{"id":3800,"date":"2026-03-06T13:02:51","date_gmt":"2026-03-06T13:02:51","guid":{"rendered":"https:\/\/itlawco.com\/?p=3800"},"modified":"2026-03-06T13:06:35","modified_gmt":"2026-03-06T13:06:35","slug":"popia-health-data-regulations-2026","status":"publish","type":"post","link":"https:\/\/itlawco.com\/fr\/popia-health-data-regulations-2026\/","title":{"rendered":"POPIA health data regulations 2026: What you need to know"},"content":{"rendered":"\n\t\t<div id=\"fws_6a60619d6ef02\"  data-column-margin=\"default\" data-midnight=\"dark\"  class=\"wpb_row vc_row-fluid vc_row\"  style=\"padding-top: 0px; padding-bottom: 0px; \"><div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\"><div class=\"inner-wrap row-bg-layer\" ><div class=\"row-bg viewport-desktop\"  style=\"\"><\/div><\/div><\/div><div class=\"row_col_wrap_12 col span_12 dark left\">\n\t<div  class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \"  data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\" >\n\t\t<div class=\"vc_column-inner\" >\n\t\t\t<div class=\"wpb_wrapper\">\n\t\t\t\t\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p><strong>Key takeaway:<\/strong> The <a href=\"https:\/\/inforegulator.org.za\/\">Information Regulator<\/a>\u2019s <em>Regulations relating to the Processing of Data Subjects&#8217; Health Information by Certain Responsible Parties, 2026<\/em> came into force today, 6 March 2026. They are binding, immediate, and enforceable. Eight categories of organisations\u2014including employers, insurers and medical schemes\u2014must now comply with explicit obligations around lawful processing, security safeguards, and cross-border data transfers.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">What are these regulations and why do they matter?<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">South Africa has, for some time, had the architecture for robust health data protection under the <a href=\"https:\/\/www.gov.za\/documents\/protection-personal-information-act\">Protection of Personal Information Act, 2013 (POPIA)<\/a>. What has sometimes been lacking is sector-specific clarity about what that protection demands in practice.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Today, the Information Regulator closes that gap. Published in Government Gazette No. 54268 (Notice No. 7198) and signed by Chairperson Adv Pansy Tlakula on 27 February 2026, the <em>Regulations relating to the Processing of Data Subjects&#8217; Health Information by Certain Responsible Parties, 2026<\/em> (the Regulations) are issued under section 112(2)<em>(c)<\/em> of POPIA. They operationalise section 32(6) of the Act and represent the most substantive sector-specific rules the Regulator has published since POPIA&#8217;s commencement provisions came into effect.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">They came into force today. There is no grace period.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Who is covered?<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The Regulations apply to eight categories of responsible party and their applicable operators:<\/p>\n<ol class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\">Insurance companies<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Medical schemes<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Medical scheme administrators<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Managed healthcare organisations<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Administrative bodies<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Pension funds<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Employers<\/li>\n<li class=\"whitespace-normal break-words pl-2\">Institutions working on behalf of employers, administrative bodies or pension funds<\/li>\n<\/ol>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The inclusion of <strong>employers<\/strong> is particularly significant. Many organisations routinely collect, store and act on employee health data\u2014through sick leave management, occupational health programmes, disability assessments and return-to-work processes\u2014without applying the same rigour as a medical scheme or insurer. The Regulations place employers squarely within the same compliance framework as sophisticated financial services entities.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">What do the Regulations require?<\/h2>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">A lawful basis for every instance of processing (Regulation 4)<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Responsible parties may not process health information (or other special personal information such as race, religion or biometrics) unless the requirements of <strong>section 27 of POPIA<\/strong> are satisfied. That section permits processing of special personal information only in narrowly defined circumstances. Consent is one, but not the only, ground.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">A general company policy acknowledging that health data will be collected is not sufficient. Each instance of processing must be mapped to an identifiable, documented ground of justification.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Explicit security safeguards (Regulation 5)<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Responsible parties must maintain the <strong>confidentiality, integrity and availability<\/strong> of health information in their possession or control. The required safeguards have two specific dimensions.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Security and confidentiality of records<\/strong> \u2014 measures must address risks associated with both physical records (paper files, printed reports) and electronic ones (databases, cloud storage, email). Many organisations have modernised their electronic security posture while leaving physical records handling surprisingly casual. Both must now be addressed.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\"><strong>Proper disposal<\/strong> \u2014 health records must be disposed of in a manner that prevents any reasonably foreseeable unauthorised access or disclosure after the information is no longer needed. Deletion protocols, paper shredding policies and archive management practices all fall under scrutiny here.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Processing must also occur under a <strong>duty of confidentiality<\/strong> \u2014 whether arising from legislation, a professional code, an employment relationship or a written agreement, as contemplated in section 32(2) of POPIA. This is a notable requirement for employers and pension funds, which may not traditionally have regarded their health data handling as governed by the same confidentiality norms that apply to a registered nurse or medical scheme administrator.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Finally, technical and organisational measures must align with <strong>generally accepted information security practices<\/strong> applicable to the responsible party&#8217;s own sector or industry, as contemplated in section 19 of POPIA. This is a contextualised standard: a large insurer will be held to practices appropriate for financial services; a small employer to a standard proportionate to its size and context.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">Cross-border transfer restrictions (Regulation 6)<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Health data may not be transferred to third parties in foreign countries unless one or more of the conditions in <strong>section 72(1) of POPIA<\/strong> are met. Those conditions include, among others, the data subject&#8217;s consent, a binding agreement between the parties, or the recipient country having comparable data protection laws in place.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">This restriction has immediate practical consequences for multinational employers who transmit employee health or disability data to offshore HR systems, and for insurers who rely on international reinsurers or processing partners.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">What does this mean for your organisation?<\/h2>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">For employers<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Employment law has always required some engagement with employee health information. What changes is the formalisation of the obligation to process that information with documented justification, under confidentiality obligations, with appropriate security controls, and with a clear disposal policy.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">HR policies and employment contracts should be reviewed. Occupational health service providers retained by employers are likely \u201coperators\u201d within the meaning of POPIA and should be subject to written operator agreements that impose equivalent obligations.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">For insurers and pension funds<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Underwriting and claims processes necessarily involve the collection and assessment of health information. The Regulations reinforce existing POPIA obligations but add specificity around security controls and cross-border transfer restrictions that should be assessed against existing data flows. Processing by third-party claims assessors, medical advisers and reinsurers deserves particular attention.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">For medical schemes and their administrators<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">These entities have long operated under the Medical Schemes Act, 1998 (Act No. 131 of 1998) and its regulations, and many have mature data governance frameworks. The new POPIA Regulations are largely complementary but introduce explicit disposal and cross-border transfer requirements that should be assessed against current practices, particularly for schemes using offshore administration platforms or technology providers.<\/p>\n<h3 class=\"text-text-100 mt-2 -mb-1 text-base font-bold\">For managed healthcare organisations<\/h3>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">The clinical nature of managed care means health data is processed at high volume and often shared across multiple parties: schemes, treating providers, pharmaceutical benefit managers. Each data flow should be assessed for POPIA compliance, and managed care contracts should reflect the confidentiality and security obligations now codified in the Regulations.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>FAQs<\/h2>\n<\/div>\n\n\n\n<div class=\"toggles \" data-br=\"none\" data-starting=\"default\" data-style=\"default\"><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60619d712dc\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60619d712dc\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Do these Regulations apply immediately?<\/a><\/h3><div id=\"toggle-panel-6a60619d712dc\" role=\"region\" aria-labelledby=\"toggle-button-6a60619d712dc\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes. Regulation 7.2 states that the Regulations commence on the date of publication in the <em>Gazette<\/em> \u2014 today, 6 March 2026. There is no transitional period.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60619d717ff\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60619d717ff\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What is \u201chealth information\u201d under the Regulations?<\/a><\/h3><div id=\"toggle-panel-6a60619d717ff\" role=\"region\" aria-labelledby=\"toggle-button-6a60619d717ff\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>The Regulations define \u201chealth information\u201d as personal information relating to the physical and\/or mental health of a data subject, including the provision of healthcare services and any testing, treatment and diagnosis which reveals information about the data subject&#8217;s health status.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60619d71caf\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60619d71caf\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Does this apply if we only process employee sick leave records?<\/a><\/h3><div id=\"toggle-panel-6a60619d71caf\" role=\"region\" aria-labelledby=\"toggle-button-6a60619d71caf\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes. Employers are explicitly listed as responsible parties within scope. Sick leave records, occupational health assessments, disability documentation and return-to-work records all constitute health information under the Regulations.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60619d72111\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60619d72111\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Can health information be shared with an offshore parent company?<\/a><\/h3><div id=\"toggle-panel-6a60619d72111\" role=\"region\" aria-labelledby=\"toggle-button-6a60619d72111\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Only if one or more of the conditions in section 72(1) of POPIA are met. Transfers solely on the basis of group policy or operational convenience are unlikely to satisfy the requirements without additional steps such as obtaining the data subject&#8217;s consent or putting binding transfer agreements in place.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60619d72540\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60619d72540\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What are the penalties for non-compliance?<\/a><\/h3><div id=\"toggle-panel-6a60619d72540\" role=\"region\" aria-labelledby=\"toggle-button-6a60619d72540\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>The Information Regulator may issue compliance notices and administrative fines of up to R10 million. Serious cases may result in criminal prosecution of responsible individuals under POPIA.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a60619d72968\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a60619d72968\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What is a \u201cresponsible party\u201d versus an \u201coperator\u201d?<\/a><\/h3><div id=\"toggle-panel-6a60619d72968\" role=\"region\" aria-labelledby=\"toggle-button-6a60619d72968\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>A responsible party determines the purpose and means of processing. An operator processes information on behalf of a responsible party. The Regulations apply to responsible parties and their applicable operators. Operators are typically bound through written operator agreements that mirror the responsible party&#8217;s obligations.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><\/div>\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">The enforcement outlook<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">One of the stated purposes of the Regulations is to give the Information Regulator a clearer enforcement framework. Until today, enforcement of health data obligations under POPIA required the Regulator to reason from general principles. These Regulations draw a more precise line.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Non-compliant organisations face the Regulator&#8217;s full enforcement toolkit. Given the Regulator\u2019s stated commitment to enforcement and the public sensitivity of health data, compliance should be treated as an immediate operational priority rather than a medium-term project.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">Five steps to take today<\/h2>\n<ol class=\"&#091;li_&amp;&#093;:mb-0 &#091;li_&amp;&#093;:mt-1 &#091;li_&amp;&#093;:gap-1 &#091;&amp;:not(:last-child)_ul&#093;:pb-1 &#091;&amp;:not(:last-child)_ol&#093;:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3\">\n<li class=\"whitespace-normal break-words pl-2\"><strong>Map<\/strong> all health data flows within your organisation and to third parties, including operators and offshore recipients.<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Review<\/strong> the legal basis for each category of processing activity and document it.<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Audit<\/strong> physical and electronic security controls against sector-appropriate standards.<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Update<\/strong> disposal and retention policies to address both digital deletion and physical destruction.<\/li>\n<li class=\"whitespace-normal break-words pl-2\"><strong>Check<\/strong> cross-border transfers for compliance with section 72(1) of POPIA and put transfer agreements in place where required.<\/li>\n<\/ol>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2 class=\"text-text-100 mt-3 -mb-1 text-&#091;1.125rem&#093; font-bold\">How ITLawCo can help<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">ITLawCo advises employers, insurers, medical schemes and financial services entities on POPIA compliance, data governance and regulatory risk. The table below maps the Regulations&#8217; key obligations to ITLawCo&#8217;s service offering.<\/p>\n<div class=\"overflow-x-auto w-full px-2 mb-6\">\n<table class=\"min-w-full border-collapse text-sm leading-&#091;1.7&#093; whitespace-normal\">\n<thead class=\"text-left\">\n<tr>\n<th class=\"text-text-100 border-b-0.5 border-border-300\/60 py-2 pr-4 align-top font-bold\" scope=\"col\">Obligation under the Regulations<\/th>\n<th class=\"text-text-100 border-b-0.5 border-border-300\/60 py-2 pr-4 align-top font-bold\" scope=\"col\">How ITLawCo can help<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Lawful basis assessment (Reg 4)<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Review and document the legal grounds for each category of health data processing across your organisation, including consent frameworks and legitimate interest assessments.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Processing inventory and data mapping<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Conduct a health data flow mapping exercise to identify what is collected, how it is used, where it is stored, and with whom it is shared.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Security safeguards \u2014 policy and procedure (Reg 5)<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Draft or update information security policies, records management procedures and data classification frameworks aligned to POPIA and sector-specific standards.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Security safeguards \u2014 physical and electronic records<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Advise on security controls for both physical and electronic health records, including access controls, encryption, and secure storage practices.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Disposal and retention (Reg 5.2.2)<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Design retention schedules and secure disposal protocols for health records in both digital and physical formats.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Confidentiality obligations (Reg 5.3)<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Draft confidentiality clauses for employment contracts, operator agreements and professional services arrangements.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Operator agreements<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Prepare POPIA-compliant operator agreements for occupational health providers, managed care organisations, claims assessors and other third-party processors.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Cross-border transfer compliance (Reg 6)<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Assess offshore data flows, identify transfers requiring justification under section 72(1) of POPIA, and draft transfer agreements or consent mechanisms where required.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Regulator engagement and enforcement response<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Advise on responses to Information Regulator enquiries, compliance notices or investigations arising from health data processing.<\/td>\n<\/tr>\n<tr>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\"><strong>Training and awareness<\/strong><\/td>\n<td class=\"border-b-0.5 border-border-300\/30 py-2 pr-4 align-top\">Deliver targeted training for HR, occupational health, compliance and IT teams on their obligations under the Regulations.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">To discuss your organisation&#8217;s compliance position, <a href=\"https:\/\/itlawco.com\/contact-us\/\">contact us<\/a>.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>End thoughts<\/h2>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">Privacy law without enforcement is aspiration. What these Regulations signal is that South Africa is moving beyond aspiration toward accountability \u2014 at least in the domain of health data. The obligations are not new in spirit; they are new in specificity, and that distinction matters when the Regulator comes knocking.<\/p>\n<p class=\"font-claude-response-body break-words whitespace-normal leading-&#091;1.7&#093;\">For regulated entities, the message is as clear as the law now is: the time to act is today.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p><em>This article is for informational purposes only and does not constitute legal advice. Organisations should seek guidance from qualified legal counsel regarding their specific compliance obligations under the Protection of Personal Information Act, 2013, and these Regulations. Health data matters are treated with strict confidentiality in all professional engagements.<\/em><\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<div class=\"_df_book df-lite\" id=\"df_3805\"  _slug=\"regulations-relating-to-the-processing-of-data-subjects-health-information-by-certain-responsible-parties-2026-popia\" data-title=\"regulations-relating-to-the-processing-of-data-subjects-health-information-by-certain-responsible-parties-2026-popia\" wpoptions=\"true\" thumbtype=\"\" ><\/div><script class=\"df-shortcode-script\" nowprocket type=\"application\/javascript\">window.option_df_3805 = {\"outline\":[],\"autoEnableOutline\":\"false\",\"autoEnableThumbnail\":\"false\",\"overwritePDFOutline\":\"false\",\"direction\":\"1\",\"pageSize\":\"0\",\"source\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/InfoRegSA-regulations-health-data.pdf\",\"wpOptions\":\"true\"}; if(window.DFLIP && window.DFLIP.parseBooks){window.DFLIP.parseBooks();}<\/script>\n<\/div>\n\n\n\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t<div id=\"fws_6a60619d75110\"  data-column-margin=\"default\" data-midnight=\"dark\"  class=\"wpb_row vc_row-fluid vc_row\"  style=\"padding-top: 0px; padding-bottom: 0px; \"><div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\"><div class=\"inner-wrap row-bg-layer\" ><div class=\"row-bg viewport-desktop\"  style=\"\"><\/div><\/div><\/div><div class=\"row_col_wrap_12 col span_12 dark left\">\n\t<div  class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \"  data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\" >\n\t\t<div class=\"vc_column-inner\" >\n\t\t\t<div class=\"wpb_wrapper\">\n\t\t\t\t\n\t<div class=\"wpb_raw_code wpb_raw_html wpb_content_element\" >\n\t\t<div class=\"wpb_wrapper\">\n\t\t\t<!-- ============================================================\n     GEO \/ SEO SCHEMA MARKUP\n     Article: POPIA health data regulations 2026: What you need to know\n     URL: https:\/\/itlawco.com\/popia-health-data-regulations-2026\/\n     Paste this block into the <head> of the page, or inject via\n     your SEO plugin's \"Custom Schema\" \/ \"Header Scripts\" field.\n     ============================================================ -->\n\n<script type=\"application\/ld+json\">\n[\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"Article\",\n    \"@id\": \"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#article\",\n    \"headline\": \"POPIA health data regulations 2026: What you need to know\",\n    \"description\": \"South Africa's Information Regulator published binding health data regulations on 6 March 2026 under POPIA. This article explains who is affected, what is required, and what organisations must do now.\",\n    \"datePublished\": \"2026-03-06\",\n    \"dateModified\": \"2026-03-06\",\n    \"inLanguage\": \"en-ZA\",\n    \"url\": \"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/\",\n    \"mainEntityOfPage\": {\n      \"@type\": \"WebPage\",\n      \"@id\": \"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/\"\n    },\n    \"image\": {\n      \"@type\": \"ImageObject\",\n      \"url\": \"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg\",\n      \"width\": 1200,\n      \"height\": 630\n    },\n    \"author\": {\n      \"@type\": \"Person\",\n      \"name\": \"Nathan-Ross Adams\",\n      \"url\": \"https:\/\/itlawco.com\/author\/itadmin\/\",\n      \"sameAs\": \"https:\/\/itlawco.com\/author\/itadmin\/\"\n    },\n    \"publisher\": {\n      \"@type\": \"Organization\",\n      \"name\": \"ITLawCo\",\n      \"url\": \"https:\/\/itlawco.com\",\n      \"logo\": {\n        \"@type\": \"ImageObject\",\n        \"url\": \"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png\"\n      }\n    },\n    \"about\": [\n      {\n        \"@type\": \"Thing\",\n        \"name\": \"Protection of Personal Information Act\",\n        \"sameAs\": \"https:\/\/www.wikidata.org\/wiki\/Q55639580\"\n      },\n      {\n        \"@type\": \"Thing\",\n        \"name\": \"Health data privacy\",\n        \"sameAs\": \"https:\/\/www.wikidata.org\/wiki\/Q1131290\"\n      },\n      {\n        \"@type\": \"Organization\",\n        \"name\": \"Information Regulator (South Africa)\",\n        \"url\": \"https:\/\/inforegulator.org.za\/\"\n      }\n    ],\n    \"mentions\": [\n      {\n        \"@type\": \"Legislation\",\n        \"name\": \"Protection of Personal Information Act, 2013\",\n        \"identifier\": \"Act No. 4 of 2013\",\n        \"jurisdiction\": \"ZA\"\n      },\n      {\n        \"@type\": \"Legislation\",\n        \"name\": \"Medical Schemes Act, 1998\",\n        \"identifier\": \"Act No. 131 of 1998\",\n        \"jurisdiction\": \"ZA\"\n      },\n      {\n        \"@type\": \"Legislation\",\n        \"name\": \"Insurance Act, 2017\",\n        \"identifier\": \"Act No. 18 of 2017\",\n        \"jurisdiction\": \"ZA\"\n      },\n      {\n        \"@type\": \"Legislation\",\n        \"name\": \"Pension Funds Act, 1956\",\n        \"identifier\": \"Act No. 24 of 1956\",\n        \"jurisdiction\": \"ZA\"\n      }\n    ],\n    \"keywords\": [\n      \"POPIA\",\n      \"health data regulations 2026\",\n      \"Information Regulator South Africa\",\n      \"section 32 POPIA\",\n      \"health information compliance\",\n      \"data protection South Africa\",\n      \"employer health data obligations\",\n      \"medical scheme POPIA\",\n      \"cross-border health data transfer\",\n      \"special personal information\"\n    ],\n    \"articleSection\": \"Data protection and privacy\",\n    \"wordCount\": 2100,\n    \"timeRequired\": \"PT10M\",\n    \"isAccessibleForFree\": true,\n    \"license\": \"https:\/\/itlawco.com\",\n    \"citation\": {\n      \"@type\": \"GovernmentPermit\",\n      \"name\": \"Government Gazette No. 54268, Notice No. 7198\",\n      \"issuedBy\": {\n        \"@type\": \"GovernmentOrganization\",\n        \"name\": \"Information Regulator (South Africa)\"\n      },\n      \"validFrom\": \"2026-03-06\"\n    }\n  },\n\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"FAQPage\",\n    \"@id\": \"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#faq\",\n    \"mainEntity\": [\n      {\n        \"@type\": \"Question\",\n        \"name\": \"Do the POPIA health data regulations 2026 apply immediately?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Yes. Regulation 7.2 states that the Regulations commence on the date of publication in the Gazette \u2014 6 March 2026. There is no transitional period.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What is health information under the POPIA health data regulations?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The Regulations define health information as personal information relating to the physical and\/or mental health of a data subject, including the provision of healthcare services and any testing, treatment and diagnosis which reveals information about the data subject's health status.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"Do the POPIA health data regulations apply to employers who only process sick leave records?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Yes. Employers are explicitly listed as responsible parties within scope of the Regulations. Sick leave records, occupational health assessments, disability documentation and return-to-work records all constitute health information under the Regulations.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"Can health information be shared with an offshore parent company under POPIA?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Only if one or more of the conditions in section 72(1) of POPIA are met. Transfers solely on the basis of group policy or operational convenience are unlikely to satisfy the requirements without additional steps such as obtaining the data subject's consent or putting binding transfer agreements in place.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What are the penalties for non-compliance with the POPIA health data regulations?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The Information Regulator may issue compliance notices and administrative fines of up to R10 million. Serious cases may result in criminal prosecution of responsible individuals under POPIA.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What is the difference between a responsible party and an operator under POPIA?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"A responsible party determines the purpose and means of processing. An operator processes information on behalf of a responsible party. The Regulations apply to responsible parties and their applicable operators. Operators are typically bound through written operator agreements that mirror the responsible party's obligations.\"\n        }\n      }\n    ]\n  },\n\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"BreadcrumbList\",\n    \"@id\": \"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#breadcrumb\",\n    \"itemListElement\": [\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 1,\n        \"name\": \"Home\",\n        \"item\": \"https:\/\/itlawco.com\"\n      },\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 2,\n        \"name\": \"Data protection and privacy\",\n        \"item\": \"https:\/\/itlawco.com\/category\/data-protection-and-privacy\/\"\n      },\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 3,\n        \"name\": \"POPIA health data regulations 2026: What you need to know\",\n        \"item\": \"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/\"\n      }\n    ]\n  },\n\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"LegalService\",\n    \"@id\": \"https:\/\/itlawco.com\/#legalservice\",\n    \"name\": \"ITLawCo\",\n    \"url\": \"https:\/\/itlawco.com\",\n    \"description\": \"ITLawCo advises employers, insurers, medical schemes and financial services entities on POPIA compliance, data governance and regulatory risk.\",\n    \"areaServed\": {\n      \"@type\": \"Country\",\n      \"name\": \"South Africa\"\n    },\n    \"serviceType\": [\n      \"POPIA compliance\",\n      \"Data governance\",\n      \"Health data privacy\",\n      \"Regulatory risk advisory\",\n      \"Operator agreement drafting\",\n      \"Cross-border data transfer compliance\",\n      \"Information Regulator engagement\"\n    ],\n    \"contactPoint\": {\n      \"@type\": \"ContactPoint\",\n      \"contactType\": \"legal enquiries\",\n      \"url\": \"https:\/\/itlawco.com\/contact-us\/\"\n    }\n  },\n\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"HowTo\",\n    \"@id\": \"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#howto\",\n    \"name\": \"How to comply with the POPIA health data regulations 2026\",\n    \"description\": \"Five steps organisations should take immediately to comply with the Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties, 2026.\",\n    \"totalTime\": \"P30D\",\n    \"step\": [\n      {\n        \"@type\": \"HowToStep\",\n        \"position\": 1,\n        \"name\": \"Map health data flows\",\n        \"text\": \"Map all health data flows within your organisation and to third parties, including operators and offshore recipients.\"\n      },\n      {\n        \"@type\": \"HowToStep\",\n        \"position\": 2,\n        \"name\": \"Review and document lawful bases\",\n        \"text\": \"Review the legal basis for each category of processing activity and document it against the grounds permitted under section 27 of POPIA.\"\n      },\n      {\n        \"@type\": \"HowToStep\",\n        \"position\": 3,\n        \"name\": \"Audit security controls\",\n        \"text\": \"Audit physical and electronic security controls against sector-appropriate information security standards as required by section 19 of POPIA.\"\n      },\n      {\n        \"@type\": \"HowToStep\",\n        \"position\": 4,\n        \"name\": \"Update disposal and retention policies\",\n        \"text\": \"Update disposal and retention policies to address both digital deletion and physical destruction of health records.\"\n      },\n      {\n        \"@type\": \"HowToStep\",\n        \"position\": 5,\n        \"name\": \"Check cross-border transfers\",\n        \"text\": \"Check all cross-border transfers for compliance with section 72(1) of POPIA and put transfer agreements or consent mechanisms in place where required.\"\n      }\n    ]\n  }\n]\n<\/script>\n\t\t<\/div>\n\t<\/div>\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"Key takeaway: The Information Regulator\u2019s Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties, 2026 came into force today, 6 March 2026. They are binding,...","protected":false},"author":1,"featured_media":3803,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-3800","post","type-post","status-publish","format-standard","has-post-thumbnail","category-data-protection-and-privacy"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>POPIA health data regulations 2026: What you need to know - ITLawCo<\/title>\n<meta name=\"description\" content=\"South Africa&#039;s Information Regulator published binding health data regulations on 6 March 2026 under POPIA. This article explains who is affected, what is required, and what organisations must do now.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itlawco.com\/fr\/popia-health-data-regulations-2026\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"POPIA health data regulations 2026: What you need to know - ITLawCo\" \/>\n<meta property=\"og:description\" content=\"South Africa&#039;s Information Regulator published binding health data regulations on 6 March 2026 under POPIA. This article explains who is affected, what is required, and what organisations must do now.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itlawco.com\/fr\/popia-health-data-regulations-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"ITLawCo\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-06T13:02:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-06T13:06:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nathan-Ross Adams\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nathan-Ross Adams\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/\"},\"author\":{\"name\":\"Nathan-Ross Adams\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/180a104e03a6d73faeb2de9137a2a995\"},\"headline\":\"POPIA health data regulations 2026: What you need to know\",\"datePublished\":\"2026-03-06T13:02:51+00:00\",\"dateModified\":\"2026-03-06T13:06:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/\"},\"wordCount\":3488,\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg\",\"articleSection\":[\"Data protection and privacy\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/\",\"name\":\"POPIA health data regulations 2026: What you need to know - ITLawCo\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg\",\"datePublished\":\"2026-03-06T13:02:51+00:00\",\"dateModified\":\"2026-03-06T13:06:35+00:00\",\"description\":\"South Africa's Information Regulator published binding health data regulations on 6 March 2026 under POPIA. This article explains who is affected, what is required, and what organisations must do now.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg\",\"width\":1536,\"height\":1024,\"caption\":\"South Africa\u2019s Information Regulator has introduced binding 2026 regulations governing the processing and protection of health information under POPIA.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/popia-health-data-regulations-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/itlawco.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"POPIA health data regulations 2026: What you need to know\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"name\":\"ITLawCo\",\"description\":\"Fast, fearless legal\",\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/itlawco.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\",\"name\":\"ITLawCo\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"width\":2854,\"height\":2883,\"caption\":\"ITLawCo\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/itlawco\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/180a104e03a6d73faeb2de9137a2a995\",\"name\":\"Nathan-Ross Adams\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g\",\"caption\":\"Nathan-Ross Adams\"},\"sameAs\":[\"https:\\\/\\\/itlawco.com\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nathan-ross-adams-a5760b9a\\\/\"],\"url\":\"https:\\\/\\\/itlawco.com\\\/fr\\\/author\\\/itadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"POPIA health data regulations 2026: What you need to know - ITLawCo","description":"South Africa's Information Regulator published binding health data regulations on 6 March 2026 under POPIA. This article explains who is affected, what is required, and what organisations must do now.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itlawco.com\/fr\/popia-health-data-regulations-2026\/","og_locale":"fr_FR","og_type":"article","og_title":"POPIA health data regulations 2026: What you need to know - ITLawCo","og_description":"South Africa's Information Regulator published binding health data regulations on 6 March 2026 under POPIA. This article explains who is affected, what is required, and what organisations must do now.","og_url":"https:\/\/itlawco.com\/fr\/popia-health-data-regulations-2026\/","og_site_name":"ITLawCo","article_published_time":"2026-03-06T13:02:51+00:00","article_modified_time":"2026-03-06T13:06:35+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg","type":"image\/jpeg"}],"author":"Nathan-Ross Adams","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Nathan-Ross Adams","Dur\u00e9e de lecture estim\u00e9e":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#article","isPartOf":{"@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/"},"author":{"name":"Nathan-Ross Adams","@id":"https:\/\/itlawco.com\/#\/schema\/person\/180a104e03a6d73faeb2de9137a2a995"},"headline":"POPIA health data regulations 2026: What you need to know","datePublished":"2026-03-06T13:02:51+00:00","dateModified":"2026-03-06T13:06:35+00:00","mainEntityOfPage":{"@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/"},"wordCount":3488,"publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"image":{"@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg","articleSection":["Data protection and privacy"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/","url":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/","name":"POPIA health data regulations 2026: What you need to know - ITLawCo","isPartOf":{"@id":"https:\/\/itlawco.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#primaryimage"},"image":{"@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg","datePublished":"2026-03-06T13:02:51+00:00","dateModified":"2026-03-06T13:06:35+00:00","description":"South Africa's Information Regulator published binding health data regulations on 6 March 2026 under POPIA. This article explains who is affected, what is required, and what organisations must do now.","breadcrumb":{"@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itlawco.com\/popia-health-data-regulations-2026\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#primaryimage","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/popia-health-data-regulations-2026-south-africa-information-regulator-governance.jpg","width":1536,"height":1024,"caption":"South Africa\u2019s Information Regulator has introduced binding 2026 regulations governing the processing and protection of health information under POPIA."},{"@type":"BreadcrumbList","@id":"https:\/\/itlawco.com\/popia-health-data-regulations-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itlawco.com\/"},{"@type":"ListItem","position":2,"name":"POPIA health data regulations 2026: What you need to know"}]},{"@type":"WebSite","@id":"https:\/\/itlawco.com\/#website","url":"https:\/\/itlawco.com\/","name":"ITLawCo","description":"Rapide, sans peur, juridique","publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itlawco.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/itlawco.com\/#organization","name":"ITLawCo","url":"https:\/\/itlawco.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","width":2854,"height":2883,"caption":"ITLawCo"},"image":{"@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/itlawco\/"]},{"@type":"Person","@id":"https:\/\/itlawco.com\/#\/schema\/person\/180a104e03a6d73faeb2de9137a2a995","name":"Nathan-Ross Adams","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/25dc8945a16b2092572617ca3935624f6c0c2b8e7f90f89e9dd3ce6611085fcb?s=96&d=mm&r=g","caption":"Nathan-Ross Adams"},"sameAs":["https:\/\/itlawco.com","https:\/\/www.linkedin.com\/in\/nathan-ross-adams-a5760b9a\/"],"url":"https:\/\/itlawco.com\/fr\/author\/itadmin\/"}]}},"_links":{"self":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/comments?post=3800"}],"version-history":[{"count":2,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3800\/revisions"}],"predecessor-version":[{"id":3808,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3800\/revisions\/3808"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media\/3803"}],"wp:attachment":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media?parent=3800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/categories?post=3800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/tags?post=3800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}