POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

Financial Mail v Sage Holdings | Privacy of juristic persons

In Financial Mail (Pty) Ltd v Sage Holdings Ltd, the Court extended personality rights to a corporation in 1993. This judgment was a significant development in our law and underpins POPIA's requirement that responsible parties protect the personal information of [...]

Kenya’s cross-border data transfer guidance note

Kenya has introduced important new guidance for organisations transferring personal data across borders. On 8 September 2026, Kenya’s Office of the Data Protection Commissioner (ODPC) published its Guidance Notes for Cross-border Data Transfers, giving organisations more detailed direction on how […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Information Security Team: Your task force for securing information and responding to incidents

A group can achieve a goal faster and more effectively than one person working alone. Information security law compliance is difficult and requires an information security team of people to do it properly. Your team should include people from [...]

The law regards automatic and electronic processes

Many organisations are reviewing processes and looking for ways to do them electronically and automatically. Putting digital first or moving from a paper-based environment to a digital environment. There are obviously huge benefits to going digital - saving time [...]

Information Regulator ramps up enforcement

Information Regulator ramps up enforcement: on 1 September 2026, the Information Regulator briefed the public and media on its latest enforcement and compliance activities under POPIA and PAIA. The briefing shows the Regulator is increasingly concerned about South Africa's cybersecurity [...]

Cybersecurity flow-down clauses – Whose compliance obligations?

A security addendum arrives from a customer. They want incident notification within 24 hours, the right to audit you on site, approval before you change a subcontractor, and cooperation with their penetration testing. These are cybersecurity flow-down clauses: contractual terms [...]

By |2026-08-12T13:35:29+02:00August 12th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Nominate someone to be a member of the information regulator

Parliament has invited the organisations and interested individuals to nominate people (or apply themselves) for the President to appoint as members of the information regulator. Do you want to nominate someone? Do you know anyone who might want to nominate [...]

By |2026-08-20T11:03:08+02:00August 5th, 2026|Categories: POPI and Data Protection|Tags: , |

Pre-investigation notice from the Information Regulator: what now?

If a complainant lodges a complaint against you for infringing their privacy rights, the information regulator can issue any one of a few types of notices to you. For example, you could receive an information notice, an enforcement notice, or [...]

Enforcement Notice from the Information Regulator: what now?

The Information Regulator may send you a POPIA enforcement notice after investigating you and finding that you have contravened POPIA by failing to lawfully process personal information. In comparison, the Information Regulator may send you an infringement notice if it [...]

Information Officer and PAIA manual for the group or each entity within the group?

The Promotion of Access to Information Act (PAIA) states that the head of a private body is the Information Officer, and they should compile a PAIA manual for the private body and update the manual regularly (unless exempt). According to […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Who needs a Data Protection Officer (DPO)?

Who must appoint a DPO? What does the General Data Protection Regulation (GDPR) require regarding a Data Protection Officer (or DPO)? This is one of the questions that the GDPR, adopted by the European Parliament in 2016, has prompted many organisations to ask. Another [...]

Who is responsible for data protection in your relationships?

Who is responsible for complying with data protection legislation (including the POPI Act in South Africa and the GDPR) where you process personal information together with someone else? It is crucial to know the answer to this question. It is [...]

By |2026-07-13T22:31:08+02:00July 10th, 2026|Categories: POPI and Data Protection|Tags: , , , , |