As businesses collect, process and commercialise increasing volumes of personal information, data privacy and information governance have become important legal and commercial considerations. South Africa’s Protection of Personal Information Act (POPIA) places significant obligations on organisations regarding how personal information is collected, used, stored, shared and protected.
O’Reilly Law advises businesses on data privacy, POPIA compliance and the lawful processing of personal information. We work with companies ranging from technology businesses and startups to established corporates, helping them develop practical privacy frameworks that support their commercial activities while managing regulatory and contractual risk.
Our lawyers assist clients with POPIA compliance programmes, privacy policies, data processing agreements, operator agreements, cross-border data transfers, direct marketing, information security obligations and responses to data breaches. We also advise businesses developing digital platforms, SaaS products and technology solutions where personal information forms an integral part of the product or service.
Compliance with POPIA extends beyond having a privacy policy on a website. Businesses should understand what personal information they process, the purposes for which it is used, where it is stored, who has access to it and the circumstances in which it is shared with third parties.
We assist clients in assessing their existing data practices and implementing proportionate legal and governance measures, including POPIA compliance assessments, information officer requirements, internal policies, consent mechanisms, contractual protections and data retention practices.
For technology businesses, privacy considerations often intersect with software licensing, SaaS agreements, cloud services, intellectual property and commercial contracting.
We advise technology companies on allocating responsibility for personal information between customers, service providers, operators and other third parties, including through appropriately drafted Data Processing Agreements (DPAs), operator provisions and cross-border data arrangements.
Businesses increasingly use international cloud infrastructure, service providers and group companies to process information across multiple jurisdictions.
Our lawyers advise on cross-border transfers of personal information under POPIA, including contractual arrangements with overseas service providers and the interaction between South African privacy requirements and international data protection frameworks.
A data breach can create regulatory, contractual and reputational consequences for a business. We assist clients in assessing suspected security compromises, determining their obligations under POPIA and managing communications with affected parties, service providers and the Information Regulator where required.
Give us a call at 021 9488 273, request a Zoom chat or send us an email at info@oreillylaw.co.za, for more info.
"*" indicates required fields

Director
Corporate & Commercial Law
Litigation & Dispute Resolution

Senior Associate
Property Law
Corporate & Commercial Law

Director
Property Law
Corporate & Commercial Law

Associate
Litigation & Dispute Resolution

Associate
Property Law
Corporate & Commercial

Consultant
Corporate & Commercial Law

Consultant
Corporate & Commercial Law

Consultant
Corporate & Commercial Law