POPIA is frequently described as applying to “all processing of personal information”. That description is incomplete. The Act contains three distinct mechanisms that can relieve a responsible party of the obligation to comply with some or all of its requirements. They operate differently, carry different procedural obligations, and have different consequences if invoked incorrectly.

This article explains what each mechanism does, who it applies to, and why confusing them is a compliance risk.

Relevant to: compliance officers, information officers, public bodies, financial sector regulators, legal practitioners, and organisations with government mandates.

The three mechanisms at a glance

POPIA limits its own reach in three ways.

The distinction between these mechanisms is not merely technical. The Regulator’s own June 2021 Guidance Note on Exemptions addresses only sections 37 and 38; it says nothing about section 6. A responsible party that does not understand the architecture of these provisions risks either overclaiming (invoking section 6 when it does not apply) or underclaiming (applying under section 37 when a simpler route exists).

Section 6: exclusions — POPIA does not apply

Section 6 removes POPIA’s application entirely for certain categories of processing. This is the most powerful of the three mechanisms because it removes all eight conditions for lawful processing, all data subject rights, and all Regulator oversight in a single step.

What section 6 covers

Section 6(1) lists five categories of excluded processing.

  • Section 6(1)(a) excludes purely personal or household activity — the family photo album, personal correspondence, domestic admin. This is the personal use exemption common to data protection frameworks globally.
  • Section 6(1)(b) excludes processing of sufficiently anonymised information — that is, information from which the data subject is no longer identifiable.
  • Section 6(1)(c) is the most consequential. It excludes processing by or on behalf of a public body that involves national security, defence, public safety, law enforcement, the prevention or detection of crime, anti-money laundering, or prosecution and execution of sentences, but only to the extent that adequate safeguards have been established in legislation. We examine this exclusion and its current constitutional limitations in our article on the POPIA national security exclusion.
  • Section 6(1)(d) excludes processing by the Cabinet and its committees, and the Executive Council of a province. Parliament deliberately excluded municipal councils from this provision — they remain fully subject to POPIA.
  • Section 6(1)(e) excludes processing for judicial functions — court proceedings, tribunals, and related activities.

The critical feature of section 6

No application is required. No Regulator notice is needed. The responsible party assesses for itself whether its processing falls within one of the section 6 categories. If it does, POPIA’s eight conditions, all data subject rights, and the Regulator’s investigative powers do not apply to that processing.

This self-assessment feature is section 6’s sharpest edge. The Information Regulator’s enforcement action against SAPS in the Krugersdorp victims’ case established that invoking section 6 incorrectly exposes the responsible party to the full force of POPIA enforcement. SAPS attempted to rely on the section 6(1)(c) national security exclusion as a blanket jurisdictional shield. The Regulator rejected this, finding that the statutory protections in the SAPS Act did not constitute adequate legislative safeguards. Section 6 is not a default protection that attaches to any security-related body.

Section 37: Regulator-granted exemptions

Section 37 operates within POPIA’s jurisdiction: it does not remove POPIA’s application, but allows a responsible party to process personal information in breach of one or more conditions for lawful processing, if the Regulator grants relief.

When section 37 applies

The Regulator may grant a section 37 exemption where either:

  1. The processing is in the public interest. POPIA defines public interest to include: the interests of national security; the prevention, detection, and prosecution of offences; important economic and financial interests of a public body; fostering compliance with legal provisions in those interests; historical, statistical, or research activity; and the special importance of freedom of expression.
  2. The processing involves a clear benefit to the data subject or a third party that outweighs, to a substantial degree, any interference with privacy.

In either case, the outweighing must be to a substantial degree: the balance must clearly favour the exemption ground, not merely tilt toward it.

What the Regulator requires

An applicant for a section 37 exemption must demonstrate specifically which conditions it seeks relief from, and why those conditions cannot be complied with. The Regulator has made clear that relief will not be granted where the impact of compliance is trivial or where the real motivation is avoiding embarrassment rather than advancing a genuine public interest.

For national security applications specifically, the Regulator requires the applicant to show: how compliance with the relevant conditions would jeopardise national security; that the processing itself is in the public interest as a safeguard for national security; and that this public interest outweighs the data subject’s privacy rights to a substantial degree.

How section 37 exemptions operate

A section 37 exemption may only be granted for specific conditions, not all eight at once. An exemption from the direct collection requirement under section 12 does not also exempt the responsible party from the purpose specification condition under section 14 or the security safeguards condition under sections 19-22.

The exemption only takes effect on the date of its publication in the Government Gazette. Until published, the responsible party must comply with all applicable conditions.

The Regulator may impose conditions on any exemption, including requirements to implement technical and organisational security measures for the information concerned. Those conditions are part of the exemption and must be complied with.

Section 38: automatic statutory exemptions

Section 38 is frequently overlooked because it requires no application and generates no formal documentation from the Regulator. It operates automatically for a specific class of processing.

What section 38 covers

Section 38 applies to processing for the purpose of discharging a “relevant function”, defined as any function of a public body, or any function conferred by law, performed with the view to protecting members of the public against:

  • financial loss due to dishonesty, malpractice, or other seriously improper conduct by, or the unfitness or incompetence of, persons in banking, insurance, investment, or other financial services, or in the management of bodies corporate; or
  • dishonesty, malpractice, or other seriously improper conduct by, or the unfitness or incompetence of, persons authorised to carry on any profession or other activity.

This is not a national security provision; instead, it’s a financial and professional regulatory provision. The Financial Sector Conduct Authority, the South African Reserve Bank, the IRBA, the HPCSA, and similar bodies are the obvious beneficiaries. An intelligence agency cannot rely on section 38.

What section 38 exempts

Processing that falls within section 38 is automatically exempt from four specific conditions: the data subject’s right to object to processing (sections 11(3) and (4)); the requirement to collect personal information directly from the data subject (section 12); the further processing compatibility requirement (section 15); and the notification obligation (section 18).

These are significant exemptions. A financial regulator investigating professional misconduct can collect information about a subject from third parties without the subject’s knowledge, process it for purposes not disclosed at collection, and need not notify the subject of that processing all without applying to the Regulator.

The documentation requirement

Unlike section 6, section 38 requires the responsible party to document its reasons for relying on the exemption. That documentation becomes material when the Regulator investigates a complaint or conducts a compliance assessment. A body that cannot produce contemporaneous documentation of why it considered section 38 to apply faces a significant evidential problem.

Why the distinction matters in practice

The accountability gap

Section 6 exclusions are self-assessed and undocumented. Section 37 exemptions are externally reviewed, Gazette-published, and conditioned. Section 38 exemptions are self-applied but require documentation and are subject to Regulator review. The accountability burden increases as you move from section 6 through section 38 to section 37.

This means a responsible party that incorrectly invokes section 6—claiming total exclusion when it does not apply—has no documentation trail and no external validation to point to when the Regulator investigates.

The national security overlap

Both section 6(1)(c) and section 37(2)(a) contemplate national security. But they operate very differently. Section 6(1)(c) removes POPIA’s application entirely for qualifying processing by public bodies—no application needed, no Regulator oversight. Section 37(2)(a) allows any responsible party (public or private) to apply to the Regulator for relief from specific conditions on national security grounds—application required, Regulator decides, conditions possible.

A private security contractor processing personal information under a government mandate cannot invoke section 6(1)(c); that provision applies to public bodies. It could apply under section 37(2)(a) if the national security public interest grounds are met. The choice of mechanism has significant compliance implications.

The partial exemption principle

Section 37 cannot grant a total exemption from all conditions. Section 6 can remove all conditions entirely. This means a responsible party that qualifies under section 6 benefits from complete removal of POPIA’s application, while a section 37 applicant receives only targeted relief from the specific conditions it applied against. Understanding which mechanism applies determines whether partial or total relief is available.

A practical decision framework

FAQs about POPIA exclusions and exemptions

An exclusion under section 6 removes POPIA’s application entirely for specific categories of processing: no conditions apply, no Regulator oversight. An exemption under section 37 or 38 operates within POPIA’s jurisdiction and provides targeted relief from specific conditions while the Act continues to apply overall.

No. Section 6(1)(c) applies only where adequate safeguards have been established in legislation for the protection of the personal information concerned. The Regulator has established, through enforcement action against SAPS, that the exclusion cannot be invoked by default. The responsible party must be able to demonstrate the statutory safeguards that apply to its specific processing.

Section 6(1)(c) applies to processing by or on behalf of a public body. A private company processing personal information under a government security mandate might qualify as acting “on behalf of” a public body, but this is legally untested. Private parties can apply for a section 37 exemption on national security grounds, subject to the Regulator’s assessment.

No, section 38 applies to functions directed at protecting the public from dishonesty or malpractice in financial services and regulated professions. It is a financial and professional regulatory provision, not a national security provision.

The responsible party remains subject to POPIA in full and is exposed to enforcement action by the Regulator. The SAPS enforcement case established this precedent. Because section 6 requires no application or documentation, an incorrect invocation leaves the responsible party with no contemporaneous record of its reasoning to present in its defence.

How ITLawCo can help

ITLawCo advises public bodies, private organisations, and legal practitioners on POPIA compliance, including which mechanism—exclusion, Regulator-granted exemption, or automatic statutory exemption—applies to specific processing activities and how to document that position correctly.

ServiceWhat we do
Exclusion and exemption analysisWe assess whether your processing qualifies under section 6, section 37, or section 38, and advise on the evidentiary basis required to rely on whichever mechanism applies.
Section 37 exemption applicationsWe prepare and submit exemption applications to the Information Regulator, including national security, law enforcement, research, and financial interest grounds.
Section 38 complianceWe advise financial sector regulators, professional oversight bodies, and other relevant function holders on the scope of the section 38 automatic exemption and the documentation required to support it.
POPIA compliance assessmentsWe review your processing operations against all applicable conditions, exclusions, and exemptions to identify where obligations apply and where they do not.
Information officer supportWe assist information officers in understanding and documenting the legal basis for each category of processing, including where exclusions or exemptions reduce or remove standard obligations.

Contact ITLawCo to discuss your organisation’s position.

This article is published by ITLawCo for general information purposes. It does not constitute legal advice and should not be relied upon as such. The law described reflects the position as at July 2025. For advice specific to your organisation’s circumstances, contact ITLawCo.

Related reading: POPIA and national security: the exclusion that requires closer scrutiny | Information Regulator 2026/27 Annual Performance Plan