News
South Africa's Information Regulator is issuing notices again
Enforcement notices through 2026, a ransomware finding against SABS, and a R10 million ceiling. POPIA compliance has moved from paper to practice.
Prem Kumar Dvivedi · 12 tháng 9, 2026
South Africa's Information Regulator published an enforcement notice against the Central Johannesburg TVET College on 20 May 2026, and issued further notices against public and private bodies in August. 2026 is the Regulator's tenth year, and the fifth since POPIA's enforcement provisions commenced.
The SABS finding is the instructive one
After a 2024 ransomware attack disrupted the South African Bureau of Standards, the Regulator conducted an own-initiative assessment and found contraventions across several POPIA conditions at once: processing excessive or irrelevant information, inadequate consent mechanisms, insufficient security safeguards, and failing to tell data subjects how their information was collected.
That pattern is worth sitting with. The incident was a security failure; the findings were mostly about governance. An organisation can be breached through no great fault and still be found wanting on what it collected, why it kept it, and whether anyone was told.
What it costs
The maximum administrative fine under POPIA is R10 million, with fines to date ranging from R100,000 to R5 million. The larger cost for most organisations is the enforcement notice itself: a public instruction to fix something, with a deadline.
What to do
Appoint and register an Information Officer, and make sure they exist in practice rather than on an org chart. Know what personal information you hold and why. Have a breach procedure that has been tested. And because the SABS case began with ransomware, treat continuity as part of privacy rather than a separate exercise — ISO 22301 and ISO/IEC 27001 are usually built together for this reason.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- ISO 22301:2019: documentation and compliance requirements
Everything ISO 22301:2019 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 tháng 9, 2026
- ISO/IEC 27001:2022: documentation and compliance requirements
Everything ISO/IEC 27001:2022 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
12 tháng 9, 2026
- ISO/IEC 27701:2025: documentation and compliance requirements
Everything ISO/IEC 27701:2025 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checkli
12 tháng 9, 2026
