POPI and Data Protection

The protection of personal information, and privacy and data protection laws (including the GDPR and the POPI Act or POPIA) are key laws in today’s information society. Information compliance or information rights are central to so many disputes. Read our insights, regulatory updates, judgment summaries, enforcement action (including fines and notes), data breaches or authority guidance.

Uber enforcement action | data transfer fine

The Dutch Data Protection Authority (DPA) recently fined Uber a hefty €290 million. But what led to this enforcement action? Well, it turns out Uber mishandled European taxi drivers' personal data when transferring it to the United States. This enforcement [...]

By |2024-08-29T13:39:22+02:00August 26th, 2024|Categories: POPI and Data Protection|Tags: , , |

NYOB’s complaint against EU parliament | Data breach

The protection of personal data is crucial, especially for institutions like the European Parliament. NYOB's complaint against the EU parliament has shed light on serious data breaches in the Parliament’s recruitment platform, PEOPLE. These breaches have compromised the personal information [...]

By |2024-08-28T14:07:09+02:00August 22nd, 2024|Categories: POPI and Data Protection|Tags: , , , |

Information security incident reports

Navigating the stormy seas of information security requires more than just a robust ship; it also demands a vigilant crew equipped with precise navigation tools. Information security incident reports are essential tools in the world of data protection. This document [...]

By |2024-08-13T18:00:45+02:00August 13th, 2024|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

AI in privacy policy drafting

Creating a privacy policy used to be as challenging as cultivating a garden in a desert—each new rule felt like a rare shower that could completely alter the terrain. Nowadays, artificial intelligence (AI) acts like a sophisticated watering system, making [...]

POPIA is here – now what? The questions to ask

The grace period for your organisation to comply with the Protection of Personal Information Act (POPI Act or POPIA) ended on 1 July 2021. Just so you know, you have to comply now. What action does your organisation need [...]

By |2024-08-26T22:06:52+02:00August 5th, 2024|Categories: POPI and Data Protection|Tags: , , , , , |

Privacy obligations in the BEC case of ENS v Hawarden

In the matter of ENS v Hawarden, the SCA overturned the judgment in the High Court in Gauteng, holding ENS liable for the loss suffered by Mrs Hawarden because of a business email compromise. The SCA's finding is primarily based [...]

South Korea fines AliExpress | Personal data violations

South Korea's privacy watchdog has just taken a big swing and fines e-commerce giant AliExpress. This move shows the country means business when it comes to protecting its citizens' personal info, even when dealing with big-name international players. Overview of [...]

AI-generated privacy policies

Creating perfect AI-generated privacy policies is like planting trees: you start with a small seed, carefully nurture it, and adjust as it grows. In today's world, where organisations constantly process personal data, privacy policies are essential for legal compliance and [...]

By |2024-07-31T11:50:14+02:00July 23rd, 2024|Categories: AI Governance, POPI and Data Protection|Tags: |

So you got a s89 assessment notice – now what?

The South African Information Regulator has been handing out a lot more s89 assessment notices recently. It's great to see the Regulator building momentum, and the growth of data protection compliance across industries because of it. But many organisations are [...]

By |2024-07-16T11:10:37+02:00July 16th, 2024|Categories: IT Law, POPI and Data Protection|Tags: , |