Following our 2024 report, the Information Regulator has invited public input on the draft Regulations on Processing Health and Sex Life Data published under the Protection of Personal Information Act (‘POPIA’).
Although section 26(1) of POPIA imposes a general prohibition on processing personal information regarding a data subject’s health and sex life, section 32(1) of the Act creates an exemption in instances where this information must be processed to facilitate:
- Compliance with an obligation imposed by law on the responsible party;
- Securing the legitimate interests of the responsible party; or
- Protecting a legitimate interest of a data subject.
In line with POPIA’s core objectives, and in light of this exemption, the proposed Regulations are designed to strengthen the protection of health and sex life data. In addition to enhancing transparency for data subjects about how their most sensitive information may be processed, retained, and destroyed, the draft Regulations empower the Information Regulator and affected individuals to challenge any processing that goes beyond the legal ambit of POPIA.
Applicable to listed responsible parties processing personal information regarding data subjects’ health or sex life for circumscribed activities, the draft instrument governs the provision of informed consent, cross-border transfers of information, the assessment of a legitimate interest, technical safeguard measures, the retention of records, and destruction of information, among other elements. Crucially, the draft Regulations require responsible parties to obtain informed consent in writing. In instances where the data subject’s consent is obtained telephonically, this must be recorded – along with the proviso that consent may be withdrawn at any time.
Once published, the Regulations will impact insurance companies, medical schemes, pension funds, managed healthcare organisations, and administrative entities involved in handling health and sex life data. In practice, the Regulations will, for example, apply to an insurance company conducting medical tests on an insured individual for the purpose of determining whether the claimant is entitled to be paid out.
Given the nature of these regulatory requirements, it is critical that institutions that handle personal information thoroughly review the draft Regulations and submit their input timeously.
Comments may be emailed to JJJansen@infoRegulator.org.za by Friday, 10th October 2025.
In the POPIA sphere, compliance not only helps businesses avoid unwanted administrative penalties and reputational harm, but also builds trust and confidence with clients and stakeholders.
For compliance-related legal advice or assistance with POPIA queries, contact our compliance specialists at compliance@stbb.co.za today.
This content is the property of STBB. We encourage the sharing of our content for informational purposes. However, if you wish to copy or reproduce our content on your own platform or website, please ensure that proper credit is given to STBB.