Skip to the content
Global Data RulesData governance rules, country by country

South Africa

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in South Africa — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: MediumEnforcement: Active

You can send personal data out of South Africa, but you need a reason the law allows. The usual one is a contract with the receiving company that gives people the same level of protection they had at home. There is no government list of approved or banned countries. There is no form to file. The privacy regulator is real, staffed and issuing orders. Its fines are small by world standards.

Data governance in South Africa

The eight things that decide how you handle data about people in South Africa. Same eight on every country page, so you can compare.

Who has to follow these rules

It can reach you without an office in South Africa, but not automatically. The law covers you if your organisation is based in South Africa. It also covers you if you are based elsewhere but use equipment or people inside South Africa to handle the data. Simply having South African customers, with everything handled abroad, is arguably outside the law. That is a narrower reach than Europe's. There is no size or revenue threshold. You do not have to appoint a local representative.

What you have to do here:
Register or notify

Where the data is allowed to live

Yes, with paperwork. The general rule is simple. You may send personal data abroad if the receiver is bound by a law, a group-wide policy or a contract. That must protect the data about as well as South African law does. There is no list of approved countries and no permission slip to collect. But several industries override this, and so does one rule that applies to every company. In those areas data either stays in the country, or needs a regulator's blessing first.

Ways to send data out:
Official 'this country is safe' decision · Approved group rules · Explicit consent · Needed for a contract

What to do: Get the paperwork for one of the routes below signed before any data leaves South Africa.

Sending data out of the country

You need a legal reason before the data goes, and you decide for yourself whether you have one. The usual route is a contract with the receiving company that carries the same protections forward. That includes to anyone they pass it on to. Group-wide internal rules also work. So does the person's own consent, or the transfer being necessary for their contract. Nobody approves it, nothing is filed, and no country is banned. Sensitive data and children's data are the exception, and do need approval.

Ways to send data out:
Official 'this country is safe' decision · Approved group rules · Explicit consent · Needed for a contract · Government sign-off needed

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

The Information Regulator enforces the law, and it is working. It has a chairperson and two other members, with two seats vacant. It issued enforcement orders against a college, a mining company and a provincial health department in May and June 2026 alone. In April 2026 it went to the High Court and got a fine against a municipality confirmed. The judge cut the fine from about 28,000 US dollars to about 14,000. Banking, insurance and tax regulators enforce their own rules separately, and are far better resourced.

How long you must keep it — and when to delete it

Both directions apply, and they pull against each other. The privacy law says delete personal data once you no longer need it. Other laws say keep it. Tax records run five years. Money-laundering checks run five years. Cross-border payment records at banks run five years. Phone and internet connection records run between three and five years. Where they clash, the keeping rule wins. The privacy law lets you hold data longer when another law requires it.

What you have to do here:
Delete data after a period · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Only one deadline actually runs, and it has no number on it. If someone accesses personal data who should not have it, you must tell the regulator and the affected people. The law says 'as soon as reasonably possible'. There are no fixed hours. A separate 72-hour reporting duty to the police is printed in the cybercrime law. It has never been switched on, so it does not apply. Financial firms have a third duty. They must report serious technology and cyber incidents to their regulators.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. First, the regulator cannot fine you for the breach itself. It must order you to fix it. Only ignoring that order becomes a crime, carrying a fine of up to 10 million rand, roughly half a million US dollars. Second, sending sensitive or children's data to a weakly protected country needs approval before you start, and you must wait. Third, letting people opt out is not consent for marketing emails or texts. Fourth, plugging a computer holding patient records into another system without permission is a criminal offence. Fifth, your accounting system in a foreign cloud probably needs the tax authority's written permission.

What you have to do here:
Get a parent's consent for children · Get consent
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

Four things are in the pipeline, and none of them is law yet. The banking and insurance regulators say they are writing a binding standard on cloud use and sending data offshore. The central bank has proposed that payment clearing and settlement data stay inside South Africa. The privacy regulator has draft rules for health and sex-life data. It also has a binding code for security gates and cameras at estates and office parks. Separately, a 72-hour police reporting duty already sits in law and can be switched on overnight.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking data must stay in the country

Official name: Currency and Exchanges Manual for Authorised Dealers, section J(D) — Offshoring and cloud computing · Issued under the Exchange Control Regulations, 1961; current edition 2026 · Regulator directive

In forceYes, with paperwork

Banks and licensed foreign-exchange dealers must apply to the central bank's Financial Surveillance Department first. They apply case by case, before moving cross-border transaction data, customer records or systems offshore or into the cloud. Storage in sanctioned countries is refused outright. So is storage anywhere that would block the regulator's access to the data.

In force since 1 January 2022

Enforced by Financial Surveillance Department, South African Reserve Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Cloud and outsourcing rules

Official name: Directive 3 of 2018 and Guidance Note 5 of 2018 — Cloud computing and the offshoring of data · D3/2018 and G5/2018, Prudential Authority · Regulator directive

In forceYes, with paperwork

Banks, controlling companies and branches of foreign banks may use cloud services and send data offshore. They must meet the Prudential Authority's requirements, and their board takes ultimate responsibility for the risk. This is a permission with conditions, not a rule about where data must sit.

In force since 17 September 2018

Enforced by Prudential Authority

How this country controls where data goes: No restriction

Not fully verified — see “What we're not sure about” below.
Insurance

Cloud and outsourcing rules (Insurance)

Official name: Joint Standard 1 of 2024 — Outsourcing by Insurers · Joint Standard 1 of 2024, issued under the Financial Sector Regulation Act 9 of 2017 · Government rules

In forceYes — store it anywhere

No rule tells insurers where to keep data. But any material outsourcing must be notified to the regulators at least 30 days in advance. That includes moving policyholder data to a cloud provider. The contract must give both the insurer and the regulators access rights. Arrangements signed before 1 December 2024 have until 1 December 2026, or their next renewal, to comply.

In force since 1 December 2024In force now, but not enforced until 1 December 2026

That is a long gap: the duty is real law today, but no penalty can follow until 1 December 2026. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by Financial Sector Conduct Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Protection of Personal Information Act, 2013 · Act No. 4 of 2013 · Act of parliament

In forceYes, with paperwork

This is South Africa's general privacy law. Data may go abroad if the recipient is covered by a law, group-wide rules or a contract giving substantially similar protection. Narrow grounds such as consent also work. There is no list of approved countries and no filing step. But sensitive and children's data going to a weakly protected country needs the Regulator's approval first. Fines are capped at 10 million rand and generally need a court to confirm them.

In force since 1 July 2020Enforced from 1 July 2021

Enforced by Information Regulator (South Africa)

How this country controls where data goes: No restriction · Accepted routes: Official 'this country is safe' decision, Approved group rules, Explicit consent, Needed for a contract, Government sign-off needed

Personal data must stay in the country

Official name: Tax Administration Act, 2011 section 30 read with Public Notice 787 of 1 October 2012 (electronic form of record-keeping) · Act No. 28 of 2011, s 30; GG 35733 Notice 787 · Government rules

In forceYes, with paperwork

If you keep tax records electronically, they must stay inside South Africa. The exception is written permission from the revenue service to keep them abroad. This applies to every industry. It is the most commonly missed data-location rule in the country, because it catches ordinary foreign-hosted accounting and business software.

In force since 1 October 2012

Enforced by South African Revenue Service

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact wording and current text of Public Notice 787 of 2012 on electronic record-keeping

    The revenue service serves the notice as a scanned image with no text layer. So we rely on the revenue service's own plain-language record-keeping page. That page states the authorisation requirement clearly. We rate the rule medium confidence.

  • The detailed content of Prudential Authority Directive 3 of 2018 and Guidance Note 5 of 2018 on cloud computing and offshoring

    Both are scanned documents with no readable text. What we say here comes from the central bank's own March 2025 consultation paper and Joint Communication 2 of 2025, which describe them. Rated medium confidence.

  • The incident notification deadline in Joint Standard 2 of 2024 on cybersecurity and cyber resilience

    An official joint communication confirms the standard took effect on 1 June 2025. We could not open the standard's own text on either regulator's site. The notification template was still in consultation in September 2025.

  • Whether any Minister has ever declared classes of 'critical data' or registered critical databases under Chapter 9 of the Electronic Communications and Transactions Act

    We found no such notice on government sources, checked 18 August 2026. We cannot prove that none exists. The power itself is confirmed from the Act.

  • Whether the Regulation of Interception of Communications Amendment Bill of 2023 has been enacted, and the current ministerial directive setting the telecoms retention period

    The government's document library shows only bill versions. We found no amendment act and no published directive. The three-to-five-year period is confirmed from the Act itself.

  • Data-location or server-location conditions in provincial gambling licences, and any rule for mapping or geospatial data

    Gambling is licensed province by province, and licence conditions are not published centrally. We found no official source, and no rule, checked 18 August 2026. Confidence is low. If you work in this industry, check before you rely on it.

  • Health record retention periods

    The National Health Act sets protections and criminal offences, but no retention period. The commonly cited six-year period comes from professional council guidance we could not open on an official site. The draft regulations on health and sex-life data were still not final on 18 August 2026.

  • Whether section 54 of the Cybercrimes Act has been brought into force by any proclamation after 30 November 2021

    The government document library shows only the 2021 commencement proclamation, which leaves out section 54. A later proclamation could exist and not be indexed.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.