Ask the Regulators: Support for PAIA compliance, e-Services and BizPortal

By |2026-02-12T15:50:58+02:00June 19th, 2025|Categories: Access to Information, POPI and Data Protection|Tags: , , , , , |

Today, the South African information regulator held a webinar called "Ask the Regulator". The purpose of the webinar was to allow participants to ask the regulator questions and for the regulator to encourage and support them in complying with POPIA […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Cybersecurity compliance fairy tales – dispelling the myths

By |2025-06-05T18:29:44+02:00June 5th, 2025|Categories: Cybersecurity Law|Tags: |

It's cybersecurity compliance fairy tale storytime. Let's banish them to the past, where they belong. Cybersecurity compliance can feel like chasing dragons — many discuss it, but few truly understand how to implement it effectively. Organisations often mistakenly believe that [...]

POPIA Manual is a Privacy Policy

By |2025-06-05T16:08:11+02:00June 4th, 2025|Categories: POPI and Data Protection|Tags: , |

A POPIA manual is actually a privacy policy. Many organisations have compiled or published a POPIA Manual, and we often receive enquiries requesting that we draft one for clients or provide a POPIA Manual template. Some people incorrectly think [...]

South African cybersecurity laws – unravelling the knot

By |2025-10-20T09:32:08+02:00June 4th, 2025|Categories: Cybersecurity Law|Tags: |

Understanding South African cybersecurity laws can feel like trying to cut through the legendary Gordian knot - a challenging yet essential task. Cyber threats are increasing rapidly, making it crucial for organisations in South Africa to understand these regulations clearly. [...]

Katiba v Tools for Humanity and others | Biometric data

By |2026-04-14T11:31:20+02:00May 30th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

Katiba v Tools for Humanity and others is Kenya's landmark High Court decision on biometric privacy. Worldcoin-linked entities violated Kenya's Data Protection Act by collecting iris and facial scans in exchange for cryptocurrency. The court halted the project and ordered [...]

SARB Cybersecurity and Cyber-Resilience Directive

By |2025-05-29T21:12:47+02:00May 29th, 2025|Categories: Cybersecurity Law|Tags: |

The South African Reserve Bank (SARB) has issued a Cybersecurity and Cyber-Resilience Directive focused on strengthening cybersecurity and cyber-resilience within the National Payment System. Since the financial sector plays a vital role in our economy, SARB expects all payment institutions [...]

Nigeria fines Meta | Data breach penalty upheld

By |2025-06-01T15:23:51+02:00May 28th, 2025|Categories: POPI and Data Protection|Tags: , , , |

In an appeal brought by Meta Platforms Inc. and WhatsApp, LLC, the Competition and Consumer Protection Tribunal confirmed that their conduct violated data protection and competition laws. The Tribunal affirmed the Federal Competition and Consumer Protection Commission's (FCCPC) decision to [...]

Proposed GDPR record-keeping exemption for SMEs

By |2025-05-30T13:19:07+02:00May 28th, 2025|Categories: POPI and Data Protection|Tags: , , |

The European Commission (EU Commission) has published a proposal for a GDPR record-keeping exemption for SMEs and small mid-cap companies (SMCs) as part of its Omnibus IV Simplification Package. If adopted, this amendment to Article 30(5) of the GDPR could [...]

King V and cybersecurity – locking down corporate governance

By |2025-05-26T14:58:04+02:00May 26th, 2025|Categories: Cybersecurity Law, Governance|Tags: , , |

The King V Code is changing corporate governance in South Africa by moving cybersecurity from a purely technical issue to a central responsibility for company boards. The Institute of Directors in Southern Africa (IoDSA) published King V's draft on 24 [...]

GDPR vs POPIA | Compare the GDPR with the POPI Act?

By |2025-05-26T11:38:49+02:00May 25th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

GDPR vs POPIA. How do they compare? The key is to identify the differences and similarities between the GDPR and the POPI Act. For example, who needs to comply with them, do they both apply to the same data [...]

AI vendor impact assessment manages risk

By |2025-05-26T12:17:56+02:00May 20th, 2025|Categories: AI Governance|Tags: , , , , |

As organisations increasingly adopt artificial intelligence (AI) systems, many turn to external providers to supply these tools. But using third-party AI without proper due diligence can expose you to serious legal, ethical, and operational risks. An AI vendor impact assessment [...]

TikTok’s GDPR transfers – Understanding the €530M fine

By |2025-05-26T11:56:58+02:00May 13th, 2025|Categories: POPI and Data Protection|Tags: , , , |

Let's discuss TikTok’s GDPR transfers. Managing cross-border data flows under GDPR can be as treacherous as navigating iceberg-strewn waters — hidden dangers lurk beneath the surface. TikTok recently discovered how severe those dangers can be, facing a landmark €530 million [...]