Compliance Lawyers in Midrand

Burger Huyser Attorneys provides regulatory-compliance legal support to Midrand-based businesses through its Midrand branch at Waterfall Crescent South, Waterfall Office Park, Bekker Road, Vorna Valley (010 022 4082), with files run through the firm’s commercial law practice. The service covers the four compliance pillars South African businesses most often face: the Companies Act 71 of 2008, the Consumer Protection Act 68 of 2008, the Protection of Personal Information Act 4 of 2013 (POPIA) and, for accountable institutions, the Financial Intelligence Centre Act 38 of 2001 (FICA). The work typically starts with a compliance gap analysis at the Midrand office, after which the firm drafts or remediates the required policies, contracts and internal manuals, and assists with regulator engagement where the Financial Intelligence Centre (FIC) or the Information Regulator opens a file.
Why Engage a Specialist Compliance Lawyer in Midrand
South African compliance is a multi-statute patchwork, and a single Midrand business can be answerable to several regulators at once depending on its sector and data footprint. The Companies Act, the Consumer Protection Act, POPIA, FICA and the National Credit Act each carry separate duties, separate timelines and separate enforcement bodies, and coordinating them through one adviser is materially easier than running parallel tracks through separate consultants.
Compliance failures also expose directors personally. Penalties under FICA include administrative fines and imprisonment for responsible individuals who fail to report suspicious transactions, and POPIA enforcement carries administrative fines and potential civil liability for non-compliant processing of personal information. A Midrand-based commercial lawyer with FICA experience is doubly relevant because the firm itself is an “accountable institution” under FICA and walks the same KYC and suspicious-transaction-reporting path it advises clients on — so the advice is delivered from inside the regime rather than from outside it.
Compliance drafted reactively, after a regulator has written a query letter, costs materially more than compliance drafted proactively as part of the business’s standing operating procedures. Burger Huyser’s commercial-law practice in Midrand is set up to take compliance instructions at the gap-analysis stage, before a regulator’s letter arrives.
The Regulatory Framework: What a Midrand Business Is On the Hook For
The table below summarises the five core statutes most Midrand businesses need to consider, and the principal document or operational layer each one touches.
| Statute | What it governs | Key document or process |
|---|---|---|
| Companies Act 71 of 2008 | Running of every registered South African business; director duties, MOI, beneficial-ownership transparency, shareholder rights | Memorandum of Incorporation, shareholders’ agreement, director records, CIPC filings |
| Consumer Protection Act 68 of 2008 (CPA) | How businesses interact with consumers; marketing, plain-language disclosure, returns, supplier agreements | Terms of sale, returns and refund policy, supplier agreements |
| Protection of Personal Information Act 4 of 2013 (POPIA) | Processing of personal information of identifiable natural and juristic persons; binds most businesses that hold customer, supplier or employee data | Privacy policy, data-processing agreements, website terms, breach-response protocol |
| Financial Intelligence Centre Act 38 of 2001 (FICA) | Core AML framework; imposes KYC, ongoing monitoring, record-keeping and suspicious-transaction reporting on accountable institutions including attorneys, estate agents, dealers in high-value goods and certain financial services providers | Risk-based KYC framework, accountable-institution onboarding procedures, FIC reporting protocol |
| National Credit Act 34 of 2005 (NCA) | Applies to credit providers, credit bureaus and intermediaries; governs credit agreements, affordability assessments and consumer credit disclosures | Credit agreements, affordability assessments, credit-provider disclosure |
Sector overlays apply on top of the core framework. FSCA-registered entities carry additional conduct-of-business obligations under the Financial Sector Regulation Act 9 of 2012, while healthcare, pharmaceutical and engineering sectors carry their own statutory councils and licensing regimes. A compliance engagement for a Midrand business typically begins with a gap analysis that identifies which of these statutes and overlays actually bind the entity, before any drafting work begins.
What the Service Covers (Scope of Engagement)
A Midrand compliance engagement through Burger Huyser runs across seven workstreams:
- Compliance gap analysis — a structured review of the client’s current contracts, policies and procedures against the applicable statutory pillars (Companies Act, CPA, POPIA, FICA, NCA).
- Companies Act compliance — drafting or reviewing the Memorandum of Incorporation, shareholders’ agreements, and director-duties and records documentation.
- POPIA compliance — privacy policies, social-media policies, website terms and conditions, email disclaimers, and data-processing and data-sharing agreements.
- FICA compliance — risk-based KYC frameworks, accountable-institution onboarding procedures, suspicious-transaction-reporting protocols, and FIC engagement where a report has been filed.
- CPA and NCA compliance — consumer-facing terms of sale, returns and refund policies, supplier agreements, and credit-provider documentation where the NCA applies.
- Internal policies and manuals — compliance summaries, internal compliance manuals, training notes, and a compliance calendar tracking licence renewals, filings and review dates.
- Regulator engagement — responding to FIC, Information Regulator or sector-specific queries, preparing representations, and managing follow-up remediation.
Why Compliance Work Lands in the Midrand Commercial Practice
Burger Huyser’s commercial law department drafts and reviews contracts, shareholders’ agreements, lease agreements and company-registration documents as a core part of the practice, so compliance sits naturally on top of that drafting layer rather than as a separate silo. J’Retha van Rensburg, specialist consultant for Commercial Law & Contracts, supports the firm’s compliance-advisory work alongside the partner-grade attorneys running the commercial files. The firm holds the Commercial Law Firm of the Year 2025 — South Africa award (5 Star Lawyers Awards 2025), which is useful as a trust signal for commercial clients evaluating a compliance engagement.
Typical Midrand Compliance Scenarios
Five recurring scenarios drive compliance instructions at the Midrand office:
- A Midrand estate agency handling a property transaction with a foreign buyer where source-of-funds documentation is required — compliance counsel assists with KYC file preparation and, if applicable, FIC reporting on cash deposits that meet the threshold.
- A Midrand-based business that has received a query letter from the Information Regulator or the FIC and needs a formal response, remediation plan and representation.
- A growing professional services firm onboarding its first POPIA privacy policy, social-media policy, website terms and email disclaimers as part of a standing compliance pack.
- A property or investment entity taking funds from a high-risk offshore counterparty, requiring enhanced due diligence and beneficial-ownership documentation that goes beyond the standard KYC pack.
- An established Midrand business opening a new line of business (for example moving into cashless payments or cross-border supply) that triggers fresh FICA, POPIA and CPA obligations.
What to Look for When Choosing a Midrand Compliance Lawyer
When selecting a compliance adviser in Midrand, the criteria that actually matter are:
- Sector-relevant experience — the lawyer should be familiar with the specific statutes that bind your business, not just generic commercial-law work.
- POPIA and FICA in one practice — many businesses need both, and coordinating them through one firm rather than two separate advisers avoids policy conflicts and duplicate KYC work.
- Director-grade accessibility — compliance escalations and regulator queries should run through a partner, not a candidate attorney.
- Local Midrand presence — in-person compliance reviews at the client’s premises are easier with a Midrand-based firm than a Sandton-only one.
- Plain-language cost conversation — fees should be quoted after the scope is clear, not estimated loosely up front.
Burger Huyser’s Midrand branch meets that profile: the office is staffed to take compliance instructions directly, J’Retha van Rensburg supports the commercial-law and compliance-advisory work as specialist consultant, and partner-grade attorneys run the commercial files end-to-end.
Practical Considerations: Cost, Timeline, What to Bring
The table below sets out the practical levers a Midrand business should plan around when scoping a compliance engagement:
| Lever | What to expect |
|---|---|
| Cost | Compliance work is typically scoped after an initial gap analysis. Burger Huyser quotes per engagement rather than on an hourly-only basis, with the scope of the gap analysis confirmed at the Midrand branch intake meeting. |
| Timeline | A straightforward policy-pack engagement (POPIA plus standard commercial contracts) typically takes a few weeks from kick-off. A full multi-statute compliance review with internal manuals runs longer depending on the size of the business. |
| What to bring | Existing MOI, shareholders’ agreement, current contracts (SLAs, provider agreements, lease agreements, sale-of-goods terms), current policies (if any) covering privacy, social media and website terms, and any prior correspondence with the FIC or Information Regulator. |
Local Filing Layer: Why the Midrand Branch Is the Right Intake Point
Compliance work is regulator-driven rather than court-driven, so there is no “Compliance Court” in Midrand to mistake for the correct forum — the controlling reference points are the Financial Intelligence Centre at fic.gov.za for FICA and the Information Regulator for POPIA. What matters in practice is the layer underneath the legal advice: the ability of the firm’s commercial lawyers to attend the client’s premises for the initial gap analysis, to hold follow-up document reviews in person rather than only by email, and to coordinate across the company’s directors, bookkeeper and existing professional advisers without a long Gauteng drive-time between meetings.
Burger Huyser Attorneys’ Midrand branch is set up for exactly that pattern of work — Waterfall Crescent South, Waterfall Office Park, Bekker Road, Vorna Valley, 1686 (010 022 4082, mobile 064 555 3358, after-hours 077 274 1932) — with the commercial-law practice running compliance files from the office alongside the firm’s other Midrand work. Businesses based further out along the Waterfall / Bekker Road corridor — Centurion to the north-east, Randburg to the south-west — can also use the Midrand office as the practical intake point, and the firm’s other Gauteng branches handle overflow work where a closer-to-home consultation is more convenient.
Frequently Asked Questions
What does a compliance lawyer in Midrand actually do?
A compliance lawyer reviews a business’s contracts, policies and operating procedures against the South African statutes that bind it — typically the Companies Act, the Consumer Protection Act, POPIA and, for accountable institutions, FICA — and drafts or remediates the documents needed to bring the business into compliance. The work also covers regulator engagement where the FIC, the Information Regulator or another body opens a file.
Does my Midrand business need a POPIA policy if I’m not in financial services?
Yes. POPIA applies to any business that processes personal information of identifiable natural or juristic persons, which captures most operating businesses regardless of sector. The Information Regulator’s enforcement focus has broadened beyond financial services into retail, hospitality, online services and the professional-services sector.
Is Burger Huyser itself subject to FICA?
Yes. South African attorneys are accountable institutions under FICA and are required to perform KYC, keep records and report suspicious transactions to the FIC. This is useful context for clients — the firm advises on FICA from inside the regime rather than from outside it.
What happens if the FIC writes to my Midrand business?
A FIC query letter should be treated as time-sensitive. The Information Regulator’s and the FIC’s enforcement timelines are short, and an inadequate response can convert an administrative query into a formal investigation. Engaging legal counsel at the Midrand branch allows for a coordinated response that compiles the requested records, makes representations on the client’s behalf and, where appropriate, engages on remediation steps.
Where is the Burger Huyser Midrand branch, and what are the hours?
Waterfall Crescent South, Waterfall Office Park, Bekker Road, Vorna Valley, Midrand, 1686. Telephone 010 022 4082, mobile 064 555 3358, after-hours 077 274 1932. Open Monday to Friday during standard business hours.
How is compliance work scoped and quoted?
Burger Huyser scopes compliance work after an initial gap analysis at the Midrand branch. The gap analysis identifies the statutes and documents in scope, after which the firm provides a fixed or capped fee for the drafting and remediation work, with separate fees quoted for ongoing retainer and regulator-engagement work where the client wants a standing arrangement.
If your Midrand-based business needs a compliance lawyer to review FICA, POPIA, Companies Act or CPA obligations, contact Burger Huyser Attorneys’ Midrand branch on 010 022 4082 (mobile 064 555 3358, after-hours 077 274 1932) or visit the office at Waterfall Crescent South, Waterfall Office Park, Bekker Road, Vorna Valley, Midrand, 1686. Compliance files are run through the firm’s commercial law practice, with the Midrand office coordinating initial gap analyses, document drafting, internal-policy work and any regulator engagement that follows. Bring the existing MOI, current contracts (SLAs, provider agreements, lease agreements, sale-of-goods terms), existing privacy and social-media policies, and any prior FIC or Information Regulator correspondence to the first meeting. The firm carries a 4.8/5 average across 250+ Google reviews (Trustindex verified “Top Rated Law Firm in South Africa”) and holds the Commercial Law Firm of the Year 2025 — South Africa award (5 Star Lawyers Awards 2025), with compliance work supported by the firm’s commercial-law specialist consultant J’Retha van Rensburg alongside the partner-grade attorneys running the commercial files.
General Information Disclaimer: This article describes Burger Huyser Attorneys’ compliance-advisory service offering in Midrand under the Companies Act, Consumer Protection Act, Protection of Personal Information Act, Financial Intelligence Centre Act and related South African legislation. It is general information, not legal advice for a specific business — compliance obligations vary by sector, by data footprint and by the specific contracts and policies already in place. Businesses should confirm current requirements, sector overlays and any Information Regulator or FIC guidance directly with the relevant regulator (fic.gov.za, gov.za) before relying on this article to discharge a specific duty.
NEED TOP LEGAL SUPPORT IN SOUTH AFRICA? CONTACT OUR LAWYERS TODAY.
Contact our team of experienced law attorneys at Burger Huyser Attorneys to assist you in all matters and procedures.
CONTACT DETAILS

