VerifyNow guide

Healthcare data residency requirements in South Africa: POPIA, KYC & cross-border rules

Healthcare data residency requirements in South Africa affect every clinic, hospital, medical scheme, health-tech, and research partner handling patient da...

Healthcare data residency requirements in South Africa: POPIA, KYC & cross-border rules

Direct answer

POPIA does not require all healthcare or identity data to be stored in South Africa. A responsible party must identify the data, purpose, parties and transfer route, then apply the ordinary POPIA conditions and any special-information rules.

Section 72 transfer routes

A South African responsible party may transfer personal information to a foreign recipient where one statutory route applies: adequate protection through law, binding corporate rules or a binding agreement; data-subject consent; contract or pre-contract necessity; a contract in the data subject's interest; or the limited benefit and impracticable-consent route.

Section 57 prior authorisation can also apply where special personal information or children's information is transferred to a country without adequate protection.

Health information

Health information is special personal information under section 26. Processing needs an authorisation under sections 27 to 33. Section 32 contains specific authorisations for healthcare professionals, healthcare bodies, insurers, medical schemes and administrators in defined circumstances, with confidentiality requirements.

Official source: POPIA and the Information Regulator's cross-border guidance.

Cloud-region decision record

Record the responsible party, operator, data categories, recipient country, section 72 ground, onward-transfer protection, access model, retention, deletion and incident route. Do not claim a VerifyNow hosting region, local-storage guarantee, encryption standard or healthcare certification unless current contractual evidence states it.

Existing VerifyNow resources