POPIA

AI Policy for Public Healthcare in the Western Cape

The AI policy for public healthcare in the Western Cape (WCG) is in motion. The policy promotes the use of AI tools to address institutional capacity constraints and varying skill levels. Meaning that developers and deployers of AI-enabled healthcare tools [...]

By |2025-10-24T14:18:50+02:00October 24th, 2025|Categories: AI Governance|Tags: , , |

Telco cybersecurity in South Africa – finding a signal in the noise

Let's talk telco cybersecurity in South Africa. Securing a telecommunications network is like trying to tune into a radio station amid heavy static: operators must carefully adjust both their security controls and their compliance processes to cut through the noise. [...]

Cybersecurity compliance mapping – finding every obligation

What is cybersecurity compliance mapping? Navigating cybersecurity compliance today is like conducting a precise archaeological dig: you must carefully uncover each layer of obligations without damaging your organisation's underlying structure. Each jurisdiction, sector, and obligation presents distinct challenges, demanding meticulous [...]

By |2025-07-31T11:41:07+02:00July 22nd, 2025|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Data classification best practices

We've all got that chaotic drawer at home — a messy collection of old chargers, mystery keys, forgotten receipts, and batteries that may or may not work. While such clutter at home might only cause mild frustration, allowing your business [...]

Ask the Regulators: Support for PAIA compliance, e-Services and BizPortal

Today, the South African information regulator held a webinar called "Ask the Regulator". The purpose of the webinar was to allow participants to ask the regulator questions and for the regulator to encourage and support them in complying with POPIA […]

GDPR vs POPIA | Compare the GDPR with the POPI Act?

GDPR vs POPIA. How do they compare? The key is to identify the differences and similarities between the GDPR and the POPI Act. For example, who needs to comply with them, do they both apply to the same data [...]

How do I comply with POPI or POPIA?

Wouldn't it be lovely if there were a comprehensive checklist that could help you comply with POPI or POPIA? Because the Protection of Personal Information (POPI) Act in South Africa is a principle-based law, it is not possible to [...]

By |2025-04-24T14:35:24+02:00April 8th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

De Jager v Netcare | Surveillance Evidence and POPIA

In De Jager v Netcare, the High Court considered whether surveillance evidence collected without consent was admissible under the Protection of Personal Information Act (POPIA). The case clarifies when personal information, including special personal information like health data, may be [...]

Concepts of controller and processor – do you really know your processing role?

Did you know that your role can change from processor to controller and back again? This is a crucial concept to understand under the General Data Protection Regulation (GDPR). In a chain of processing activities, a controller and processor's role [...]

How POPIA affects AI

Artificial intelligence is transforming industries, but South Africa’s Protection of Personal Information Act (POPIA) sets clear rules for AI systems that process personal data. Businesses and organisations using AI must follow POPIA’s data protection principles to avoid legal risks and [...]

By |2025-01-31T17:14:00+02:00January 31st, 2025|Categories: POPI and Data Protection|Tags: , , |

Navigating AI Governance in South African Law: An Overview

Building AI without legal guidance is like constructing a bridge without blueprints—it might stand for a while, but it's destined to collapse. As AI continues to rapidly integrate into the South African business environment, aligning it and its use [...]

Information security incident reports

Navigating the stormy seas of information security requires more than just a robust ship; it also demands a vigilant crew equipped with precise navigation tools. Information security incident reports are essential tools in the world of data protection. This document [...]

By |2024-08-13T18:00:45+02:00August 13th, 2024|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |