Search legal guides

Search MJ Kotze Inc legal guides and articles

Data, Privacy & Website

Cross-Border Data Transfer Agreement in South Africa

Send personal information offshore — to a cloud host, group company, or overseas processor — on a POPIA section 72 footing that actually holds, with the adequacy, onward-transfer, and operator obligations the Act demands.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

What is a cross-border data transfer agreement?

A cross-border data transfer agreement (also called a data transfer agreement, transborder data flow agreement, or international data transfer agreement) is a contract that lets a responsible party in South Africa lawfully transfer personal information to a recipient outside the country — for example a foreign cloud provider, an offshore call centre, a group holding company, or an overseas customer or supplier. Under the Protection of Personal Information Act 4 of 2013 (POPIA), sending personal information out of South Africa is not free — it is regulated by a single provision, section 72, which prohibits the transfer unless one of a closed list of grounds is met. The agreement is the practical tool that satisfies the most common ground: it makes the foreign recipient contractually subject to a binding agreement that provides an adequate level of protection substantially similar to POPIA, and binds it to the same conditions on any onward transfer to a fourth country. Where the foreign recipient is processing the information for the South African business (a cloud host, a payroll bureau, an analytics vendor), it is an operator, so the same contract usually carries the operator and security obligations POPIA requires under sections 19 to 21 as well. It is the South African equivalent of the EU GDPR’s standard contractual clauses (SCCs) — a written instrument that exports POPIA-grade protection along with the data.

Is a cross-border data transfer agreement legally binding and required in South Africa?

Yes — and for most offshore transfers it is effectively required. As a contract, a cross-border data transfer agreement is binding in South Africa on ordinary common-law principles, provided it meets the usual requirements of consensus, lawful purpose, certainty, and possibility. But the more important point is statutory: under section 72 of POPIA, a responsible party may not transfer personal information to a third party in a foreign country unless one of five grounds applies. The primary ground is that the recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection — one that upholds principles for reasonable processing substantially similar to POPIA’s conditions, and that includes onward-transfer provisions substantially similar to section 72 itself. The other grounds are: the data subject consents to the transfer; the transfer is necessary for the performance or conclusion of a contract between the data subject and the responsible party (or a contract concluded in the data subject’s interest); or the transfer is for the data subject’s benefit where consent is not reasonably practicable but would likely be given. Because South Africa has no list of “adequate” countries and the Information Regulator has issued no formal adequacy decisions, in practice the responsible party carries the burden of securing adequacy — and a properly drafted data transfer agreement is how most businesses discharge it. Critically, the agreement does not transfer away liability: under POPIA the responsible party remains accountable for the personal information even after it leaves the country, and where the foreign recipient is an operator, section 21 requires a written contract obliging it to maintain the security safeguards in section 19. So the document is binding as a matter of contract and load-bearing as a matter of compliance — without it, the offshore transfer is usually simply unlawful. The leading academic treatment, Coetzee, Cross-Border Data Flows and the Protection of Personal Information Act 4 of 2013 — Part II: The Data Transfer Provision [2024] PER 48, confirms that section 72 is the single transborder-flow provision and that the binding-agreement route is the workable mechanism for lawful export.
A responsible party in the Republic may not transfer personal information about a data subject to a third party who is in a foreign country unless the third party who is the recipient of the information is subject to a law, binding corporate rules or binding agreement which provide an adequate level of protection that effectively upholds principles for reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information … and includes provisions, that are substantially similar to this section, relating to the further transfer of personal information; or the data subject consents to the transfer; or the transfer is necessary for the performance of a contract; or the transfer is for the benefit of the data subject.
Protection of Personal Information Act 4 of 2013, s 72 (transfers of personal information outside the Republic)
A responsible party must, in terms of a written contract between the responsible party and the operator, ensure that the operator which processes personal information for the responsible party establishes and maintains the security measures referred to in section 19. … A responsible party must secure the integrity and confidentiality of personal information in its possession or under its control by taking appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information; and unlawful access to or processing of personal information.
Protection of Personal Information Act 4 of 2013, ss 19 & 21 (security safeguards and the operator written-contract requirement)
Chapter 9 of POPIA regulates transborder information flows through a single provision, section 72, which regulates the transfer of personal information by a responsible party in the Republic to a third party in a foreign country, and the binding-agreement mechanism is the principal route by which a responsible party can lawfully effect such a transfer while exporting an adequate level of protection.
Coetzee J, "Cross-Border Data Flows and the Protection of Personal Information Act 4 of 2013 — Part II: The Data Transfer Provision" [2024] PER 48 (Potchefstroom Electronic Law Journal)

When you need a Cross-Border Data Transfer

  • Before hosting personal information (customer records, HR data, CRM, backups) on cloud infrastructure or SaaS whose servers or support are located outside South Africa — most global cloud providers process or store data offshore, triggering section 72.
  • When sharing employee, client, or supplier personal information with an overseas parent, subsidiary, or affiliate in a group of companies — the agreement (or binding corporate rules) supplies the section 72(1)(a) adequacy ground for intra-group transfers.
  • When outsourcing a function that involves personal information to an offshore provider — payroll, call centre, debt collection, IT support, analytics, or KYC/identity verification — where that provider is an operator processing on your behalf.
  • When selling, marketing to, or contracting with foreign customers or partners and you must send their or third parties’ personal information across the border to perform the deal.
  • When a foreign head office, regulator, or platform requires personal information from your South African operation, and you need a lawful basis plus contractual safeguards before exporting it.

What a Cross-Border Data Transfer should contain

1

Section 72 lawful basis / transfer ground

State expressly which section 72 ground the transfer relies on — adequate protection via this binding agreement, binding corporate rules, data-subject consent, contractual necessity, or benefit to the data subject. Recording the basis is what makes the transfer demonstrably lawful, not merely contractual, and is the first thing the Information Regulator will look for.

2

Adequate level of protection (POPIA-equivalent obligations)

Bind the foreign recipient to data-protection standards substantially similar to POPIA’s eight conditions — purpose limitation, processing limitation, security safeguards, data-subject rights, and accountability. This is the substance of the section 72(1)(a) “adequate level of protection” requirement; vague promises to “comply with applicable law” do not satisfy it.

3

Onward-transfer (further transfer) restriction

Prohibit the recipient from transferring the personal information to a fourth country or further sub-processor unless that onward recipient is bound by protection substantially similar to section 72. POPIA expressly requires the agreement to contain onward-transfer provisions; omitting this clause leaves a hole the Act will not tolerate.

4

Operator and security obligations (ss 19 & 21)

Where the recipient processes the information for you (an operator), include the written operator terms POPIA demands: process only on documented instructions, maintain the section 19 security safeguards, keep the information confidential, and not process for the operator’s own purposes. This is mandatory under section 21, not optional.

5

Security breach notification

Require the recipient to notify you immediately of any actual or suspected unauthorised access to or acquisition of the personal information, with enough detail and speed for you to meet your own POPIA notification duties to the Information Regulator and affected data subjects under section 22. Build in timelines, not a general “as soon as possible”.

6

Scope, purpose and data-subject categories

Define exactly what personal information is transferred, the categories of data subjects, and the limited purposes for which it may be processed. A precise data map keeps the transfer within purpose limitation and supports the adequacy and accountability obligations; a sweeping “any personal information” clause undermines both.

7

Audit, assistance and data-subject rights

Give yourself rights to audit or obtain assurance of compliance, and require the recipient to assist you in responding to data-subject access, correction, and deletion requests and to Regulator enquiries. Because liability stays with you, you need contractual levers to actually verify and enforce the offshore party’s compliance.

8

Return or deletion and retention limits

On termination or once the purpose ends, require the recipient to return or securely destroy the personal information and all copies (including backups) and to certify it. POPIA does not allow indefinite offshore retention, so the contract must align with your retention policy and close out the data once it is no longer needed.

9

Liability, indemnity, governing law and jurisdiction

Allocate liability for non-compliance, take an indemnity for breaches that expose you to Regulator action, and choose South African governing law and an enforceable forum. Since the responsible party remains accountable under POPIA regardless of contract, a meaningful indemnity and an enforceable dispute mechanism are essential, not boilerplate.

POPIA section 72 grounds vs GDPR transfer mechanisms — at a glance

FeaturePOPIA (South Africa)EU GDPR (for comparison)
Governing provisionSection 72 of POPIA — a single transborder-flow provisionChapter V (Articles 44–50)
Adequacy routeNo official list of adequate countries; responsible party assesses adequacy itselfEuropean Commission adequacy decisions for listed countries
Contract routeA binding agreement giving “adequate level of protection” + onward-transfer termsStandard contractual clauses (SCCs) approved by the Commission
Group routeBinding corporate rules within a group of undertakingsBinding corporate rules approved by a supervisory authority
Consent routeData subject consents to the transfer (informed)Explicit consent (a derogation, used narrowly)
Who stays liableResponsible party remains accountable after exportController (and exporter) remains accountable

Common South African pitfalls

  • Assuming a normal contract or NDA is enough: an ordinary services contract or confidentiality agreement does not satisfy section 72. The transfer is only lawful if a specific section 72 ground is met, and the agreement must carry POPIA-equivalent adequacy and onward-transfer terms — generic confidentiality wording does not.
  • Relying on the recipient’s “applicable law” instead of binding it: assuming a US or other foreign provider is adequate because it “complies with its own laws” is risky — South Africa has no adequacy list, and laws like the US CLOUD Act can cut against POPIA-level protection. The safe route is to bind the recipient to adequate protection in the contract itself.
  • Forgetting the onward-transfer clause: section 72 specifically requires the agreement to include provisions, substantially similar to section 72, governing further transfers to a fourth country or sub-processor. A transfer agreement that lets the recipient pass the data on freely fails the statutory test.
  • Treating cloud storage as “not a transfer”: hosting personal information on offshore servers, or even granting offshore support staff access, is a cross-border transfer for POPIA purposes. Many businesses overlook this because the data “stays in the cloud”, but section 72 still applies.
  • Believing the contract shifts liability offshore: it does not. Under POPIA the responsible party remains accountable for the personal information even after it leaves the country, so the agreement must give you real audit, breach-notification, and indemnity rights — not a false sense that the problem is now the recipient’s.
  • Over-relying on consent: data-subject consent is one valid ground, but it is fragile — it must be informed and can be withdrawn, and it is impractical to obtain and maintain at scale. For routine operational transfers (cloud, group, outsourcing), the binding-agreement or binding-corporate-rules route is far more robust.

Frequently asked questions

Can I store South African personal information on offshore or cloud servers under POPIA?

Yes, but only on a section 72 ground. Hosting personal information outside South Africa is a cross-border transfer, so it is lawful only if the offshore provider is bound (by law, binding corporate rules, or a binding agreement) to an adequate level of protection substantially similar to POPIA, or another section 72 ground applies. A cross-border data transfer agreement is the usual way to satisfy this.

What does section 72 of POPIA actually require?

Section 72 prohibits a responsible party from transferring personal information to a third party in a foreign country unless one of five grounds applies: the recipient is bound to an adequate level of protection (by law, binding corporate rules, or a binding agreement with onward-transfer terms); the data subject consents; the transfer is necessary to perform or conclude a contract; or the transfer is for the data subject’s benefit and consent is not reasonably practicable.

Is a cross-border data transfer agreement legally binding in South Africa?

Yes. It is binding as an ordinary contract once it meets the common-law requirements of agreement, lawful purpose, and certainty. More importantly, it is the instrument that makes an offshore transfer lawful under section 72 of POPIA — without a valid section 72 ground, the transfer itself is unlawful even if the surrounding commercial contract is otherwise enforceable.

Does South Africa have an “adequacy list” like the EU?

No. POPIA does not name countries that provide adequate protection, and the Information Regulator has not issued formal adequacy decisions. The burden falls on each responsible party to assess and document the adequacy of the foreign recipient’s protection — which is precisely why a binding agreement imposing POPIA-equivalent obligations is the practical route to lawful transfer.

How is a POPIA data transfer agreement different from GDPR standard contractual clauses?

They do the same job — exporting data-protection standards with the data — but differ in form. The EU has pre-approved standard contractual clauses (SCCs) and an official adequacy list; POPIA has neither. Under section 72 you draft a binding agreement that delivers an “adequate level of protection” substantially similar to POPIA, including onward-transfer restrictions, rather than adopting a fixed approved template.

Do I still need an operator agreement if I have a transfer agreement?

Often the two are combined. Where the offshore recipient processes personal information for you (a cloud host, payroll bureau, or analytics vendor), it is an operator, so section 21 of POPIA requires a written contract obliging it to maintain the section 19 security safeguards and to notify you of breaches. A good cross-border data transfer agreement carries those operator and security terms alongside the section 72 grounds.

Who is liable if the offshore recipient mishandles the data?

The South African responsible party remains accountable under POPIA even after the information leaves the country — the transfer agreement does not shift that statutory accountability offshore. That is why the contract should give you audit rights, prompt breach notification, and an indemnity, so you can verify compliance and recover loss if the recipient fails. The Regulator looks to you first.

Can I rely on the data subject’s consent for cross-border transfers?

You can — consent is a valid section 72 ground — but it is fragile. It must be informed (the data subject must understand the transfer and its risks) and it can be withdrawn, and obtaining and maintaining consent at scale is impractical for routine operational transfers. For ongoing cloud, group, or outsourcing flows, the binding-agreement or binding-corporate-rules route is more durable.

Sources & authority

This guide is general information, not legal advice. It reflects the law as at June 2026.

Get your Cross-Border Data Transfer reviewed or drafted

Upload an existing document for a fixed-fee review, or have a bespoke Cross-Border Data Transfer drafted for your business — personally, by a senior corporate and commercial attorney. No obligation to proceed.

Review: Fixed fee from R8 325 (excl. VAT) · 24-hour turnaroundDraft: Fixed fee from R8 175 (excl. VAT)

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.