Short answer: for most businesses, no. The Protection of Personal Information Act 4 of 2013 (POPIA) does not contain a general data-localisation requirement, so you may store personal information on servers outside South Africa. What POPIA does regulate is sending personal information to a third party in a foreign country (section 72), and some sectors, contracts and public-sector rules add their own location requirements. This article explains where the real obligations lie and when hosting locally is still the sensible choice.
Residency, localisation and sovereignty
These terms get used interchangeably, but they mean different things:
- Data residency - where your data is physically stored, often as a business choice.
- Data localisation - a legal rule that data must be stored (or a copy kept) inside a country.
- Data sovereignty - the idea that data is subject to the laws of the country where it sits, including access by that country's authorities.
POPIA is not a localisation law. It regulates how personal information is processed wherever you process it, as long as you, the responsible party, are domiciled in South Africa or use means in South Africa to process it (section 3).
What section 72 actually says
Section 72 says a responsible party may not transfer personal information about a data subject to a third party in a foreign country unless one of these applies:
- Adequate protection - the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection, effectively upholding principles substantially similar to POPIA's conditions, and includes similar provisions for onward transfers.
- Consent - the data subject consents to the transfer.
- Contract with the data subject - the transfer is necessary to perform a contract between the data subject and the responsible party, or for pre-contractual steps taken at the data subject's request.
- Contract in the data subject's interest - the transfer is necessary for a contract concluded in the interest of the data subject between the responsible party and a third party.
- Benefit of the data subject - the transfer is for the data subject's benefit, it is not reasonably practicable to get consent, and they would likely give it if asked.
Most commercial cloud services rely on the first ground, through their data processing terms, or on the contract grounds. Transfers of special personal information or children's information to a country without adequate protection may also need prior authorisation from the Information Regulator under section 57.
Using an overseas host is therefore lawful when you can point to one of these grounds and you have assessed the provider. See POPIA section 72 and AI APIs for a worked example with AI services.
Where location requirements do come from
Even without a POPIA localisation rule, you may still be told to keep data in South Africa by:
- Client contracts - enterprise and government customers often specify data location in their procurement terms.
- Sector regulators - financial services, health and telecoms bodies may issue their own rules or guidance on outsourcing and cloud use. Check the requirements that apply to your licence.
- Public-sector policy - national data and cloud policy has discussed keeping certain government data in South Africa. If you supply the state, read the tender documents carefully.
- Group policy - your own board or head office may simply prefer local storage.
Because these differ by industry and change over time, get professional advice for your specific situation rather than relying on a general article.
Why many businesses choose local anyway
Even when not required, keeping data in South Africa has practical advantages:
| Factor | Local hosting | Overseas hosting |
|---|---|---|
| Section 72 analysis for the main data store | Not needed | Needed and documented |
| Network distance to SA users | Short | Longer, varies by region |
| Billing | Rand, with SA VAT invoices | Often foreign currency |
| Support hours | SA business hours | May be in other time zones |
| Governing law and courts | South African | Often foreign |
| Global audience reach | Needs a CDN for far-away users | Can be closer to users abroad |
The trade-off is honest: if most of your users are in Europe, a European region may serve them better. If they are in South Africa, local hosting keeps things simpler. Our comparison of South African versus overseas hosting goes through latency, currency and support in more detail.
Residency is about more than your main server
A common mistake is to host the app in Johannesburg and assume every copy of the data is local. Map every place personal information goes:
- Database and file storage - where the primary copy lives.
- Backups - which region, and for how long.
- Email delivery - transactional email services often process messages abroad.
- Error tracking and logs - stack traces often contain email addresses and IDs.
- Analytics and advertising pixels - visitor data sent to overseas platforms.
- AI APIs - prompts that contain customer details.
- Support tools - helpdesk and CRM systems.
Each of these is a potential section 72 transfer. Record them in a simple data map: service, data sent, country, legal ground, link to terms. That document answers most questions an auditor, client or the Information Regulator is likely to ask.
How NewHost fits
NewHost runs its servers in Johannesburg, so apps, managed databases and backups hosted with us stay in South Africa. We act as your operator for hosted content, as described in our privacy policy. Third-party services you connect to your app yourself (email senders, analytics, AI providers) are outside that and need their own assessment.
Frequently asked questions
Does POPIA require personal information to be stored in South Africa?
No. POPIA has no general data-localisation requirement. It restricts transfers to third parties in foreign countries under section 72, which lists the grounds on which such transfers are allowed.
Is using a US or European cloud provider a POPIA breach?
Not in itself. It is lawful if a section 72 ground applies, such as a binding agreement giving adequate protection or the data subject's consent, and if you meet POPIA's other conditions like security safeguards.
Do I need consent to store data overseas?
Consent is only one of the grounds in section 72. Many businesses rely instead on adequate protection through the provider's data processing terms, or on the transfer being necessary for a contract with the customer.
Are backups stored abroad a cross-border transfer?
If a third party in a foreign country stores or can access the backup, treat it as one. Check where your host and any backup service store copies, and document the legal ground.
If you want your apps, databases and backups kept in South Africa with rand billing, look at our managed databases or compare hosting plans.