Skip to content
Earn 20% commission referring clients to a real law firm Become an Affiliate →
SJNM & Co. Attorneys logoSJNM & Co. AttorneysOne Power Trio. Every Case Covered.
Regulatory & data compliance

Regulatory & Data Compliance

Compliance advisory and documentation across the frameworks that actually apply to South African businesses handling personal data, card payments, or customers abroad: POPIA, PCI DSS, GDPR (for EU customers or data), FICA, King IV, ISO 27001, Companies Act governance, and CCPA (for California customers).

What this involves

We assess which of these actually apply to your business, run a gap analysis against each, and produce the documentation a regulator, auditor, or acquiring bank will actually ask to see — not a generic template, but one built around how your business actually collects, stores, and moves data and money.

POPIA and GDPR overlap heavily but are not identical — a business serving both South African and EU customers needs a data protection approach that satisfies both regimes at once, including cross-border transfer rules, which we build as one coherent framework rather than two competing checklists.

PCI DSS applies to any business that stores, processes, or transmits card data, including via a third-party payment gateway — we advise on which PCI DSS SAQ (self-assessment questionnaire) level applies and what compensating controls and documentation your acquiring bank will expect.

FICA (Financial Intelligence Centre Act) duties — client due diligence, record-keeping, and suspicious transaction reporting — catch more businesses than expected, including estate agents, attorneys, and certain retailers, not just banks.

King IV is a corporate governance code, not a statute, but is treated as a compliance benchmark by JSE-listed entities, their suppliers, and increasingly by funders and B-BBEE verification agencies — we advise on applying it proportionately for a smaller or unlisted business rather than over-engineering it.

ISO 27001 (information security management) and the Companies Act's governance and record-keeping duties are frequently required by enterprise customers or investors as a precondition of doing business — we help build the policy and evidence trail needed to pass that due diligence.

How long does it take?

A gap analysis is usually completed within 2 to 3 weeks. The resulting documentation pack typically follows within a further 3 to 6 weeks, depending on scope.

What will it cost?

R18 000 to R45 000 excl. VAT

Covers: Gap analysis across the frameworks that apply to your business.

Based on 12 to 30 hours of Attorney time at our rate of R1 500 per hour, excluding VAT.

This is an estimate, not a quote. The final fee depends on the facts and how complex your matter turns out to be, and your Attorney confirms it in writing before work starts. Court fees, sheriff’s fees, counsel and other disbursements are charged separately.

Ask for a firm quote

This page is general information, not legal advice for your situation. See our Disclaimer.

How it works

  1. Tell us

    Send a short message, WhatsApp us or call. No account and no documents needed to start.

  2. An Attorney reviews

    A named, admitted Attorney reads your situation and explains your options and costs plainly, including when this is not the right route.

  3. We act, you stay informed

    We prepare the work, the Attorney signs off before anything is filed or sent, and you are kept up to date throughout.

Ask about Regulatory & Data Compliance

Prefer to write? Tell us what is going on and we will reply by email. If it is urgent, say so.