The Law Has Its Eye on Your Streams, Posts, and Data

Professionals analysing digital information and cybersecurity, representing legal compliance for data protection, streaming services, social media and AI regulation.

The legal landscape governing AI, data protection and cybersecurity is shifting quickly – here’s what you need to know.

THE OTT HONEYMOON IS OVER

Broadcasters like DStv and the SABC hold ICASA licences and pay for the privilege. Streaming and messaging giants? Free pass. Major double standard, and ICASA has noticed.

ICASA’s 2026/27 Annual Performance Plan confirms a formal market inquiry into over-the-top (“OTT”) platforms, examining their impact on telecoms and broadcasting. The net is wide: instant messaging, streaming, social media, and online gaming, with WhatsApp, Telegram, Showmax, Netflix, YouTube, Facebook, X, Instagram, Xbox, PlayStation 6, and Steam all named explicitly. No ICASA levy, no Regulations, no borders. OTT platforms are simply vibing and thriving – for now.

Nothing is decided yet. But the process has moved from political rhetoric to an active regulatory workstream. Subscription hikes, if they come, are still some way off.

YOUR POSTS, ON BLAST

The Draft White Paper on Audio and Audiovisual Media Services and Online Safety – now in its third iteration, published for comment in July 2025 – wants to regulate the content itself: YouTube videos, podcasts, social media posts, all potentially answerable to an independent online safety ombudsman.

As of the most recent public reporting available, that final version had not yet been published, and the Minister has more recently described the policy as still being “finalised,” alongside a separate plan to introduce an Electronic Communications Amendment Bill to modernise licensing. ICASA’s own 2026/27 planning documents, published around the same time, still treat OTT and content regulation as matters at the discussion-paper stage. While the finalisation timeline has slipped past its own stated deadline, this is now genuinely close rather than a distant prospect. The three-stage, twenty-four-month rollout once anticipated may still apply once the policy is finalised, but a firm start date isn’t yet public.

POPIA WOKE UP AND CHOSE ENFORCEMENT

The January 2025 amendments to the Regulations changed the playbook:

  • “Delete my number” is now legally binding

Data subjects can now demand deletion of their personal information via multiple channels – including WhatsApp. A casual “delete my details” message may carry legal weight.

  • It’s official – email is cancelled

Since 1 April 2025, the Information Regulator’s e-portal has been the only channel for reporting data breaches. The only misstep – if your server is compromised and staff are locked out of email, how do they get the OTP to access the portal? Incomplete submissions or delays still invite enforcement action. Don’t do it for the plot – test your process now.

  • “No consent, just vibes” doesn’t fly anymore

Cross-border transfers now demand more. Responsible parties are required to conduct legitimate interest assessments in the absence of consent from data subjects.

  • Every call, on the record

Consent for direct marketing still stands, but every call must be transcribed and sent to the data subject afterward.

THE GLOW-UP: CYBERSECURITY SAID “NEW YEAR, NEW ME”

A Directive issued by the South African Reserve Bank in May 2024 shifts the posture from cybersecurity to cyber resilience – a recovery-driven approach. It’s no longer about keeping attackers out. It’s about how fast you bounce back.

  • The buck stops at the boardroom.

Boards and executives now own cyber risk. When something goes wrong, it’s leadership and not IT who must explain why their cybersecurity policies weren’t strong enough. Déjà vu? POPIA got there first: the head of the organisation typically serves as the Information Officer.

  • Trust issues? Good.

Test, don’t trust. Incident response plans must be stress-tested through simulations, penetration tests, and breach rehearsals. A fire drill for your software – you don’t wait for the building to burn to check if the exits work.

  • Claim denied? Could never be you… if you follow the steps.

Cyber insurance claims hinge on the reporting sequence, starting with notifying the Information Regulator via the e-portal. Miss a step, and your claim may be denied outright.

THE BOTTOM LINE? READ THE ROOM.

The regulatory landscape is catching up with how we actually live and work: online, on-demand, and across borders. The law isn’t just playing defence anymore. It’s building for recovery, for accountability and for a digital world that finally looks like the one we inhabit.