Information Regulator

Insights, news or developments related to the Information Regulator in South Africa, including updates on webinars or events held by them.

Notification of security compromise to the Information Regulator | Guideline and support

The information regulator published a Guideline on notification of security compromises to the information regulator in July 2020. The guideline explains the procedure responsible parties or information officers should follow to notify the regulator of a security compromise or data [...]

Information regulator annual performance plan for 2025 to 2026 APP

The information regulator has presented its draft annual performance plan (regulator APP) for 1 April 2025 to 31 March 2026. It has presented them in different formats to different audiences. For example, the regulator held a stakeholder engagement on 5 [...]

Information Regulator in South Africa

The Information Regulator was created by the Protection of Personal Information Act (POPI Act). POPI gives the Information Regulator teeth - it has extensive powers to investigate and fine responsible parties. Data subjects can complain to the Information Regulator [...]

Lancet Laboratories enforcement action | Security

The Information Regulator issued a POPIA enforcement notice against Lancet Laboratories in September 2024 for failing to comply with the breach notifications required by POPIA. The Information Regulator conducted a POPIA compliance assessment following the numerous security compromises experienced by [...]

Information Regulator aims to step up enforcement

The information regulator briefed the public and the media on 11 September 2024 on some enforcement activities over the last quarter (since 1 April 2024). The central theme was that the regulator has taken various enforcement actions but hasn't succeeded [...]

State Security Agency (SSA) enforcement action | ANA expenditure

The Information Regulator issued an enforcement notice to the State Security Agency (SSA) regarding a PAIA record request. The SSA had refused to provide the information to the requester. This refusal prompted the Regulator to investigate and issue the SSA […]

Guidance note on the processing of personal information of a voter by a political party and independent candidate

The information regulator issued a new guidance note on the processing of personal information of a voter by political parties and independent candidates as well as highlighting how to combat misinformation and disinformation in terms of the provisions of the [...]

IEC Security Compromise: a case study on notifying the regulator

With the general elections set to be held on 29 May 2024, the last thing South Africans want to hear are details of a security compromise at the IEC. On the other hand, the Information Regulator is in need [...]

SAPS enforcement action | security compromise part 2

In less than 18 months, the information regulator has cracked down on SAPS security compromise. This investigation stems from a security compromise where sensitive details, including personal information, were leaked on WhatsApp. The leaked information reportedly included details related to [...]

Will FT Rams Consulting also get an infringement notice?

Getting an enforcement notice from the regulator is not the worst thing that can happen to FT Rams Consulting or any other non-compliant organisation. You will agree with me, after reading the discussion below, that getting an infringement notice is [...]

How a POPIA exemption can help your non-profit

Non-profits all need to find a balance between achieving data privacy and achieving their important operational goals. Most people know, at this point, that POPIA and other data protection laws are at the heart of that data privacy. Compliance [...]

By |2025-02-28T13:53:48+02:00February 29th, 2024|Categories: POPI and Data Protection|Tags: , , , |