The Applicability of the GDPR to the South African Road Accident Fund (RAF)

Executive Summary

  • The RAF is a statutory public body in South Africa that collects, holds, and processes a lot of personal information (claimants, medical data, third parties).
  • South Africa has its own strong data protection framework: POPIA (Protection of Personal Information Act, 2013).
  • While RAF must comply principally with POPIA, there are circumstances under which GDPR (General Data Protection Regulation of the EU) may also apply to RAF — particularly when dealing with personal data of EU persons, or when interacting with EU-based service providers or international cross-border transfers involving the EU.
  • This white paper analyses where those overlaps are, what risks and responsibilities RAF should consider, and what practical steps can ensure dual compliance (POPIA + GDPR) to avoid regulatory, legal, or reputational harm.

Background: RAF, POPIA, and GDPR

Road Accident Fund (RAF)

  • The RAF was established under the Road Accident Fund Act No. 56, 1996 and is a public entity responsible for compensating people injured due to negligent driving, etc. Its operations involve collecting claims, medical reports, personal identifiers, banking details, etc. (raf.co.za)
  • RAF publishes a Privacy Notice, meaning they are aware of data protection obligations. (raf.co.za)

POPIA (South Africa)

  • The Protection of Personal Information Act (Act 4 of 2013) regulates how personal information is processed in South Africa. It came into effect July 1, 2020, with a grace period that ended on June 30, 2021. (InfoTrust)
  • POPIA provides many rights similar to GDPR: lawful bases, data subject rights (access, correction, deletion, etc.), security safeguards, accountability, etc. (InfoTrust)

GDPR (EU) Overview

  • GDPR applies primarily to entities in the EU, but also extraterritorially (Art. 3 GDPR) to organizations outside the EU that process personal data of persons in the EU in certain contexts (offering services, monitoring behaviour).
  • GDPR has strong requirements for high-risk processing, data transfers outside the EU, breach notification, and rights of data subjects.

When Could GDPR Apply to RAF?

Even though RAF is a South African entity, there are scenarios under which GDPR could have relevance:

  1. Data of EU Citizens or Residents
  2. #BBD0E0 »