POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

Kenya’s cross-border data transfer guidance note

Kenya has introduced important new guidance for organisations transferring personal data across borders. On 8 September 2026, Kenya’s Office of the Data Protection Commissioner (ODPC) published its Guidance Notes for Cross-border Data Transfers, giving organisations more detailed direction on how […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Information Regulator ramps up enforcement

Information Regulator ramps up enforcement: on 1 September 2026, the Information Regulator briefed the public and media on its latest enforcement and compliance activities under POPIA and PAIA. The briefing shows the Regulator increasingly concerned about South Africa's cybersecurity environment. [...]

Cybersecurity flow-down clauses – Whose compliance obligations?

A security addendum arrives from a customer. They want incident notification within 24 hours, the right to audit you on site, approval before you change a subcontractor, and cooperation with their penetration testing. These are cybersecurity flow-down clauses: contractual terms [...]

By |2026-08-12T13:35:29+02:00August 12th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Nominate someone to be a member of the information regulator

Parliament has invited the organisations and interested individuals to nominate people (or apply themselves) for the President to appoint as members of the information regulator. Do you want to nominate someone? Do you know anyone who might want to nominate [...]

By |2026-08-20T11:03:08+02:00August 5th, 2026|Categories: POPI and Data Protection|Tags: , |

Pre-investigation notice from the Information Regulator: what now?

If a complainant lodges a complaint against you for infringing their privacy rights, the information regulator can issue any one of a few types of notices to you. For example, you could receive an information notice, an enforcement notice, or [...]

Enforcement Notice from the Information Regulator: what now?

The Information Regulator may send you a POPIA enforcement notice after investigating you and finding that you have contravened POPIA by failing to lawfully process personal information. In comparison, the Information Regulator may send you an infringement notice if it [...]

Information Officer and PAIA manual for the group or each entity within the group?

The Promotion of Access to Information Act (PAIA) states that the head of a private body is the Information Officer, and they should compile a PAIA manual for the private body and update the manual regularly (unless exempt). According to […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Who needs a Data Protection Officer (DPO)?

Who must appoint a DPO? What does the General Data Protection Regulation (GDPR) require regarding a Data Protection Officer (or DPO)? This is one of the questions that the GDPR, adopted by the European Parliament in 2016, has prompted many organisations to ask. Another [...]

Who is responsible for data protection in your relationships?

Who is responsible for complying with data protection legislation (including the POPI Act in South Africa and the GDPR) where you process personal information together with someone else? It is crucial to know the answer to this question. It is [...]

By |2026-07-13T22:31:08+02:00July 10th, 2026|Categories: POPI and Data Protection|Tags: , , , , |

Map activities, not information or data flows

You should map activities (rather than information, data flows, or processes) as a first step toward complying with data protection laws (such as the GDPR and the Protection of Personal Information Act (POPI Act)). The law requires larger organisations to […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Central Johannesburg TVET College enforcement action | POPIA breaches

The Central Johannesburg TVET College enforcement action confirms that the Information Regulator will act when POPIA conditions are not met. On 22 May 2026, the Regulator issued its first formal enforcement notice of the year, following complaints lodged by employees [...]

What’s so tricky about a Data Retention Policy?

Is there anything tricky about a Data Retention Policy? Does anyone get a headache thinking about what to include in the policy and what outcomes it will help achieve? Is drafting a Data Retention Policy a simple matter of slapping [...]