The four categories of processing that trigger prior authorisation under Section 57
Under the Protection of Personal Information Act (POPIA), prior authorisation is required only for specific categories of processing. Section 57 sets out four situations in which a responsible party must obtain authorisation from the Information Regulator before the processing may begin. These categories reflect activities that the legislature regarded as carrying a heightened risk to the rights of data subjects.
Understanding the scope of each category is essential. Organisations that fail to recognise when the obligation is triggered risk committing an offence by proceeding without authorisation or by continuing to process while an investigation is under way.
The first category applies when a responsible party plans to process any unique identifier of a data subject for a purpose other than the one for which it was specifically collected, and with the aim of linking that information with information processed by other responsible parties.
A unique identifier is any data element that distinguishes a data subject from others within a group. Examples include identity numbers, account numbers, employee numbers, IP addresses, device identifiers, biometric templates, cookie identifiers, location data, and combinations of personal attributes.
This category is particularly relevant in modern digital environments. Systems that reuse identifiers for access control, fraud prevention, online advertising, cross-device tracking, federated identity services, or artificial intelligence applications often involve secondary purposes and data linking. Facial recognition systems, lifestyle monitoring platforms, and data aggregation tools frequently fall within this description.
Where authorisation is granted, the unique identifier may only be processed under appropriate safeguards.
The second category applies when a responsible party processes information on criminal behaviour or on unlawful or objectionable conduct on behalf of third parties. This includes reference checks relating to past conduct or disciplinary action taken against a data subject.
Examples include criminal record enquiries, fraud detection and prevention services, reference checks for employment or other purposes, and research into unlawful or objectionable conduct. Processing of this nature can have significant consequences for individuals, which is why the law requires prior scrutiny by the Regulator.
The third category covers the processing of information for the purposes of credit reporting. This includes the creation of credit reports based on personal payment history, lending activity and creditworthiness, which are then used by lenders or credit providers to assess a data subject’s creditworthiness.
Credit bureaux and any person processing personal information for credit reporting purposes fall within this category. The activities involved — accepting consumer credit information, verifying accuracy, retaining records, issuing reports, and developing credit scoring systems — are closely regulated under both POPIA and the National Credit Act.
The fourth category applies when special personal information, or the personal information of children, is transferred to a third party in a foreign country that does not provide an adequate level of protection for the processing of personal information.
Special personal information includes data relating to religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour. Transfers of children’s personal information to countries without adequate protection also trigger the requirement.
This category has wide practical application. Cloud computing services, data backup solutions, international research collaborations, health-related platforms, and AI systems that process special or children’s information outside South Africa may all fall within its scope if the destination country lacks adequate protection.
These four categories are not exhaustive descriptions of high-risk processing. They are the specific triggers that require prior authorisation. Many contemporary systems — particularly those involving artificial intelligence, biometric processing, large-scale data linking, or cross-border infrastructure — engage one or more of them.
From a governance perspective, the obligation carries weight under King V. Boards are expected to oversee data and technology risks with appropriate accountability. Processing that requires prior authorisation is, by definition, processing that the law regards as higher risk. Identifying these activities early and ensuring that proper assessments are completed forms part of responsible oversight.
The starting point for compliance is accurate recognition of when the requirement applies. Organisations that map their processing activities against these four categories are better placed to meet their obligations, to prepare meaningful Personal Information Impact Assessments, and to avoid the significant consequences of proceeding without the required authorisation.