Emma Quiding has been interested in the intersection between law and technology since 2016, when she studied Law and Computer Science as part of an academic programme at Harvard University. Nearly a decade later, she is proud to have developed a career in exactly that intersection, practising in the field of data protection, technology law, and information governance. Her work focuses on helping organisations assess and improve how they process personal information in practice, not only on paper.
Emma has a strong specialisation in privacy and data protection assessments, including personal information impact assessments (PIIAs) and transfer impact assessments (TIAs). She works closely with organisations to assess their existing practices, processes, and procedures against the requirements of applicable data protection laws, including POPIA and the GDPR, and against the data protection standards that data subjects are entitled to expect. Her aim is to help organisations move beyond seeing privacy as a compliance burden and towards treating it as a practical, embedded priority that runs through all levels of the organisation.
Emma prioritises close, collaborative working relationships with her clients. She takes the time to understand each client’s context, risk profile, and commercial realities, and works alongside them to develop solutions that are both legally sound and practical. Her approach is grounded in partnership, combining legal expertise with an understanding of how organisations actually operate.
See her insights.
At Michalsons, Emma supports clients across industries by using the firm’s 4‑pronged approach to help:
Learning
- Conducting tailored training sessions and workshops on POPIA, data protection principles, and privacy risk management
- Delivering practical training on conducting PIIAs and understanding privacy risks in products and services
- Supporting awareness programmes that align legal requirements with operational realities
- Ensuring that deliverables are understandable and digestible to ensure organisations understand the legal advice given
Programme
- Assisting organisations to design and implement practical data protection compliance programmes
- Supporting privacy governance structures and internal accountability frameworks
- Advising on privacy risk assessments and remediation planning
- Conducting regulator-ready assessments that ensure a company’s privacy structures meet the Information Regulator’s standards
Software
Supporting organisations by understanding and highlighting when privacy management software and data governance tools should be considered and adopted
Services
- Drafting, reviewing, and updating privacy policies, PAIA manuals, data processing agreements, and internal data protection documentation
- Conducting PIIAs and TIAs, including assessments of cross-border data transfers within Africa and from the EEA
- Advising on POPIA and GDPR alignment for organisations operating across jurisdictions
- Responding to and advising on data breaches and security incidents
- Drafting, reviewing, and negotiating IT, SaaS, and technology-related contracts
- Advising on access to information requests and PAIA processes
- Providing practical legal advice and opinions tailored to a client’s specific operational context
Emma enjoys working in collaborative environments and is committed to helping organisations build sustainable, trustworthy data practices that support both compliance and long-term value.
Emma was involved with technology throughout her university career. During her time at the University of Cape Town she:Â Â
- Worked as the social media administrator for the University of Cape Town Rowing Club. Â
- Achieved distinctions in both the Cyber Law and Intellectual Property Law electives. Â
- Gained experience in drafting notices of privacy, privacy policies and data-processing agreements. Â
