South Africa: Data Protection

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
Checkout, But Make It AI: Legal Considerations For Shopping Agents
As artificial intelligence shopping agents evolve from simple search tools to autonomous purchasing assistants, South African businesses face critical questions about data collection, consumer protection, and legal responsibility that existing frameworks like POPIA were never designed to address. How should organisations navigate AI disclosure requirements, handle voluntarily shared sensitive information, and establish governance protocols when their chatbots can independently compare products, personalise
South Africa Privacy
E
ENS
Article
AfCFTA Digital Trade Pilots Make Governance A Market-entry Test
African nations are accelerating digital trade infrastructure through the AfCFTA framework, with Kenya, Morocco and Nigeria piloting cross-border systems while governments strengthen data protection and tax frameworks. Hardware innovation, 5G deployment and fintech convergence are creating new commercial pathways, but market access now depends as much on regulatory alignment as commercial capability. The question facing businesses is whether they can build governance readiness fast enough to compete in Afri
Worldwide International
AA
Adams & Adams
Article
Data Derived From AI: Understanding The Legal Risks Of Synthetic Data, Embeddings And AI-generated Data
AI systems are generating new categories of data that challenge traditional SaaS contract definitions, creating potential disputes between vendors and customers over ownership and usage rights. As synthetic data, embeddings, and vector databases emerge from AI processes, existing contractual frameworks for anonymised and aggregated data may prove inadequate to address the commercial, legal, and regulatory risks these novel datasets present.
South Africa Media & IT
E
ENS
Article
The Bot In The Room: Does Automated Access Trigger POPIA's Breach Notification?
South African data protection law requires organisations to notify regulators and affected individuals when personal information is accessed or acquired by unauthorised persons, but what exactly constitutes "access," "acquisition," or "reasonable grounds to believe" a breach has occurred? This analysis examines these undefined legal concepts through the lens of established cybersecurity frameworks and digital forensics practices, exploring how they apply to modern cyber-attacks and automated tools in the co
South Africa Privacy
E
ENS
See more