POPIA

POPIA Compliance Assessment | The regulator’s health check

What if I told you that the Information Regulator is fond of health checks? Would you envision something as scary (to many) as a tooth extraction or blood test, or would you envision what it actually is: a POPIA Compliance [...]

Achieving information security compliance in South Africa’s public sector

South Africa has taken significant strides in promoting accountability in the public sector for information security compliance. The Protection of Personal Information Act (POPIA) and Promotion of Access to Information Act (PAIA) continue to be a major focus for the [...]

Information officers in South African organisations

Information is the currency of our modern age, and guarding this currency is the quintessential role of information officers in South African organisations. The evolving landscape of data protection laws in South Africa, with the enactment of the Promotion of [...]

By |2026-03-23T13:56:41+02:00May 12th, 2023|Categories: POPI and Data Protection|Tags: , , |

Safi v Gascoigne | BEC

In Safi v Gascoigne, Safi sued Gascoigne Randon and Associates, a conveyancing firm, for a loss of R889,308.50 from a business email compromise (BEC).  Who should care about this judgment and why? The public because they need to be aware [...]

Hawarden v Edward Nathan Sonnenbergs (ENS) | BEC

In Hawarden v Edward Nathan Sonnenbergs (ENS), Hawarden succeeded in suing ENS for the loss of R5.5 million because of a Business Email Compromise (BEC). Hawarden was ENS' client.  The court said that ENS owed a general duty of care [...]

Directive on public service information security | DPSA

The directive on public service information security is the South African Department of Public Service and Administration's (DPSA) latest effort to address the government's vulnerability to cyberattacks. This development comes four months after the Minister issued the directive on [...]

By |2024-03-27T15:47:16+02:00September 22nd, 2022|Categories: Cybersecurity Law, IT Law|Tags: , , , |

Information regulator strategic plan for 2022/3 to 2026/7 – a heads up

The information regulator released the Information Regulator Strategic Plan for 2022/3 to 2026/7. The plan outlines the steps that the regulator will take to implement its vision for 2027. The regulator's key focus is to fulfil its dual mandate as [...]

Directive on cloud computing in the public service | DPSA

The South African Department of Public Service and Administration (DPSA) has gazetted a directive on cloud computing in the public service. In essence, the directive instructs government departments on adopting, using, managing, scaling, and terminating cloud services. I’ve written [...]

By |2024-08-14T13:18:59+02:00February 21st, 2022|Categories: IT Law|Tags: , , , , |

Infringement notice from the information regulator: what now?

The information regulator will serve an infringement notice to a responsible party that the regulator believes has breached a provision of POPIA. No responsible party wants to receive an infringement notice or enforcement notice. It is even more intimidating than [...]

What low-risk small business should and shouldn’t do for POPIA

If you have less than 50 employees and your processing of personal information does not pose a significant risk to people, here is what you should and shouldn't do. Most importantly, don't panic. No one is going to jail. There [...]

By |2022-12-20T15:44:53+02:00October 24th, 2021|Categories: POPI and Data Protection|Tags: , |

Data protection is a journey, not a destination

As a member of the Michalsons data protection programme, you’ve conquered the mountain by raising awareness, planning your steps to protect personal information, and implementing those steps. Now you’re enjoying your mountain’s view and walking the scenic contour path [...]

By |2022-12-02T10:37:03+02:00September 9th, 2021|Categories: POPI and Data Protection|Tags: , , , |

When are photos biometric data under data protection law?

When are photos biometric data under data protection law? This is a hot question at the moment because data protection laws attach stricter principles to the processing of biometric data which falls under sensitive data. Biometric photos are processed [...]

By |2021-08-10T08:50:36+02:00August 6th, 2021|Categories: POPI and Data Protection|Tags: , , , , , |