# Protection of Personal Information Act (Act 4 of 2013)

Framework id: `popia`. Data Protection. Publisher: Republic of South Africa. Version: 2013 (effective 2021). Region: South Africa. Mapping licence: CC BY-SA 4.0.
Source text: https://www.gov.za/documents/protection-personal-information-act

Each line is a clause, the NIST SP 800-53 controls OSA maps to it, and OSA's estimate of how far those controls cover it.
Clause titles and coverage figures are OSA's own summaries and estimates. No line-by-line check against the source text is recorded for this framework, so quote the source, not this card.

## Clauses (30, average coverage 30%)
- s5 Rights of data subjects: PT-01, PT-04, PT-05, PT-06 (25%)
- s8 Condition 1 — Accountability: PT-01, PM-01, PM-02, PM-03, PM-09, AU-01, AU-02, CM-13, PL-01 (45%)
- s9 Condition 2 — Lawfulness of processing: PT-01, PT-02 (20%)
- s10 Condition 2 — Minimality: AC-06, PT-07, CM-12 (50%)
- s11 Condition 2 — Consent, justification and objection: PT-02, PT-04 (25%)
- s12 Condition 2 — Collection directly from data subject: PT-05 (20%)
- s13 Condition 3 — Collection for a specific purpose: PT-01, PT-03, PT-05, CM-13 (50%)
- s14 Condition 3 — Retention and restriction of records: AU-11, SI-12, CM-12, MP-06 (55%)
- s15 Condition 4 — Further processing limitation: PT-03, PT-07, CM-13 (35%)
- s16 Condition 5 — Information quality: SI-01, SI-06, SI-07, SI-10, SI-18 (45%)
- s17 Condition 6 — Documentation by responsible party: AU-01, AU-02, CM-08, CM-12, CM-13, RA-02, PL-02 (50%)
- s18 Condition 6 — Notification to data subject when collecting personal information: AC-08, PT-05 (30%)
- s19 Condition 7 — Security measures on integrity and confidentiality of personal information: AC-01, AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AU-01, AU-02, AU-06, AU-09, CA-01, CA-02, CA-07, CM-01, CM-02, CM-03, CM-06, CM-07, CP-01, CP-02, CP-09, CP-10, IA-01, IA-02, IA-04, IA-05, IR-01, IR-04, MA-01, MA-02, MP-01, MP-02, MP-04, MP-06, PE-01, PE-02, PE-03, PL-01, PL-02, PM-01, PM-09, PS-01, PS-03, PS-06, RA-01, RA-03, RA-05, RA-07, SC-01, SC-07, SC-08, SC-12, SC-13, SC-28, SI-01, SI-02, SI-03, SI-04, SI-07 (90%)
- s20 Condition 7 — Information processed by operator: SA-09, PS-07, SR-01, SR-02, SR-03 (55%)
- s21 Condition 7 — Security measures regarding information processed by operator: SA-04, SA-09, SR-01, SR-02, SR-03, SR-05 (60%)
- s22 Condition 7 — Notification of security compromises: IR-01, IR-02, IR-04, IR-05, IR-06, IR-07, IR-08, IR-09, AU-06 (55%)
- s23-24 Condition 8 — Access to personal information and correction of personal information: PT-06, SI-18 (20%)
- s25 Condition 8 — Manner of access: PT-06 (15%)
- s26-27 Prohibition on processing special personal information — general authorisation: AC-16, PT-01, PT-03, PT-07 (25%)
- s28-33 Authorisation for processing specific categories of special personal information: PT-07, AC-16 (15%)
- s34-35 Processing of personal information of children: PT-04, PT-07 (15%)
- s55 Information officer — duties and responsibilities: PM-02, PS-09 (20%)
- s56 Deputy information officers — designation and delegation: PS-09 (15%)
- s57-59 Prior authorisation by Information Regulator: CA-06, PT-02 (10%)
- s69 Direct marketing by means of unsolicited electronic communications: PT-04, PT-05 (15%)
- s70 Directories: PT-05 (10%)
- s71 Automated decision-making: PT-08 (10%)
- s72 Transborder information flows — transfers outside the Republic: AC-04, SA-09, SC-07 (10%)
- s73-99 Enforcement — complaints, investigations, and regulatory powers: AU-06, IR-06 (5%)
- s100-109 Offences, penalties, and administrative fines: no control mapped (0%)

## More
- A pattern's controls with their clauses in this framework: /api/v1/patterns/{id}/crosswalk?framework=popia
- Control-to-clause mappings as JSON: /api/v1/frameworks/popia?fields=mappings&per_page=100
- Rationale and gaps for each clause, as JSON: https://raw.githubusercontent.com/opensecurityarchitecture/osa-data/main/data/framework-coverage/popia.json
- Page for people: /frameworks/popia/
