Back to Explore
🔒

Records & POPIA

Cross-Border Data Transfer Compliance

Lawfulness of transfers of personal information outside South Africa under POPIA Section 72.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Sending personal information offshore requires a lawful basis

Section 72 of POPIA prohibits the transfer of personal information out of South Africa unless a specific lawful ground applies, such as comparable foreign protection, data-subject consent or contractual necessity. Cloud services, offshore processors and global systems mean these transfers happen routinely and often unknowingly. AuditPro Core surfaces flows of personal information across the border and tests each against a valid section 72 ground so that unlawful transfers are identified before they become an Information Regulator matter.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Cross-border flows

61

Without lawful basis

14

23% of flows

To inadequate jurisdictions

9

Cloud vendors

27

Transfer flows by legal basis

Transfers lacking lawful basis

System / vendorDestinationData typeRecords
HR SaaS platformUnited StatesEmployee records9400
Email archiveIrelandCorrespondence280000
Analytics toolSingaporeCitizen usage64000

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

The default is prohibition

Cross-border transfer is not permitted unless one of the section 72 grounds is satisfied. The burden is on the responsible party to establish the lawful basis, not on the regulator to prove its absence.

Adequacy of foreign protection

Transfer is permitted where the recipient is bound by a law, code or contract upholding principles substantially similar to POPIA. Assessing and documenting that adequacy is part of establishing the ground.

Invisible transfers through cloud

Many transfers occur silently when data is stored or processed on offshore infrastructure. Mapping where data physically resides is essential because a transfer cannot be assessed if it is not known.

Onward transfer risk

A lawful transfer to one country can be undone if that recipient onward-transfers to a third country without equivalent protection. The chain of custody, not just the first hop, must be considered.

How AuditPro Core Bridges the Gap

  • Flow mapping: transfers of personal information outside South Africa are identified across systems and processors.
  • Ground validation: each transfer is tested against a section 72 basis such as adequacy, consent or contract.
  • Exception workflow: transfers lacking a documented lawful ground are flagged for remediation or cessation.
  • Audit-ready export: transfer registers and their lawful bases export to evidence POPIA compliance.

Key Takeaways

  • Cross-border transfer is prohibited by default unless a section 72 ground applies.
  • Document the adequacy of the recipient's data-protection regime.
  • Map data residency, because cloud processing creates invisible transfers.
  • Consider onward transfers, not just the first hop out of the country.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.