POPI Act

Who is responsible for data protection in your relationships?

Who is responsible for complying with data protection legislation (including the POPI Act in South Africa and the GDPR) where you process personal information together with someone else? It is crucial to know the answer to this question. It is [...]

By |2026-07-13T22:31:08+02:00July 10th, 2026|Categories: POPI and Data Protection|Tags: , , , , |

Central Johannesburg TVET College enforcement action | POPIA breaches

The Central Johannesburg TVET College enforcement action confirms that the Information Regulator will act when POPIA conditions are not met. On 22 May 2026, the Regulator issued its first formal enforcement notice of the year, following complaints lodged by employees [...]

Information Regulator in South Africa

The Information Regulator was created by the Protection of Personal Information Act (POPI Act). POPI gives the Information Regulator teeth - it has extensive powers to investigate and fine responsible parties. Data subjects can complain to the Information Regulator, [...]

Zulu Nyala Game Ranch v Christiaan Beukes | Using confidential customer database

In Zulu Nyala Game Ranch v Christiaan Beukes, the High Court interdicted and ordered a former employee (Beukes) who used their employer's (Zulu Nyala Game Ranch) confidential customer database to start a competing business to stop using and delete it. […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Information Regulator stakeholder engagement in Cape Town

The Information Regulator stakeholder engagement revealed the regulator's thinking on how to comply with the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA). More importantly, the regulator confirmed expected amendments to the POPIA [...]

Practical data classification framework

Managing data effectively in any organisation can feel like navigating an intricate roundabout without clear signage — a confusing, inefficient, and costly process prone to mistakes. Poor data quality can significantly impact your organisation's decision-making capabilities, resulting in operational inefficiencies, [...]

By |2025-07-04T07:04:30+02:00June 21st, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , |

GDPR vs POPIA | Compare the GDPR with the POPI Act?

GDPR vs POPIA. How do they compare? The key is to identify the differences and similarities between the GDPR and the POPI Act. For example, who needs to comply with them, do they both apply to the same data [...]

Personal data deletion rights: Navigating your responsibilities

Personal data deletion rights aren't just paperwork — they're like removing permanent marker from a whiteboard: simple to describe but tricky to do correctly. Data protection laws now give people more rights to control their personal information. One crucial right [...]

By |2025-04-10T10:45:22+02:00April 8th, 2025|Categories: POPI and Data Protection|Tags: , |

How do I comply with POPI or POPIA?

Wouldn't it be lovely if there were a comprehensive checklist that could help you comply with POPI or POPIA? Because the Protection of Personal Information (POPI) Act in South Africa is a principle-based law, it is not possible to [...]

By |2025-04-24T14:35:24+02:00April 8th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Beyond consent: Better grounds for processing personal data

Today, processing personal data is not just a technical matter but a legal requirement governed by strict rules. Relevant data protection laws generally state that every data processing activity must have a legal basis. Although many believe that consent is [...]

By |2025-02-20T12:20:17+02:00February 20th, 2025|Categories: POPI and Data Protection|Tags: , |