The Central Johannesburg TVET College enforcement action confirms that the Information Regulator will act when POPIA conditions are not met. On 22 May 2026, the Regulator issued its first formal enforcement notice of the year, following complaints lodged by employees (data subjects) against the College (reasonable party). If your organisation processes personal information in South Africa, this enforcement notice applies to you. At the heart of it is your Information Officer (IO). Every organisation has one by default, and POPIA places specific legal responsibilities squarely on their shoulders.
You as the IO and Deputy IO have 21 responsibilities and must comply – that is the law and this enforcement notice makes that clear.
Background
The Central Johannesburg TVET College was placed under administration after a number of employees were found to have concealed criminal records and conflicts of interest. To restore good governance, the College collected Verification Reports from employees to verify their qualifications and criminal records.
On 6 September 2022, the acting Chief Financial Officer (CFO) mistakenly included these Verification Reports in a folder containing finance policies and emailed it to various staff members. The Administrator recalled the email two days later and took corrective internal action against those responsible for forwarding it. However, even though the Regulator acknowledged these remedial steps, it was still not sufficient compliance as per POPIA.
What the Regulators found: the violations
- Condition 1 — Accountability (section 8 of POPIA)
- The Central Johannesburg TVET College had not registered an IO or deputy IO with the Regulator.
- Without a registered IO, accountability had no clear owner. This failure contributed to the other compliance issues that followed.
- Condition 4 — Further processing limitation (section 15 of POPIA)
- Central Johannesburg TVET College collected the Verification Reports for one specific reason: to check employee qualifications and criminal records.
- Sharing those reports with employees who had nothing to do with it breached POPIA. Even if this was by accident.
- Furthermore, the Regulator overruled its own Enforcement Committee, which had found no breach because the processing was for a legitimate purpose and in the public interest. The Regulator disagreed, as those justifications do not exist in section 15(3) of POPIA.
- Condition 7 — Security safeguards (sections 19 and 22 of POPIA)
- The Central Johannesburg TVET College kept no system to separate sensitive records from other documents, and had no registered IO. Basic POPIA safeguards were simply not in place.
- Additionally, the moment unauthorised employees accessed the Verification Reports, the Central Johannesburg TVET College had to report the incident to the Regulator and notify the affected data subjects. They did neither.
Central Johannesburg TVET College enforcement action: the Regulator’s orders
- The Central Johannesburg TVET College must register an Information Officer and deputy IO and provide proof of registration within 31 days to the Regulator.
- They must inform the affected employees of the security compromise in compliance with section 22 of POPIA and provide proof within 31 days.
- They must submit a written apology to the affected employees for the breach of their personal information. The college must then submit proof of the apology within 31 days.
- They must take appropriate disciplinary action against the employee responsible for the unlawful sharing of personal information and submit proof within 60 days.
- They must submit their POPIA Compliance Framework to the Regulator within 31 days, including a Privacy Policy, Retention Policy and Schedule, Incident Response Policy, and Information Privacy and Security Policy. If there is no framework they must develop and then submit one within 120.
- They must conduct POPIA awareness and training for all employees and submit proof of completion, including attendance registers, within 90 day.
Non-compliance with an enforcement notice is a criminal offence under POPIA, carrying a fine, imprisonment of up to 10 years, or both.
Actions you can take
- Register your IO and deputy IO with the Information Regulator by completing registration on the eServices Portal. For more guidance, read our post on how to do this.
- Fulfil every IO responsibility by joining our Information officer programme. For a full overview of your options and the actions available to you as an IO, visit our guide.
- Develop a POPIA Compliance Framework for your organisation by asking us to develop one for you or empower yourself to do it by joining our Data Protection programme. For more details, explore our POPIA compliance framework guide.
- Raise awareness among your employees on POPIA-specific issues by providing training tailored to your organisation’s unique requirements. Contact Michalsons to run the workshops on your behalf, or work through the managing an awareness and training programme module in our Data Protection programme.