Information Regulator ramps up enforcement: on 1 September 2026, the Information Regulator briefed the public and media on its latest enforcement and compliance activities under POPIA and PAIA. The briefing shows the Regulator is increasingly concerned about South Africa’s cybersecurity environment. It also flags continued non-compliance with direct marketing rules and low levels of PAIA compliance, particularly in the public sector.
The main message was that organisations need to stop treating privacy and access-to-information compliance as a tick-box exercise. The regulator expects organisations to make POPIA and PAIA part of their day-to-day operations and compliance culture.
Security compromises are increasing at an alarming rate
The Regulator has received more than 8,000 security compromise notifications to date, including over 1,220 since its briefing on 1 April 2026. At that rate, it expects to receive more than 3,000 reported compromises this financial year.
The Regulator called the rate of security compromises ‘very alarming’, warning that cyber incidents harm more than just data subjects. They also disrupt essential services, damage organisational reputation, erode public confidence, and carry broader economic consequences.
The regulator also indicated that some organisations are not reporting security compromises, meaning the actual number of incidents may be higher than the reported figures.
The regulator issued an enforcement notice against SABS
The Regulator issued an enforcement notice against the South African Bureau of Standards (SABS) after a 2024 ransomware attack encrypted its systems and disrupted operations. Crucially, the notice wasn’t for being a victim of the attack. No organisation can guarantee that. It was for what the attack exposed: weak security safeguards, unpatched known vulnerabilities, poor consent mechanisms and no incident response plan. SABS now has 90 days to fix its policies, run personal information impact assessments and put proper security measures in place.
The takeaway: a cyberattack doesn’t automatically mean a POPIA breach. What matters is whether an organisation took appropriate steps to protect personal information beforehand.
Direct marketing remains a major concern
Direct marketing remains one of the regulator’s key areas of concern. The regulator said that it received more than 3,800 complaints last year, with approximately 10% relating to direct marketing.
The regulator referred two direct marketing matters to the Enforcement Committee: the OUTsurance enforcement action and a separate matter involving MTN. The regulator said these matters raise important questions about how section 69 of POPIA is interpreted and applied, particularly regarding unsolicited electronic communications.
One unresolved issue is whether direct marketing telephone calls fall within POPIA’s concept of an electronic communication. The regulator acknowledged the industry’s view that telephone calls do not fall within the definition, but indicated that the direct marketing matters before the Enforcement Committee may provide greater clarity.
The regulator welcomes the NCC pre-emptive block registry
The regulator welcomed the recent CPA amendment regulations aimed at tackling unsolicited marketing communications. In particular, it described the pre-emptive block registry as an important additional tool against unwanted direct marketing. But registering on the NCC registry doesn’t replace POPIA. Responsible parties must still meet their POPIA obligations when marketing directly. The Regulator has also engaged the National Consumer Commission to explore cooperation on public awareness and complaints.
The regulator is investigating several organisations
The regulator confirmed that it is investigating or assessing several public and private sector organisations for possible POPIA compliance issues, including the National Credit Regulator, Truecaller, Pick n Pay, Gauteng Department of e-Government, Land Bank and Standard Bank.
POPIA referrals from the Madlanga Commission
Furthermore, privacy issues are increasingly intersecting with the criminal justice system. On 23 July 2025, the President established the Judicial Commission of Inquiry into Criminality, Political Interference, and Corruption in the Criminal Justice System, chaired by Justice Madlanga. In February 2026, the Commission referred concerns to the Regulator about alleged unlawful processing of personal information by the former city manager of Ekurhuleni Metropolitan Municipality. The Regulator accepted the referral and opened an own-initiative investigation under section 76(3) of POPIA. It has since referred the matter to the Enforcement Committee. On 4 August 2026, the Commission made further referrals, prompting additional investigations. These are ongoing, and the Regulator will not comment on the merits until they are complete.
The regulator continues to challenge the publication of matric results
The regulator continues its legal challenge over the Department of Basic Education’s publication of matric results by appealing the last court decision. The High Court set aside the Regulator’s notices in December 2025 and refused leave to appeal in June 2026. Still, the Regulator says the dispute raises important questions about applying POPIA to learners’ personal information. Therefore, it is pursuing it further. The Regulator sees such cases as key to building South Africa’s POPIA jurisprudence, offering more certainty on data subjects’ rights and responsible parties’ obligations.
PAIA compliance remains too low
The regulator also raised significant concerns about compliance with PAIA annual reporting obligations. Municipalities remain a particular concern. Only 91 of South Africa’s 257 municipalities submitted annual reports, representing approximately 35% compliance. The Regulator plans to intensify PAIA compliance monitoring and engagement with oversight structures. Poor PAIA compliance undermines transparency and accountability. It also limits the public’s constitutional right of access to information.
The regulator wants stronger PAIA enforcement powers
One of the regulator’s continuing difficulties is that PAIA does not provide the same enforcement mechanisms as POPIA. Where someone fails to comply with a POPIA enforcement notice, the regulator can ultimately issue a fine. Under PAIA, enforcement is more difficult and may require the regulator to pursue criminal proceedings against a non-compliant information officer. The regulator is therefore pursuing amendments to PAIA to strengthen its enforcement powers. It has also approached Parliament seeking the power, in certain circumstances, to release information itself where an institution has failed to comply with an order requiring disclosure.
Infringers are now paying some POPIA fines
The position on fines has changed significantly since earlier regulator briefings. The regulator confirmed that the IEC and Lancet Laboratories have each paid R100,000 fines. It also referred to a municipal fine that was initially R500,000 but a court reduced it to R250,000. Other infringement matters remain subject to legal proceedings. The Regulator still finds POPIA’s enforcement process restrictive. Responsible parties usually get a chance to comply with an enforcement notice before the Regulator imposes a fine. If they comply in time, the Regulator can’t fine them on that basis.
Compliance must go beyond the information officer
The main message from the briefing was that organisations cannot leave POPIA and PAIA compliance entirely to their information officer. Employees throughout the organisation need to understand why personal information is collected, how it will be used, and what happens to it afterwards. Compliance must become part of the organisation’s culture.
Actions you can take
- Conduct general awareness training on POPIA and PAIA by inviting your employees to attend our live webinar series.
- Dive deeper into this briefing by watching the full media briefing on YouTube.