Compliance Lawyers in Pretoria

Updated: August 2, 2026
Reading Time: 13 min

Compliance lawyers in Pretoria advise businesses on the regulatory framework they operate under — principally the Companies Act 71 of 2008, the Consumer Protection Act 68 of 2008 (CPA), the Protection of Personal Information Act 4 of 2013 (POPIA), and the Promotion of Access to Information Act 2 of 2000 (PAIA) — and assist with the day-to-day document and policy work that keeps a business compliant. That work covers Memorandum of Incorporation (MOI) reviews, shareholder-agreement audits, service-level-agreement vetting, privacy-policy drafting, internal compliance-manual development, and the annual PAIA report lodgement through the Information Regulator’s e-Services portal. Most compliance mandates do not end in litigation; they are handled through proactive review, policy drafting, and risk-flagging before a breach, complaint, or regulator inspection occurs.

Why a Pretoria Business Needs a Compliance Lawyer

Statutory duties in South Africa are not optional. The Companies Act, CPA, POPIA, and PAIA each impose filing, policy, and reporting obligations on businesses regardless of size or sector, and the regulators that enforce them — the Information Regulator for POPIA and PAIA, the National Consumer Commission for the CPA, and the Companies and Intellectual Property Commission (CIPC) for the Companies Act — all operate from Pretoria. A registered entity that processes personal information, sells to consumers on standard terms, extends credit, or receives access-to-information requests is on the hook for compliance under at least one of these statutes, and often several at once.

Non-compliance carries real downside. POPIA enforcement can attract administrative fines up to R10 million. The National Consumer Commission can hand down administrative penalties under the CPA. CIPC non-compliance findings can attract director-duty scrutiny under the Companies Act. Most of those consequences are avoidable, because the bulk of compliance work is preventive — most issues are caught and resolved during a document review (MOI, shareholders’ agreement, SLAs, privacy policies) before they escalate into a complaint, regulator query, or dispute.

A Pretoria-based compliance lawyer who knows the local business landscape and the regulators based in the capital can also flag sector-specific obligations — municipal bylaws, industry licensing, accountable-institution status under FICA — that generic advisory tends to miss. Burger Huyser’s Pretoria (Menlyn) branch is set up to handle exactly this kind of regulator-facing work for businesses operating in and around the Tshwane metro, from Menlyn and Hatfield through Centurion and into the surrounding Gauteng corridor.

What a Compliance Lawyer Does (Scope of Engagement)

Compliance instructions usually fall into one of three engagement buckets — a one-off document or filing, a defined project, or an ongoing retainer — but the underlying scope of work is consistent across them.

Document and policy review

  • Memorandum of Incorporation (MOI) reviews, or Memorandum of Association where no MOI exists.
  • Shareholders’-agreement audits against current regulatory requirements.
  • Service-level-agreement, lease-agreement, and sale-of-goods contract vetting.

Compliance gap analysis

  • Auditing existing agreements and policies against the current Companies Act, CPA, POPIA, PAIA, NCA, and FICA framework.
  • Flagging exposure and recommending remediation steps.

Policy and manual drafting

  • Privacy policies, social-media policies, website terms and conditions, and email disclaimers.
  • Internal compliance manuals, FICA frameworks for accountable institutions, and supplier/provider-agreement templates.

Statutory filings and lodgements

  • Annual PAIA reports via the Information Regulator’s e-Services portal.
  • CIPC filings for Companies Act compliance, including B-BBEE ownership-structuring work where a transaction alters the scorecard.

Retainer or ongoing advisory

  • Monthly retainer arrangements that cover recurring compliance work — policy upkeep, contract vetting, and ad hoc queries — for businesses that want predictable legal support without an in-house compliance function.

Breach response

  • First-response legal advice when a POPIA breach, a CPA complaint to the National Consumer Commission, or a regulator query has already landed.

The firm’s commercial-law practice runs these instructions out of the Pretoria branch, which means the same attorney who drafts a privacy policy can step into a breach-response matter without the handover delays that come from moving between departments.

The Core Regulatory Framework That Drives Compliance Work

The statutes below are the ones that shape most day-to-day compliance briefs in the Pretoria market. They are national in scope, but the relevant regulators and filing infrastructure sit in the capital — which is part of why a Pretoria-based attorney is well placed to handle the work.

Statute What it requires Typical compliance work
Companies Act 71 of 2008 MOI, shareholder records, director duties, CIPC filings MOI reviews, shareholders’-agreement audits, director-duty advice, CIPC filings
Consumer Protection Act 68 of 2008 (CPA) Fair dealing, supplier accountability, marketing standards SLA reviews, sale-of-goods contract vetting, customer-facing terms and conditions
Protection of Personal Information Act 4 of 2013 (POPIA) Lawful processing of personal information, security safeguards, breach notification Privacy-policy drafting, data-flow audits, breach-response protocol design, staff training
Promotion of Access to Information Act 2 of 2000 (PAIA) Section 14 manuals on records held; annual reports to the Information Regulator from public and private bodies PAIA-manual compilation, Section 32 manual updates, annual report lodgement via the Regulator’s e-Services portal
National Credit Act 34 of 2005 (NCA) Consumer-credit agreements, reckless-lending assessment, registration of credit providers Credit-provider agreement vetting, registration renewals, affordability-assessment compliance
Financial Intelligence Centre Act 38 of 2001 (FICA) KYC, suspicious-transaction reporting, accountable-institution registration Internal FICA frameworks, accountable-institution registration support, RMCP drafting
B-BBEE (commercial-compliance overlay) Ownership, management and skills-development targets that drive procurement and tender eligibility B-BBEE ownership-structuring advice; restructuring work where a transaction alters the scorecard

The Annual Compliance Trigger: PAIA Reporting Via the Information Regulator

The most date-specific, recurring compliance trigger for Pretoria-based businesses is the annual PAIA report. Both public and private bodies must lodge the report through the Information Regulator’s e-Services portal regardless of sector or size, and the annual lodgement window closes in late June each year — the 2025/26 window was scheduled to close on 30 June 2026. Missing the deadline is not treated as a soft administrative miss: the Information Regulator treats non-lodgement as a compliance finding on inspection.

Work that runs alongside the report itself includes Section 14 PAIA-manual compilation, decision-matrix documentation (which categories of request are granted or refused, and why), updating the contact details for the Information Officer, and lodging any prior-year backlogs. The annual lodgement usually pairs naturally with broader POPIA advice on personal-information processing, because once the information-governance framework is being reviewed the privacy policy, the data-flow register, and the breach-response protocol all sit on the same desk.

Compliance in Pretoria: Filings Through the Information Regulator and CIPC

Pretoria is the administrative capital and the seat of several national regulators whose filings intersect with everyday compliance work — the Information Regulator (PAIA reports and POPIA complaints), the Companies and Intellectual Property Commission (Companies Act filings), and the National Consumer Commission (CPA complaints) all operate from this jurisdiction. For businesses operating in and around Pretoria this is usually a logistical plus: compliance advice can be handled by Pretoria-based attorneys and filings made without crossing provinces, and the underlying procedures work the same way whether the business is based in Menlyn, Hatfield, Centurion, or the broader Tshwane metro.

Burger Huyser Attorneys maintains a Pretoria branch at Unit 4, 1st Floor, Block 5, Glen Manor Office Park, 138 Frikkie De Beer Street, Menlyn, Pretoria, 0063, telephone 012 471 5700, with after-hours mobile 064 548 4838, open Monday to Friday 7:30am to 4:30pm. The firm is a member of the Pretoria Attorneys Association and fields commercial-law and contract instructions from the Menlyn office — the practice area compliance work sits under.

What to Look for When Choosing a Compliance Lawyer

The right compliance lawyer for a Pretoria business is rarely a single-issue drafter. Regulatory exposure tends to arrive bundled, and the lawyer who only handles POPI policies cannot advise on a Companies Act query that lands in the same inbox. A few selection criteria that hold up across sectors:

  • Regulatory breadth — the lawyer should know more than one statute and be able to scope work across Companies Act, CPA, POPIA, and PAIA in a single engagement.
  • Up-to-date knowledge — the regulatory framework shifts. POPIA’s enforcement sections came into force in phases through 2021, and PAIA-manual guidance has tightened since the e-Services portal was introduced. Advice should be based on the current versions of the Acts and Regulations, not on training-time knowledge.
  • Industry familiarity — compliance issues vary by sector. FICA drives the work for accountable institutions; CPA drives consumer-facing businesses; NCA drives credit providers; POPIA cuts across any data processor. A lawyer who knows the client’s industry catches sector-specific risks first.
  • Preventive, not reactive — the value of compliance work is catching issues upstream. Lawyers who only engage post-breach or post-complaint miss the early-stage work that keeps clients out of trouble.
  • Practical, plain-language advice — compliance documents are read by the staff who have to follow them. Lawyers who hand over legalese-only policies miss the operational reality and produce shelf-ware.
  • Transparent pricing — compliance work is often better suited to a monthly retainer than per-instruction fees. Ask whether the firm offers retainer arrangements and how they scope the recurring work.

Burger Huyser’s commercial-law practice at the Menlyn branch is structured around multi-statute mandates — the same attorney typically drafts the privacy policy, reviews the MOI, and files the PAIA report, so the client is not bouncing between advisers to keep the framework aligned.

Practical Considerations: Cost, Engagement Style, What to Bring

Most compliance mandates fall into one of three buckets, and the right fee structure depends on which bucket the work sits in.

Engagement type Examples Typical fee basis
One-off instruction MOI review, PAIA report lodgement, single privacy-policy update Per-instruction fee
Defined project Full gap analysis, internal-manual build, multi-policy drafting Per-instruction fee, quoted after scoping
Ongoing retainer Policy upkeep, contract vetting, ad hoc regulator queries Monthly retainer

What to bring to the first consultation:

  • Memorandum of Incorporation (or Memorandum of Association if no MOI exists).
  • Shareholders’ agreement.
  • Standard customer or supplier contracts.
  • Current privacy policy (if any).
  • Prior years’ PAIA reports (if lodged).
  • A short list of the business’s main regulatory touchpoints — does it process personal information, extend credit, sell to consumers, or handle access-to-information requests.

On timeline, most pieces of compliance work are bounded by what the client already has. A PAIA-report lodgement can be turned around within a few working days once records are collated. A full document audit — MOI, shareholders’ agreement, customer contracts, and privacy policy — usually runs two to four weeks. The bigger drag on timeline is usually client-side: businesses that cannot produce their existing policies or contracts in time extend the engagement more than the legal work itself does. Burger Huyser Attorneys quotes compliance work either on a per-instruction basis or on a monthly retainer for clients with ongoing needs, with pricing confirmed after the initial consultation at the Pretoria (Menlyn) branch on 012 471 5700.

Frequently Asked Questions

What does a compliance lawyer actually do?

A compliance lawyer advises a business on the regulatory framework it operates under — the Companies Act 71 of 2008, the Consumer Protection Act 68 of 2008, the Protection of Personal Information Act 4 of 2013, and the Promotion of Access to Information Act 2 of 2000 — and handles the document and policy-level work that keeps the business compliant. Typical instructions include Memorandum of Incorporation and shareholder-agreement reviews, service-level-agreement vetting, privacy-policy drafting, internal compliance-manual development, statutory filings such as the annual PAIA report to the Information Regulator, and first-response advice if a regulator query or complaint has already landed.

Is compliance work the same as litigation?

No. Compliance work is advisory and document-led — most mandates are handled through reviews, drafting, and filings rather than courtroom appearances. Where a compliance issue escalates (an Information Regulator inspection, a CPA complaint to the National Consumer Commission, or a POPIA breach with downstream litigation risk), the compliance lawyer typically refers the matter to a litigation attorney or works alongside one. Burger Huyser runs compliance work through its commercial-law practice rather than its litigation department because the work is preventive rather than contentious.

Which Act matters most for my business?

It depends on what the business does. Every registered company has at least some Companies Act duties (MOI, CIPC filings, director-duty compliance). Any business that processes personal information has POPIA duties. Any business that sells to consumers on standard terms has CPA exposure. Any public or private body that handles access-to-information requests has PAIA duties and must lodge an annual report to the Information Regulator. Credit providers, accountable institutions under FICA, employers, and sector-specific licensees each have their own statutory overlay — a gap analysis with a compliance lawyer maps the actual obligations to the actual business rather than guessing.

How much does compliance work cost in Pretoria?

Costs depend on scope. A one-off PAIA-report lodgement with a current manual costs less than a full Memorandum of Incorporation and shareholder-agreement audit, and retainer arrangements for ongoing compliance work are quoted separately. Burger Huyser Attorneys confirms pricing after the initial consultation at the Pretoria (Menlyn) branch on 012 471 5700.

How long does compliance work take?

Most pieces of compliance work are bounded by what the client already has. A PAIA report for lodgement can be turned around within a few working days once records are collated. A full document audit — Memorandum of Incorporation, shareholders’ agreement, customer contracts, and privacy policy — usually runs two to four weeks. The bigger drag on timeline is usually client-side: businesses that cannot produce their existing policies or contracts in time extend the engagement more than the legal work itself does.

When is the next PAIA report deadline?

The Information Regulator’s e-Services portal closes the annual PAIA-report lodgement window in late June each year, and the 2025/26 window was scheduled to close on 30 June 2026. Both public and private bodies must lodge by the deadline — the duty is not size- or sector-dependent. Burger Huyser’s Pretoria branch handles Section 14 PAIA-manual preparation and the annual report lodgement for clients who do not have an in-house compliance function.

For Pretoria-based businesses that need a compliance lawyer to handle regulatory advisory or recurring filings, Burger Huyser Attorneys fields compliance work from its Menlyn branch (Unit 4, 1st Floor, Block 5, Glen Manor Office Park, 138 Frikkie De Beer Street, 012 471 5700, after-hours 064 548 4838), under the firm’s commercial-law practice and led at the Pretoria branch by director Herman Bonnet. The firm takes instructions ranging from Memorandum of Incorporation reviews and shareholder-agreement audits to PAIA-manual compilation, POPIA privacy-policy drafting, and the annual PAIA report lodgement through the Information Regulator’s e-Services portal. Burger Huyser carries a 4.8/5 average across 250+ Google reviews (Trustindex verified, “Top Rated Law Firm in South Africa”) and was named Best Multi-Sector Law Firm 2023 — Johannesburg by Acquisition International. Initial consultations are booked through the Pretoria branch directly.

General Information Disclaimer: This article describes the general scope of compliance legal work in South Africa under the Companies Act 71 of 2008, the Consumer Protection Act 68 of 2008, the Protection of Personal Information Act 4 of 2013, and the Promotion of Access to Information Act 2 of 2000, together with related sector-specific legislation such as the National Credit Act and FICA. It is general legal information, not advice for a specific business — the regulatory framework applies differently to every entity depending on its sector, size, and data-processing profile, and businesses should consult a qualified compliance attorney about their own situation before relying on any of the above.

NEED TOP LEGAL SUPPORT IN SOUTH AFRICA? CONTACT OUR LAWYERS TODAY.

Contact our team of experienced law attorneys at Burger Huyser Attorneys to assist you in all matters and procedures.

CONTACT DETAILS

DISCIPLINARY HEARINGS