South Africa’s Protection of Personal Information Act 4 of 2013 (POPIA) is recognised as a comprehensive data protection framework. What is less widely understood is that it contains an exclusion capable of removing its application entirely and that the conditions attached to that exclusion are not being systematically verified.

This article explains what the national security exclusion does, who it affects, where it currently falls short, and what the legal landscape looks like following the General Intelligence Laws Amendment Act 37 of 2024 (GILAB) and the Constitutional Court’s judgment in AmaBhungane.

Relevant to: compliance officers, information officers, government departments, private security contractors, legal practitioners, and organisations subject to POPIA.

The exclusion in plain terms

What does POPIA’s national security exclusion actually do?

Section 6(1)(c) of POPIA provides that the Act does not apply to the processing of personal information by or on behalf of a public body where that processing involves national security, defence, or public safety or where its purpose is the prevention, detection, or prosecution of offences.

This is a total exclusion. Not a partial relaxation of requirements. A complete removal of POPIA’s jurisdiction. None of the eight conditions for lawful processing apply. No data subject rights arise. The Information Regulator has no oversight authority.

The exclusion is, however, conditional. It applies only “to the extent that adequate safeguards have been established in legislation for the protection of such personal information”.

That proviso is carrying significant constitutional weight. Whether it is being satisfied in practice is a question South African law has not yet authoritatively answered.

What makes this exclusion unusual

Three features of section 6(1)(c) distinguish it from equivalent provisions in other jurisdictions.

No procedure for invoking it

Unlike the United Kingdom, which requires a ministerial certificate as documented evidence that a national security exemption applies, South Africa imposes no equivalent requirement. A public body decides internally that its processing involves national security, and the Act ceases to apply. No application to the Regulator is required. No external verification takes place.

“National security” is not defined in POPIA

The most authoritative statutory definition appears in the National Strategic Intelligence Act 39 of 1994 (NSIA), which frames national security around specific threats: terrorism, espionage, sabotage, hostile foreign intervention, and serious violence directed at overthrowing the constitutional order.

Critically, the NSIA definition explicitly provides that national security does not include lawful political activity, advocacy, protest or dissent. This is reinforced by the Johannesburg Principles on National Security, Freedom of Expression and Access to Information (1995)—an internationally recognised expert framework produced in South Africa at the post-apartheid transition—which provide that national security may only be invoked to protect the country’s existence or territorial integrity against force, not to shield governments from embarrassment, conceal the functioning of public institutions, or suppress dissent. Processing of personal information about persons engaged in lawful protest or democratic advocacy cannot legitimately invoke the POPIA exclusion on national security grounds.

The “adequate safeguards” condition has never been judicially interpreted

No South African court has determined what “adequate safeguards established in legislation” means, which statutes qualify, or what happens when a body invokes the exclusion but the relevant safeguards legislation is constitutionally deficient.

The adequate safeguards problem

Which legislation currently qualifies as adequate safeguards?

The adequate safeguards condition is the provision’s constitutional load-bearer. It is what allows section 6(1)(c) to coexist with the section 36 limitation clause, which requires that limitations on rights be reasonable, justifiable, and accomplished through the least restrictive means available.

Several statutes have been identified as candidates, each with a different scope.

The Tax Administration Act 28 of 2011 (section 69) obliges SARS to preserve the secrecy of information it holds and prohibits disclosure to non-SARS officials. For SARS’s specific revenue functions, this constitutes a credible confidentiality framework.

The Financial Intelligence Centre Act 38 of 2001 (section 40) imposes access controls over FICA-held information and requires written agreements for inter-entity data sharing. For anti-money laundering and terrorism financing identification functions, this is the strongest safeguards candidate currently in operation.

RICA — the Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002 — was historically the primary safeguards instrument for communications interception by security services. The Constitutional Court’s 2021 judgment in AmaBhungane Centre for Investigative Journalism NPC v Minister of Justice and Correctional Services changed this position significantly.

The AmaBhungane consequence and its sequel

The Court declared RICA unconstitutional in five respects: insufficient judicial independence; no post-surveillance notification; inadequate ex parte safeguards; no procedures for managing, storing and destroying surveillance data; and no special protections for journalists or lawyers. For POPIA purposes the data management deficiency is most significant: RICA provided no clarity on what intercepted data must be retained, where, by whom, for what purpose, or when it must be destroyed. The Court endorsed the European Court of Human Rights’ Weber minimum standards as the benchmark any adequate framework must meet. Those standards remain unmet.

The Court also declared the National Communications Centre’s bulk surveillance operations unlawful: the NSIA’s general power to “gather, correlate, evaluate and analyse” intelligence cannot authorise mass interception without specifying manner, circumstances, duration or data management rules. A general enabling power does not constitute adequate safeguards.

Parliament was given 36 months to cure the defects. It did not. RICA’s invalidity took full effect in February 2024 and the designated judge’s term expired in September 2024, rendering RICA entirely inoperable.

In President of the Republic of South Africa v Speaker of the National Assembly and Others [2025] ZACC 12, decided unanimously on 25 July 2025, the Constitutional Court intervened a second time. It deemed RICA to include a new designated judge definition—three retired High Court judges, nominated by the Chief Justice, appointed for a non-renewable 24-month term—and extended the interim journalist, lawyer, and post-surveillance notification protections from the original order.

Of the five deficiencies, two now have interim remedies. Three remain entirely unaddressed: the ex parte gap (section 16(7) still requires directions to be issued without notice or hearing, exactly as the Court left it in 2021); the data management gap; and the bulk interception accountability gap. The constitutional declaration of invalidity stands. The President’s advisors found Parliament’s own Amendment Bill constitutionally inadequate on notification grounds and referred it back in November 2024. South Africa is four years on from AmaBhungane without a valid legislative cure, and RICA in its current interim form does not satisfy the Weber benchmark that section 6(1)(c) requires.

The legislative history: what was intended and what was enacted

The South African Law Reform Commission’s 2009 Project 124 Report is the foundational pre-legislative document underlying POPIA. Comparing the SALRC’s draft Bill against the enacted Act reveals changes made during the parliamentary process with significant legal consequences.

The SALRC required adequate safeguards to be established in specific legislation. Parliament dropped the word “specific a change that lowers the threshold considerably. “Legislation” is satisfied by any applicable statute with relevant protective provisions. “Specific legislation” would have required a dedicated statutory scheme tailored to the processing in question.

The SALRC’s consultation record also contains a finding directly relevant to how the exclusion should be interpreted today: “Broad and vague exemptions erroneously assume that one must give up core information principles to protect national security”. Most respondents to the SALRC’s consultation explicitly opposed blanket exemptions from all privacy principles. This legislative history supports a narrow rather than expansive reading of the exclusion’s scope.

GILAB: a framework that does not yet exist

What does GILAB change, and when does it take effect?

The General Intelligence Laws Amendment Act 37 of 2024 (GILAB) was assented to on 25 March 2025. Its commencement date has not been proclaimed. None of its provisions are currently operative law.

When commenced, GILAB will insert section 2B into the NSIA, creating the first express statutory basis for NCC bulk interception operations, closing the legal gap AmaBhungane identified when it declared NCC bulk surveillance unlawful for lack of any statutory authority. Section 2B requires judicial approval by a retired judge nominated by the Chief Justice before bulk interception may proceed.

GILAB will also insert section 2C, requiring that regulations governing the processing, storage, sharing, and destruction of bulk interception data take into account principles that closely mirror POPIA’s eight conditions, including accountability, processing limitations, purpose specification, and post-surveillance notification. This would be the first data management framework for intelligence-collected personal information that meets the Weber minimum standards the Constitutional Court endorsed in AmaBhungane.

Three important limitations qualify this development.

  1. First, section 2C applies only to bulk interception data generated by the NCC, not to the full range of targeted surveillance authorised under RICA. The three AmaBhungane deficiencies that remain unaddressed—the ex parte safeguards gap, the data management gap in RICA’s sections 35 and 37, and the bulk interception accountability gap—are not touched by GILAB. The data management framework goes into the NSIA, not into RICA itself.
  2. Second, the principles are directives to regulation-making, not operative obligations. Regulations must be made within 12 months of commencement. Until they are, no POPIA-equivalent protections exist.
  3. Third, under section 6(4) of the NSIA, regulations made under the Act may be kept secret, not published in the Gazette. If the safeguards on which the exclusion relies are contained in unpublished ministerial regulations, neither the public nor the courts can assess whether they are adequate.
  4. A fourth limitation: GILAB’s pending amendments to RICA itself are confined entirely to renaming, substituting new agency names in existing definitions. No data management framework, notification provisions, or ex parte safeguards are added to RICA by GILAB.

The enforcement action against SAPS

Has the exclusion been successfully challenged?

The most concrete test of the exclusion’s limits came through the Information Regulator’s enforcement action against the South African Police Service arising from the Krugersdorp mob rape victims’ case.

SAPS officials shared a WhatsApp message containing the victims’ names, ages, and residential addresses, which entered the public domain. SAPS attempted to rely on section 6 as a blanket exclusion, arguing that as a public body investigating a crime, POPIA did not apply.

The Regulator rejected this interpretation. The investigation concluded that the privacy protections within the SAPS Act and related regulations did not constitute “adequate safeguards” as section 6 requires. The enforcement notice required SAPS to notify the victims, issue a public apology, investigate the responsible officers, and integrate POPIA compliance into standard training.

The precedent is clear: section 6 is not a jurisdictional shield that automatically protects any security-related body. It is conditional. A body that cannot demonstrate adequate legislative safeguards remains fully subject to POPIA.

Practical implications for organisations

Who does this actually affect, and how?

Private contractors under government security mandates

Organisations processing personal information under a government security contract face legal uncertainty about whether they qualify as processing “on behalf of a public body” for national security purposes. The law is untested on this point, and relying on the exclusion without legal advice carries risk.

Organisations subject to terrorism reporting obligations

PCDATARA section 12, as amended in 2022, provides that no confidentiality obligation—including those imposed by POPIA—affects the duty to report suspected terrorism to police. Any organisation that has reason to suspect that another person intends to commit or has committed a terrorism offence must report this, regardless of any POPIA processing limitation.

Government departments holding personal information

NSIA section 3(5) provides that, notwithstanding any law to the contrary, no department of State may withhold information from the intelligence services when it is reasonably required for an investigation. This override operates independently of POPIA and cannot be resisted on data protection grounds.

Mobile network operators and the section 40 regime

Section 40 of RICA requires mobile operators to collect and store subscriber identity information for five years after contract termination, and permits law enforcement agencies to access it by written request: no interception direction required, no judicial oversight. This creates a parallel personal information processing regime sitting alongside POPIA rather than within it. For organisations holding SIM registration data, understanding how section 40 interacts with POPIA’s conditions is a distinct compliance question from the section 6 exclusion analysis.

Even without invoking the total exclusion in section 6, POPIA’s own conditions contain national security exceptions. Sections 12, 15, and 18 allow departures from direct collection, purpose limitation, and notification requirements where national security necessity genuinely exists. These exceptions apply to any responsible party, not only security agencies.

FAQs about POPIA’s national security exclusion

Not in full. Section 6(1)(c) excludes POPIA’s application to public bodies processing personal information for national security, defence, law enforcement, or public safety purposes — but only where adequate legislative safeguards exist in other legislation. RICA, the primary safeguards instrument for communications interception, was declared constitutionally invalid in AmaBhungane (2021) in five respects. A second Constitutional Court intervention in July 2025 (President v Speaker [2025] ZACC 12) restored RICA’s operability through interim relief, but three of those five deficiencies — data management, ex parte safeguards, and bulk interception accountability — remain entirely unaddressed. RICA in its current interim form does not meet the minimum standards the Court itself endorsed as the benchmark for adequate safeguards.

Only if it is processing personal information on behalf of a qualifying public body for a national security purpose. A private company cannot invoke the exclusion based on its own assessment of security necessity. The legal basis for any such claim remains untested in South African courts.

Partially, and only when commenced. GILAB will introduce POPIA-equivalent data management principles for bulk interception data. It does not create a comprehensive data protection framework for all intelligence processing. Its provisions are not yet law.

It establishes that the section 6 exclusion cannot be invoked by default. A public body must be able to point to specific legislation providing adequate privacy safeguards. Invoking the exclusion without that foundation exposes the body to the full force of POPIA enforcement.

The bottom line

Section 6(1)(c) of POPIA is constitutionally defensible in principle. A conditional exclusion—one that removes the Act’s application only where adequate legislative safeguards exist—is a legitimate approach to balancing privacy and security. The difficulty lies in how that condition is being applied.

The “adequate safeguards” standard is currently assessed by the bodies that benefit from satisfying it. There is no external verification, no documented decision, and no independent review. The primary legislation historically relied upon for communications interception (RICA) was declared constitutionally invalid in 2021 and remains so today. A second Constitutional Court intervention in July 2025 restored RICA’s operability through an interim order of indefinite duration, but the declaration of invalidity stands and key deficiencies—including the absence of a data management framework—remain unaddressed. Parliament has failed to produce a constitutionally acceptable cure in four years. The President’s own advisors found Parliament’s attempt inadequate and sent the Bill back for reconsideration.

What South Africa’s national security exclusion currently lacks is not legal imagination, but institutional accountability. The path toward closing that gap runs through GILAB’s commencement, a constitutionally valid RICA amendment, a formal cooperation framework between the Information Regulator and the Inspector-General of Intelligence, and—in time—a court willing to define what “adequate safeguards” actually requires.

Until that framework is in place, the exclusion remains one of the most consequential and least scrutinised provisions in South African data protection law. Those operating within its boundaries should do so with care, and those affected by it deserve to know that the safeguards meant to protect them have not yet been independently verified.

How ITLawCo can help

ITLawCo advises public bodies, private organisations, and legal practitioners on data protection compliance across South Africa’s complex regulatory landscape, including where POPIA intersects with national security, intelligence, and law enforcement obligations.

ServiceWhat we do
POPIA compliance assessmentsWe review your organisation’s processing activities against POPIA’s eight conditions for lawful processing, identify where national security exceptions or exclusions may apply, and advise on the legal basis required to rely on them safely.
Section 6 exclusion analysisIf your organisation is a public body—or processes personal information on behalf of one—we assess whether the section 6(1)(c) exclusion applies, whether adequate legislative safeguards exist, and what risk exposure arises where those safeguards are absent or legally contested.
GILAB readinessWith GILAB assented to but not yet commenced, now is the time to understand what changes when it takes effect. We advise on the new intelligence structures, the pending bulk interception data management framework, and how organisations should prepare.
Terrorism reporting and compelled disclosureWe advise on the intersection of POPIA’s processing conditions with mandatory reporting obligations under PCDATARA and compelled disclosure provisions under the NSIA, including how to respond when security agencies request personal information your organisation holds.
RICA operator obligationsWe advise mobile network operators and organisations holding SIM registration data on the interaction between RICA’s section 40 retention and access requirements and POPIA’s conditions for lawful processing, including how law enforcement access requests should be managed.
Information officer supportWe assist information officers in understanding the boundaries of POPIA’s application, drafting processing records that account for national security exceptions, and responding to data subject requests where security considerations are relevant.

Contact ITLawCo to discuss your organisation’s specific position.

This article is published by ITLawCo for general information purposes. It does not constitute legal advice and should not be relied upon as such. The law described reflects the position as at July 2025, including the Constitutional Court’s judgment in President of the Republic of South Africa v Speaker of the National Assembly and Others [2025] ZACC 12 decided on 25 July 2025. For advice specific to your organisation’s circumstances, contact ITLawCo.