Cross-Border Transfers of Special and Children’s Personal Information

When cross-border transfers of special or children’s personal information need prior authorisation

The fourth category of processing that requires prior authorisation under the Protection of Personal Information Act (POPIA) concerns the transfer of certain sensitive categories of personal information to a third party in a foreign country that does not provide an adequate level of protection. Specifically, a responsible party must obtain authorisation from the Information Regulator before transferring special personal information, or the personal information of children, to such a country.

This requirement reflects the increased risk that arises when sensitive information leaves South Africa’s legal framework and is processed under a different, and potentially weaker, set of protections.

What information is covered

Special personal information includes data relating to:

The personal information of children is also covered. In addition, the guide refers to vulnerable persons in the context of certain transfers, particularly where health or welfare-related data is involved.

When the obligation is triggered

Prior authorisation is required when this information is transferred to a third party in a foreign country that does not offer an adequate level of protection for the processing of personal information. The focus is therefore on both the nature of the information and the level of protection available in the destination country.

Practical examples are widespread. They include:

Artificial intelligence systems frequently rely on cloud processing and cross-border data flows. Where these systems process special personal information or children’s data in countries without adequate protection, the prior authorisation requirement is likely to apply.

Why this category matters

Special personal information and children’s personal information are subject to stricter conditions under POPIA precisely because of the potential harm that can arise from their misuse. Transferring such information to a jurisdiction with weaker safeguards increases the risk that data subjects will not enjoy equivalent protection. The prior authorisation process allows the Information Regulator to examine whether the proposed transfer is lawful and whether appropriate measures are in place.

The role of the Personal Information Impact Assessment

A thorough Personal Information Impact Assessment is essential before an application is submitted. The Regulator will investigate the lawfulness of the processing. The assessment should therefore examine the nature of the information being transferred, the purpose of the transfer, the identity and location of the recipient, the risks to data subjects, and the safeguards that will be applied. Applications that lack this level of analysis are more likely to encounter delay or refusal.

Governance considerations

From a governance perspective, cross-border transfers of sensitive information fall squarely within the accountability expectations associated with King V. Boards are required to oversee data and technology risks, including those that arise from reliance on foreign infrastructure and service providers. Evidence that higher-risk transfers have been identified, assessed and submitted for prior authorisation where required supports the demonstration of responsible oversight.

Consequences of non-compliance

Transferring special personal information or children’s personal information to a country without adequate protection without the required authorisation is an offence. Continuing with the transfer after notification but before the Regulator has completed its investigation is also an offence. Both can attract fines, imprisonment, or administrative penalties of up to R10 million.

Organisations that rely on foreign cloud services, international research partnerships, global IT platforms or AI systems processing sensitive South African data need to examine these arrangements carefully. Where the conditions in Section 57 are met, prior authorisation is a legal prerequisite. Meeting it effectively depends on early identification of relevant transfers and a clear, well-documented assessment of the privacy risks involved.