POPIA

Cybersecurity compliance mapping – finding every obligation

What is cybersecurity compliance mapping? Navigating cybersecurity compliance today is like conducting a precise archaeological dig: you must carefully uncover each layer of obligations without damaging your organisation's underlying structure. Each jurisdiction, sector, and obligation presents distinct challenges, demanding meticulous [...]

By |2025-07-31T11:41:07+02:00July 22nd, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Data classification best practices

We've all got that chaotic drawer at home — a messy collection of old chargers, mystery keys, forgotten receipts, and batteries that may or may not work. While such clutter at home might only cause mild frustration, allowing your business [...]

Ask the Regulators: Support for PAIA compliance, e-Services and BizPortal

Today, the South African information regulator held a webinar called "Ask the Regulator". The purpose of the webinar was to allow participants to ask the regulator questions and for the regulator to encourage and support them in complying with POPIA […]

GDPR vs POPIA | Compare the GDPR with the POPI Act?

GDPR vs POPIA. How do they compare? The key is to identify the differences and similarities between the GDPR and the POPI Act. For example, who needs to comply with them, do they both apply to the same data [...]

How do I comply with POPI or POPIA?

Wouldn't it be lovely if there were a comprehensive checklist that could help you comply with POPI or POPIA? Because the Protection of Personal Information (POPI) Act in South Africa is a principle-based law, it is not possible to [...]

By |2025-04-24T14:35:24+02:00April 8th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Information Regulator in South Africa

The Information Regulator was created by the Protection of Personal Information Act (POPI Act). POPI gives the Information Regulator teeth - it has extensive powers to investigate and fine responsible parties. Data subjects can complain to the Information Regulator [...]

De Jager v Netcare | Surveillance Evidence and POPIA

In De Jager v Netcare, the High Court considered whether surveillance evidence collected without consent was admissible under the Protection of Personal Information Act (POPIA). The case clarifies when personal information, including special personal information like health data, may be [...]

Concepts of controller and processor – do you really know your processing role?

Did you know that your role can change from processor to controller and back again? This is a crucial concept to understand under the General Data Protection Regulation (GDPR). In a chain of processing activities, a controller and processor's role [...]

How POPIA affects AI

Artificial intelligence is transforming industries, but South Africa’s Protection of Personal Information Act (POPIA) sets clear rules for AI systems that process personal data. Businesses and organisations using AI must follow POPIA’s data protection principles to avoid legal risks and [...]

By |2025-01-31T17:14:00+02:00January 31st, 2025|Categories: POPI and Data Protection|Tags: , , |

Navigating AI Governance in South African Law: An Overview

Building AI without legal guidance is like constructing a bridge without blueprints—it might stand for a while, but it's destined to collapse. As AI continues to rapidly integrate into the South African business environment, aligning it and its use [...]

Information security incident reports

Navigating the stormy seas of information security requires more than just a robust ship; it also demands a vigilant crew equipped with precise navigation tools. Information security incident reports are essential tools in the world of data protection. This document [...]

By |2024-08-13T18:00:45+02:00August 13th, 2024|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

POPIA is here – now what? The questions to ask

The grace period for your organisation to comply with the Protection of Personal Information Act (POPI Act or POPIA) ended on 1 July 2021. Just so you know, you have to comply now. What action does your organisation need [...]

By |2024-08-26T22:06:52+02:00August 5th, 2024|Categories: POPI and Data Protection|Tags: , , , , , |