GDPR Audits for South African Businesses

4 Minute read
Janine Stols
Managing Director | Governance & ISO 27001 Specialist
GDPR Audits for South African Businesses
In this article

Share this article

GDPR is not a European problem that South African businesses can ignore. The regulation applies extraterritorially to organisations that process the personal data of EU data subjects — including those that sell to EU customers, employ EU staff, and operate EU-facing platforms. For South African businesses with EU ties, GDPR compliance has to operate alongside POPIA, not in place of it. A structured audit is the cleanest way to know where the organisation actually stands.

The short answer

GDPR audits for South African businesses assess extraterritorial applicability, lawful-basis mapping, data-subject rights operations, Data Protection Officer structure, breach-notification readiness, and international transfer mechanisms. The audit produces evidence that both EU and South African Information Regulator stakeholders can rely on — and aligns with the POPIA programme rather than duplicating it.

GDPR readiness increasingly affects international procurement qualification, customer due diligence, cloud-provider onboarding, and enterprise trust for South African organisations operating globally.

GDPR reaches outside the EU — extraterritorial scope

Many South African organisations transfer EU personal data indirectly through cloud and SaaS providers, making visibility into transfer governance increasingly important even when the organisation itself is locally headquartered.

GDPR Article 3 sets out the extraterritorial scope: it applies to non-EU organisations that offer goods or services to EU data subjects or monitor their behaviour. South African businesses selling to EU customers, running EU-facing platforms, or employing EU staff fall in scope. The first question an audit answers is whether GDPR applies — and to which processing activities. A surprising number of South African organisations are out of scope for this assessment.

Mature GDPR programmes maintain Records of Processing Activities (ROPAs) that map processing purpose, lawful basis, retention, transfer, and security controls across the organisation.

Lawful basis — six grounds, not one

GDPR Article 6 sets out six lawful bases for processing: consent, contract, legal obligation, vital interests, public task, and legitimate interests. The right basis depends on the processing purpose and is documented for each processing activity, not for the organisation. Consent is frequently overused — for many business contexts (employment, contract performance, legitimate interests) other bases are more appropriate and less fragile.

Data subject rights — the operational test

Data subjects have rights to access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. An audit tests whether the organisation can actually operationalise these — receive a request, identify the data subject, extract or modify the personal data, and respond within statutory timeframes (typically one month under GDPR). Many organisations have the policy but not the operational capability.

Data Protection Officer — when it is required and what it covers

GDPR Article 37 requires a DPO appointment in three cases: public-authority processing, core processing requiring regular and systematic monitoring at scale, or processing of special categories at scale. For South African businesses with EU ties, the DPO requirement often overlaps with the POPIA Information Officer role — but they are not identical. Audit clarifies whether a DPO is required and whether the existing structure satisfies both regimes.

International transfers — the post-Schrems II framework

Transferring personal data from the EU to South Africa requires a valid transfer mechanism. South Africa does not have an EU adequacy decision, so transfers typically rely on Standard Contractual Clauses (SCCs) supplemented by Transfer Impact Assessments under the post-Schrems II framework. The audit examines transfer mechanisms, supplementary safeguards, and the documented impact assessments — areas where SA businesses are commonly under-prepared.

Where GDPR and POPIA align, and where they differ

The principles overlap heavily — lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. The mechanics differ: GDPR has an explicit 72-hour breach notification, formal DPO requirements, broader extraterritorial reach, and direct fining authority. An integrated programme that satisfies both regimes is more efficient than running two parallel compliance functions.

Key Takeaways

  • GDPR applies extraterritorially — South African businesses selling to or monitoring EU data subjects are in scope.
  • Six lawful bases exist; consent is overused. Document the correct basis for each processing activity.
  • Data subject rights are an operational test — most organisations have a policy but not a capability.
  • DPO requirements may overlap with the POPIA Information Officer role — verify whether the existing structure satisfies both.
  • International transfers from the EU to South Africa rely on SCCs and Transfer Impact Assessments post-Schrems II.
  • An integrated GDPR / POPIA programme is more efficient than two parallel compliance functions.

How Cyber Resilience Can Help

Cyber Resilience helps organisations assess GDPR applicability, strengthen privacy governance, and align cross-border compliance obligations with existing POPIA programmes through structured audit and advisory engagements.

Speak to our team to arrange a GDPR readiness discussion.

Janine Stols

Managing Director | Governance & ISO 27001 Specialist

Jeanine Stols is the Managing Director of Cyber Resilience and a certified ISO/IEC 27001 Lead Auditor with more than 15 years of experience across cybersecurity governance, risk management, compliance, and security assurance.

She works closely with organisations across regulated and operationally complex environments to strengthen governance maturity, improve audit readiness, and align cybersecurity programmes to operational resilience objectives.

Expertise

ISO 27001 • Governance • Risk Management • Compliance • ISMS

Frequently asked questions

Does GDPR apply to us if we have no office in the EU?

Possibly. GDPR Article 3 extends to non-EU organisations that offer goods or services to EU data subjects or monitor their behaviour. A South African e-commerce site selling to EU customers, an employer with EU staff, or a platform tracking EU users is typically in scope. A scoping conversation clarifies which processing activities apply.

What is the relationship between GDPR and POPIA?

POPIA was designed with GDPR in mind, and the principles overlap heavily. The mechanics differ — GDPR has an explicit 72-hour breach notification, formal DPO requirements, and broader extraterritorial reach. Organisations subject to both typically integrate the programme rather than maintain duplicate compliance functions.

What is a Transfer Impact Assessment?

Following the Schrems II decision, organisations transferring personal data from the EU to non-adequate countries (including South Africa) must assess whether the recipient country’s laws provide essentially equivalent protection — and document the assessment alongside the Standard Contractual Clauses. The TIA documents the analysis and any supplementary safeguards required.

What are GDPR penalties, and can they be enforced in South Africa?

GDPR allows fines up to €20 million or 4% of annual global turnover, whichever is higher. Enforcement against organisations outside the EU is increasingly active and is being pursued through international cooperation arrangements and, in some cases, asset attachment in EU jurisdictions where the organisation has a presence.

Related Insights

Cyber resilience insights grounded in operational reality.

Practical guidance, operational perspectives, regulatory insights, and forensic-led thinking across cybersecurity, governance, resilience, and digital risk.

Need Clarity on your CURRENT RESILIENCE POSTURE?

Whether you need a focused assessment, operational support, governance maturity, or incident response guid-ance, we will help you understand your current position and build a practical path forward.