GDPR

Privacy management software and data protection

Privacy management software is disrupting the data protection industry by automating manual processes, offering collective problem-solving, and improving user experiences. You can typically use it for things you would have done manually as a data protection officer, including running privacy [...]

By |2024-01-17T13:41:15+02:00February 10th, 2023|Categories: POPI and Data Protection|Tags: , , |

Meta and Privacy by Design

Organisations must prioritise privacy by design as supervisory bodies are increasing enforcement efforts. The Irish Data Protection Commission (DPC) fined Meta significantly for processing the personal data of Facebook users in violation of GDPR after an investigation found deficiencies in [...]

By |2023-02-28T20:27:40+02:00February 8th, 2023|Categories: POPI and Data Protection|Tags: , , , |

Data portability under data protection laws (GDPR and POPIA)

Data portability refers to the ability to move data from one platform or service provider to another. The GDPR, in Article 20, gives all data subjects the right to data portability. This right is echoed in POPIA and PAIA [...]

By |2023-04-11T22:34:48+02:00February 2nd, 2023|Categories: POPI and Data Protection|Tags: , , |

Undisclosed AI systems and data protection

Using AI systems without telling anyone is tempting, but their undisclosed use is problematic, according to relevant data protection laws. It infringes on the principle of transparency by preventing data subjects from understanding how their personal data is processed, and [...]

Privacy by Design and data protection

Privacy by design has been part of data protection law for a while. However, the practical need to apply it is growing. Let's discuss what it is and how the relevant authorities have used it in the context of data [...]

By |2023-01-30T18:40:02+02:00January 13th, 2023|Categories: POPI and Data Protection|Tags: , , , |

EU Data Act | Free flow of non-personal data

The EU Data Act aims to create a coherent framework for sharing non-personal data in the European Union (EU), which means that organisations and public bodies will be able to store and process non-personal data wherever they choose. The General [...]

By |2022-11-14T20:57:24+02:00November 14th, 2022|Categories: Information Law|Tags: , , , , |

How does Schrems II affect DPAs?

Max Schrems’ journey with Meta (previously Facebook) and the Irish Data Protection Commission highlights the care organisations must observe when they deal with the personal data of the international community. Although there is an 80% similarity in privacy laws across [...]

Lexing Insights | Legal framework for encryption tools

Initially used by military leaders and diplomats, cryptology has become an integral part of our daily lives since the advent of the Internet. This science of secret writing, which is divided into two types (cryptography and cryptanalysis), is today essential [...]

When are photos biometric data under data protection law?

When are photos biometric data under data protection law? This is a hot question at the moment because data protection laws attach stricter principles to the processing of biometric data which falls under sensitive data. Biometric photos are processed [...]

By |2021-08-10T08:50:36+02:00August 6th, 2021|Categories: POPI and Data Protection|Tags: , , , , , |

How much does data protection compliance cost?

Now there is a good question. Many people ask us how much does data protection compliance (or more specifically GDPR compliance or POPIA compliance) cost. I'm afraid there is no simple answer but I can give you some guidance to [...]

By |2022-12-14T09:38:35+02:00May 25th, 2021|Categories: POPI and Data Protection|Tags: , , |

A practical approach to implement POPIA

Many organisations are trying to implement POPIA. They're trying to assess the impact of POPIA on their organisation and then analyse the gap. This makes a lot of sense because you need to understand the impact and the gaps before [...]

By |2026-07-10T13:47:51+02:00May 19th, 2020|Categories: POPI and Data Protection|Tags: , , , , , |

Data protection audit by an authority | GDPR audit

Data protection authorities around the world have started to do a data protection audit (or GDPR audit) on controllers to check that they comply with data protection law. Essentially, the authority compares your organisation to a data protection law that [...]