Tag: POPIA
NDA residuals clauses – can memory undermine confidentiality?
A Non-Disclosure Agreement (NDA) creates a protected space in which parties can exchange commercially sensitive information. Yet a few apparently innocuous words dealing with information retained in “unaided memory” may materially reduce that protection. In extreme cases, they may undermine the commercial purpose of the NDA itself.
Promotional competitions – is there a free lunch when you win...
A brand runs an on-pack promotion: buy a product, find the code inside, enter it on an app, and you might win a prize. The prize could range from a free lunch to an all-expenses-paid trip to Paris. Thousands of people enter, and a winner is drawn. The marketing team would love to announce the winner with a photograph and a celebratory post on social media. However, the winner would rather not.
SME cybersecurity – turning David’s compliance to a Goliath advantage
The enterprise Goliath is worried about its suppliers. These Small and Medium-sized Enterprises (SMEs) are underprepared. They are also disproportionately targeted. In fact, 43% of cyber-attacks target their digital front door. In addition, the Protection of Personal Information Act (POPIA) holds large organisations legally responsible when a supplier is breached.
Boards are underestimating the AI agent risk
Artificial Intelligence (AI) is rapidly moving from experimentation to execution within South African organisations. Organisations increasingly embed AI agents across business functions, including finance, customer service, IT and operations. However, a significant governance concern is emerging.
Surveillance, Privacy and Consent – smart glasses raise the risks
EssilorLuxottica and Meta sold more than seven million Ray-Ban and Oakley-branded smart glasses in 2025. Sales of these intelligent wearables increased almost threefold compared with 2023. As a result, the category moved into the mainstream.
Data resilience governance – the AI trust backbone
South African organisations are moving quickly from Artificial Intelligence (AI) experimentation to deployment. The latest South African Generative AI Roadmap 2025 highlights this shift. It found that 67% of respondents reported current GenAI adoption. This figure is up from 45% in 2024. Therefore, organisations are moving from planning to active use.
Using AI to protect data from cybercriminals is crucial
The cybersecurity landscape is rapidly changing, with hackers increasingly utilising Artificial Intelligence (AI) to carry out sophisticated attacks on their targets. To defend against these AI-driven threats, organisations must adopt data protection solutions that harness AI, essentially “fighting fire with fire”. This is the foundation of using AI to protect data from cybercriminals.
Online protection – platforms are the problem, not children
Australia’s decision to ban children under 16 from social media, with Denmark eyeing similar measures for under-15s, has reignited a global debate about children, technology and harm. The political appeal is obvious: draw a clear line, claim protection and move on. But from a South African legal and policy perspective, this approach is both insufficient and misdirected. It treats children as the problem, rather than the digital systems that systematically fail them.
Who is the UBO? – knowing is vital for any deal
Knowing who the ultimate beneficial owner (UBO) of an entity is before engaging in any type of business deal, is a critical task that is often overlooked. This is particularly true in today’s increasingly stringent regulatory environment, in which organisations are increasingly expected to understand who they are doing business with to help fight fraud.
Where will GDPR & POPIA leave digital marketing?
The EU’s General Data Protection Regulation (GDPR) officially came into force on 25 May, followed by its local cousin, POPIA in the second or third quarter of the year. You may be feeling this already – who hasn’t received a flood of Privacy Policy and Data Protection Policy updates from around the world. Both GDPR and POPIA are set to dramatically change the way South African organisations do business – especially how personal data is handled and stored.































