Legal & Risk: What Businesses Need to Watch
2026-06-13
This week’s news highlights two critical legal and compliance risks: property investment dynamics in South Africa and the regulatory challenges of large-scale corporate acquisitions. These stories often dominate economic headlines but often overlook the nuanced legal implications for businesses.
Source: [“Ultra-Rich Africans Piling into Property to Preserve Wealth, Standard Bank Says”](https://www.moneyweb.co.za/news/south-africa/ultra-rich-africans-piling-into-property-to-preserve-wealth-standard-bank-says/) — Moneyweb
South Africa’s property market is experiencing a surge in investment by ultra-wealthy individuals, a trend that raises red flags for tax compliance and anti-money laundering (AML) enforcement. Under the South African Companies Act 71 of 2008, foreign entities and high-net-worth individuals must disclose ownership structures and source of funds when acquiring property. Failure to comply risks penalties under the Criminal Procedure Act 51 of 1977 (Section 305, money laundering provisions).
Additionally, the Preservation of Assets Act 18 of 2016 (POPIA’s ancillary legislation) mandates that property transactions exceeding R10 million must be reported to the South African Revenue Service (SARS). Businesses acquiring land or real estate should review their due diligence protocols to ensure compliance with AML and tax reporting obligations.
Source: [“Blockworks Acquires Messari, Combining the Two Largest Crypto Data Platforms”](https://www.cityam.com/blockworks-acquires-messari-combining-the-two-largest-crypto-data-platforms/) — City AM (relevant contextual parallels).
While not directly related to the fiber acquisition, the growing emphasis on data consolidation highlights risks for businesses involved in mergers or acquisitions. In South Africa, the Companies Act 71 of 2008 requires approval from the Competition Commission for deals exceeding R1 billion, and POPIA mandates rigorous data protection assessments. For example, if Vodacom’s acquisition of Maziv involves processing personal data (e.g., customer information), the company must ensure data impact assessments and contractual data transfer clauses comply with POPIA’s Section 17 (processing of personal information).
In the UK, similar acquisitions would require alignment with the UK GDPR: cross-border data transfers must ensure adequate safeguards, and the Data Protection Act 2018 (DPA) imposes stricter penalties for non-compliance.
The upcoming SA gig economy regulations, hinted at in last week’s context, may mirror EU approaches under the Digital Services Act (DSA) and AI Act. Businesses relying on AI-driven workforce models (e.g., autonomous delivery systems or AI recruitment) must prepare for employment law reviews under the Labour Relations Act 66 of 1995 (LRA) and ensure AI systems do not violate fairness principles under the Employment Equity Act 55 of 1998.
---
Compliance Actions for CLOs
---
**
**
The gig economy regulatory context requires verification by a qualified attorney, as SA’s legislative trajectory is still evolving. Additionally, the interplay between POPIA and international data transfers in cross-border acquisitions needs further legal scrutiny. This analysis is not legal advice but a research aid for in-house CLOs.