South Africa: Privacy

Subscribe
Privacy law and privacy regulation thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics including GDPR, data protection, data privacy, and privacy protection.
Article
Checkout, But Make It AI: Legal Considerations For Shopping Agents
As artificial intelligence shopping agents evolve from simple search tools to autonomous purchasing assistants, South African businesses face critical questions about data collection, consumer protection, and legal responsibility that existing frameworks like POPIA were never designed to address. How should organisations navigate AI disclosure requirements, handle voluntarily shared sensitive information, and establish governance protocols when their chatbots can independently compare products, personalise
South Africa Privacy
E
ENS
Article
The Bot In The Room: Does Automated Access Trigger POPIA's Breach Notification?
South African data protection law requires organisations to notify regulators and affected individuals when personal information is accessed or acquired by unauthorised persons, but what exactly constitutes "access," "acquisition," or "reasonable grounds to believe" a breach has occurred? This analysis examines these undefined legal concepts through the lens of established cybersecurity frameworks and digital forensics practices, exploring how they apply to modern cyber-attacks and automated tools in the co
South Africa Privacy
E
ENS
Article
ID Like To Know: Unique Identifiers Under POPIA
When organisations assign unique identifiers like account numbers or reference codes to individuals, do these identifiers fall outside data protection laws? A recent South African court case challenges conventional assumptions about what constitutes personal information under POPIA, raising critical questions about pseudonymisation, identifiability standards, and compliance obligations that every organisation processing such data must understand.
South Africa Privacy
E
ENS
See more

Related Country Guides

Article
Unique Identifiers: The POPIA Issue That Can Derail Data Commercialisation Or Monetisation
South African organisations pursuing data monetisation initiatives face a critical regulatory requirement under POPIA that many overlook: using unique identifiers to link datasets across entities may require prior authorisation from the Information Regulator. This legal blind spot affects customer-360 programmes, AI initiatives, data enrichment projects, and commercial partnerships where identifiers like ID numbers or customer references are used to match information between responsible parties.
South Africa Media & IT
E
ENS
Article
Data Localisation In The Public Sector: Where Should Government Data Reside?
South Africa's government directive mandates that all government data must reside within national borders when using cloud computing services, creating complex compliance challenges as modern cloud environments often involve cross-border data flows. This requirement forces government institutions and technology providers to carefully examine the entire data lifecycle, from storage and backup to access and processing, while ensuring compliance with the Protection of Personal Information Act.
South Africa Media & IT
E
ENS
Article
Checkout, But Make It AI: Legal Considerations For Shopping Agents
As artificial intelligence shopping agents evolve from simple search tools to autonomous purchasing assistants, South African businesses face critical questions about data collection, consumer protection, and legal responsibility that existing frameworks like POPIA were never designed to address. How should organisations navigate AI disclosure requirements, handle voluntarily shared sensitive information, and establish governance protocols when their chatbots can independently compare products, personalise
South Africa Privacy
E
ENS
See more
Article
Visitor Data At The Gate: Is Your Estate Communicating Clearly Enough?
Residential estates routinely collect visitor information at security gates, but many fail to properly communicate how this personal data is used, stored, and shared. As regulatory scrutiny intensifies under POPIA, estates, HOAs, and managing agents must ensure visitors receive clear privacy notices at the point of collection. This article examines practical steps for aligning gate security practices with data protection requirements.
South Africa Privacy
FW
Fairbridges
See more