# Automate your POPIA Compliance with CookieYes

> For the complete site index, see [llms.txt](/llms.txt). Every page is also available as Markdown: replace the trailing slash with `.md` (`/pricing/` becomes `/pricing.md`), or send `Accept: text/markdown` to the page URL itself.

> Is your business POPIA compliant? As privacy takes a firmer grip, here are the steps you can take to protect your business from legal risks.

**Source:** https://www.cookieyes.com/popia-compliance/

---

# Kickstart your POPIA compliance and avoid legal fines

Align your business with POPIA’s conditions for consent in just minutes with our end-to-end cookie consent solution.

[Become POPIA Compliant](https://app.cookieyes.com/trial?plan=pro-monthly&ref=lp_POPIA_hero)

14-day free trial Cancel anytime

![Kickstart your POPIA compliance and avoid legal fines](https://assets.cookieyes.com/popia_hero_8ecf013620.svg)

## The #1 cookie consent solution, trusted by 1.5 Million+ websites

![Decathlon](https://assets.cookieyes.com/decathlon_a23456d440.svg)

![KFC](https://assets.cookieyes.com/kfc_73dc90db22.svg)

![Dominos](https://assets.cookieyes.com/dominos_9ce9dc7569.svg)

![Heineken](https://assets.cookieyes.com/heineken_f0fca7d239.svg)

![Forbes](https://assets.cookieyes.com/forbes_b76200d4a5.svg)

![Toyota](https://assets.cookieyes.com/toyota_71a8106b6a.svg)

![Renault](https://assets.cookieyes.com/renault_d254f28337.svg)

## Check your POPIA Compliance

CookieYes will scan your website and keep you informed on the personal data your website collects through cookies.

![Cookie Scanner](https://assets.cookieyes.com/cookie_scanner_img_dbb23c8c7a.svg)

![POPIA compliance overview](https://assets.cookieyes.com/popia_launch_8951bebb38.svg)

Protection of Personal Information Act (POPIA or POPI Act) is a data protection law in South Africa that aims to regulate the processing of personal information by public and private entities. The Act seeks to protect the privacy of individuals and ensure that their personal data is processed in a fair and transparent manner. POPIA came into full effect on July 1, 2020.

## POPIA Compliance Checklist for Websites

- Obtain user consent for cookies and trackers
- Maintain a record of all user consent
- Include an accurate, up-to-date privacy policy
- Limit data collection only for legitimate purposes
- Notify data breaches to DPAs and users

## Prepare for POPIA compliance with CookieYes

### Obtain informed consent for cookies

POPIA requires that businesses process personal data only after obtaining informed consent from users and must let users withdraw consent easily.

With CookieYes you can

- Scan your website against a 100,000+ cookie database
- Display a custom cookie banner that fits your brand
- Show a consent revisit widget for users to withdraw consent

![Obtain informed consent for cookies](https://assets.cookieyes.com/cookie_banner_baeba64edd.svg)

### Put consent management in auto-pilot

As obtaining consent is a key provision in POPIA, businesses should take measures to ensure ongoing compliance with the requirements for consent and proof of consent.

With CookieYes you can

- Auto-block all third-party cookies prior to user consent
- Schedule cookie scanning for continuous compliance
- Record consent logs for proof of consent during audits

![Put consent management in auto-pilot](https://assets.cookieyes.com/consent_management_730052a633.svg)

### Generate POPIA-compliant policies

Under POPIA, businesses should implement a privacy policy to meet ‘openness’, a required condition for the processing and include information on the personal data collected, the purpose of collection, and more.

With CookieYes you can

- Use our pre-built, legally-compliant policy templates
- Generate your privacy policy and cookie policy in minutes
- Simply copy-paste the legal policies to your website

![Generate POPIA-compliant policies](https://assets.cookieyes.com/policy_generators_dc10b32d81.svg)

## Achieve cookie compliance without spending hours

[Become POPIA Compliant](https://app.cookieyes.com/trial?plan=pro-monthly&ref=lp_POPIA_center)

14-day free trial

Cancel anytime

## Learn more about POPIA and take the next step towards compliance

![What is POPIA?](https://assets.cookieyes.com/popia_icon_3f502a1c20.svg)

### What is POPIA?

The Protection of Personal Information Act (POPIA) is a South African data protection law that imposes obligations on companies for processing personal data and grants certain rights to individuals to safeguard their privacy. POPIA aims to regulate how personal information is processed by public and private bodies and to ensure that personal data is processed in a fair, lawful, and transparent manner.

![Who does POPIA apply to?](https://assets.cookieyes.com/apply_to_icon_c0205ce9f2.svg)

### Who does POPIA apply to?

POPIA or the POPI Act applies to organisations processing the personal information of South Africans. Under POPIA, personal information can be related to a “natural person” and a “juristic person” i.e. a company, partnership, or other legal entity.

POPIA also provides for certain exclusions and exemptions, including data processing for purely personal or household activities, for personal irretrievably de-identified data, or if the data processor is the State and the processing is in service of national security or the prevention of crime.

![What are consumer rights under POPIA?](https://assets.cookieyes.com/apply_to_icon_c0205ce9f2.svg)

### What are consumer rights under POPIA?

![Right to be informed](https://assets.cookieyes.com/icon_info_33ae4f8847.svg)

#### Right to be informed

The right to know about the personal data a business collects about them and how it is used and shared.

![Right to access](https://assets.cookieyes.com/icon_access_2e8b82213f.svg)

#### Right to access

The right to access personal data and to have it available in a clear and readable format, free of cost.

![Right to correct](https://assets.cookieyes.com/icon_correction_d30a9d9c52.svg)

#### Right to correct

The right to request to correct, update, or complete personal data about them.

![Right to object](https://assets.cookieyes.com/icon_object_98cb8e7c13.svg)

#### Right to object

The right to object and restrict the processing of personal data, and have information on the consequences of refusal.

![Right to opt-out of automated processing](https://assets.cookieyes.com/optout_icon_2f4f42e141.svg)

#### Right to opt-out of automated processing

The right to not be subject to a decision which is based solely on the automated processing of personal information.

![Right to complain](https://assets.cookieyes.com/icon_complain_b6a5620bca.svg)

#### Right to complain

The right to challenge an organization’s compliance with an individual accountable for the organization’s compliance.

![Right to civil action](https://assets.cookieyes.com/balance_icon_22a1a97ce0.svg)

#### Right to civil action

The right to institute a civil action for damages against an organization for breach of any provision of the Act.

![What is the penalty for non-compliance?](https://assets.cookieyes.com/apply_to_icon_c0205ce9f2.svg)

### What is the penalty for non-compliance?

POPIA outlines penalties for non-compliance, which depend on the nature and severity of the violation. The monetary fines for more serious offences can go up to ZAR10 million (approx. €490,000). Individuals responsible for serious violations may face imprisonment for up to 10 years.

For less serious offences, the maximum penalty can be imprisonment not exceeding 12 months or a reduced fine. Data subjects who suffer as a result of a violation of POPIA can also initiate civil proceedings against the organisation for damages.

## FAQ on POPIA Compliance

**What is the POPIA Act in South Africa?**

The Protection of Personal Information Act 4 of 2013 (POPI Act) is a South African law that aims to protect the personal information of individuals. The Act aims to regulate how personal information is processed and provide individuals with rights and remedies to protect their personal information. POPIA highlights eight foundational conditions that organizations must comply with in order to protect personal information.

POPIA or POPI Act took effect on July 1, 2020, and enforcement began after a 1 year grace period on July 1, 2021.

**What is personal information in POPIA?**

Personal information in POPIA is defined as "information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person." It is important to note that POPIA's definition of PI also includes a juristic person, i.e. an organization recognized by law to have rights and responsibilities like a natural person.

This information about a person includes but is not limited to demographic details like name, age, race, gender, contact information such as email address, physical address, phone number, financial, employment and educational information, medical history and biometric information.

**What are the exceptions to the POPIA Act?**

There are some exceptions to the applicability of POPI Act South Africa. It does not apply if:

- Data processing is carried out for personal or household activity,
- Data is de-identified and cannot be re-identified again
- Data processing is done by or on behalf of a public body For national security
- For the purpose of prevention, detection, and assistance in the identification of the proceeds of unlawful activities
- By the Cabinet and its committees or the Executive Council of a province
- Judicial functions of a court or
- Terrorist and related activities

**Does POPIA allow data transfer outside South Africa?**

POPIA limits the transfer of personal data outside South Africa unless at least one of the prescribed safeguards set out by the Act is met and the transfer does not put the personal information at risk of breach of confidentiality or security.

Section 72 of POPI Act sets out the conditions for the cross-border transfer of personal information. These include consent from the data subject, the recipient of the PI is subject to Binding Corporate Rules (BCRs) and processing conditions should be established "in harmony with international standards" and if the transfer is necessary to fulfil the terms of a contract.

**Who is the regulatory authority for POPIA South Africa?**

The Information Regulator is the regulatory authority for POPI Act South Africa. It is the independent statutory body established by the Act and is responsible for monitoring and enforcing POPIA compliance by public and private bodies.

The Information Regulator has the power to investigate complaints, issue fines and take legal action against non-compliant entities. It will regulate both POPIA and the Promotion of Access to Information Act or PAIA.

**Does GDPR apply to South Africa?**

The GDPR has extra-territorial scope, meaning entities outside of the EU/EEA that collect the personal data of EU/EEA residents can come under the purview of GDPR.

This means businesses in South Africa that process the personal data of EU consumers must ensure that it is adequately protected, in accordance with GDPR standards.

As POPI Act of South Africa shares many similarities to GDPR, compliance with POPIA can also be a step towards compliance with GDPR.

**Where can I find additional resources on POPIA?**

Here are some links you can refer to for additional reading:

- [Official Text of POPIA](https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf)
- [Simplified Guide on POPIA South Africa](https://www.cookieyes.com/blog/popia-south-africa/)

## Fast-track your POPIA compliance in minutes

Set up a cookie consent banner in 3 simple steps and automate your compliance.

[Become POPIA Compliant](https://app.cookieyes.com/trial?plan=pro-monthly&ref=lp_POPIA_bottom)

14-day free trial

Cancel anytime

**Form**

- Enter your website URL (`url`, text, required)

Submit: "Scan website"