It’s a new year and a new decade. And as technology, business, and society develop we’ll encounter new and interesting legal challenges. The question is: can we accurately predict what 2020 has in store for us?

Predictions are a tricky business and can make a fool out of anybody. Even the Financial Times, who like us, are leaders in their industry, find themselves proven wrong. That’s the nature of the beast we suppose.

With that said though, many of our previous predictions have proven to be right. And it’s our hope that with this forecast we’ll be able to empower you to plan your year ahead.

Stay ahead of the rest by reading our 2020 predictions.

Data protection reaches the USA

The California Consumer Privacy Act (CCPA), the state’s new data protection law commenced on 1 January 2020, ushering in a new decade of data protection in the USA. The implementation of this law is an important step forward for our global business landscape because it not only impacts business within the USA but it impacts business with the USA. The CCPA deadline is 1 July 2020. You can access it quickly and read it on all your devices by going to consumerprivacyact.com.

It seems that the tides are changing in the States as the country finally realises that it needs an umbrella-style law, much like the GDPR. We predict that they’ll begin to enact federal privacy laws as well as individual state laws over the course of 2020.

More people will ask “Who owns the data?”

As data becomes the most valuable incorporeal, more people will be asking – who owns the data?

We anticipate seeing several large contractual and intellectual property disputes over the issue of ownership. Through these disputes, the concept of ownership will have to be adjusted to the digital context allowing for information law or data law to emerge as its own field.

The era of robots and AI

In the 20’s, the race to regulate robots and AI will speed up as technology develops. So far, over 20 countries across the world have adopted strategies to regulate robots and AI. In Africa, Kenya and Tunisia have taken the lead with South Africa shortly behind. The South African government have announced that it will develop a strategy by March 2020, meaning there will be interesting developments in this field.

Over the course of the year, we’ll be hosting presentations and webinars on this topic.

POPIA soon to commence – South Africa

We predict that the South African President will likely proclaim the POPIA commencement date to be on about 1 April 2020 – setting the POPIA deadline to about 1 April 2021. You can access it quickly and read it on all your devices by going to popia.co.za.

Those who haven’t started implementation will have to keep these dates in mind and kickstart their efforts now as implementation is no small task.

In preparation for POPIA, we’ve developed the Data Protection Programme. The programme is an online tool, a step-by-step solution, that’s supported by webinars, easy access laws, templates, and forums to ensure your organisation gets a head start.

Cybercrime laws will further develop

While the internet and the emergence of our digital economy represent significant opportunities, these opportunities also introduce the possibility of cybercrimes. There are a number of global cybercrime laws in existence, but we’ll be welcoming new and updated cybercrime law in 2020.

South Africa, in particular, is said to be enacting the Cybercrimes Bill this year, and while the new law is welcome, we forecast that its implementation will take time. The potential benefit of the Cybercrimes Bill is that it will combat cybercrime by making it easier to catch and prosecute criminals.

Information security is more important than ever

Data and information have become a key part of our everyday lives, meaning that in this new information age, data can be likened to the ‘new oil’. With this in mind, we have to be vigilant about protecting information against threats.

Failing to do this doesn’t just mean losing data. Consider how sensitive information can be, data can range from a person’s banking details to their medical records. Meaning that the consequences of losing data can range from financial loss to suffering or even physical harm.

If your organisation are third party data processors then a failure to protect that information may mean you not only suffer damage but could also be responsible for damage to others. An information security breach will often lead to personal loss, third party liability, compliance failures (and penalties) and reputational damage.

Even the best-prepared entities can be victims of data compromises and it is for this reason that we advise our clients carefully consider incident response management and effective recovery strategies.

Many will take action to comply with the Kenyan Data Protection Act

Another comprehensive data protection law, the Kenya Data Protection Act, acts as a further step forward for protecting personal information in Africa. The Act came into effect on 25 November 2019 and is modelled closely on the GDPR (which has become the standard for data protection). In addition, the Act introduces the role of Data Protection Commissioner, an individual set to regulate how the law is enforced in Kenya.

Organisations will seek to manage their legal spend

The economic downturn will increase the already gathering momentum and pressure to move from time-based fees to fixed fees and other non-time-based fee arrangements (like retainers).

Many industries, like big tech, are growing their legal teams and for good reason. They’ll begin asking (if they haven’t already) – ‘How much should we be spending on legal and compliance?’.

In 2020, the saying ‘If you think compliance is expensive, try non-compliance’ will be truer than ever. We’ve seen many clients share the same problems and requirements when aiming to meet the same regulations. Which is why with our experience and guidance you’ll be able to comply in a faster, cheaper manner than if you tried it alone.

European privacy regulations enacted for electronic communications

2020 will see Europe finally enacting their Privacy and Electronic Communications Regulations (ePrivacy Regulations), which together with the GDPR, will act as the second column of data protection regulation in the EU.

ePrivacy Regulations will set the tone for direct electronic marketing regulations, meaning we’ll see a global evolution of marketing tactics as strategist adjust their campaigns to align with mandated customer privacy.

Software as a service continues to gather momentum

Software as a Service or SaaS, also known as cloud computing, will increasingly become a part of our personal and working lives. Currently, several SaaS offerings already form a part of Michalsons IT infrastructure.

“Anything” as a Service will also gather momentum – lawyers will even offer Compliance as a Service or Law as a Service