South Africa South Africa POPIA data protection

South Africa's Information Regulator Is Right to Prefer Compliance Orders Over Fines, and Its Court Record Shows Why

The Regulator's fines on state bodies keep being cut or set aside, while its 90-day SABS order targets the security failures behind a rising breach count.

POPIA Enforcement in 2026 People of Internet Research · South Africa 1,220 Breaches reported since April Security compromises notified from… 3,000+ Projected breaches this year The Regulator's estimate for the 2… R10M Maximum administrative fine The statutory cap under POPIA sect… 49% Public bodies filing PAIA reports 417 of 853 public bodies submitted… peopleofinternet.com
POPIA Enforcement in 2026 People of Internet Research · South Africa 1,220 Breaches reported since April 3,000+ Projected breaches this ye… R10M Maximum administrative f… 49% Public bodies filing PAIA repo… peopleofinternet.com

Key Takeaways

South Africa's Information Regulator marked its tenth anniversary year with a media briefing on 31 August 2026. According to the Werksmans summary of the briefing, 1,220 security compromises were reported between 1 April and 31 August 2026. The Regulator projects more than 3,000 by the end of the financial year. The Regulator itself called the rate "very alarming", as Moonstone reported.

The strongest case for tougher enforcement

The case for aggressive enforcement is serious. The Protection of Personal Information Act (POPIA, Act 4 of 2013) requires a responsible party to secure personal information through "appropriate, reasonable technical and organisational measures", including regular verification that safeguards work, under section 19. Breach notifications are running at a pace that suggests many organisations treat that duty as optional. Public bodies hold the most sensitive records, and citizens cannot opt out of dealing with them. If a regulator lets state departments off lightly, it weakens its credibility with private firms. Section 109 allows administrative fines of up to R10 million, so a R5 million fine is a deliberate signal that the Regulator is willing to use the tool.

What the fines have actually achieved

The record of the fines the Regulator has imposed is thin. The Regulator disclosed R5 million fines against both the Department of Justice and the Department of Basic Education. The Justice fine is still in litigation. The Basic Education fine was set aside by the High Court, in December 2025 according to Moonstone. The R500,000 fine against Blouberg Municipality was halved to R250,000 after a court challenge. The smaller R100,000 fine against the Electoral Commission was paid. Of the fines the briefing described, the ones that survived scrutiny were the small ones.

That pattern has a cost beyond the failed cases. A fine on a government department is paid out of a public budget, so it reduces the money available for the security upgrades the fine is meant to prompt. Litigation between two arms of the state also consumes legal budgets on both sides for years. The department is not deterred and the citizen whose data leaked is not helped. Where the target is a private company, a fine at least changes a profit calculation. For a department, the effect is much weaker.

The SABS notice is the better model

The more promising step in the briefing was the enforcement notice to the South African Bureau of Standards (SABS). The Regulator opened an own-initiative assessment after SABS's 2024 ransomware attack. Per Werksmans, it found problems including excessive or irrelevant processing, inadequate consent mechanisms and insufficient security safeguards. SABS has 90 days to revise its policies, carry out personal information impact assessments and put protective measures in place.

This is proportionate regulation in practice. It gives the organisation a defined list of things to fix and a deadline, and it lets the Regulator verify the fix. It is also harder to challenge on procedural grounds than a large penalty, and the order concerns future conduct, which is what actually reduces harm. The test will come after the 90 days. If SABS complies, the notice becomes a template for the thousands of organisations reporting breaches. If it does not, the Regulator has a clear escalation route with a documented record.

Volume is not the same as harm

The headline breach count needs careful reading. A rise in notifications can partly reflect better reporting, since POPIA's section 22 notification duty has been in force for years and awareness is growing. A regulator should not treat a rising count as proof of rising negligence. It also cannot investigate every notification. The Regulator will have to triage by the sensitivity of the data, the number of people affected and whether the organisation had reasonable safeguards in place before the incident.

The Regulator's own capacity matters too. On the PAIA side, Werksmans reports that only 417 of 853 public bodies (about 49%) submitted their annual reports. That shows how much of the compliance gap sits inside government itself. A regulator that is stretched across both statutes does better when it publishes clear guidance and follows through on a few well-chosen orders than when it fines widely and loses in court.

Open questions on private-sector targets

The Regulator also confirmed continuing investigations, including into Truecaller and the Gauteng Department of E-Government. The Truecaller inquiry will be the more interesting test for the tech sector. Caller-ID and contact-sharing services raise real questions about consent when a user uploads an address book containing other people's numbers. The Regulator should set out which specific POPIA conditions it thinks were breached, and should publish its reasoning, so that developers can build compliant products. Investors and startups need predictable rules, and an investigation announced by briefing without a published legal theory does not provide them.

What the Regulator should do next

Three things follow from the record. First, prefer enforcement notices with deadlines and public follow-up to headline fines, especially against public bodies. Second, when it does fine, make sure the reasoning is strong enough to survive court review, because each reversal weakens the next case. Third, publish a triage framework that separates negligent breaches from breaches suffered despite reasonable safeguards. South Africa's data protection regime is only ten years old. Its credibility will come from orders that stick and rules that businesses can predict, not from the size of the penalty announced.

Sources & Citations

  1. POPIA Section 19: Security measures
  2. POPIA Section 109: Administrative fines
  3. Information Regulator media statements
  4. Werksmans: The Regulator is Watching
  5. Moonstone: Information Regulator sounds alarm over data breaches