In May 2026, the Information Regulator issued a POPIA enforcement notice against the Central Johannesburg TVET College after a staff member accidentally emailed colleagues a folder that contained three employees’ credential-verification reports. The striking feature of this particular enforcement notice is not the mistake itself; it is what the mistake exposed. The Regulator’s findings turned on the compliance foundations that were missing long before anyone hit “send”.
For any organisation that processes employee or customer data, the notice is a compact lesson in why POPIA compliance is structural, not incidental.
Key takeaways
- A single human error escalated into a multi-front enforcement action because the underlying compliance architecture was absent: no registered Information Officer, no compliance framework, no staff training, and poor separation of sensitive files.
- Registering the Information Officer and deputies with the Regulator is a legal duty under section 55. Its absence was treated both as an accountability breach (section 8) and as evidence of inadequate security measures (section 19).
- “Legitimate purpose” and “public interest” are not bases for further processing under section 15. To share personal information for a new purpose, you must fit a lawful basis in section 15(3), such as consent.
- The breach-notification duty in section 22 is independent and unforgiving. Recalling the email, investigating, and apologising internally did not discharge the duty to notify the Regulator and the affected data subjects.
- POPIA’s enforcement teeth are sharper than PAIA’s: non-compliance with the notice is an offence carrying a fine or up to ten years’ imprisonment, and the remedy against the notice is an appeal to the Regulator under section 97, within 30 days.
What happened
The college had been placed under administration to restore governance, including verifying employees’ qualifications and requiring declarations of criminal records and conflicts of interest. To do this it collected personal credential-verification reports on staff.
In the course of rolling out new finance policies, the Acting Chief Financial Officer mistakenly included three employees’ verification reports in a folder of policy documents and emailed it to various staff. The affected employees learned of it on 6 September 2022. The Administrator recalled the email on 8 September, explained that the distribution was an error, and took corrective action against those who had forwarded it.
The three employees complained to the Regulator. After an investigation and an Enforcement Committee report, the Regulator found that the college had interfered with the protection of their personal information, and issued a section 95 enforcement notice.
What the Regulator found
The notice is useful because it works through several POPIA conditions in turn and records where the Regulator parted ways with its own Enforcement Committee.
Accountability (Condition 1, section 8)
The college had neither registered its Information Officer with the Regulator nor designated and registered deputy information officers. Because the Information Officer is responsible for POPIA compliance, the Regulator treated this as a foundational accountability failure.
Further processing (Condition 4, section 15)
The verification reports had been collected to strengthen governance. Sharing them with staff who had no role in that exercise was “further processing” that was incompatible with the original purpose, and no lawful basis under section 15(3)—including consent—applied.
Notably, the Regulator overruled its Enforcement Committee here. The Committee had concluded there was no section 15(1) breach because the processing served a “legitimate purpose” and was “in the public interest”. The Regulator rejected that reasoning, pointing out that those concepts do not appear in section 15(3) and cannot be read into the compatibility test.
Security safeguards and breach notification (Condition 7, sections 19 and 22)
Storing the verification reports in the same folder as finance policies, combined with the unregistered Information Officer, pointed to an absence of the organisational measures section 19 requires. That was a section 19 breach.
Separately, the misdirected email was a security compromise that triggered the section 22 duty to notify both the Regulator and the affected data subjects. None of them was notified. The internal staff email recalling the document did not satisfy that statutory obligation, so the Regulator found a section 22 breach as well.
What the Regulator did not find
Two allegations failed, which is equally instructive:
- The Regulator agreed with the Committee that the initial collection and verification did not breach the processing-limitation condition (section 11), because the college had a legitimate-interest basis for it.
- It also found no breach of the prohibition on processing special personal information (section 26(b)). The one verification report in evidence contained only a name, identity number, date of birth and contact number, no criminal-record or other special data.
The orders
The remedies are far more demanding than a simple “fix it”, and several are public-facing:
- Register the Information Officer (section 55(2)) and designate and register deputies, with proof to the Regulator within 31 days.
- Notify the Regulator and the affected data subjects of the security compromise under section 22, with proof within 31 days.
- Issue a written apology to the complainants, emailed to all employees and published across all the college’s communication channels, with proof within 31 days.
- Take disciplinary action against the employee who shared the information, with proof within 60 days.
- Submit a POPIA compliance framework—privacy notice, retention policy and schedule, incident-response policy, and information-privacy-and-security policy—within 31 days (or develop one within 120 days if it does not exist).
- Conduct POPIA awareness and training for all staff, with proof within 90 days.
What this means for your organisation
For information officers and executives
Register your Information Officer and deputies with the Regulator now if you have not already. This decision shows the Regulator treating non-registration not as a technicality but as evidence that an organisation lacks the governance to process personal information safely.
For HR and people functions
Employee data is a frequent source of POPIA exposure. Verification reports, qualifications, and conduct records are collected for a defined purpose, and circulating them more widely—even internally, even by mistake—can amount to incompatible further processing. Separate sensitive files from general working documents.
For IT, security and incident response
A misdirected internal email is a notifiable security compromise. Build a section 22 response that runs in parallel with any internal remediation: recalling the message and disciplining staff is good practice, but it does not replace notifying the Regulator and the data subjects.
For compliance and risk leads
The orders here—framework, training, public apology—are the components of a programme the college should have had in place beforehand. The cheapest version of this notice is the one you never receive, by standing the framework up in advance.
Appeal and consequences
Because this is a POPIA matter, the college’s remedy is an appeal to the Regulator under section 97(1), within 31 days of receiving the notice — not the court route that applies to access-to-information decisions under PAIA. Failure to comply with the notice is an offence carrying a fine or imprisonment of up to ten years, or both.
It is worth noting the contrast with the access-to-information enforcement notices issued by the same Regulator on the same day. Those run under PAIA, are challenged in court under section 82, and carry a three-year maximum. This POPIA notice underlines the Regulator’s dual mandate — and the heavier penalties on the data-protection side.
FAQs
Do you have to register your Information Officer with the Information Regulator?
Yes, registering the Information Officer (and any deputies) is required under section 55 of POPIA. In this matter, the failure to register was treated as both an accountability breach and a sign of inadequate security measures.
Is an accidental email containing personal information a POPIA breach?
It can be. Sharing personal information beyond its original purpose is “further processing” that must have a lawful basis under section 15(3); if it does not, the disclosure breaches POPIA even when it was a mistake. A misdirected email may also be a security compromise that must be reported under section 22.
What must an organisation do after a personal information breach in South Africa?
Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, section 22 requires the responsible party to notify both the Regulator and the affected data subjects. Internal corrective steps do not discharge this duty.
Can “legitimate interest” or “public interest” justify further processing under POPIA?
Not as free-standing grounds for further processing. Section 15(3) sets out the bases on which further processing is compatible with the original purpose; “legitimate purpose” and “public interest” are not among them. The Regulator made this point expressly in overruling its Enforcement Committee.
What are the penalties for ignoring a POPIA enforcement notice?
Failure to comply with an enforcement notice is an offence. On conviction it carries a fine or imprisonment of up to ten years, or both.
How do you challenge a POPIA enforcement notice?
A responsible party may appeal to the Information Regulator under section 97(1) of POPIA within 30 days of receiving the notice.
This article is provided for general information and does not constitute legal advice. It discusses a public regulatory decision; no confidential personal information of the data subjects is disclosed. If your organisation needs to register an Information Officer, respond to a personal-information breach, or build a POPIA compliance framework, ITLawCo would be glad to assist. Contactez-nous.




