POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

Cybersecurity flow-down clauses – Whose compliance obligations?

A security addendum arrives from a customer. They want incident notification within 24 hours, the right to audit you on site, approval before you change a subcontractor, and cooperation with their penetration testing. These are cybersecurity flow-down clauses: contractual terms [...]

By |2026-08-12T13:35:29+02:00August 12th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Nominate someone to be a member of the information regulator

Parliament has invited the organisations and interested individuals to nominate people (or apply themselves) for the President to appoint as members of the information regulator. Do you want to nominate someone? Do you know anyone who might want to nominate [...]

By |2026-08-20T11:03:08+02:00August 5th, 2026|Categories: POPI and Data Protection|Tags: , |

Pre-investigation notice from the Information Regulator: what now?

If a complainant lodges a complaint against you for infringing their privacy rights, the information regulator can issue any one of a few types of notices to you. For example, you could receive an information notice, an enforcement notice, or [...]

Enforcement Notice from the Information Regulator: what now?

The Information Regulator may send you a POPIA enforcement notice after investigating you and finding that you have contravened POPIA by failing to lawfully process personal information. In comparison, the Information Regulator may send you an infringement notice if it [...]

Information Officer and PAIA manual for the group or each entity within the group?

The Promotion of Access to Information Act (PAIA) states that the head of a private body is the Information Officer, and they should compile a PAIA manual for the private body and update the manual regularly (unless exempt). According to […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Who needs a Data Protection Officer (DPO)?

Who must appoint a DPO? What does the General Data Protection Regulation (GDPR) require regarding a Data Protection Officer (or DPO)? This is one of the questions that the GDPR, adopted by the European Parliament in 2016, has prompted many organisations to ask. Another [...]

Who is responsible for data protection in your relationships?

Who is responsible for complying with data protection legislation (including the POPI Act in South Africa and the GDPR) where you process personal information together with someone else? It is crucial to know the answer to this question. It is [...]

By |2026-07-13T22:31:08+02:00July 10th, 2026|Categories: POPI and Data Protection|Tags: , , , , |

Map activities, not information or data flows

You should map activities (rather than information, data flows, or processes) as a first step toward complying with data protection laws (such as the GDPR and the Protection of Personal Information Act (POPI Act)). The law requires larger organisations to […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Central Johannesburg TVET College enforcement action | POPIA breaches

The Central Johannesburg TVET College enforcement action confirms that the Information Regulator will act when POPIA conditions are not met. On 22 May 2026, the Regulator issued its first formal enforcement notice of the year, following complaints lodged by employees [...]

What is a private body or organisation?

The law treats a private body differently from a public body, so it is essential that you know the difference. Some laws (like POPIA and PAIA) require private bodies to do specific things (like submit a PAIA report). You can [...]

NCC opt-out registry is a crisis for marketers

The NCC opt-out registry is a crisis for marketers. The new direct marketing regulations under the CPA may be one of the most burdensome compliance obligations marketers will face in years. Marketers must register, pay ongoing fees and opt people [...]

Gated Access Code of Conduct under POPIA

On 30 April 2026, the Information Regulator published the draft Gated Access Code of Conduct under POPIA. It applies to owners, managers, and their security and technology service providers at any gated premises, including residential estates and office parks. The [...]

By |2026-06-23T15:42:55+02:00May 5th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , |