Compliance

Data protection and security when outsourcing to South Africa

Data protection is the most common question from UK and European buyers — and the one most often handled badly in contracts. Here is what good looks like.

Last reviewed September 2026By the Callrica editorial team11 min read

Short answer

Outsourcing customer contact to South Africa can be fully compliant, but it needs the right paperwork and controls. South Africa does not have UK or EU adequacy status, so UK organisations normally use the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and EU organisations use the EU Standard Contractual Clauses, each with a transfer risk assessment. In South Africa, providers must comply with the Protection of Personal Information Act (POPIA). Contracts should fix where data is processed, control subcontracting, and require security standards such as SOC 2, ISO 27001 and PCI DSS where relevant.

Key points

  • South Africa has no UK or EU adequacy decision — use the IDTA, UK Addendum or EU SCCs plus a transfer risk assessment.
  • POPIA, in force since July 2021, is broadly aligned with GDPR principles and applies to providers in South Africa.
  • Keeping data hosted in the UK, EU or your own cloud, with agents using secure virtual desktops, reduces risk.
  • Vague contract wording about 'relevant legislation' is not a lawful transfer mechanism.
  • Ask for independent assurance: SOC 2 reports, ISO 27001 certificates and PCI DSS attestations.

Not legal advice

This guide summarises common requirements in general terms. Laws and regulator guidance change; take advice from qualified data protection lawyers for your situation.

UK GDPR: transferring UK personal data to South Africa

When a South African provider receives, stores or even remotely accesses personal data of UK customers, UK GDPR treats this as a restricted transfer. Because South Africa is not covered by UK adequacy regulations, you need an appropriate safeguard. For most outsourcing arrangements that means:

  1. The International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses (useful if you also transfer EU data).
  2. A transfer risk assessment considering the laws and practices in South Africa and the protections in place. The ICO provides a tool and guidance for this.
  3. Supplementary measures where needed — encryption, access controls, data minimisation and keeping data hosted outside South Africa.

The UK’s Data (Use and Access) Act 2025 updated the framework for international transfers. Check the ICO’s current guidance, but for South Africa the practical approach above remains standard.

A common contract failure

Clauses that let a provider relocate services “anywhere in the world” through agents or subcontractors, or that say data will be “used with due cognisance of relevant legislation”, do not meet UK GDPR requirements. Contracts should specify:

  • the approved delivery locations and data hosting locations;
  • that any change of location or new subcontractor requires your prior written consent;
  • the transfer mechanism, attached as a schedule;
  • processing instructions, security measures, breach notification and audit rights.

EU GDPR

For EU personal data, use the EU Standard Contractual Clauses (the module for controller-to-processor or processor-to-processor as appropriate) with a transfer impact assessment. If you transfer both UK and EU data, the SCCs with the UK Addendum can cover both.

POPIA: South Africa’s data protection law

The Protection of Personal Information Act (POPIA) has been fully enforceable since 1 July 2021 and is overseen by the Information Regulator. Key points for clients:

  • It sets eight conditions for lawful processing — accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation — broadly aligned with GDPR principles.
  • A provider acting as an operator (similar to a processor) must process only with the knowledge or authorisation of the responsible party, keep information confidential, and be bound by a written contract requiring security safeguards.
  • Security compromises must be notified to the Regulator and affected individuals.
  • Section 72 restricts transfers of personal information out of South Africa unless conditions are met, such as the recipient being bound by adequate law or binding agreements — relevant when data flows back to you or to other countries.
  • Direct marketing by electronic communication requires consent or an existing customer relationship, which matters for outbound programmes.

Australia: APP 8

Under the Privacy Act 1988, Australian Privacy Principle 8 generally requires you to take reasonable steps to ensure an overseas recipient handles personal information consistently with the APPs, and you may be accountable for its acts. Build APP-aligned obligations, audit rights and breach notification into the contract. APRA-regulated entities also need to meet CPS 230 requirements for material service providers.

United States

Requirements depend on your sector and states: HIPAA Business Associate Agreements for health information, GLBA safeguards for financial data, state privacy laws such as the CCPA/CPRA, and payment card rules. Outbound programmes must follow the TCPA and telemarketing rules; collections must follow the FDCPA and Regulation F.

Security standards and assurance

Standard What it tells you When to ask for it
SOC 2 Type 1 Controls are suitably designed at a point in time Minimum assurance for most programmes
SOC 2 Type 2 Controls operated effectively over 6–12 months Larger or sensitive programmes; US buyers often expect it
ISO/IEC 27001 A certified information security management system Common for UK and EU buyers
PCI DSS Card data is handled securely Any programme taking card payments
ISO 22301 Business continuity management Critical services

Ask for current reports or certificates, their scope (which sites and services are covered) and any exceptions noted by auditors.

Practical controls that reduce risk

  • Host data outside the contact centre: keep data in the UK, EU or your own cloud; agents access through virtual desktops with no local storage.
  • Clean-desk and device controls: no personal phones on the floor, disabled USB ports, printing blocked.
  • Payment security: DTMF masking or secure IVR so agents never hear or see card numbers.
  • Least-privilege access with multi-factor authentication and regular access reviews.
  • Screen and call recording with controlled retention and redaction.
  • Vetting and training: background checks, confidentiality agreements and regular data protection training.
  • Monitoring and testing: security monitoring, penetration tests and continuity exercises.

Due diligence checklist

  • Which legal entity will process the data, and where?
  • Which subcontractors are used, and where?
  • Which transfer mechanism will be used, and who completes the transfer risk assessment?
  • Current SOC 2, ISO 27001 and PCI DSS evidence, with scope.
  • Data retention and deletion approach.
  • Breach history and notification process.
  • Business continuity and disaster recovery test results.

Frequently asked questions

Does South Africa have UK GDPR adequacy?

No. At the time of writing, South Africa is not covered by UK adequacy regulations or an EU adequacy decision. Transfers of UK or EU personal data therefore need an appropriate safeguard, such as the UK IDTA, the UK Addendum to the EU SCCs, or the EU SCCs.

What is POPIA?

The Protection of Personal Information Act 4 of 2013 is South Africa's main data protection law. It became fully enforceable on 1 July 2021 and is overseen by the Information Regulator. It sets conditions for lawful processing similar to GDPR principles, requires written contracts with operators (processors), security safeguards and breach notification, and restricts transfers of personal information out of South Africa.

Can our customer data stay in the UK if agents are in South Africa?

Often, yes. Many programmes keep data in UK, EU or client-owned cloud environments and give agents access through secure virtual desktops or browser-based applications. Viewing or accessing data from South Africa is still treated as a transfer or restricted transfer, so you still need a transfer mechanism, but the risk and the security controls are easier to manage.

What is the difference between SOC 2 Type 1 and Type 2?

A SOC 2 Type 1 report assesses whether a provider's controls are suitably designed at a point in time. A Type 2 report tests whether those controls operated effectively over a period, usually six to twelve months. Type 2 gives more assurance.

Sources

  1. ICO: A guide to international transfers
  2. ICO: Adequacy regulations
  3. Information Regulator (South Africa)
  4. OAIC: Australian Privacy Principles

Get a costed proposal for your contact centre

Tell us about your volumes, channels and markets. We will come back within one business day with questions, an indicative cost and the options worth considering — including if South Africa is not the right fit.