The Information Regulator’s DoJ enforcement action, followed by the DoJ infringement notice, highlights the risks of failing to address a personal information compromise under the Protection of Personal Information Act (POPIA). The Department of Justice (DoJ) failed to secure the data of over 250,000 officials and non-officials. In May 2023, the regulator issued an enforcement notice requiring remedial action within 31 days, including renewing antivirus software licenses. The DoJ did not comply, resulting in an infringement notice sent in July 2023 and a R5 million fine. On 29 September 2023, the DoJ issued a court application to take this fine on review to the High Court.

DoJ enforcement action

The regulator issued an enforcement notice order on the DoJ, which requires them to take several remedial actions to comply with POPIA within 31 days. The DoJ must also submit proof of completion to the regulator for all remedial actions.

The regulator found that the DoJ breached several provisions of POPIA (Section 19(1)–(3)) because they failed to:

  • implement adequate security measures to protect personal information, and
  • uphold the rights of the data subjects by not protecting their personal information.

 In respect of the breach of section 19(1), the regulator ordered the DoJ to:

  • Provide the regulator with copies of the Personal Information Impact Assessment (PIIA) and the compliance framework in terms of regulation 4(1)(a) of POPIA.
  • Report the security compromise to the South African Police Service (SAPS).
  • Renew the Anti-Virus software, the SIEM license and the Intrusion Detection System.
  • Institute disciplinary proceedings against the official(s) who are responsible for the renewal of the licenses
  • Provide POPIA training to all staff.

In respect of the breach of section 19(2), the regulator ordered the DoJ to:

  • Take reasonable measures to identify all foreseeable internal and external risks to personal information in its possession or under its control.
  • Establish and maintain appropriate safeguards against the risks identified.
  • Regularly verify that the safeguards are effectively implemented.
  • Update the safeguard measures in response to new risks or deficiencies.

In respect of the incident response (section 19(3))

  • Update the Incident Response Plan by incorporating all applicable provisions of POPIA.
  • Implement the Public Service Corporate Governance of Information and Communication Technology Framework, dated December 2012.

What you can learn from this DoJ enforcement action

The DoJ enforcement action issued serves as a reminder of the importance of complying with the provisions of POPIA. Organisations that collect and process personal information must ensure that they have implemented adequate security measures to protect this information from unauthorised access or use. Ongoing training and awareness will make organisations more resilient in their approach to POPIA. For example, the more aware your staff are about POPIA, the more proactive they will be in implementing measures to comply.

DoJ infringement notice

The consequences for non-compliance with the enforcement action was clear. If the DoJ did not comply they would be guilty of an offence, and the regulator may impose an administrative fine of up to R10 million.

On the 3rd of July 2023, the Information Regulator found that the DoJ did not comply with certain conditions of the enforcement action issued on 9 May 2023. For example, it required the DoJ to prove that the Anti-Virus licence, SIEM licence, and Intrusion Detection System licence had been renewed. It also required the DoJ to institute disciplinary proceedings against officials responsible for failing to renew these licences. The Regulator gave the DoJ 31 days to comply, but it failed to do so. Although the DoJ could have appealed the enforcement notice, it chose not to.

The DoJ had a few options available to them:

  • Pay the fine within 30 days
  • Make a payment arrangement with the regulator to pay the administrative fine in instalments, or
  • Take the matter to court.

The DoJ has since decided to take the matter on review to the High Court

What you can learn from the DoJ infringement notice

The DoJ could have avoided an administrative fine by simply complying with the orders in the enforcement notice. If they did not agree with the regulator’s decision, they can lodged an appeal but they did not so do. Lastly, if the DoJ could not comply with the license renewals timeously, they could have asked the regulator for an extension by supplying the regulator with reasons.

Actions you can take:

To avoid receiving a similar DoJ enforcement action, responsible parties should:

To avoid receiving a similar DoJ infringement notice, responsible parties should:

  • Understand the consequences of an infringement notice by reading our post about it.
  • Get up to speed by understanding why the DoJ received an enforcement notice from the regulator.
  • Be updated about the latest developments on fines by joining our data protection programme.