Related Document - PDF file.
This quarter’s data privacy update highlights a clear shift from
compliance on paper to compliance that can be proved. Locally,
the Information Regulator’s recent POPIA and PAIA enforcement
notices show that public and private bodies must report security
compromises, justify refusals of access, honour settlement
agreements and keep proper evidence of their decisions.
Internationally, developments in Canada and the UK point in
the same direction: regulators are focusing on accountable AI
deployment, meaningful safeguards, and accessible internal
complaint-handling. For South African responsible parties and
information officers, the practical message is simple: privacy
governance must be documented, responsive and capable of
withstanding regulatory scrutiny.