Records & POPIA
Cross-Border Data Transfer Compliance
Lawfulness of transfers of personal information outside South Africa under POPIA Section 72.
Sending personal information offshore requires a lawful basis
Section 72 of POPIA prohibits the transfer of personal information out of South Africa unless a specific lawful ground applies, such as comparable foreign protection, data-subject consent or contractual necessity. Cloud services, offshore processors and global systems mean these transfers happen routinely and often unknowingly. AuditPro Core surfaces flows of personal information across the border and tests each against a valid section 72 ground so that unlawful transfers are identified before they become an Information Regulator matter.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Cross-border flows
61
Without lawful basis
14
23% of flows
To inadequate jurisdictions
9
Cloud vendors
27
Transfer flows by legal basis
Transfers lacking lawful basis
| System / vendor | Destination | Data type | Records |
|---|---|---|---|
| HR SaaS platform | United States | Employee records | 9400 |
| Email archive | Ireland | Correspondence | 280000 |
| Analytics tool | Singapore | Citizen usage | 64000 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
The default is prohibition
Cross-border transfer is not permitted unless one of the section 72 grounds is satisfied. The burden is on the responsible party to establish the lawful basis, not on the regulator to prove its absence.
Adequacy of foreign protection
Transfer is permitted where the recipient is bound by a law, code or contract upholding principles substantially similar to POPIA. Assessing and documenting that adequacy is part of establishing the ground.
Invisible transfers through cloud
Many transfers occur silently when data is stored or processed on offshore infrastructure. Mapping where data physically resides is essential because a transfer cannot be assessed if it is not known.
Onward transfer risk
A lawful transfer to one country can be undone if that recipient onward-transfers to a third country without equivalent protection. The chain of custody, not just the first hop, must be considered.
How AuditPro Core Bridges the Gap
- Flow mapping: transfers of personal information outside South Africa are identified across systems and processors.
- Ground validation: each transfer is tested against a section 72 basis such as adequacy, consent or contract.
- Exception workflow: transfers lacking a documented lawful ground are flagged for remediation or cessation.
- Audit-ready export: transfer registers and their lawful bases export to evidence POPIA compliance.
Key Takeaways
- Cross-border transfer is prohibited by default unless a section 72 ground applies.
- Document the adequacy of the recipient's data-protection regime.
- Map data residency, because cloud processing creates invisible transfers.
- Consider onward transfers, not just the first hop out of the country.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
