Key takeaway: The Information Regulator’s Regulations relating to the Processing of Data Subjects’ Health Information by Certain Responsible Parties, 2026 came into force today, 6 March 2026. They are binding, immediate, and enforceable. Eight categories of organisations—including employers, insurers and medical schemes—must now comply with explicit obligations around lawful processing, security safeguards, and cross-border data transfers.

What are these regulations and why do they matter?

South Africa has, for some time, had the architecture for robust health data protection under the Protection of Personal Information Act, 2013 (POPIA). What has sometimes been lacking is sector-specific clarity about what that protection demands in practice.

Today, the Information Regulator closes that gap. Published in Government Gazette No. 54268 (Notice No. 7198) and signed by Chairperson Adv Pansy Tlakula on 27 February 2026, the Regulations relating to the Processing of Data Subjects’ Health Information by Certain Responsible Parties, 2026 (the Regulations) are issued under section 112(2)(c) of POPIA. They operationalise section 32(6) of the Act and represent the most substantive sector-specific rules the Regulator has published since POPIA’s commencement provisions came into effect.

They came into force today. There is no grace period.

Who is covered?

The Regulations apply to eight categories of responsible party and their applicable operators:

  1. Insurance companies
  2. Medical schemes
  3. Medical scheme administrators
  4. Managed healthcare organisations
  5. Administrative bodies
  6. Pension funds
  7. Employers
  8. Institutions working on behalf of employers, administrative bodies or pension funds

The inclusion of employers is particularly significant. Many organisations routinely collect, store and act on employee health data—through sick leave management, occupational health programmes, disability assessments and return-to-work processes—without applying the same rigour as a medical scheme or insurer. The Regulations place employers squarely within the same compliance framework as sophisticated financial services entities.

What do the Regulations require?

A lawful basis for every instance of processing (Regulation 4)

Responsible parties may not process health information (or other special personal information such as race, religion or biometrics) unless the requirements of section 27 of POPIA are satisfied. That section permits processing of special personal information only in narrowly defined circumstances. Consent is one, but not the only, ground.

A general company policy acknowledging that health data will be collected is not sufficient. Each instance of processing must be mapped to an identifiable, documented ground of justification.

Explicit security safeguards (Regulation 5)

Responsible parties must maintain the confidentiality, integrity and availability of health information in their possession or control. The required safeguards have two specific dimensions.

Security and confidentiality of records — measures must address risks associated with both physical records (paper files, printed reports) and electronic ones (databases, cloud storage, email). Many organisations have modernised their electronic security posture while leaving physical records handling surprisingly casual. Both must now be addressed.

Proper disposal — health records must be disposed of in a manner that prevents any reasonably foreseeable unauthorised access or disclosure after the information is no longer needed. Deletion protocols, paper shredding policies and archive management practices all fall under scrutiny here.

Processing must also occur under a duty of confidentiality — whether arising from legislation, a professional code, an employment relationship or a written agreement, as contemplated in section 32(2) of POPIA. This is a notable requirement for employers and pension funds, which may not traditionally have regarded their health data handling as governed by the same confidentiality norms that apply to a registered nurse or medical scheme administrator.

Finally, technical and organisational measures must align with generally accepted information security practices applicable to the responsible party’s own sector or industry, as contemplated in section 19 of POPIA. This is a contextualised standard: a large insurer will be held to practices appropriate for financial services; a small employer to a standard proportionate to its size and context.

Cross-border transfer restrictions (Regulation 6)

Health data may not be transferred to third parties in foreign countries unless one or more of the conditions in section 72(1) of POPIA are met. Those conditions include, among others, the data subject’s consent, a binding agreement between the parties, or the recipient country having comparable data protection laws in place.

This restriction has immediate practical consequences for multinational employers who transmit employee health or disability data to offshore HR systems, and for insurers who rely on international reinsurers or processing partners.

What does this mean for your organisation?

For employers

Employment law has always required some engagement with employee health information. What changes is the formalisation of the obligation to process that information with documented justification, under confidentiality obligations, with appropriate security controls, and with a clear disposal policy.

HR policies and employment contracts should be reviewed. Occupational health service providers retained by employers are likely “operators” within the meaning of POPIA and should be subject to written operator agreements that impose equivalent obligations.

For insurers and pension funds

Underwriting and claims processes necessarily involve the collection and assessment of health information. The Regulations reinforce existing POPIA obligations but add specificity around security controls and cross-border transfer restrictions that should be assessed against existing data flows. Processing by third-party claims assessors, medical advisers and reinsurers deserves particular attention.

For medical schemes and their administrators

These entities have long operated under the Medical Schemes Act, 1998 (Act No. 131 of 1998) and its regulations, and many have mature data governance frameworks. The new POPIA Regulations are largely complementary but introduce explicit disposal and cross-border transfer requirements that should be assessed against current practices, particularly for schemes using offshore administration platforms or technology providers.

For managed healthcare organisations

The clinical nature of managed care means health data is processed at high volume and often shared across multiple parties: schemes, treating providers, pharmaceutical benefit managers. Each data flow should be assessed for POPIA compliance, and managed care contracts should reflect the confidentiality and security obligations now codified in the Regulations.

FAQs

Yes. Regulation 7.2 states that the Regulations commence on the date of publication in the Gazette — today, 6 March 2026. There is no transitional period.

The Regulations define “health information” as personal information relating to the physical and/or mental health of a data subject, including the provision of healthcare services and any testing, treatment and diagnosis which reveals information about the data subject’s health status.

Yes. Employers are explicitly listed as responsible parties within scope. Sick leave records, occupational health assessments, disability documentation and return-to-work records all constitute health information under the Regulations.

Only if one or more of the conditions in section 72(1) of POPIA are met. Transfers solely on the basis of group policy or operational convenience are unlikely to satisfy the requirements without additional steps such as obtaining the data subject’s consent or putting binding transfer agreements in place.

The Information Regulator may issue compliance notices and administrative fines of up to R10 million. Serious cases may result in criminal prosecution of responsible individuals under POPIA.

A responsible party determines the purpose and means of processing. An operator processes information on behalf of a responsible party. The Regulations apply to responsible parties and their applicable operators. Operators are typically bound through written operator agreements that mirror the responsible party’s obligations.

The enforcement outlook

One of the stated purposes of the Regulations is to give the Information Regulator a clearer enforcement framework. Until today, enforcement of health data obligations under POPIA required the Regulator to reason from general principles. These Regulations draw a more precise line.

Non-compliant organisations face the Regulator’s full enforcement toolkit. Given the Regulator’s stated commitment to enforcement and the public sensitivity of health data, compliance should be treated as an immediate operational priority rather than a medium-term project.

Five steps to take today

  1. Map all health data flows within your organisation and to third parties, including operators and offshore recipients.
  2. Review the legal basis for each category of processing activity and document it.
  3. Audit physical and electronic security controls against sector-appropriate standards.
  4. Update disposal and retention policies to address both digital deletion and physical destruction.
  5. Check cross-border transfers for compliance with section 72(1) of POPIA and put transfer agreements in place where required.

How ITLawCo can help

ITLawCo advises employers, insurers, medical schemes and financial services entities on POPIA compliance, data governance and regulatory risk. The table below maps the Regulations’ key obligations to ITLawCo’s service offering.

Obligation under the RegulationsHow ITLawCo can help
Lawful basis assessment (Reg 4)Review and document the legal grounds for each category of health data processing across your organisation, including consent frameworks and legitimate interest assessments.
Processing inventory and data mappingConduct a health data flow mapping exercise to identify what is collected, how it is used, where it is stored, and with whom it is shared.
Security safeguards — policy and procedure (Reg 5)Draft or update information security policies, records management procedures and data classification frameworks aligned to POPIA and sector-specific standards.
Security safeguards — physical and electronic recordsAdvise on security controls for both physical and electronic health records, including access controls, encryption, and secure storage practices.
Disposal and retention (Reg 5.2.2)Design retention schedules and secure disposal protocols for health records in both digital and physical formats.
Confidentiality obligations (Reg 5.3)Draft confidentiality clauses for employment contracts, operator agreements and professional services arrangements.
Operator agreementsPrepare POPIA-compliant operator agreements for occupational health providers, managed care organisations, claims assessors and other third-party processors.
Cross-border transfer compliance (Reg 6)Assess offshore data flows, identify transfers requiring justification under section 72(1) of POPIA, and draft transfer agreements or consent mechanisms where required.
Regulator engagement and enforcement responseAdvise on responses to Information Regulator enquiries, compliance notices or investigations arising from health data processing.
Training and awarenessDeliver targeted training for HR, occupational health, compliance and IT teams on their obligations under the Regulations.

To discuss your organisation’s compliance position, contact us.

End thoughts

Privacy law without enforcement is aspiration. What these Regulations signal is that South Africa is moving beyond aspiration toward accountability — at least in the domain of health data. The obligations are not new in spirit; they are new in specificity, and that distinction matters when the Regulator comes knocking.

For regulated entities, the message is as clear as the law now is: the time to act is today.

This article is for informational purposes only and does not constitute legal advice. Organisations should seek guidance from qualified legal counsel regarding their specific compliance obligations under the Protection of Personal Information Act, 2013, and these Regulations. Health data matters are treated with strict confidentiality in all professional engagements.