Enforcement Action

Avoid enforcement action by getting our insights into the latest fines and notices authorities have issued and practical tips on how to avoid them.

Only some are linked below. To read all previous insights and be alerted to future insights, join the relevant Michalsons programme. You can view the public and the “Members only” ones if you are a member and logged in.

Advanced Computer Software Group enforcement action | Ransomware

The Information Commissioner’s Office (ICO) has fined Advanced Computer Software Group Ltd (ACSG) £3.07 million following a ransomware incident that exposed the personal data of 79,404 people. The ICO found that ACSG failed to implement adequate security measures, leaving [...]

PAIA compliance assessments by information regulator

South Africa’s Information Regulator conducts PAIA compliance assessments on public and private bodies in terms of section 77H of the Promotion of Access to Information Act (PAIA). PAIA plays a crucial role in an organisation's transparency and accountability to the [...]

Lancet Laboratories enforcement action | Security

The Information Regulator issued a POPIA enforcement notice against Lancet Laboratories in September 2024 for failing to comply with the breach notifications required by POPIA. The Information Regulator conducted a POPIA compliance assessment following the numerous security compromises experienced by [...]

Information Regulator aims to step up enforcement

The information regulator briefed the public and the media on 11 September 2024 on some enforcement activities over the last quarter (since 1 April 2024). The central theme was that the regulator has taken various enforcement actions but hasn't succeeded [...]

DoJ enforcement action | Personal information compromise

The Information Regulator’s DoJ enforcement action, followed by the DoJ infringement notice, highlights the risks of failing to address a personal information compromise under the Protection of Personal Information Act (POPIA). The Department of Justice (DoJ) failed to secure the [...]

Lingo Telecom enforcement action | Robocalling fine

The Federal Communications Commission (FCC) proposed a landmark enforcement action against Lingo Telecom, a voice service provider, for violations of caller ID authentication rules under the STIR/SHAKEN framework. This proposal followed the transmission of thousands of spoofed robocalls, including deepfake [...]

By |2025-04-01T16:58:38+02:00September 1st, 2024|Categories: POPI and Data Protection|Tags: , , |

Information Regulator’s media briefing – PAIA points

The Information Regulator's media briefing unpacked PAIA points and gave insights into the state of access to information. These points shed light on successes and areas which need improvement to adhere to PAIA. PAIA points in the Information Regulator's media [...]

By |2025-08-11T06:49:36+02:00August 19th, 2024|Categories: Access to Information|Tags: , , , |

State Security Agency (SSA) enforcement action | ANA expenditure

The Information Regulator issued an enforcement notice to the State Security Agency (SSA) regarding a PAIA record request. The SSA had refused to provide the information to the requester. This refusal prompted the Regulator to investigate and issue the SSA […]

IEC Security Compromise: a case study on notifying the regulator

With the general elections set to be held on 29 May 2024, the last thing South Africans want to hear are details of a security compromise at the IEC. On the other hand, the Information Regulator is in need [...]

Pinnacle Life enforcement notice | Unsolicited marketing calls

The Information Commissioner’s Office (ICO) issued a monetary penalty to Pinnacle Life Limited in its latest Pinnacle Life enforcement notice, a UK-based insurance broker, for breaching direct marketing laws. The £80,000 penalty highlights the importance of robust compliance with the [...]

By |2026-02-11T15:42:53+02:00April 1st, 2024|Categories: POPI and Data Protection|Tags: , , |

SAPS enforcement action | security compromise part 2

In less than 18 months, the information regulator has cracked down on SAPS security compromise. This investigation stems from a security compromise where sensitive details, including personal information, were leaked on WhatsApp. The leaked information reportedly included details related to [...]