In February 2024, I sat in a room at the National Conference on the Integrated Criminal Justice System, hosted by the Department of Justice in Johannesburg, South Africa. Deputy President Mashatile delivered the keynote. The room was full of judges, ministers, and law reform commissioners. When someone proposed using AI for bail hearings, the room responded with excitement.
I responded with questions. Who built this system? What data was it trained on? What happens to our biometric information when it leaves the country? Do we have the regulatory framework to govern what we are about to adopt?
Nobody had clean answers. And that is the landscape I work in every day: a world where technology moves first, and governance catches up later. In South Africa, that gap is not abstract. We recorded 1,607 data breaches in just six months of 2025[1], a 60 percent increase from the previous year. The Cell C ransomware breach exposed customer ID numbers and financial data[2]. A ransomware group exfiltrated 3.8TB from Gauteng provincial systems in 2026[3]. The threat is not coming. It is here.
I moved into security because of protection. Not in an abstract sense, but the practical kind: understanding what it means when data is compromised, when a contract has a gap, when a company signs something it does not fully understand. My legal training gave me the ability to see the damage. My security work gives me the tools to prevent it.
The clearest point of intersection is the contract. Every MSA, BAA, or NDA carries assumptions about data: who holds it, who can access it, and who is liable if it is compromised. I have reviewed enough agreements to know that most businesses sign them without auditing the technical reality behind the legal language. That misalignment is not a drafting problem. It is a security failure sitting inside a legal document.
South Africa’s POPIA amended regulations, which came into force in April 2025[4], tightened direct marketing consent requirements and expanded the Information Regulator’s enforcement powers. The FSCA and Prudential Authority Joint Standard on Cybersecurity took effect in June 2025[5], placing explicit compliance obligations on financial institutions. These are not distant frameworks. They are active obligations that require both legal understanding and technical implementation to meet.
Working alongside Doug Wendt in client negotiations, and under the guidance of Stephanie Thesie in operations, I have come to understand that compliance and contracts do not exist in isolation from finance and operations. A contract carries weight that must be understood in full. The moment you see that, law and security stop being separate disciplines and become the same responsibility.
The most common mistake is treating compliance as an event. A business achieves ISO 27001 or passes a SOC 2 audit and considers the work done. It is not done. That is the starting point.
South Africa currently has no standalone AI law[6]. The draft National AI Policy was withdrawn after it was found to contain AI-hallucinated citations[7]. A revised framework is not expected before early 2027[8]. Businesses that wait for legislation to govern their AI adoption will spend years catching up to those who governed themselves.
Inside CRM environments, the risk is concentrated. AI features that touch contact data and communication history are data processing activities with legal implications under POPIA. When those features are adopted without review, without data processing agreements, without security assessment, the exposure is real and immediate.
Three things. First, treat security and legal compliance as a single function. The contracts you sign must reflect the controls you actually have in place. Second, build a verifiable security posture. Transparency is a competitive advantage. Third, choose partners who govern technology, not just implement it.
At Wendt Partners, a HubSpot Elite Solutions Partner operating under SOC 2 and ISO/IEC 27001 certification, we sit at that intersection by design. With a dedicated legal and compliance function and a verifiable security posture, governance is embedded in how we operate. Our Trust Center at trust.wendtpartners.com reflects that commitment. Security is not something we added. It is how we were built.
1. Werksmans Attorneys (2026). Code Red to Code Regulated: South Africa’s Data, AI and Cybersecurity Shift in 2025.
2. Apliso Plus (2026). Prevent Data Breaches and Compliance Risks for South African Businesses in 2026.
3. Apliso Plus (2026). Prevent Data Breaches and Compliance Risks for South African Businesses in 2026.
4. Werksmans Attorneys (2026). POPIA Amended Regulations: Key Changes Effective April 2025.
5. Werksmans Attorneys (2026). FSCA and PA Joint Standard on Cybersecurity and Cyber Resilience Requirements.
6. Michalsons (2026). South African AI Policy: Guidance and Overview.
7. African Law Business (2026). SA Confirms Review of National AI Policy.
8. Michalsons (2026). South African AI Policy: Implementation Timeline.
Legal matters: legal@wendtpartners.com
Security posture: trust.wendtpartners.com
About Bernice Kapinga
Bernice B. Kapinga is the Technology, Security, Contracts & Compliance Manager at Wendt Partners, where she leads work across legal operations, information security, governance, contracts, and compliance. She holds an LLB from the University of South Africa, has postgraduate training in cybersecurity, and played a key role in Wendt Partners achieving its third consecutive year of ISO/IEC 27001 certification. She is also an Associate Member of the Institute of Internal Auditors South Africa and is pursuing the Certified Internal Auditor (CIA) designation.
Connect with Bernice on LinkedIn