On April 7, 2025, South Africa’s Information Regulator announced a new requirement for organizations to report data breaches—referred to under local law as “security compromises”—via an online eServices Portal. The announcement marks a significant procedural shift in how companies must comply with the Protection of Personal Information Act, 2013 (“POPIA”), South Africa’s data protection
Cov Africa
Cov Africa Blogs
Latest from Cov Africa
Kenya’s AI Strategy 2025–2030: Signals for Global Companies Operating in Africa

Kenya has released its first National Artificial Intelligence Strategy (2025–2030), a landmark document on the continent that sets out a government-led vision for ethical, inclusive, and innovation-driven AI adoption. Framed as a foundational step in the country’s digital transformation agenda, the strategy articulates policy ambitions that will be of interest to global companies developing,…
Long-Awaited POPIA Guidance on Direct Marketing Published by South Africa’s Information Regulator
The Information Regulator recently published its Guidance Note on Direct Marketing (“Guidance Note”), providing clarity on how personal information can be lawfully processed under the Protection of Personal Information Act (“POPIA”). The Guidance Note offers actionable steps for organizations to align their marketing practices with these principles, fostering responsible marketing that complies with both the…
Protecting Children’s Privacy Under POPIA: Insights from South Africa’s 2023 High School Results Case
South Africa’s Protection of Personal Information Act (“POPIA”) imposes strict requirements on processing personal information, especially that of children. Under South African law, a child is a natural person under the age of 18. Recent enforcement action against the Department of Basic Education (“DBE’) highlights the importance of obtaining parental consent and using privacy-respecting methods…
Africa Technology Regulatory Update: Adoption of the AfCFTA Protocol on Digital Trade
What has happened?
The African Continental Free Trade Area (“AfCFTA”) has emerged as a pivotal opportunity that will set the framework for future trade across Africa. Amid the prospects, one of the challenges has been the fragmented and diverse regulatory environment, coupled with regulators adopting policies that are not conducive for multinationals to make investments…
How the Biden Administration can Make AGOA More Effective
The African Growth and Opportunity Act (AGOA) has served as the cornerstone of the U.S.-Africa commercial relationship for more than two decades but it is set to expire on September 30, 2025. While the legislation’s unilateral trade preferences have provided economic benefits for countries across sub-Saharan Africa, AGOA as a whole remains underutilized. To ensure…
Overview of South Africa’s Draft National Data and Cloud Policy
If there is a silver lining to most crises, the accelerated move toward digitized commerce globally and in Africa may be one positive outcome of the COVID-enforced lockdown. It is welcome news there that the South African Minister of Communications and Digital Technologies (“Minister”) published the Draft National Data and Cloud Policy (in Government Gazette…
Africa Compliance Minute Series – Getting to the Root of the Problem: Considerations for Conducting an Effective Root Cause Analysis
Our Africa Anti-Corruption Practice has previously outlined key considerations for handling internal investigations and remediation of compliance issues in Africa. Here, we take a closer look at a particular aspect of remediation, the root cause analysis. After the dust settles on an investigation identifying misconduct, a root cause analysis can serve as the most effective…
Final Countdown to POPIA Compliance – Five Critical Steps to Take Before July 1st, 2021

In Episode 12 of our Inside Privacy Audiocast, together with special guest Advocate Pansy Tlakula, Chairperson of the Information Regulator of South Africa, we discussed the Information Regulator’s mandate, and the implementation of data protection legislation in South Africa. Now, with less than a month to go before South Africa’s Protection of Personal Information Act,…
Inside Privacy Audiocast: Episode 6 – View from Johannesburg Part II: Top Data Policy Trends to Look Out For in Africa
Recently, there has been a significant level of attention given to data protection and privacy matters on the Continent, and in the just the past year, we have seen new laws proposed or enacted in places like Nigeria, Egypt, Kenya, and of course South Africa, although prior to that, places like Morocco, Ghana and Mali…