POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

GDPR certified: How to obtain GDPR certification

For many, being GDPR certified or obtaining GDPR certification is the holy grail. It provides proof that you comply with the GDPR and other data protection laws. This is especially true for processors that process personal data on behalf [...]

Truecaller enforcement action | Caller ID & spam blocking

The Information Regulator (Regulator) is investigating Truecaller. Data subjects complained about how, among other things, Truecaller processes personal information. There is currently no enforcement notice against Truecaller, but the investigation signals a shift. Data subjects in South Africa are actively […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Justin Brewer v Otter AI | Consent for AI meeting assistants

In Brewer v Otter.ai, the U.S District Court for the Northern District of California, Justin Brewer filed a class-action lawsuit against Otter.ai. Brewer alleges that Otter.ai's "Otter Notetaker" and "OtterPilot" tool deceptively record private conversations without proper consent and use [...]

Telco cybersecurity in South Africa – finding a signal in the noise

Let's talk telco cybersecurity in South Africa. Securing a telecommunications network is like trying to tune into a radio station amid heavy static: operators must carefully adjust both their security controls and their compliance processes to cut through the noise. [...]

Digital Law Company v Meta | Extraterritorial application of South African law

In Digital Law Company v Meta, the High Court in South Africa (Gauteng Local Division Johannesburg) sanctioned a joint consent order in which Meta agreed to take a number of steps, including removing accounts, disclosing the subscriber information behind [...]

Case study: Quickloan privacy violation in Uganda

The Quickloan privacy violation marks a significant milestone for data protection enforcement in Uganda, demonstrating that non-compliance carries real consequences. In July 2025, Uganda's Personal Data Protection Office (PDPO) secured its first-ever criminal conviction under the Data Protection and Privacy [...]

Personal Information Impact Assessment (PIIA) under POPIA

A Personal Information Impact Assessment (PIIA) under POPIA is a process that helps organisations understand and mitigate the data protection risks to data subjects associated with processing personal information. Under South Africa’s Protection of Personal Information Act, 4 of [...]

Cybersecurity compliance mapping – finding every obligation

What is cybersecurity compliance mapping? Navigating cybersecurity compliance today is like conducting a precise archaeological dig: you must carefully uncover each layer of obligations without damaging your organisation's underlying structure. Each jurisdiction, sector, and obligation presents distinct challenges, demanding meticulous [...]

By |2025-07-31T11:41:07+02:00July 22nd, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Data classification best practices

We've all got that chaotic drawer at home — a messy collection of old chargers, mystery keys, forgotten receipts, and batteries that may or may not work. While such clutter at home might only cause mild frustration, allowing your business [...]

Zimbabwe’s Cyber and Data Protection Act | Overview

Zimbabwe’s Cyber and Data Protection Act clearly sets out how organisations must collect, use, and protect personal information. Alongside the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, it forms a comprehensive legal [...]

By |2025-08-27T13:24:27+02:00June 30th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Case study: 23andMe data breach

The 23andMe data breach exposed highly sensitive personal and genetic information. Canadian and UK regulators found that 23andMe failed to implement adequate security measures and violated their respective data protection laws. This breach highlights how poor security and slow response [...]

By |2025-07-03T11:08:33+02:00June 26th, 2025|Categories: POPI and Data Protection|Tags: , , |