The Regulator Is Eyeing Your Data, Your Streams and Your Posts

Professional using a tablet, representing digital regulation, online platforms, data privacy and cybersecurity compliance.
The legal landscape governing AI, data protection and cybersecurity is shifting; here is what you need to know.

POPIA Tightens Its Grip

Most of us know that the Protection of Personal Information Act 4 of 2013 (“POPIA”) regulates how responsible parties process personal information. But the January 2025 amendments to the Regulations introduced changes worth paying attention to:
  1. Cross-border transfers now require a legitimate interest assessment if you are unable to obtain consent from the data subject. “They’re overseas, so it’s fine” no longer cuts it.
  2. Objection channels have expanded. Data subjects can now demand deletion of personal information via multiple channels, including WhatsApp. A message saying “delete my details” may carry legal weight.
  3. Telemarketers face new transcription duties. Consent for direct marketing can be obtained, but the content of every call must be transcribed and sent to the data subject thereafter.
Data breach reporting goes digital. The Information Regulator has introduced a mandatory e-portal as the sole channel for reporting data breaches. The e-portal requires detailed disclosure: the impact, the steps taken to minimise damage, whether the data was retrieved securely. Unfortunately, the e-portal embodies a circular problem: if your company’s server is compromised and employees are locked out of their email accounts, how do they receive the OTP needed to access the reporting portal? Regardless, immediate notification is non-negotiable, and delays invite hefty fines.

From Cybersecurity to Cyber Resilience

A fundamental shift is underway. A directive issued by the South African Reserve Bank in May 2024 signals a move from a purely defensive posture to recovery-driven resilience. The question is no longer just “Can we block the attack?” but “How fast can we recover?” Governance starts at the top. Boards and executives now “own” cyber risk. When something goes wrong, it’s leadership, not the IT department, that must explain why policies weren’t strong enough. If this sounds familiar to you, you’re not wrong. The cyber resilience model mirrors POPIA’s requirement that the head of the organisation should typically serve as Information Officer. Test, don’t trust. Incident response plans must be stress-tested through regular simulations, penetration tests, and breach rehearsals. Think of it as a fire drill for your software; you don’t wait for the building to burn before checking if the exits work. Insure wisely. Cyber insurance is advisable, but claims hinge on proper reporting sequence starting with notifying the Information Regulator via the e-portal. Miss a step and your claim may be rejected outright.

Developments are brewing that could reshape your personal digital life.

  1. The streaming squeeze.
The Electronic Communications Act 26 of 2005 currently requires broadcasters like DStv and the SABC to hold Independent Communications Authority of South Africa (“ICASA”) licences, complete with hefty annual fees. Over-the-top (“OTT”) service providers (such as Netflix, Spotify and other streaming platforms) bear no such burden. There is now a push to change that, bringing OTT providers into the licensing fold to level the playing field. The knock-on effect? Subscription fees will likely rise as these platforms absorb licensing costs they never budgeted for.
  1. Your content, regulated.
A draft White Paper on Audio and Audiovisual Services and Online Safety, published in July 2025, proposes extending regulation beyond platforms to user-generated content itself. YouTube videos, podcasts, social media posts are some examples that could fall within scope. The framework envisions an independent online safety ombudsman to handle complaints and set content standards. Platforms would be required to shape their user policies around governmental mandates, not just their own terms of service. Take a breath, though. This is still in draft form, with public comment already closed. The legislature anticipates a three-stage rollout over twenty-four months. Nothing changes tomorrow. The key takeaway? Regulation is catching up with how we actually live and work – online, on-demand, and across borders. The law is not just playing defence anymore. It’s building for recovery, for accountability, and for a digital world that looks increasingly like the one we inhabit.