POPIA vs GDPR: Key Differences for SA Website Owners
They look similar and are not. Consent, lawful grounds, penalties and breach reporting all differ, and reusing a GDPR policy will leave you exposed.
Similar enough to be dangerous
POPIA was drafted with European data protection law in view, and the family resemblance is real. That is precisely the problem. The similarity tempts South African businesses into using a GDPR policy with the names changed, and the places where the two diverge are exactly the places that then go wrong.
This is what actually differs, and what it means for a South African site.
POPIA protects companies, not just people
The single largest structural difference. GDPR protects natural persons. POPIA protects both natural and juristic persons, so information about a company, a trust or a close corporation is personal information here in a way it simply is not in Europe.
That has practical consequences a European template never contemplates. Your B2B contact database is regulated. A company's banking details, its contact people, and its trading history are personal information belonging to the company itself. If you sell to businesses and imported a GDPR policy, your policy does not describe the majority of what you actually process.
Direct marketing: the difference is narrower than usually claimed
You will often read that GDPR requires opt-in for everything while POPIA allows opt-out for customers. That overstates it in both directions.
Both regimes have an existing customer exception. Europe's soft opt-in, under the ePrivacy rules, lets you market similar products to someone who bought from you and was given a chance to object. POPIA's section 69(3) is materially the same idea, with its own conditions.
The genuine POPIA-specific point is section 69(2), which has no clean European equivalent: you may approach a non-customer once, in a prescribed form, to ask for consent. That form is Form 4 of the Regulations, and a request must substantially comply with it. So cold outreach is not flatly prohibited here, it is tightly formalised. See is cold emailing legal in South Africa.
The other divergence: POPIA's section 69 covers electronic communication, meaning stored messages. Live phone calls fall outside it and sit under the Consumer Protection Act instead.
Breach notification: no 72 hour rule here
GDPR gives you 72 hours to notify the supervisory authority. POPIA gives no deadline at all. Section 22 requires notification to the Regulator and to affected data subjects as soon as reasonably possible after discovering the compromise.
Less obvious, and more often wrong in practice, is that the contents of the notice differ. POPIA's section 22(5) requires the possible consequences, the measures you have taken or intend to take, a recommendation of what the person should do, and the identity of the unauthorised person if you know it. It does not ask for the approximate number of people affected, which GDPR does. A template built on the European list is answering the wrong question.
POPIA also permits notification by any one of several routes, including a prominent notice on your website, where GDPR expects individual communication in most cases. See your POPIA breach response plan.
Penalties work differently, not just at a different scale
The usual comparison is 20 million euros against R10 million. The amounts are the least interesting part.
Under GDPR a supervisory authority can fine you for the infringement itself. Under POPIA the R10 million administrative fine sits at the end of a ladder: investigation, then an enforcement notice, and a fine only if you fail to comply with that notice. The fine attaches to ignoring the Regulator rather than to the original mistake, which gives a South African business a step at which a problem is still fixable.
POPIA also carries criminal offences, up to ten years for things like obstructing the Regulator or unlawfully dealing in account numbers, which has no real GDPR analogue. And under section 99 a data subject may claim civil damages whether or not there was intent or negligence. See POPIA fines and penalties.
Other differences that catch people out
- The Information Officer is not a DPO. Under POPIA the head of the organisation holds the role by default, and must be registered with the Regulator before taking up duties. GDPR only requires a data protection officer in defined cases, and does not require registration.
- PAIA has no European equivalent. Every private body in South Africa needs a section 51 manual, including sole traders. Nothing in a GDPR compliance programme will tell you this. See PAIA manual requirements.
- Prior authorisation. Section 57 requires authorisation from the Regulator before certain processing, including processing criminal behaviour information on behalf of third parties. GDPR's prior consultation is a narrower and different mechanism.
- Lawful grounds are similar but not identical. Both list six, but POPIA's are worded differently and the phrasing matters when you are justifying a decision. Quoting GDPR's wording in a POPIA policy is a common tell.
Does GDPR compliance make you POPIA compliant?
No, and this is the assumption worth dismantling, because it is comforting and wrong.
A GDPR programme gives you a genuine head start on structure: lawful grounds, a records-of-processing habit, security thinking, a breach process, respect for data subject rights. Those transfer.
What it will not give you is the parts POPIA has and Europe does not. A GDPR-compliant business operating in South Africa can still have no PAIA manual, an unregistered Information Officer, a privacy notice that ignores juristic persons entirely, a breach template asking the wrong questions, and no idea that section 57 exists. Every one of those is a gap the European framework never prompts you to look for.
If you serve customers in both jurisdictions you have to satisfy both. Start from POPIA for your South African operations and treat GDPR as an additional layer, rather than assuming the European work has already covered you.
POPIA Ready generates documents drafted for South African law rather than adapted from European templates, free to preview. The free checklist will show you which of the SA-specific gaps apply to you.
General guidance on South African law as at August 2026, not legal advice. Whether GDPR applies to you at all depends on your activities in the EU, and that question deserves a professional opinion.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview