When must I comply with PAIA? PAIA scope of application

By |2026-03-06T14:49:33+02:00February 4th, 2026|Categories: Access to Information|Tags: , |

The scope of application of PAIA is triggered when the conduct of a body (public or private) affects the rights of South Africans. Specifically, a body must comply with PAIA when a person may require access to the records it [...]

Regulatory approach for AI in South Africa – What should it be?

By |2026-02-04T14:33:22+02:00February 4th, 2026|Categories: AI Governance|Tags: , |

What should the regulatory approach for AI in South Africa be? Artificial Intelligence (AI) has exploded globally - just look at ChatGPT. While AI offers enormous potential to drive innovation and inclusive growth, it also raises serious concerns, from AI-generated [...]

JSE enforcement action | Access to share trading information

By |2026-02-12T11:36:25+02:00February 2nd, 2026|Categories: Access to Information, POPI and Data Protection|Tags: , , , , , |

The Information Regulator has issued a PAIA enforcement notice against the Johannesburg Stock Exchange (JSE) after it refused to grant access to share trading records. This JSE enforcement action requires the JSE to notify affected third parties and reconsider whether […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

The South African AI Act: latest developments

By |2026-02-11T14:33:21+02:00January 27th, 2026|Categories: AI Governance|Tags: , , , , |

There will be no standalone South African AI Act. Instead, South Africa will have a sector-specific, risk-based approach to AI regulation. This approach aligns with international best practices followed by the UK and Australia, which seek to use existing laws [...]

The law in 2026 – our predictions

By |2026-02-02T10:22:10+02:00January 25th, 2026|Categories: Access to Information, AI Governance, Cybersecurity Law, IT Law, Life@Law, POPI and Data Protection|Tags: , |

Welcome to the law in 2026! At the beginning of each year, we look ahead to help you prioritise your next steps. This is the law regarding digital, data and tech in 2026. We try to predict what will happen [...]

Minister of Basic Education v Information Regulator | Appealing an enforcement notice

By |2026-01-23T16:10:07+02:00January 23rd, 2026|Categories: POPI and Data Protection|Tags: , , , , |

In Minister of Basic Education v Information Regulator, the High Court set aside the regulator’s enforcement notice issued to the DBE. The notice tried to stop the Department from publishing the matric results using examination numbers. The judgment provides guidance [...]

Cybersecurity compliance for officers – From librarian to navigator

By |2026-02-11T17:47:00+02:00January 22nd, 2026|Categories: Cybersecurity Law, POPI and Data Protection|Tags: , , , , |

Let's talk cybersecurity compliance for officers. Many organisations treat cybersecurity compliance like a library. They collect policies, file them away, and assume that because the shelf is complete, the building is safe. But in 2026, regulators aren't looking for a [...]

Department of Basic Education enforcement action | Consent

By |2026-07-14T15:09:44+02:00January 8th, 2026|Categories: POPI and Data Protection|Tags: , , , , , , , |

The Information Regulator argues that it is unlawful for the Department of Basic Education (DBE) to publish matric results in newspapers using a learner's exam number without consent. The regulator issued an enforcement notice to the DBE and then fined […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Lessons to learn from the Information Regulator priotities

By |2026-10-02T13:23:46+02:00December 3rd, 2025|Categories: Access to Information, POPI and Data Protection|Tags: , , , , |

Understanding the Information Regulator's priorities is no longer just good practice; it's essential to avoid enforcement action. Having attended the Regulator's recent stakeholder breakfast, we can distil the key lessons and confirmed changes that will shape the compliance landscape in […]

Unlock exclusive content, join a Michalsons Programme!

Members should log in to access this content. If you're not a member then join a Michalsons programme.

Information Regulator stakeholder engagement in Cape Town

By |2025-12-03T14:07:58+02:00December 2nd, 2025|Categories: Access to Information, POPI and Data Protection|Tags: , , , , |

The Information Regulator stakeholder engagement revealed the regulator's thinking on how to comply with the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA). More importantly, the regulator confirmed expected amendments to the POPIA [...]

Do I need an App EULA or App Terms of Use?

By |2026-03-19T09:48:25+02:00November 22nd, 2025|Categories: Contracts|Tags: , , |

Many people are wondering whether they need an App EULA (or Application End User Licence Agreement) for the App (or application) they have developed (such as an iPhone App, Mac App, or iPad App). It might be an App for [...]