POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

Pre-investigation notice from the Information Regulator: what now?

If a complainant lodges a complaint against you for infringing their privacy rights, the information regulator can issue any one of a few types of notices to you. For example, you could receive an information notice, an enforcement notice, or [...]

Enforcement Notice from the Information Regulator: what now?

The Information Regulator may send you a POPIA enforcement notice after investigating you and finding that you have contravened POPIA by failing to lawfully process personal information. In comparison, the Information Regulator may send you an infringement notice if it [...]

Information Officer and PAIA manual for the group or each entity within the group?

The Promotion of Access to Information Act (PAIA) states that the head of a private body is the Information Officer, and they should compile a PAIA manual for the private body and update the manual regularly (unless exempt). According to […]

Who is responsible for data protection in your relationships?

Who is responsible for complying with data protection legislation (including the POPI Act in South Africa and the GDPR) where you process personal information together with someone else? It is crucial to know the answer to this question. It is [...]

By |2026-07-13T22:31:08+02:00July 10th, 2026|Categories: POPI and Data Protection|Tags: , , , , |

Map activities, not information or data flows

You should map activities (rather than information, data flows, or processes) as a first step toward complying with data protection laws (such as the GDPR and the Protection of Personal Information Act (POPI Act)). The law requires larger organisations to […]

Central Johannesburg TVET College enforcement action | POPIA breaches

The Central Johannesburg TVET College enforcement action confirms that the Information Regulator will act when POPIA conditions are not met. On 22 May 2026, the Regulator issued its first formal enforcement notice of the year, following complaints lodged by employees [...]

What is a private body or organisation?

The law treats a private body differently from a public body, so it is essential that you know the difference. Some laws (like POPIA and PAIA) require private bodies to do specific things (like submit a PAIA report). You can [...]

NCC opt-out registry is a crisis for marketers

The NCC opt-out registry is a crisis for marketers. The new direct marketing regulations under the CPA may be one of the most burdensome compliance obligations marketers will face in years. Marketers must register, pay ongoing fees and opt people [...]

Gated Access Code of Conduct under POPIA

On 30 April 2026, the Information Regulator published the draft Gated Access Code of Conduct under POPIA. It applies to owners, managers, and their security and technology service providers at any gated premises, including residential estates and office parks. The [...]

By |2026-06-23T15:42:55+02:00May 5th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , |

Standard Bank | Data breach

Standard Bank, Africa’s largest bank, has disclosed a data breach affecting a number of its clients. This raises concerns about rising cybersecurity risks across South Africa’s financial sector. Standard Bank directly communicated with their clients and confirmed that someone had […]

OUTsurance enforcement action | Direct live call marketing

Direct marketing is under scrutiny as South Africa’s Information Regulator takes enforcement action against OUTsurance following an investigation into its direct live-call marketing practices. The case could become a landmark test of whether live telephone calls fall under section 69 […]

Does POPIA apply to journalists? Generally, no.

Does POPIA apply to journalists? If POPIA does not apply to you, what must you consider when processing personal information? These are two important questions to ask if you are a journalist who has concerns about the personal information you [...]

By |2026-03-19T16:51:06+02:00March 18th, 2026|Categories: Media Law, POPI and Data Protection|Tags: , , , , |