South Africa's Information Regulator marked ten years of existence on August 31, 2026 with a briefing that doubled as a case for more power. Chairperson Advocate Pansy Tlakula disclosed that the body — formally established in December 2016, with POPIA's enforcement provisions live for five years now — has logged more than 8,000 security-compromise notifications since enforcement began, including over 1,220 in the first five months of the 2026/27 financial year alone, a pace the Regulator projects will top 3,000 for the year. Alongside a fresh 90-day compliance order against the South African Bureau of Standards (SABS) over its 2024 ransomware breach, Tlakula named the culprit for the Regulator's underwhelming fine record: POPIA's grace period.
The steelman
The Regulator's frustration is not manufactured. Under the current structure, a responsible party found in violation gets time to remedy the defect — and if it complies within that window, no fine follows, no matter how serious the underlying failure. Tlakula put it plainly: public bodies "comply within the timeframes, and once they comply, we cannot move forward with the fine." With breach notifications trending toward roughly 3,000 a year and South Africa ranking among the world's most-targeted jurisdictions for ransomware and phishing, a regulator that can only fine repeat, defiant non-compliance — not the underlying negligence — has a real deterrence gap. Moving toward the GDPR model, where a fine attaches the moment non-compliance is established, would align South Africa with the EU standard many local exporters already have to meet contractually, and it would stop organizations treating a POPIA notice as a compliance deadline extension rather than a violation finding.
But the fine record so far is a caution, not a mandate
The Regulator's own track record complicates the case for immediate, GDPR-style penalties. It has issued exactly two administrative fines at the R5-million ceiling that survived enforcement notices ignored past their grace period: one against the Department of Justice in 2023, for letting antivirus licensing lapse and then failing to act on a remedial notice, and one against the Department of Basic Education in November 2024, for publishing matric results by examination number.
The second of those fines no longer exists. A full bench of the Pretoria High Court — Mooki J, with Molopa-Sethosa J and Morgan AJ concurring — set aside both the enforcement notice and the R5-million infringement notice on December 12, 2025, ruling that an exam number that identifies nobody without extraneous knowledge is not "personal information" under POPIA at all, and ordered the Regulator to pay costs. The Department of Basic Education's own account of the litigation, and the government's public confirmation that the court had reserved judgment before ruling against the Regulator, are both on the public record. The Regulator's application for leave to appeal was refused on June 3, 2026 — three months before it stood at a podium arguing it needs the power to fine faster.
That sequence matters because the grace period is not only a shield for negligent responsible parties — it is also the buffer that let this dispute reach a court instead of extracting R5 million from a department for conduct three judges found lawful. Removing it doesn't just speed up punishment of clear-cut violators like the Department of Justice; it also compresses the runway for good-faith disagreements about what POPIA actually covers, of which the matric-results case shows the Regulator's own reading can be wrong.
SABS shows the better template
The SABS order, by contrast, is closer to what proportionate enforcement should look like. Rather than reaching for a fine against an entity already recovering from a ransomware attack, the Regulator ran an own-initiated assessment, found specific POPIA failures — excessive data retention, weak consent mechanisms, inadequate security safeguards — and gave SABS 90 days to fix them under a compliance order. That is deterrence calibrated to capacity: it forces remediation without extracting scarce public funds from a body still restoring its systems, and it leaves the fine in reserve for the genuinely defiant, the way the Department of Justice case used it.
What real reform should target
There is a legitimate legislative fix here, but it isn't a blanket removal of the grace period. POPIA's statutory ceiling of R10 million per contravention already dwarfs the Regulator's actual output — it has hit the R5-million mark exactly twice in a decade, and lost one of those two on appeal. If the goal is GDPR-equivalent deterrence, Parliament would also need to revisit that flat cap, since the EU regime scales fines to global turnover, not a fixed rand figure. A narrower reform — preserving the grace period for good-faith, first-time findings while allowing immediate fines only where a party ignores a prior enforcement notice, the fact pattern in the Justice Department case — would close the actual gap the Regulator has identified without inviting more DBE-style reversals. Given that the Regulator is simultaneously flagging its own staffing and technical-capacity constraints, tightening how it uses existing tools should come before Parliament hands it a faster trigger.