News

South Africa's Information Regulator is issuing notices again

Enforcement notices through 2026, a ransomware finding against SABS, and a R10 million ceiling. POPIA compliance has moved from paper to practice.

Prem Kumar Dvivedi · 12 September 2026

South Africa's Information Regulator published an enforcement notice against the Central Johannesburg TVET College on 20 May 2026, and issued further notices against public and private bodies in August. 2026 is the Regulator's tenth year, and the fifth since POPIA's enforcement provisions commenced.

Source: Werksmans Attorneys — The regulator is watching: new enforcement signals for POPIA and PAIA compliance

The SABS finding is the instructive one

After a 2024 ransomware attack disrupted the South African Bureau of Standards, the Regulator conducted an own-initiative assessment and found contraventions across several POPIA conditions at once: processing excessive or irrelevant information, inadequate consent mechanisms, insufficient security safeguards, and failing to tell data subjects how their information was collected.

That pattern is worth sitting with. The incident was a security failure; the findings were mostly about governance. An organisation can be breached through no great fault and still be found wanting on what it collected, why it kept it, and whether anyone was told.

What it costs

The maximum administrative fine under POPIA is R10 million, with fines to date ranging from R100,000 to R5 million. The larger cost for most organisations is the enforcement notice itself: a public instruction to fix something, with a deadline.

What to do

Appoint and register an Information Officer, and make sure they exist in practice rather than on an org chart. Know what personal information you hold and why. Have a breach procedure that has been tested. And because the SABS case began with ransomware, treat continuity as part of privacy rather than a separate exercise — ISO 22301 and ISO/IEC 27001 are usually built together for this reason.

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles