POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

What is a private body or organisation?

The law treats a private body differently from a public body, so it is essential that you know the difference. Some laws (like POPIA and PAIA) require private bodies to do specific things (like submit a PAIA report). You can [...]

NCC opt-out registry is a crisis for marketers

The NCC opt-out registry is a crisis for marketers. The new direct marketing regulations under the CPA may be one of the most burdensome compliance obligations marketers will face in years. Marketers must register, pay ongoing fees and opt people [...]

Gated Access Code of Conduct under POPIA

On 30 April 2026, the Information Regulator published the draft Gated Access Code of Conduct under POPIA. It applies to owners, managers, and their security and technology service providers at any gated premises, including residential estates and office parks. The [...]

By |2026-06-23T15:42:55+02:00May 5th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , |

Standard Bank | Data breach

Standard Bank, Africa’s largest bank, has disclosed a data breach affecting a number of its clients. This raises concerns about rising cybersecurity risks across South Africa’s financial sector. Standard Bank directly communicated with their clients and confirmed that someone had […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

OUTsurance enforcement action | Direct live call marketing

Direct marketing is under scrutiny as South Africa’s Information Regulator takes enforcement action against OUTsurance following an investigation into its direct live-call marketing practices. The case could become a landmark test of whether live telephone calls fall under section 69 […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Does POPIA apply to journalists? Generally, no.

Does POPIA apply to journalists? If POPIA does not apply to you, what must you consider when processing personal information? These are two important questions to ask if you are a journalist who has concerns about the personal information you [...]

By |2026-03-19T16:51:06+02:00March 18th, 2026|Categories: Media Law, POPI and Data Protection|Tags: , , , , |

Lodge a PAIA or POPIA complaint with the Regulator

Do you want to lodge a PAIA complaint or POPIA complaint with the Information Regulator in South Africa? Has someone failed to give you access to information or infringed on your privacy? In this article, we’ll help you know how [...]

Liquid Telecom enforcement action | Recording meeting without consent

The Liquid Telecom enforcement action regarding recording meeting without consent arises from a decision where Kenya’s data protection regulator fined Liquid Telecommunications Kenya 700,000 Kenyan Shillings for unlawfully recording and retaining a former executive's Zoom meeting without consent. The ruling […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Rules or Regulations on the processing of Health Information under POPIA 2026

The information regulator prescribed rules or regulations on the processing of health information under POPIA on 6 March 2026. The Health Information Regulations apply to specific responsible parties (not everyone) who process personal information concerning a data subject’s health for […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Guidance Note on Conducting a Personal Information Impact Assessment

The Information Regulator plans to draft a Guidance Note on Conducting a Personal Information Impact Assessment (PIIA). The regulator plans to develop this in their next financial year ending 31 March 2027. We assume that the guidance note will be [...]

FT Rams Consulting enforcement action | Email direct marketing

The Information Regulator is taking enforcement action against FT Rams Consulting for non-compliance with section 69 of POPIA - the section that deals with direct marketing. This FT Ram Consulting fine of R200k follows a complaint from a data subject […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Blouberg Municipality enforcement action | Further processing of financial disclosures

The regulator has fined Blouberg Municipality R500 000 after a complaint from a former employee. This Blouberg Municipality enforcement action arose because the municipality unlawfully published the employee’s personal information on its website in a declaration of interest. As a […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.