Search legal guides

Search MJ Kotze Inc legal guides and articles

Regulatory compliance · South Africa

Regulatory compliance

The regulatory regimes South African businesses actually have to get right — explained plainly, backed by the words of the Act, the Regulations and the regulators’ own guidance.

  • Every claim cited to the Act
  • Position as at June 2026
  • Written by a practising attorney
Quick answer

Why this hub exists

Most South African business owners discover their compliance obligations the hard way — a bank requests FICA documents, a customer demands a refund, the Information Regulator opens its reporting portal, or a deal stalls because a beneficial-ownership filing is missing. Each of these belongs to a different statute, with a different regulator and a different deadline, and the rules are widely misunderstood.

This hub brings those regimes together. Each topic states the legal position plainly, then backs it with the exact words of the Act, the Regulations or the regulator’s own guidance — so you can check every claim against the source. Two regimes are deep enough to have their own hubs: FICA and POPIA. The rest are explained here, with cross-links to the Finance & Credit Law hub for the National Credit Act and to our corporate guides where they overlap.

The complete cluster · 9 topics

Explore the hub

The regulatory regimes South African businesses actually have to get right — grouped by theme. Each links to a plain-language guide backed by the words of the Act, or to the full hub where one already exists.

Financial crime & AML

2 topics

Data & digital

3 topics

Consumer & market conduct

2 topics

Corporate governance & empowerment

2 topics

Common questions

Frequently asked questions

  • Most businesses must deal with several at once: POPIA (data protection) and PAIA (an access-to-information manual) apply to virtually everyone; the Consumer Protection Act applies to anyone selling to the public; ECTA applies if you sell online; and FICA applies to listed “accountable institutions”. Companies also carry ongoing Companies Act and beneficial-ownership duties.

  • FICA is anti-money-laundering law: “accountable institutions” must verify clients, identify beneficial owners, keep records and report suspicious activity. POPIA is data-protection law: it governs how any responsible party may lawfully collect, use, store and share personal information. Many businesses must comply with both.

  • Yes. Since the small-business exemption lapsed on 31 December 2021, every “private body” — every company, close corporation, trust running a business, partnership and sole proprietor — must have a PAIA manual available, and the Information Regulator requires private bodies to lodge an annual report.

  • Chapter VII of the ECT Act requires an online supplier to disclose a defined list of information before checkout (identity, address, full price, delivery time, return policy and more), to let the customer review and correct the order, and to honour a seven-day cooling-off right on most goods and services.

  • They vary by regime — from administrative penalties and infringement notices (POPIA fines up to R10 million; FICA penalties from the Financial Intelligence Centre) to criminal liability for directors and, under the Consumer Protection Act and Competition Act, turnover-based fines. Most regulators escalate: a notice to fix first, a fine if it is ignored.

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Work with an attorney

Get compliance right for your business

From a focused compliance health-check to a full programme, Martin Kotze gives practical advice grounded in the Acts — not box-ticking. This hub is general guidance, not advice on your specific facts.