POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

Information Regulator in South Africa

The Information Regulator was created by the Protection of Personal Information Act (POPI Act). POPI gives the Information Regulator teeth - it has extensive powers to investigate and fine responsible parties. Data subjects can complain to the Information Regulator, [...]

Guidance note on Transborder Flows of Information under POPIA

The regulator will publish a Guidance Note on Transborder Flows of Information to and from South Africa under POPIA. They will not wait for the finalisation of the African Continental Free Trade Agreement. They have been consulting with other authorities, [...]

Zulu Nyala Game Ranch v Christiaan Beukes | Using confidential customer database

In Zulu Nyala Game Ranch v Christiaan Beukes, the High Court interdicted and ordered a former employee (Beukes) who used their employer's (Zulu Nyala Game Ranch) confidential customer database to start a competing business to stop using and delete it. […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

JSE enforcement action | Access to share trading information

The Information Regulator has issued a PAIA enforcement notice against the Johannesburg Stock Exchange (JSE) after it refused to grant access to share trading records. This JSE enforcement action requires the JSE to notify affected third parties and reconsider whether […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

The law in 2026 – our predictions

Welcome to the law in 2026! At the beginning of each year, we look ahead to help you prioritise your next steps. This is the law regarding digital, data and tech in 2026. We try to predict what will happen [...]

Minister of Basic Education v Information Regulator | Appealing an enforcement notice

In Minister of Basic Education v Information Regulator, the High Court set aside the regulator’s enforcement notice issued to the DBE. The notice tried to stop the Department from publishing the matric results using examination numbers. The judgment provides guidance [...]

Cybersecurity compliance for officers – From librarian to navigator

Let's talk cybersecurity compliance for officers. Many organisations treat cybersecurity compliance like a library. They collect policies, file them away, and assume that because the shelf is complete, the building is safe. But in 2026, regulators aren't looking for a [...]

By |2026-02-11T17:47:00+02:00January 22nd, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Department of Basic Education enforcement action | Consent

The Information Regulator argues that it is unlawful for the Department of Basic Education (DBE) to publish matric results in newspapers using a learner's exam number without consent. The regulator issued an enforcement notice to the DBE and then fined […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Lessons to learn from the Information Regulator priotities

Understanding the Information Regulator's priorities is no longer just good practice; it's essential to avoid enforcement action. Having attended the Regulator's recent stakeholder breakfast, we can distil the key lessons and confirmed changes that will shape the compliance landscape in […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Information Regulator stakeholder engagement in Cape Town

The Information Regulator stakeholder engagement revealed the regulator's thinking on how to comply with the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA). More importantly, the regulator confirmed expected amendments to the POPIA [...]

DORA compliance for vendors – a practical playbook

DORA compliance for vendors is now a live requirement, and selling technology to European financial firms is therefore like constructing a new building in a crowded city: you must meet the code, welcome inspections, and prove the structure can take [...]

By |2025-11-14T19:33:31+02:00November 14th, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |