked 18 August 2026
National Data and Cloud Policy
Government policy document · General Notice 2533, Government Gazette 50741, 31 May 2024, issued under section 3(5) of the Electronic Communications Act 36 of 2005
Government data that concerns national security and sovereignty must be stored only on infrastructure inside South Africa, and government cloud is bought through the State Information Technology Agency. This is a policy, so it directs government bodies and their suppliers rather than binding the private sector directly.
Enforced by Department of Communications and Digital Technologies
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryApplies to government data about national security and sovereignty. Other government data is not location-restricted by the policy.
- Register or notifyThe State Information Technology Agency is the responsible authority for sourcing data infrastructure and cloud services for government.
Sources
- Official sourceDepartment of Communications and Digital TechnologiesNational Data and Cloud Policy, Government Gazette 50741, 31 May 2024
gov.za
“The State Information Technology Agency (SITA) shall be the responsible authority, by virtue of its legislative mandate, to source data infrastructure and cloud services for the government.”
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Protection of Personal Information Act, 2013
Act of parliament · Act No. 4 of 2013
South Africa's general privacy law. Data may go abroad if the recipient is covered by a law, group-wide rules or a contract giving substantially similar protection, or on narrow grounds such as consent. There is no list of approved countries and no filing step, but sensitive and children's data going to a weakly protected country needs the Regulator's prior approval. Fines are capped at 10 million rand and generally require a court to confirm them.
Enforced by Information Regulator (South Africa)
Transfer model: No restriction · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Government sign-off needed
What it makes you do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people object
- Secure the data
- Report breaches to the regulatorAs soon as reasonably possible after discovery. No fixed number of hours.
- Tell affected people
- Written vendor contractA written contract with any supplier processing on your behalf is required.
- Register or notifyThe information officer, by default the head of the organisation, must be registered with the Regulator before taking up those duties.
- Assess high-risk projectsA personal information impact assessment is required of information officers under the Regulations.
- Put a transfer safeguard in place
- Get a parent's consent for children — applies at: under 18
- Delete data after a period
What it costs if you get it wrong
- Fixed maximum fine: ZAR 10 million — about $560 thousandAdministrative fine by infringement notice, available only where an offence under the Act has been committed
- Criminal liability: Up to 10 years imprisonmentFailure to comply with an enforcement notice, obstruction of the Regulator, or unlawful acts involving account numbers
- Order to stopAn enforcement notice may require the responsible party to stop processing
- Claims by individualsCivil action for damages by a data subject, with or without fault on the part of the responsible party
Sources
- Official sourceGovernment of South AfricaProtection of Personal Information Act 4 of 2013
gov.za
Link checked 18 August 2026
- Official sourcePresidency of the Republic of South AfricaProclamation R21 of 2020 — commencement of sections 2 to 38, 55 to 109, 111 and 114(1)-(3) on 1 July 2020
gov.za
“1 July 2020 as the date on which (i) sections 2 to 38; (ii) sections 55 to 109; (iii) section 111; and (iv) section 114(1), (2) and (3) ... shall commence.”
Link checked 18 August 2026
- Official sourceInformation Regulator (South Africa)Amended Regulations relating to the Protection of Personal Information (published for implementation 17 April 2025)
inforegulator.org.za
Link checked 18 August 2026
Tax Administration Act, 2011 section 30 read with Public Notice 787 of 1 October 2012 (electronic form of record-keeping)
Government rules · Act No. 28 of 2011, s 30; GG 35733 Notice 787
Every business keeping tax records electronically must keep them inside South Africa unless the revenue service gives written permission to keep them abroad. This applies to all industries and is the single most commonly missed data-location rule in the country, because it catches ordinary foreign-hosted accounting and enterprise software.
Enforced by South African Revenue Service
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryElectronic tax records must be kept in South Africa unless a senior revenue service official authorises a location outside the country.
- Keep data for a minimum period — 5 yearsFive years from submission of the return, or until an audit or investigation is concluded.
What it costs if you get it wrong
- Fixed maximum fineNon-compliance penalties under the Tax Administration Act; amount depends on the taxpayer's assessed income
Sources
- Official sourceSouth African Revenue ServiceRecord keeping
sars.gov.za
“In the following instances you must request SARS for authorisation to deviate from the above-mentioned requirements: Where records are to be kept in a different form; and/or Where the electronic records are kept at a place physically located outside of South Africa.”
Link checked 18 August 2026
- Official sourceSouth African Revenue ServicePublic Notices — Notice 787, GG 35733, Electronic form of record-keeping in terms of section 30(1)(b), 1 October 2012
sars.gov.za
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact wording and current text of Public Notice 787 of 2012 on electronic record-keeping
The revenue service serves the notice as a scanned image with no text layer, so we rely on the revenue service's own plain-language record-keeping page, which states the authorisation requirement clearly. The rule is therefore rated medium confidence.
The detailed content of Prudential Authority Directive 3 of 2018 and Guidance Note 5 of 2018 on cloud computing and offshoring
Both are scanned documents with no extractable text. What we assert comes from the central bank's own March 2025 consultation paper and Joint Communication 2 of 2025, which describe them. Rated medium confidence.
The incident notification deadline in Joint Standard 2 of 2024 on cybersecurity and cyber resilience
We confirmed from an official joint communication that the standard took effect on 1 June 2025, but could not open the standard's own text on either regulator's site, and the notification template was still in consultation in September 2025.
Whether any Minister has ever declared classes of 'critical data' or registered critical databases under Chapter 9 of the Electronic Communications and Transactions Act
No such notice was found on government sources, checked 18 August 2026. We cannot prove a negative; the power itself is verified from the Act.
Whether the Regulation of Interception of Communications Amendment Bill of 2023 has been enacted, and the current ministerial directive setting the telecoms retention period
Only bill versions appear in the government's document library; no amendment act and no published directive were located. The three-to-five-year statutory band is verified from the Act itself.
Data-location or server-location conditions in provincial gambling licences, and any rule for mapping or geospatial data
Gambling is licensed province by province and licence conditions are not published centrally; no official source was located. No rule found, checked 18 August 2026, low confidence.
Health record retention periods
The National Health Act sets protection and criminal offences but no retention period; the commonly cited six-year period comes from professional council guidance we could not open on an official domain. The draft regulations on health and sex-life data were still not final on 18 August 2026.
Whether section 54 of the Cybercrimes Act has been brought into force by any proclamation after 30 November 2021
The government document library shows only the 2021 commencement proclamation, which excludes section 54. A later proclamation could exist and not be indexed.
60-day cadence. Two binding financial-sector instruments on cloud and offshoring are in the pipeline, either of which would change the sector ratings, and three dormant switches (the uncommenced 72-hour reporting duty, the critical-database powers, and the telecoms retention directive) can each be flipped by proclamation or gazette notice without consultation.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
South Africa versus
Compare