South Africa: Privacy

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
The Bot In The Room: Does Automated Access Trigger POPIA's Breach Notification?
South African data protection law requires organisations to notify regulators and affected individuals when personal information is accessed or acquired by unauthorised persons, but what exactly constitutes "access," "acquisition," or "reasonable grounds to believe" a breach has occurred? This analysis examines these undefined legal concepts through the lens of established cybersecurity frameworks and digital forensics practices, exploring how they apply to modern cyber-attacks and automated tools in the co
South Africa Privacy
E
ENS
Article
ID Like To Know: Unique Identifiers Under POPIA
When organisations assign unique identifiers like account numbers or reference codes to individuals, do these identifiers fall outside data protection laws? A recent South African court case challenges conventional assumptions about what constitutes personal information under POPIA, raising critical questions about pseudonymisation, identifiability standards, and compliance obligations that every organisation processing such data must understand.
South Africa Privacy
E
ENS
Article
Visitor Data At The Gate: Is Your Estate Communicating Clearly Enough?
Residential estates routinely collect visitor information at security gates, but many fail to properly communicate how this personal data is used, stored, and shared. As regulatory scrutiny intensifies under POPIA, estates, HOAs, and managing agents must ensure visitors receive clear privacy notices at the point of collection. This article examines practical steps for aligning gate security practices with data protection requirements.
South Africa Privacy
FW
Fairbridges
See more
Article
Data Derived From AI: Understanding The Legal Risks Of Synthetic Data, Embeddings And AI-generated Data
AI systems are generating new categories of data that challenge traditional SaaS contract definitions, creating potential disputes between vendors and customers over ownership and usage rights. As synthetic data, embeddings, and vector databases emerge from AI processes, existing contractual frameworks for anonymised and aggregated data may prove inadequate to address the commercial, legal, and regulatory risks these novel datasets present.
South Africa Media & IT
E
ENS
Article
The Bot In The Room: Does Automated Access Trigger POPIA's Breach Notification?
South African data protection law requires organisations to notify regulators and affected individuals when personal information is accessed or acquired by unauthorised persons, but what exactly constitutes "access," "acquisition," or "reasonable grounds to believe" a breach has occurred? This analysis examines these undefined legal concepts through the lens of established cybersecurity frameworks and digital forensics practices, exploring how they apply to modern cyber-attacks and automated tools in the co
South Africa Privacy
E
ENS
See more
Article
Visitor Data At The Gate: Is Your Estate Communicating Clearly Enough?
Residential estates routinely collect visitor information at security gates, but many fail to properly communicate how this personal data is used, stored, and shared. As regulatory scrutiny intensifies under POPIA, estates, HOAs, and managing agents must ensure visitors receive clear privacy notices at the point of collection. This article examines practical steps for aligning gate security practices with data protection requirements.
South Africa Privacy
FW
Fairbridges
See more