POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

Practical data classification framework

Managing data effectively in any organisation can feel like navigating an intricate roundabout without clear signage — a confusing, inefficient, and costly process prone to mistakes. Poor data quality can significantly impact your organisation's decision-making capabilities, resulting in operational inefficiencies, [...]

By |2025-07-04T07:04:30+02:00June 21st, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , |

Ask the Regulators: Support for PAIA compliance, e-Services and BizPortal

Today, the South African information regulator held a webinar called "Ask the Regulator". The purpose of the webinar was to allow participants to ask the regulator questions and for the regulator to encourage and support them in complying with POPIA […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

POPIA Manual is a Privacy Policy

A POPIA manual is actually a privacy policy. Many organisations have compiled or published a POPIA Manual, and we often receive enquiries requesting that we draft one for clients or provide a POPIA Manual template. Some people incorrectly think [...]

By |2025-06-05T16:08:11+02:00June 4th, 2025|Categories: POPI and Data Protection|Tags: , |

Katiba v Tools for Humanity and others | Biometric data

Katiba v Tools for Humanity and others is Kenya's landmark High Court decision on biometric privacy. Worldcoin-linked entities violated Kenya's Data Protection Act by collecting iris and facial scans in exchange for cryptocurrency. The court halted the project and ordered [...]

Nigeria fines Meta | Data breach penalty upheld

In an appeal brought by Meta Platforms Inc. and WhatsApp, LLC, the Competition and Consumer Protection Tribunal confirmed that their conduct violated data protection and competition laws. The Tribunal affirmed the Federal Competition and Consumer Protection Commission's (FCCPC) decision to [...]

Proposed GDPR record-keeping exemption for SMEs

The European Commission (EU Commission) has published a proposal for a GDPR record-keeping exemption for SMEs and small mid-cap companies (SMCs) as part of its Omnibus IV Simplification Package. If adopted, this amendment to Article 30(5) of the GDPR could [...]

GDPR vs POPIA | Compare the GDPR with the POPI Act?

GDPR vs POPIA. How do they compare? The key is to identify the differences and similarities between the GDPR and the POPI Act. For example, who needs to comply with them, do they both apply to the same data [...]

TikTok’s GDPR transfers – Understanding the €530M fine

Let's discuss TikTok’s GDPR transfers. Managing cross-border data flows under GDPR can be as treacherous as navigating iceberg-strewn waters — hidden dangers lurk beneath the surface. TikTok recently discovered how severe those dangers can be, facing a landmark €530 million [...]

WhatsApp enforcement action | POPIA breaches

South Africa’s Information Regulator has issued a formal enforcement notice against WhatsApp for failing to comply with the Protection of Personal Information Act (POPIA).This marks a significant step in enforcing South Africa’s data protection laws and signals that the Regulator [...]

Password manager: a quick win to improve security

Get a password manager to improve your security. You have signed up for a new service, and they ask you to create a password. The thought of having to create a new password is a nightmare for you. You ask [...]

By |2025-06-09T12:22:44+02:00April 26th, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: |

The POPIA Amendment Regulations 2025 commence

The POPIA Amendment Regulations commenced with immediate effect on 17 April 2025. These amended regulations cover new proposed rules of procedure, administrative fines, and expand the data subject's rights to their personal information.  In this post, we summarise the regulations, [...]