Legal & Risk: What Businesses Need to Watch
2026‑09‑03
When headlines roar about new solar parks or a revamped pay‑TV lineup, most business leaders instinctively focus on revenue potential. Few stop to ask whether the regulatory gears behind those moves have been put in place. Below are three stories from this week that reveal hidden legal and compliance traps.
---
Teraco used 399 GWh of electricity in 2025, tripling its 2021 figure – a jump that signals aggressive industrial scaling and a new solar facility slated for next year【Teraco's electricity consumption triples in four years】(https://techcentral.co.za/teraco-energy-consumption-sediba-solar/285665/) — TechCentral.
Large power take‑off (PTO) triggers regulatory reporting under the Electricity Regulation Act and the National Energy Regulator of South Africa’s (NERSA) obligations to verify that suppliers can meet the increased load. Failure to submit updated consumption forecasts may expose Teraco to penalties or forced load shedding.
Moreover, the rapid rise in demand often outpaces the statutory Renewable Energy Targets, potentially breaching commitments under the Renewable Energy Independent Power Producer Procurement Programme (REIPPPP). If the new solar facility is not integrated correctly, Teraco could face claims for non‑compliance that affect its creditworthiness and investor relations.
---
The Information Regulator has logged over 8,000 cybersecurity breaches, underscoring a massive data‑protection crisis in SA【Personal information of millions of South Africans exposed in 8,000 data breaches】(https://mybroadband.co.za/news/security/665532-personal-information-of-millions-of-south-africans-exposed-in-8000-data-breaches.html) — MyBroadband.
Under the POPIA Act 4 of 2013, any breach that compromises personal information must be reported to the Information Regulator within a specified timeframe (often 72 hours). Many companies mistakenly believe only large breaches require notification, overlooking that even minor incidents involving sensitive data trigger a reporting duty.
Additionally, POPIA imposes fines up to R5 million per contravention and requires organisations to maintain records of all processing activities. Failure to do so can lead to significant financial penalties and reputational damage, especially for entities handling high volumes of personal data such as telecoms or e‑commerce platforms.
---
The upcoming overhaul of DStv’s pay‑TV packages, especially the removal of sports licensing “bandages,” signals a shift in content pricing and distribution【Looming DStv package overhaul finally rips the sports bandage off】(https://www.moneyweb.co.za/news/companies-and-deals/looming-dstv-package-overhaul-finally-rips-the-sports-bandage-off/) — Moneyweb.
When a provider restructures packages, it must re‑negotiate all content licence agreements. The terms of existing contracts may not automatically carry over to new bundles, exposing DStv to breach claims from rights holders if the new arrangements fall short of contractual obligations or statutory minimums.
The Consumer Protection Act (CPA) also mandates transparent pricing and accurate representation of bundled services. A sudden price hike or omission of promised channels can trigger consumer protection investigations and lead to fines up to R500,000 per offence.
Finally, cross‑border distribution – for example streaming DStv content to the EU – raises EU Audiovisual Media Services Directive compliance issues such as localised advertising quotas and children’s content safeguards that must be re‑checked in light of the new package structure.
---
Each headline may appear to be a commercial win – an expansion of solar capacity, a surge in user data, or a refreshed content lineup. Yet the underlying regulatory frameworks and statutory obligations can quietly erode those gains if left unaddressed. A vigilant CLO should interrogate every growth story with questions about reporting, licensing, and data‑protection responsibilities before executives cheer.
**
**
The interpretations above are preliminary work product and rely on publicly reported facts. They do not constitute legal advice. For definitive guidance, particularly regarding NERSA filings, REIPPPP compliance, or POPIA breach notification timelines, please engage qualified counsel who can review the specific contractual language and operational details of your business.
---
Sources