The Information Regulator was created by the Protection of Personal Information Act (POPI Act). POPI gives the Information Regulator teeth – it has extensive powers to investigate and fine responsible parties. Data subjects can complain to the Information Regulator and takes action on behalf of data subjects. It regulates both POPIA and PAIA. It reports to Parliament and is the South African equivalent of the Information Commissioner in the UK. You can find other authorities in this list of data protection authorities, commissioners or regulators (DPAs).

More about the Information Regulator

Yes, it began its work on 1 December 2016. The Information Regulator is “independent and is subject only to the Constitution and to the law and must be impartial and perform its functions and exercise its powers without fear, favour or prejudice.” (section 39). The Information Regulator is accountable to the National Assembly.

Without fear, favour or prejudice

The regulator has an annual budget of R136 million for the year starting 1 April 2025.

Who are the office bearers of the Information Regulator?

The office of the Information Regulator is currently made up of Adv Pansy Tlakula as the chair, Adv Cordelia Stroom and Mr Johannes Weapond as full-time members, and Ms Alison Tilley and Mr Mfana Gwala as part-time members. The President of South Africa officially appointed the current office bearers (with the exception of Ms Alison Tilley) with effect from 1 December 2021 for a five-year term until 30 November 2026.

Before that, the President appointed the previous members on 26 October 2016 with effect from 1 December 2016. As part of the process, the National Assembly recommended the appointment the office bearers on 7 September 2016. And before that Parliament invited everyone to nominate people and shortlisted candidates for Parliament to appoint as members of the Information Regulator.

The regulator currently has about 100 employees and plans to hire another 40 people over the next financial year.

Action you can take

Where is the Information Regulator?

It has one central office in Gauteng. The Information Regulator has published final POPIA regulations and it has a website. It is on LinkedIn, twitter and facebook.

The Information Regulator plans

The Information Regulator publishes plans regularly. They include both five-year strategic plans and annual performance plans (APP).

  • Every five years, the Regulator sets out a strategic plan that outlines its goals for promoting compliance with POPIA and PAIA. The plan emphasises improving data protection and access to information by increasing public awareness, ensuring regulatory compliance, and conducting thorough risk assessments.
  • The Regulator also complies an annual performance plan (APP) that outlines its key priorities it aims to achieve within that specific financial year. It breaks down the steps needed to implement its long-term strategic plan, allocate resources and monitor performance.

What are the responsibilities of the Information Regulator?

Information RegulatorThe powers, duties and functions of the Regulator are to:

  • provide education,
  • monitor and enforce compliance,
  • consult with interested parties,
  • handle complaints,
  • conduct research and to report to Parliament,
  • do various things regards codes of conduct,
  • facilitate cross-border cooperation in the enforcement of privacy laws by participating in any initiative that is aimed at such cooperation, and
  • a few other things specified in section 40(1) of POPIA.

One of the functions of the Information Regulator is to protect data subjects from harm and ensure that their personal information is protected by responsible parties. Similar to the Public Protector, the Information Regulator can hold responsible parties accountable for not complying with POPIA or PAIA.

The Information Regulator must “take account of international obligations accepted by South Africa and consider any developing general international guidelines relevant to the better protection of individual privacy.”

What you must do with the Information Regulator

Some responsible parties must get prior authorisation from the Information Regulator before processing personal information, but those that need to are limited. There is a good chance that you do not need to get authorisation. If you are not sure, we can help you to work out whether you need to get authorisation or not. Remember, it is a criminal offence if you do not get authorisation when you should have, and there is the possibility of a fine or up to 12 months imprisonment. But by far, the greater risk is that you might not be able to process personal information.

All responsible parties must register their Information Officer with the Information Regulator. The original deadline to do this was 1 July 2021.

Image courtesy of the South African Government (May 2014) pursuant to a Creative Commons licence. We have not changed the image.