
South African business legislation, from data protection to anti-money laundering requirements to tax administration, is periodically amended, and treating any compliance summary, including this one, as permanently current is how a business ends up unknowingly non-compliant with a requirement that changed after the article was written.
Build this into an ongoing habit rather than a once-off compliance check.
Data protection compliance is reviewed and amended periodically
The Protection of Personal Information Act and its regulations are periodically reviewed and amended, and a business handling personal information needs to check its current compliance position against the Information Regulator’s current guidance, not an earlier summary.
Any business collecting customer data through marketing, loyalty programmes or online forms should treat this as an ongoing compliance area to actively monitor, not a box ticked once.
Financial and anti-money laundering requirements evolve too
Anti-money laundering and counter-terrorist financing requirements affect a broader range of businesses than commonly assumed, particularly those handling client funds or acting as accountable institutions under the relevant legislation, and amendments to this framework happen periodically.
Confirm your specific obligations directly with the Financial Sector Conduct Authority if your business handles client funds or falls into a regulated category.
Build a genuine habit of checking, not a once-off review
Set a regular schedule, quarterly or biannually, to check for compliance updates relevant to your specific sector, rather than only reacting when a problem or a specific news story prompts it.
A professional adviser, accountant or attorney who tracks these changes as part of their own practice is often a more reliable ongoing source than self-directed monitoring alone, particularly for a business without dedicated compliance capacity.
Treat any specific compliance article as a starting point
Confirm any specific requirement mentioned in an article, including this one, against the current legislation or the relevant regulator’s own published guidance before relying on it for a real compliance decision.
Our guide to compliance certificates a business actually needs covers the broader category-based approach to compliance, worth revisiting periodically as regulations shift.
Frequently asked questions
Does legislation stay fixed once summarised in an article?
No. It’s periodically reviewed and amended, so any summary, including this one, should be treated as a starting point, not a permanent reference.
Which areas of compliance change relatively often?
Data protection requirements and anti-money laundering and counter-terrorist financing regulations are both periodically amended.
Who needs to worry about anti-money laundering requirements?
A broader range of businesses than commonly assumed, particularly those handling client funds or classified as accountable institutions.
How often should compliance updates be checked?
On a regular schedule, quarterly or biannually, rather than only reactively when a problem or news story prompts it.
Should a professional adviser be used to track compliance changes?
Often worth it, particularly for a business without dedicated compliance capacity, since it’s part of an adviser’s own ongoing practice.
Further reading
Originally published in 2025. Updated September 2026 into guidance on building an ongoing habit of tracking compliance changes, rather than a fixed year-specific update.
