Data protection enforcement action

Direct marketing fines: How to avoid them

The Information Commissioner’s Office (ICO) in the UK handed out ten direct marketing fines in the last year. We've all received annoying direct marketing calls at some point in our lives but for some organisations direct marketing is vital. If [...]

Using an outsourced DPO to avoid fines

Data protection regulations are becoming increasingly strict. In response, many organisations are turning to outsourced Data Protection Officers (DPOs) to ensure that their organisation remains fully compliant. An outsourced DPO helps an organisation follow its data protection plan and makes [...]

SAPS enforcement action | security compromise part 1

The information regulator issued its first enforcement notice to SAPS. After conducting an independent investigation, the regulator found that SAPS breached several conditions for the lawful processing of personal data. The regulator also found that SAPS failed to notify the [...]

Data protection fines in Africa

Data protection fines in Africa are on the rise as more authorities enforce compliance with data protection laws. Data protection authorities in Angola and Kenya have hit the ground running by enforcing data protection laws. In this article, we highlight [...]

GDPR enforcement actions – March 2023

As the saying goes, "March comes in like a lion and goes out like a lamb". Regarding GDPR enforcement actions collated in March 2023, the lion has roared. Recent enforcement actions related to the General Data Protection Regulation (GDPR) in [...]

Draft POPIA Rules for the Enforcement Committee

The Information Regulator published a notice calling for comments on the draft POPIA Rules for the Enforcement Committee (Committee). The draft Rules outline the Procedure that the Enforcement Committee must follow when the regulator refers a POPIA complaint to them [...]

National Department of Health enforcement action | Access to information

The South African Information Regulator (IR) has referred the National Department of Health (NDoH) to the enforcement committee because the NDoH has not provided information about personal data it collected during the COVID-19 pandemic. The regulator might issue an enforcement [...]

How to make the Information Regulator happy with your organisation

Picture yourself sitting on your couch at home, causally flicking through channels. The Information Regulator and data protection are the last things on your mind; and yet there you are, stumbling onto a press conference the Information Regulator is doing. [...]

Information Regulator versus SAPS. The scalding tea.

By now, you’d have heard about SA’s latest battle: Information Regulator versus SAPS. But what’s the actual tea? Why’s our Information Regulator taking on SAPS? Do they even have the authority to take on SAPS? Perhaps you think POPIA doesn’t apply [...]

By |2024-08-15T14:52:06+02:00September 1st, 2022|Categories: POPI and Data Protection|Tags: , |

Information regulator establishes enforcement committee

The information regulator has finally established the enforcement committee (committee). The Protection of Personal Information Act (POPIA) provides for the establishment of an Enforcement Committee (see section 93). The committee has a key role to play in supporting the information [...]

Infringement notice from the information regulator: what now?

The information regulator will serve an infringement notice to a responsible party that the regulator believes has breached a provision of POPIA. No responsible party wants to receive an infringement notice or enforcement notice. It is even more intimidating than [...]

Youtube and COPPA – what do you need to know?

The Federal Trade Commission (FTC) recently hit YouTube and Google with a $170 million fine due to YouTube collecting children's personal data without their parent's consent. The FTC relied on the Children's Online Privacy Protection Act (COPPA) as a basis [...]