South Africa’s POPIA grace period ends
The one-year grace period under South Africa’s Protection of Personal Information Act ends today, and full compliance is now required.
Insights for the Middle East and Africa.
The one-year grace period under South Africa’s Protection of Personal Information Act ends today, and full compliance is now required.
Kuwait’s telecoms and IT regulator CITRA approves a Data Privacy Protection Regulation for service providers, including 72-hour breach notification.
The Dubai International Financial Centre’s new GDPR-style Data Protection Law No. 5 of 2020 takes effect.
Kenya’s Data Protection Act 2019 comes into force, introducing GDPR-style obligations, registration and 72-hour breach notification.
Council of Europe Convention 108 and its Additional Protocol enter into force for Morocco, strengthening the country’s Law 09-08 data protection regime.
Bahrain’s Personal Data Protection Law No. 30 of 2018 comes into force.
Uganda’s Data Protection and Privacy Act 2019 commences, introducing registration, security safeguards and breach notification requirements.
Abu Dhabi’s Department of Health launches ADHICS, a mandatory information and cyber security standard for healthcare entities.
Israel’s Privacy Protection (Data Security) Regulations now set tiered security requirements for databases.
Mauritius’s GDPR-aligned Data Protection Act 2017 comes into force, with registration, DPIA and 72-hour breach notification requirements.
Researchers revealed Triton, malware built to tamper with industrial safety systems, after an incident at a Middle East facility.
Qatar becomes the first GCC state to issue a general data protection law, setting security, breach and transfer rules.