Authority Guidance

Follow best practices by knowing the latest guidance issued by authorities with our unique insights.

Only some are linked below. To read all previous insights and be alerted to future insights, join the relevant Michalsons programme. You can view the public and the “Members only” ones if you are a member and logged in.

Rules or Regulations on the processing of Health Information under POPIA 2026

The information regulator prescribed rules or regulations on the processing of health information under POPIA on 6 March 2026. The Health Information Regulations apply to specific responsible parties (not everyone) who process personal information concerning a data subject’s health for […]

Guidance Note on Conducting a Personal Information Impact Assessment

The Information Regulator plans to draft a Guidance Note on Conducting a Personal Information Impact Assessment (PIIA). The regulator plans to develop this in their next financial year ending 31 March 2027. We assume that the guidance note will be [...]

Guidance note on Transborder Flows of Information under POPIA

The regulator will publish a Guidance Note on Transborder Flows of Information to and from South Africa under POPIA. They will not wait for the finalisation of the African Continental Free Trade Agreement. They have been consulting with other authorities, [...]

Important Notice: Non-Compliance with PAIA Forms

Did you receive an email from the Information Regulator with the title "Important Notice: Non-Compliance with PAIA Forms"? Don't panic; it doesn't necessarily mean that you are specifically non-compliant, and there are simple actions you can take to check whether [...]

By |2025-09-22T16:30:42+02:00August 31st, 2025|Categories: Access to Information|Tags: , , , |

Notification of security compromise to the Information Regulator | Guideline and support

The information regulator published a Guideline on notification of security compromises to the information regulator in July 2020. The guideline explains the procedure responsible parties or information officers should follow to notify the regulator of a security compromise or data [...]

Nigerian data controller and processor registration

As Nigeria keeps stepping up its data protection game, companies looking to do business there must stay on top of what’s required under the Nigeria Data Protection Act (NDPA) 2023. One key thing to know is that under the NDPA, [...]

By |2025-03-26T09:30:00+02:00March 25th, 2025|Categories: POPI and Data Protection|Tags: , , |

Guidance note on direct marketing in South Africa

The regulator has issued a guidance note on direct marketing as regulated by section 69 of POPIA. The regulator has noted on many occasions that it has received an increasing number of complaints about the processing of personal information in [...]

Guidance note on the processing of personal information of a voter by a political party and independent candidate

The information regulator issued a new guidance note on the processing of personal information of a voter by political parties and independent candidates as well as highlighting how to combat misinformation and disinformation in terms of the provisions of the [...]

Tanzanian judiciary introduces AI for enhanced efficiency

In an ambitious and unprecedented move towards modernising its judicial processes, the Tanzanian judiciary has introduced AI into its transcriptions and translations system. Chief Justice Prof Ibrahim Hamis Juma announced this development during the Law Week commemoration event at Chinangali [...]

By |2024-08-26T22:03:45+02:00March 8th, 2024|Categories: AI Governance|Tags: , , |

DIFC courts issue guidelines for AI in legal proceedings

I recently discovered an intriguing development that marks a significant step forward in legal proceedings within the Dubai International Financial Centre (DIFC) courts. To embrace technological advancements, the DIFC courts have issued a novel set of guidelines for using AI-generated [...]

By |2024-08-26T22:02:49+02:00February 14th, 2024|Categories: AI Governance|Tags: , , , |

Guidelines on procedures for making information electronically available

The information regulator issued a guideline on procedures for making information electronically available (dated March 2022). The purpose of the guideline is to recommend the procedures for public and private bodies to make information electronically available to enable people to obtain [...]

EDPB Guideline | Dark patterns in social media platform interfaces

The European Data Protection Board (EDPB) published guidelines relating to dark patterns on social media platforms. If social media platforms designers don't follow the guidelines, they could infringe the EU General Data Protection Regulation (GDPR). The guidelines provide designers with [...]