All Topics

Subscribe
Article
The Bot In The Room: Does Automated Access Trigger POPIA's Breach Notification?
South African data protection law requires organisations to notify regulators and affected individuals when personal information is accessed or acquired by unauthorised persons, but what exactly constitutes "access," "acquisition," or "reasonable grounds to believe" a breach has occurred? This analysis examines these undefined legal concepts through the lens of established cybersecurity frameworks and digital forensics practices, exploring how they apply to modern cyber-attacks and automated tools in the co
South Africa Privacy
E
ENS
Article
Why African Financial Institutions Should Be Exploring DORA
As financial institutions increasingly rely on cloud computing, SaaS platforms, and AI technologies, technology contracts are evolving from simple commercial documents into critical operational resilience tools. The European Union's Digital Operational Resilience Act (DORA) exemplifies this shift, offering valuable insights for African financial institutions on how contractual mechanisms can actively support cybersecurity, business continuity, and third-party risk management in an interconnected technology
South Africa Media & IT
E
ENS
Article
Data Derived From AI: Understanding The Legal Risks Of Synthetic Data, Embeddings And AI-generated Data
AI systems are generating new categories of data that challenge traditional SaaS contract definitions, creating potential disputes between vendors and customers over ownership and usage rights. As synthetic data, embeddings, and vector databases emerge from AI processes, existing contractual frameworks for anonymised and aggregated data may prove inadequate to address the commercial, legal, and regulatory risks these novel datasets present.
South Africa Media & IT
E
ENS
See more