What responsible parties can expect when applying for prior authorisation
Once a responsible party determines that planned processing falls within one of the categories requiring prior authorisation under the Protection of Personal Information Act (POPIA), a formal application must be submitted to the Information Regulator. The process that follows is structured and time-bound. Understanding it is essential, because the responsible party may not proceed with the processing until the Regulator has completed its investigation or has indicated that a more detailed investigation will not be conducted.
The Information Regulator has published a prescribed form that must be used to notify it of processing that requires prior authorisation. At present, the primary electronic channel for submission is email to the designated address. Applications may also be submitted by post or by hand at the Regulator’s physical address.
The quality of the submission matters. Because the Regulator will investigate the lawfulness of the proposed processing, the application should be supported by a thorough Personal Information Impact Assessment and should clearly address the relevant conditions for lawful processing under POPIA. Incomplete or poorly prepared applications increase the likelihood of delay.
On receipt of the form, the Regulator records the request on its system and issues an acknowledgement, usually by email or letter, containing a reference number for the application.
The responsible party must then suspend the processing activity that is subject to prior authorisation. Processing may not continue until the Regulator has either completed its investigation or confirmed that a more detailed investigation will not be conducted.
Within four weeks of the notification, the Regulator must inform the responsible party in writing whether or not it intends to conduct a more detailed investigation. Two outcomes are possible at this stage:
If the Regulator elects to conduct a more detailed investigation, it must inform the responsible party in writing of the reasonable period within which it plans to complete that investigation. This period may not exceed thirteen weeks.
During this time, the processing remains suspended. If the responsible party has properly suspended the processing and has not received a decision within the thirteen-week period, it may presume a decision in its favour and continue with the processing.
At the end of the investigation, the Regulator must issue a written statement to the responsible party concerning the lawfulness of the processing.
If the Regulator finds that the processing is lawful, the responsible party may proceed in accordance with that finding. If the Regulator finds that the processing is unlawful, it may serve an enforcement notice. The notice will set out the nature of the interference with the protection of personal information and the reasons for that conclusion. It may require the responsible party to:
The process is designed to give the Regulator an opportunity to examine higher-risk processing before it begins. For responsible parties, this means that early identification of activities requiring prior authorisation is essential. Leaving the application until late in a project lifecycle can result in significant delay, particularly if a detailed investigation is triggered.
This is especially relevant for digital and artificial intelligence systems that involve the reuse of unique identifiers, biometric processing, credit-related profiling, or cross-border transfers of special or children’s personal information. These activities often fall within the prior authorisation categories and may attract closer scrutiny.
From a governance perspective, the process also supports accountability under King V. Boards overseeing higher-risk data and technology activities need visibility of regulatory engagements that can affect the organisation’s ability to proceed with planned processing. Clear records of applications submitted, timelines observed, and decisions received form part of that oversight.
The prior authorisation process is procedural, but its consequences are practical. Organisations that understand the steps, respect the suspension requirement, and support their applications with proper assessments are better placed to navigate it efficiently and to avoid the significant penalties associated with non-compliance.