GDPR is not a European problem that South African businesses can ignore. The regulation applies extraterritorially to organisations that process the personal data of EU data subjects — including those that sell to EU customers, employ EU staff, and operate EU-facing platforms. For South African businesses with EU ties, GDPR compliance has to operate alongside POPIA, not in place of it. A structured audit is the cleanest way to know where the organisation actually stands.
The short answer
GDPR audits for South African businesses assess extraterritorial applicability, lawful-basis mapping, data-subject rights operations, Data Protection Officer structure, breach-notification readiness, and international transfer mechanisms. The audit produces evidence that both EU and South African Information Regulator stakeholders can rely on — and aligns with the POPIA programme rather than duplicating it.
GDPR readiness increasingly affects international procurement qualification, customer due diligence, cloud-provider onboarding, and enterprise trust for South African organisations operating globally.
GDPR reaches outside the EU — extraterritorial scope
Many South African organisations transfer EU personal data indirectly through cloud and SaaS providers, making visibility into transfer governance increasingly important even when the organisation itself is locally headquartered.
GDPR Article 3 sets out the extraterritorial scope: it applies to non-EU organisations that offer goods or services to EU data subjects or monitor their behaviour. South African businesses selling to EU customers, running EU-facing platforms, or employing EU staff fall in scope. The first question an audit answers is whether GDPR applies — and to which processing activities. A surprising number of South African organisations are out of scope for this assessment.
Mature GDPR programmes maintain Records of Processing Activities (ROPAs) that map processing purpose, lawful basis, retention, transfer, and security controls across the organisation.
Lawful basis — six grounds, not one
GDPR Article 6 sets out six lawful bases for processing: consent, contract, legal obligation, vital interests, public task, and legitimate interests. The right basis depends on the processing purpose and is documented for each processing activity, not for the organisation. Consent is frequently overused — for many business contexts (employment, contract performance, legitimate interests) other bases are more appropriate and less fragile.
Data subject rights — the operational test
Data subjects have rights to access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making. An audit tests whether the organisation can actually operationalise these — receive a request, identify the data subject, extract or modify the personal data, and respond within statutory timeframes (typically one month under GDPR). Many organisations have the policy but not the operational capability.
Data Protection Officer — when it is required and what it covers
GDPR Article 37 requires a DPO appointment in three cases: public-authority processing, core processing requiring regular and systematic monitoring at scale, or processing of special categories at scale. For South African businesses with EU ties, the DPO requirement often overlaps with the POPIA Information Officer role — but they are not identical. Audit clarifies whether a DPO is required and whether the existing structure satisfies both regimes.
International transfers — the post-Schrems II framework
Transferring personal data from the EU to South Africa requires a valid transfer mechanism. South Africa does not have an EU adequacy decision, so transfers typically rely on Standard Contractual Clauses (SCCs) supplemented by Transfer Impact Assessments under the post-Schrems II framework. The audit examines transfer mechanisms, supplementary safeguards, and the documented impact assessments — areas where SA businesses are commonly under-prepared.
Where GDPR and POPIA align, and where they differ
The principles overlap heavily — lawful processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. The mechanics differ: GDPR has an explicit 72-hour breach notification, formal DPO requirements, broader extraterritorial reach, and direct fining authority. An integrated programme that satisfies both regimes is more efficient than running two parallel compliance functions.
Key Takeaways
- GDPR applies extraterritorially — South African businesses selling to or monitoring EU data subjects are in scope.
- Six lawful bases exist; consent is overused. Document the correct basis for each processing activity.
- Data subject rights are an operational test — most organisations have a policy but not a capability.
- DPO requirements may overlap with the POPIA Information Officer role — verify whether the existing structure satisfies both.
- International transfers from the EU to South Africa rely on SCCs and Transfer Impact Assessments post-Schrems II.
- An integrated GDPR / POPIA programme is more efficient than two parallel compliance functions.
How Cyber Resilience Can Help
Cyber Resilience helps organisations assess GDPR applicability, strengthen privacy governance, and align cross-border compliance obligations with existing POPIA programmes through structured audit and advisory engagements.
Speak to our team to arrange a GDPR readiness discussion.
