International Data Transfer Addendum Template for South Africa
Generate a bespoke document
What is a International Data Transfer Addendum?
The International Data Transfer Addendum is essential for organizations transferring personal information outside of South Africa's borders. It is required when a South African entity (data exporter) needs to transfer personal information to an entity in another country (data importer) and must ensure compliance with Section 72 of the Protection of Personal Information Act (POPIA). This document should be used whenever personal information is being transferred internationally, whether through cloud services, outsourcing arrangements, intra-group transfers, or service provider relationships. The addendum includes crucial provisions regarding data protection measures, responsibilities of both parties, security requirements, and mechanisms for ensuring adequate protection of personal information in the receiving jurisdiction. It is particularly important given South Africa's strict data protection requirements and the need to ensure continued protection of personal information once it leaves South African jurisdiction.
Trusted by high-performance teams
About the International Data Transfer Addendum
When you transfer personal information from South Africa to another country, you need an International Data Transfer Addendum to comply with the Protection of Personal Information Act (POPIA). This document creates binding legal obligations between data exporters and importers, ensuring personal information receives adequate protection even after crossing South African borders.
When do you need this document?
You must use this addendum whenever your South African business transfers personal information internationally. Common scenarios include using cloud storage services hosted overseas, outsourcing customer service to foreign call centres, sharing employee data with international subsidiaries, or engaging overseas suppliers who process personal information. The document is also essential for multinational companies conducting intra-group data transfers and businesses using international payment processors or marketing platforms that handle South African customer data.
Key legal considerations
The addendum must establish clear roles and responsibilities for both parties. Data exporters retain primary liability under POPIA, while data importers must implement equivalent security measures. Key clauses should address data processing purposes and limitations, security safeguards and breach notification procedures, data subject rights and access mechanisms, and audit rights and compliance monitoring. The agreement must also specify data retention periods, deletion requirements upon contract termination, and procedures for handling regulatory inquiries. Sub-processor arrangements require additional protections, including due diligence requirements and flow-down obligations to ensure all parties maintain POPIA compliance standards.
Legal requirements in South Africa
Under Section 72 of POPIA, international transfers are only permitted when the receiving country provides adequate protection or when specific safeguards are implemented. The Information Regulator has issued guidance requiring contractual measures that ensure equivalent protection standards. Your addendum must demonstrate that the foreign jurisdiction maintains data protection laws substantially similar to POPIA, or implement compensating controls through contractual obligations. The agreement must also establish South African law as governing law for data protection matters and provide mechanisms for data subjects to exercise their rights. Additionally, you must conduct transfer impact assessments to evaluate risks in the destination country and implement supplementary measures where necessary to maintain POPIA's protection standards.
GOVERNING LAW
Applicable law
This International Data Transfer Addendum is drafted to comply with South Africa law. Key legislation includes:
Section 72 of POPIA: Specific provision dealing with transfers of personal information outside South Africa, including conditions for transfer and requirements for adequate protection
Constitution of South Africa (Section 14): Constitutional right to privacy which forms the basis for data protection legislation in South Africa
Information Regulator Guidance Notes: Guidelines and requirements issued by South Africa's Information Regulator regarding international data transfers
EU General Data Protection Regulation (GDPR): While not South African law, GDPR should be considered as a reference point due to its influence on international data transfer standards and potential application to transfers involving EU entities
Electronic Communications and Transactions Act 2002: Relevant for electronic data transfers and digital communications aspects of international data flows
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

