An introduction to prior authorisation under POPIA and why it matters for responsible parties
The Protection of Personal Information Act (POPIA) contains a specific mechanism designed to give the Information Regulator advance notice of certain high-impact processing activities. This mechanism is known as prior authorisation. It applies to a limited set of processing operations that the legislature regarded as carrying a heightened risk to the rights of data subjects.
Prior authorisation is not a general approval process for all processing of personal information. It is a targeted requirement that applies only when a responsible party plans to carry out one of the specific activities listed in Section 57 of the Act. In these cases, the responsible party must notify the Information Regulator and may not proceed with the processing until the Regulator has completed its investigation or has indicated that a more detailed investigation will not be conducted.
The underlying purpose is protective. Certain forms of processing have the potential to affect data subjects in significant ways — for example, by linking previously separate identifiers, by examining past conduct, by generating credit profiles, or by transferring sensitive information to countries that do not offer comparable protection. The prior authorisation process gives the Regulator an opportunity to examine the lawfulness of that processing before it begins.
This requirement sits alongside the broader duties of Information Officers. Among those duties is the obligation to ensure that a Personal Information Impact Assessment is conducted so that adequate measures exist to comply with the conditions for lawful processing. A well-prepared assessment is particularly important when prior authorisation is required, because the Regulator will investigate the lawfulness of the proposed processing. Incomplete or poorly reasoned applications increase the likelihood of delay or refusal.
The practical effect of the rule is that responsible parties must identify relevant processing activities early. This is not always straightforward. Modern digital systems, including those that use artificial intelligence, frequently involve the reuse of identifiers, the combination of datasets, automated profiling, biometric processing, or reliance on cloud infrastructure located outside South Africa. Many of these activities fall squarely within the categories that trigger prior authorisation.
From a governance perspective, the requirement also carries weight under King V. Boards are expected to oversee data, information and technology in a way that maintains accountability and manages risk. Processing that requires prior authorisation is, by definition, processing that the law regards as higher risk. Evidence that such activities have been properly identified, assessed and, where necessary, submitted to the Regulator forms part of the practical demonstration of that oversight.
Failure to comply carries significant consequences. Processing without the required authorisation, or continuing to process before the Regulator has completed its investigation, constitutes an offence. The same applies to non-compliance with a statement issued by the Regulator after investigation. Penalties can include fines, imprisonment, or administrative fines of up to R10 million.
Prior authorisation is therefore both a legal requirement and a governance signal. It marks certain processing activities as requiring heightened attention. Organisations that treat it merely as an administrative notification risk underestimating its purpose. Those that integrate it into their privacy and project processes — supported by proper impact assessments and clear accountability — are better placed to meet their obligations under POPIA and to demonstrate responsible oversight of higher-risk processing activities.
The mechanism exists to protect data subjects from processing that carries particular risk. Meeting it effectively depends on early identification, careful assessment, and a clear understanding of when the obligation is triggered.