data protection

No cookies? ePrivacy may still apply

Your company is building a mobile app. Developers add a third-party software development kit (SDK), such as an analytics or attribution tool. That is where ePrivacy device access can become relevant. The privacy review starts with the usual GDPR questions. [...]

Kenya’s cross-border data transfer guidance note

Kenya has introduced important new guidance for organisations transferring personal data across borders. On 8 September 2026, Kenya’s Office of the Data Protection Commissioner (ODPC) published its Guidance Notes for Cross-border Data Transfers, giving organisations more detailed direction on how […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Webinar | Q&A | Finding answers to your legal questions

The regulatory and compliance landscape is continually evolving, raising new questions and challenges. We know you are working through our programmes and have many questions you would like answers to. This is why we’re allowing you to ask us any [...]

Webinar | Having a regulatory representative in Africa

As organisations expand into African markets, they increasingly need to navigate different laws, regulators and compliance requirements. For example, if an organisation plans to process people's personal information in a country, it will likely need to register with the relevant [...]

Who needs a Data Protection Officer (DPO)?

Who must appoint a DPO? What does the General Data Protection Regulation (GDPR) require regarding a Data Protection Officer (or DPO)? This is one of the questions that the GDPR, adopted by the European Parliament in 2016, has prompted many organisations to ask. Another [...]

Digital sovereignty in South Africa: Control is paramount

Digital sovereignty is an increasingly important business consideration. Many organisations and public sector functions are grappling with how to achieve it. Some think that digital sovereignty requires a trade-off between the benefits of using hyper-scalers' digital infrastructure, on the one [...]

Standard Bank | Data breach

Standard Bank, Africa’s largest bank, has disclosed a data breach affecting a number of its clients. This raises concerns about rising cybersecurity risks across South Africa’s financial sector. Standard Bank directly communicated with their clients and confirmed that someone had […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Personal Information Impact Assessment (PIIA) under POPIA

A Personal Information Impact Assessment (PIIA) under POPIA is a process that helps organisations understand and mitigate the data protection risks to data subjects associated with processing personal information. Under South Africa’s Protection of Personal Information Act, 4 of [...]

Zimbabwe’s Cyber and Data Protection Act | Overview

Zimbabwe’s Cyber and Data Protection Act clearly sets out how organisations must collect, use, and protect personal information. Alongside the Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, it forms a comprehensive legal [...]

By |2025-08-27T13:24:27+02:00June 30th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Case study: 23andMe data breach

The 23andMe data breach exposed highly sensitive personal and genetic information. Canadian and UK regulators found that 23andMe failed to implement adequate security measures and violated their respective data protection laws. This breach highlights how poor security and slow response [...]

By |2025-07-03T11:08:33+02:00June 26th, 2025|Categories: POPI and Data Protection|Tags: , , |

Proposed GDPR record-keeping exemption for SMEs

The European Commission (EU Commission) has published a proposal for a GDPR record-keeping exemption for SMEs and small mid-cap companies (SMCs) as part of its Omnibus IV Simplification Package. If adopted, this amendment to Article 30(5) of the GDPR could [...]

WhatsApp enforcement action | POPIA breaches

South Africa’s Information Regulator has issued a formal enforcement notice against WhatsApp for failing to comply with the Protection of Personal Information Act (POPIA).This marks a significant step in enforcing South Africa’s data protection laws and signals that the Regulator [...]