Skip to content
Cyber Horizon
All frameworks

// Privacy

Protection of Personal Information Act Compliance Software

South Africa's data protection law, structured around eight conditions for lawful processing.

Framework at a glance

Short name

POPIA

Version

2021

Category

Privacy

Controls

95

What POPIA covers

95 controls across 10 domains — every one tracked, owned and evidenced in Cyber Horizon.

Chapter 3 Part A — Conditions for Lawful Processing

48 controls
  • POPIA-001 Responsible party accountability
  • POPIA-002 Lawfulness of processing
  • POPIA-003 Minimality of processing
  • POPIA-004 Justification for processing
  • POPIA-005 Consent as a basis for processing

Chapter 3 Part B — Special Personal Information

9 controls
  • POPIA-049 Prohibition on processing special personal information
  • POPIA-050 General authorisation for special personal information
  • POPIA-051 Regulator authorisation for special personal information
  • POPIA-052 Religious or philosophical beliefs
  • POPIA-053 Race or ethnic origin

Chapter 3 Part C — Children's Personal Information

3 controls
  • POPIA-058 Prohibition on processing children's personal information
  • POPIA-059 General authorisation for children's personal information
  • POPIA-060 Regulator authorisation for children's personal information

Chapter 2 — Rights of Data Subjects

7 controls
  • POPIA-061 Right to be notified of collection and of security compromises
  • POPIA-062 Right to access personal information held
  • POPIA-063 Right to request correction, destruction or deletion
  • POPIA-064 Right to object to processing
  • POPIA-065 Right to object to direct marketing

Chapter 5 — Information Officers

5 controls
  • POPIA-068 Information Officer duties and responsibilities
  • POPIA-069 Encouraging compliance and the PAIA manual
  • POPIA-070 Handling requests and cooperation with the Regulator
  • POPIA-071 Registration of the Information Officer with the Regulator
  • POPIA-072 Designation of deputy information officers

Chapter 6 — Prior Authorisation

3 controls
  • POPIA-073 Processing subject to prior authorisation
  • POPIA-074 Regulator responsibilities for prior authorisation
  • POPIA-075 Duty not to process pending authorisation

Chapter 8 — Rights re Direct Marketing, Directories & Automated Decisions

9 controls
  • POPIA-076 Consent for direct marketing by electronic communications
  • POPIA-077 Single approach to obtain consent
  • POPIA-078 Existing-customer direct marketing exception
  • POPIA-079 Sender identity and opt-out mechanism
  • POPIA-080 Notification before inclusion in directories

Chapter 9 — Transborder Information Flows

3 controls
  • POPIA-085 Conditions for transborder transfers
  • POPIA-086 Adequate protection in the recipient country
  • POPIA-087 Consent, contract and benefit grounds for transfer

Chapter 7 — Codes of Conduct

2 controls
  • POPIA-088 Issuing and content of codes of conduct
  • POPIA-089 Application, compliance and effect of codes of conduct

Chapter 10 — Enforcement

6 controls
  • POPIA-090 Complaints to the Regulator
  • POPIA-091 Investigation of complaints by the Regulator
  • POPIA-092 Assessment of compliance by the Regulator
  • POPIA-093 Enforcement notices
  • POPIA-094 Civil remedies

How Cyber Horizon automates POPIA

Every POPIA control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is Protection of Personal Information Act?

South Africa's data protection law, structured around eight conditions for lawful processing.

How many controls does Protection of Personal Information Act have?

Protection of Personal Information Act (2021) has 95 controls in Cyber Horizon's catalogue, organised across 10 domains.

How does Cyber Horizon help with Protection of Personal Information Act?

Cyber Horizon maps Protection of Personal Information Act into a shared control library alongside every other framework you run, so evidence collected once counts towards POPIA and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See POPIA mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of POPIA in Cyber Horizon.