Data Processing Addendum Template for South Africa

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Processing Addendum?

A Data Processing Addendum is required whenever an organization (the responsible party) engages another party (the operator) to process personal information on its behalf in South Africa. This document supplements existing service agreements to ensure compliance with the Protection of Personal Information Act (POPIA) and related data protection regulations. It defines critical aspects such as processing limitations, security requirements, breach notification procedures, and cross-border transfer mechanisms. The DPA is essential for organizations handling personal information through third-party service providers, cloud services, or other external processors, and helps demonstrate compliance with South African data protection requirements while managing risk in data processing relationships.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

South Africa

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Processing Addendum

When your organization engages third-party service providers to process personal information in South Africa, you need a Data Processing Addendum (DPA) to comply with the Protection of Personal Information Act (POPIA). This critical document supplements your existing service agreements and establishes clear legal obligations for both the responsible party (data controller) and the operator (data processor).

When do you need this document?

You require a Data Processing Addendum whenever you engage external parties to process personal information on your behalf. This includes cloud service providers handling customer data, payroll companies processing employee information, marketing agencies managing customer databases, or IT support companies accessing systems containing personal data. The document is also essential when working with sub-processors or when transferring personal information across borders. Under POPIA, responsible parties must ensure operators process personal information only as instructed and maintain appropriate security measures.

Key legal considerations

Your Data Processing Addendum must clearly define the scope and purpose of processing, ensuring alignment with POPIA's lawful processing conditions. The document should specify security measures, including technical and organizational safeguards to protect personal information. Breach notification procedures are crucial, requiring operators to notify responsible parties within specified timeframes. The addendum must address data subject rights, including procedures for handling access requests, corrections, and deletions. Cross-border transfer clauses are essential if data leaves South Africa, requiring adequate protection measures or Information Regulator approval. Include audit rights allowing you to verify the operator's compliance and termination clauses specifying data return or destruction procedures.

Legal requirements in South Africa

Under POPIA, responsible parties remain liable for operators' data processing activities, making comprehensive addendums essential for compliance. The Information Regulator of South Africa requires clear documentation of processing relationships and may impose penalties for non-compliance. Your addendum must align with POPIA's eight conditions for lawful processing, including accountability, processing limitation, and security safeguards. If processing involves special personal information categories, additional consent and protection measures apply. Cross-border transfers require adequate protection mechanisms or specific authorization from the Information Regulator. The document should reference relevant provisions from the Electronic Communications and Transactions Act for electronic data security and the Consumer Protection Act for consumer data rights. Ensure your addendum includes Data Protection Officer contact details where required and establishes clear governance structures for ongoing compliance monitoring.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it