Contracting using a clickwrap agreement | Click-through contracting

By |2026-09-16T13:22:21+02:00September 4th, 2026|Categories: Contracts, IT Law|Tags: , , , , , |

You've probably come across a clickwrap agreement without even realising it. Some people call this the click-through contracting model. It is a quick method for users and consumers to agree to the terms of service providers. Technology has made buying [...]

IT agreements: Order of precedence clarity

By |2026-09-04T09:37:47+02:00September 4th, 2026|Categories: Contracts, Electronic Transactions Law|Tags: |

Navigating an IT agreement is like piecing together a jigsaw puzzle. It's multi-layered, intricate, and prone to missing connections. In the age of digital contracts, order of precedence is important. Think about it: IT contracts are complex and can span [...]

Information Regulator ramps up enforcement

By |2026-09-23T09:37:19+02:00September 2nd, 2026|Categories: Access to Information, POPI and Data Protection|Tags: , , , |

Information Regulator ramps up enforcement: on 1 September 2026, the Information Regulator briefed the public and media on its latest enforcement and compliance activities under POPIA and PAIA. The briefing shows the Regulator is increasingly concerned about South Africa's cybersecurity [...]

PAIA section 83(4) report for private bodies | PAIA report

By |2026-09-02T15:18:18+02:00August 31st, 2026|Categories: Access to Information|Tags: , , , |

All private bodies must submit a PAIA section 83(4) report (PAIA report) to the Information Regulator in accordance with a notice published by the Regulator. The regulator has requested private bodies to submit this report annually in terms of [...]

PAIA section 32 report for public bodies | PAIA annual report

By |2026-09-02T15:53:27+02:00August 31st, 2026|Categories: Access to Information|Tags: , , , |

The information officer of every public body in South Africa must submit a PAIA section 32 report to the Information Regulator annually. Section 32 of PAIA makes it compulsory - a regulatory requirement. PAIA gives effect to section 32 [...]

EU Data Act switching: cloud exits

By |2026-08-31T12:45:36+02:00August 31st, 2026|Categories: Cybersecurity Law, Data governance, IT Law, Tech Law|Tags: , , , , , |

A company group with a subsidiary in the EU decides that the cloud SaaS platform it has used for years is no longer the right fit. EU Data Act switching rules now shape what happens next. Legal counsel is asked [...]

Mashashane v SABC | Exhaust internal remedies

By |2026-09-21T09:56:47+02:00August 25th, 2026|Categories: Access to Information|Tags: , , , , , |

In Mashashane v SABC, the Gauteng Local Division considered an urgent application under the Promotion of Access to Information Act 2 of 2000 (PAIA). Mashashane, the applicant, sought to compel the SABC to disclose a copy of an old Speak […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Cybersecurity flow-down clauses – Whose compliance obligations?

By |2026-08-12T13:35:29+02:00August 12th, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

A security addendum arrives from a customer. They want incident notification within 24 hours, the right to audit you on site, approval before you change a subcontractor, and cooperation with their penetration testing. These are cybersecurity flow-down clauses: contractual terms [...]

Nominate someone to be a member of the information regulator

By |2026-08-20T11:03:08+02:00August 5th, 2026|Categories: POPI and Data Protection|Tags: , |

Parliament has invited the organisations and interested individuals to nominate people (or apply themselves) for the President to appoint as members of the information regulator. Do you want to nominate someone? Do you know anyone who might want to nominate [...]

Pre-investigation notice from the Information Regulator: what now?

By |2026-07-31T13:36:30+02:00July 27th, 2026|Categories: POPI and Data Protection|Tags: , , |

If a complainant lodges a complaint against you for infringing their privacy rights, the information regulator can issue any one of a few types of notices to you. For example, you could receive an information notice, an enforcement notice, or [...]

Enforcement Notice from the Information Regulator: what now?

By |2026-07-27T14:07:36+02:00July 26th, 2026|Categories: POPI and Data Protection|Tags: , , , , , |

The Information Regulator may send you a POPIA enforcement notice after investigating you and finding that you have contravened POPIA by failing to lawfully process personal information. In comparison, the Information Regulator may send you an infringement notice if it [...]