
European data protection law can apply to a South African business that has no European office. The test is whether you offer goods or services to people in Europe, or monitor their behaviour, which catches online sellers shipping there, businesses accepting European bookings, and anyone tracking European visitors to their site.
The good news is that the local law requires most of the same things.
When it applies to you
If you deliberately target customers in Europe, by pricing in euros, shipping there, or marketing to them, or if you track and profile people located there, the regulation can reach you regardless of where you are based.
Simply having a website that Europeans can visit does not, by itself, mean you are targeting them. The question is whether you are directing your activity at that market.
It overlaps heavily with POPIA
The South African Protection of Personal Information Act, overseen by the Information Regulator, was drafted with similar principles: a lawful basis for processing, transparency about what you hold and why, security, and rights for the individual.
A business genuinely complying with the local law is most of the way to the European one. Doing the local work properly is therefore the efficient route rather than treating them as two projects.
What compliance actually requires
Know what personal information you hold, where it came from, why you have it and who you share it with. Have a lawful basis for each use, and tell people plainly in language they can understand.
Get real consent for direct marketing, with a working opt-out honoured immediately. Be able to respond when someone asks what you hold, wants it corrected or wants it deleted. And secure it properly, since a breach carries notification obligations under both regimes.
Where it bites hardest
Suppliers and processors. If you use overseas services to store or process customer data, you remain responsible for what they do with it, and contracts should reflect that.
Corporate clients increasingly push these obligations down to suppliers contractually, which means data protection has become a condition of winning work rather than only a legal duty. Registration and compliance basics at the Companies and Intellectual Property Commission are checked alongside it during vendor onboarding.
Frequently asked questions
Does European data law apply to a South African business?
It can, if you target customers in Europe or monitor people located there, regardless of where you are based.
Does having a website Europeans can visit count?
Not by itself. The question is whether you are directing your activity at that market, such as pricing in euros or shipping there.
How does it relate to POPIA?
They share principles closely. Genuine local compliance covers most of the European requirements.
What does compliance require in practice?
Knowing what data you hold and why, a lawful basis for each use, real consent for marketing, honouring rights requests, and securing it.
Am I responsible for my suppliers?
Yes. If overseas services process your customer data, you remain responsible and your contracts should reflect that.
Further reading
Originally published in June 2018. Updated September 2026 to explain when European data protection law reaches a South African business.
