data protection

Digital sovereignty in South Africa: Control is paramount

Digital sovereignty is an increasingly important business consideration. Many organisations and public sector functions are grappling with how to achieve it. Some think that digital sovereignty requires a trade-off between the benefits of using hyper-scalers' digital infrastructure, on the one [...]

Webinar | Q&A | Finding answers to your legal questions

The regulatory and compliance landscape is continually evolving, raising new questions and challenges. We know you are working through our programmes and have many questions you would like answers to. This is why we’re allowing you to ask us any [...]

Standard Bank | Data breach

Standard Bank, Africa’s largest bank, has disclosed a data breach affecting a number of its clients. This raises concerns about rising cybersecurity risks across South Africa’s financial sector. Standard Bank directly communicated with their clients and confirmed that someone had […]

Personal Information Impact Assessment (PIIA) under POPIA

A Personal Information Impact Assessment (PIIA) under POPIA is a process that helps organisations understand and mitigate the data protection risks to data subjects associated with processing personal information. Under South Africa’s Protection of Personal Information Act, 4 of [...]

Zimbabwe’s Cyber and Data Protection Act | Overview

Zimbabwe’s Cyber and Data Protection Act clearly sets out how organisations must collect, use, and protect personal information. Alongside the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, it forms a comprehensive legal [...]

By |2025-08-27T13:24:27+02:00June 30th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Case study: 23andMe data breach

The 23andMe data breach exposed highly sensitive personal and genetic information. Canadian and UK regulators found that 23andMe failed to implement adequate security measures and violated their respective data protection laws. This breach highlights how poor security and slow response [...]

By |2025-07-03T11:08:33+02:00June 26th, 2025|Categories: POPI and Data Protection|Tags: , , |

Proposed GDPR record-keeping exemption for SMEs

The European Commission (EU Commission) has published a proposal for a GDPR record-keeping exemption for SMEs and small mid-cap companies (SMCs) as part of its Omnibus IV Simplification Package. If adopted, this amendment to Article 30(5) of the GDPR could [...]

WhatsApp enforcement action | POPIA breaches

South Africa’s Information Regulator has issued a formal enforcement notice against WhatsApp for failing to comply with the Protection of Personal Information Act (POPIA).This marks a significant step in enforcing South Africa’s data protection laws and signals that the Regulator [...]

Workshop | Privacy impact assessment masterclass

In a digital-first world, organisations are increasingly expected to design with privacy in mind. Whether you're working in legal, compliance, product, IT, or operations, understanding how to assess and mitigate privacy risks is essential to staying compliant, protecting your organisation’s [...]

By |2025-09-19T14:43:18+02:00April 10th, 2025|Categories: , , |Tags: , , |

How do I comply with POPI or POPIA?

Wouldn't it be lovely if there were a comprehensive checklist that could help you comply with POPI or POPIA? Because the Protection of Personal Information (POPI) Act in South Africa is a principle-based law, it is not possible to [...]

By |2025-04-24T14:35:24+02:00April 8th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Advanced Computer Software Group enforcement action | Ransomware

The Information Commissioner’s Office (ICO) has fined Advanced Computer Software Group Ltd (ACSG) £3.07 million following a ransomware incident that exposed the personal data of 79,404 people. The ICO found that ACSG failed to implement adequate security measures, leaving [...]