Regulatory Updates

Gain insights on the latest regulatory updates related to digital, data and tech and what action they require of you by reading the latest updates (including alerts).

Only some are linked below. To read all previous insights and be alerted to future insights, join the relevant Michalsons programme. You can view the public and the “Members only” ones if you are a member and logged in.

Webinar | Q&A | Finding answers to your legal questions

The regulatory and compliance landscape is continually evolving, raising new questions and challenges. We know you are working through our programmes and have many questions you would like answers to. This is why we’re allowing you to ask us any [...]

Webinar | Sustaining your compliance efforts

We bring you up to speed with our insights on the latest legal developments regarding digital, data and tech. We help you consider the practical actions you should take to sustain your compliance efforts. We filter out the noise for [...]

PAIA section 83(4) report for private bodies | PAIA report

All private bodies must submit a PAIA section 83(4) report (PAIA report) to the Information Regulator in accordance with a notice published by the Regulator. The regulator has requested private bodies to submit this report annually in terms of [...]

PAIA section 32 report for public bodies | PAIA annual report

The information officer of every public body in South Africa must submit a PAIA section 32 report to the Information Regulator annually. Section 32 of PAIA makes it compulsory - a regulatory requirement. PAIA gives effect to section 32 [...]

By |2026-09-02T15:53:27+02:00August 31st, 2026|Categories: Access to Information|Tags: , , , |

Lawful Direct Marketing | Complying with the NCC Opt Out registry

The new direct marketing regulations under the Consumer Protection Act have introduced one of the most significant compliance obligations marketers have faced in years. Businesses that engage in direct marketing are required to register on the National Consumer Commission (NCC) [...]

By |2026-07-27T12:45:00+02:00June 4th, 2026|Categories: |Tags: , , , |

Central Johannesburg TVET College enforcement action | POPIA breaches

The Central Johannesburg TVET College enforcement action confirms that the Information Regulator will act when POPIA conditions are not met. On 22 May 2026, the Regulator issued its first formal enforcement notice of the year, following complaints lodged by employees [...]

Cryptocurrency Regulation in South Africa

South Africa has built one of the most detailed regulatory frameworks for cryptocurrency on the African continent. With innovative fintech players leading the way, more people are turning to cryptocurrency for payments, investments, and cross-border transfers. But with growth [...]

NCC opt-out registry is a crisis for marketers

The NCC opt-out registry is a crisis for marketers. The new direct marketing regulations under the CPA may be one of the most burdensome compliance obligations marketers will face in years. Marketers must register, pay ongoing fees and opt people [...]

Gated Access Code of Conduct under POPIA

On 30 April 2026, the Information Regulator published the draft Gated Access Code of Conduct under POPIA. It applies to owners, managers, and their security and technology service providers at any gated premises, including residential estates and office parks. The [...]

By |2026-06-23T15:42:55+02:00May 5th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , |

Regulation of Cybersecurity Services in South Africa by PSiRA

PSiRA may expand its regulation of cybersecurity services in South Africa. What would this mean for cybersecurity service providers? How do you, as a cybersecurity service provider, feel about being regulated by the Private Security Industry Regulatory Authority (PSiRA)? PSiRA, [...]

By |2026-03-23T14:09:45+02:00March 17th, 2026|Categories: Cybercrime, Cybersecurity Law|Tags: , , , |

Rules or Regulations on the processing of Health Information under POPIA 2026

The information regulator prescribed rules or regulations on the processing of health information under POPIA on 6 March 2026. The Health Information Regulations apply to specific responsible parties (not everyone) who process personal information concerning a data subject’s health for […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Artificial Intelligence in the South African financial sector | FSCA AI report

Artificial Intelligence in the South African financial Sector is a fast-growing use case. The way it will be regulated is noted in our earlier posts on the latest developments in AI regulation. South Africa will adopt a risk-based, technology-neutral and industry-specific [...]

By |2026-02-27T17:52:38+02:00February 11th, 2026|Categories: AI Governance|Tags: , |