Cybersecurity law compliance: Getting it ‘just right’

By |2025-03-27T16:17:39+02:00March 20th, 2025|Categories: Cybersecurity Law|Tags: |

Like Goldilocks sampling porridge, businesses face the challenge of getting their cybersecurity measures 'just right' — not too weak to invite breaches nor too cumbersome to stifle operations. In today's landscape, fraught with AI-driven scams and rampant ransomware attacks, achieving [...]

Implementing the cybersecurity triad

By |2025-03-18T19:10:59+02:00March 18th, 2025|Categories: Cybersecurity Law|Tags: |

Implementing the cybersecurity triad effectively is like managing traffic at a busy intersection. 'Confidentiality', 'Integrity', and 'Availability' each represent a different stream of traffic. If one stream isn't managed correctly, it disrupts everything, causing chaos and risks to security. Cyber [...]

AI voice cloning scams

By |2025-03-18T13:54:08+02:00March 17th, 2025|Categories: AI Governance, Cybersecurity Law|Tags: , , , |

Artificial intelligence (AI) brings convenience to our lives, but imagine your voice being stolen and used as a weapon by criminals. AI voice cloning scams use your voice, or that of someone you trust, to deceive you into transferring money [...]

Information regulator annual performance plan for 2025 to 2026 APP

By |2025-03-26T11:52:16+02:00March 5th, 2025|Categories: Access to Information, POPI and Data Protection|Tags: , |

The information regulator has presented its draft annual performance plan (regulator APP) for 1 April 2025 to 31 March 2026. It has presented them in different formats to different audiences. For example, the regulator held a stakeholder engagement on 5 [...]

Do you need to register as a Cryptography Provider?

By |2025-03-20T11:30:32+02:00March 5th, 2025|Categories: IT Law|Tags: , , , , |

You need to register as a cryptography provider if you provide encryption-related products and services or electronic-signature-related offerings. Cryptography and encryption present a challenge to security-conscious governments in that it allows you to conceal your message content from the authorities. [...]

De Jager v Netcare | Surveillance Evidence and POPIA

By |2025-03-29T09:26:59+02:00February 28th, 2025|Categories: POPI and Data Protection|Tags: , , , , |

In De Jager v Netcare, the High Court considered whether surveillance evidence collected without consent was admissible under the Protection of Personal Information Act (POPIA). The case clarifies when personal information, including special personal information like health data, may be [...]

DeepSeek banned over privacy concerns

By |2025-02-26T13:59:06+02:00February 26th, 2025|Categories: AI Governance|Tags: , |

DeepSeek, a Chinese artificial intelligence (AI) chatbot, faces bans and suspensions worldwide due to serious privacy and security concerns. Governments and regulators have flagged the chatbot’s data practices - raising alarms over potential national security risks and non-compliance with data [...]

Information security vs cyber security: What’s the difference?

By |2025-10-07T14:44:32+02:00February 26th, 2025|Categories: Cybersecurity Law|Tags: , , |

Information Security vs Cyber Security - what’s the Difference? Information security and cybersecurity are not separate concepts—they are the same discipline applied in different eras. Information security existed long before digital technology, focusing on protecting physical records and sensitive information. [...]

Data protection in Bulgaria

By |2025-02-25T15:26:37+02:00February 25th, 2025|Categories: POPI and Data Protection|Tags: , |

Data protection is a critical element of Bulgaria's fast-evolving digital economy. As businesses explore innovative technologies, foreign investment grows, and data-driven services expand, compliance with the GDPR and the Bulgarian Personal Data Protection Act (PDPA) is essential for safeguarding consumer [...]

Joint Standard on Cybersecurity and Cyber Resilience Requirements

By |2026-05-06T09:39:25+02:00February 24th, 2025|Categories: Cybersecurity Law|Tags: , , |

The Joint Standard on Cybersecurity and Cyber Resilience Requirements sets the minimum standards for financial institutions to implement best practices and processes to identify and guard against cybersecurity and cyber resilience risks. The Financial Sector Conduct Authority (FSCA) and the [...]

CPA amendments: What they could mean for direct marketing

By |2026-03-09T16:34:45+02:00February 21st, 2025|Categories: Marketing Law, POPI and Data Protection|Tags: , , |

The Department of Trade, Industry, and Competition (DTIC) plans to make CPA amendments to the Consumer Protection Act (CPA) regulations. These CPA regulation amendments aim to address direct marketing practices in South Africa by introducing a National government-run opt-out registry [...]