On 8 June 2026, the Information Regulator issued a PAIA enforcement notice against the Gauteng Department of Health, ordering it to release records it had already agreed to disclose more than a year earlier. The Gauteng Department of Health enforcement notice is a study in what happens when a public body treats a Settlement Certificate as optional, and it carries pointed lessons for government departments, information officers, and anyone seeking records from the state.
This article explains what was requested, how the Department’s conduct unravelled over two years, and what the Regulator’s order means for the access-to-information landscape.
Key takeaways
- Deemed refusal—the failure of a public body to respond to a request within the statutory period—is itself a PAIA breach, and it is not cured by later engaging in settlement.
- A Settlement Certificate issued by the PAIA Division under reg 12(4) as per form 10 of Annexure A is binding. Failing to honour it is a separate and serious failure; one that the Settlement Certificate itself contemplates will result in Enforcement Committee referral.
- Bare assertions of compliance, unsupported by explanation or evidence, will not satisfy the Regulator when a complainant has placed specific, uncontroverted proof of non-disclosure on the record.
- For public bodies, access to records is peremptory under section 11 of PAIA. Unlike requests to private bodies, no rights-based justification is required from the requester; the burden falls entirely on the body to justify any withholding.
- Non-compliance with this enforcement notice is an offence under section 77K of PAIA, carrying a fine or up to three years’ imprisonment.
Background: records, a settlement, and a broken promise
The records sought
In July 2023, journalist Jeffrey Wicks submitted two requests to the Department under PAIA:
- A schedule of payments to suppliers and service providers of Mamelodi Hospital for transactions between R300 000 and R499 999, covering January 2020 to June 2023, including purchase order details, supplier names, B-BBEE certificates, and company registration documents (“the Mamelodi Hospital Records”).
- All internal audit reports and annexures generated by the Department’s Chief Directorate: Audit and Compliance between January 2020 and January 2023 (“the Audit Reports Records”).
The broader context provided by the complainant was significant. The requests related to the investigation into the assassination of Ms Babita Deokaran, the Department’s then Chief Director of Financial Accounting, who had been investigating allegations of widespread fraud and corruption in the Department.
Deemed refusal and the settlement
The Department never responded to either request, nor to the subsequent internal appeal lodged in September 2023. Its silence constituted deemed refusal under section 27 of PAIA at the request stage and deemed dismissal under section 77(7) at the appeal stage.
The complainant then approached the Information Regulator’s PAIA Division in March 2024. After the Division engaged the Department, the parties concluded a Settlement Agreement on 30 July 2024. Under the resulting Settlement Certificate, the Department agreed to grant access to the requested records, with certain personal information redacted, within 30 days.
That should have been the end of the matter.
Post-settlement non-compliance
It was not. By September 2024—more than 30 days after the Settlement Certificate—the complainant reported that no audit reports had been disclosed and certain purchase orders were missing. What followed was a protracted process over nearly a year:
- The Department told the PAIA Division in March 2025 that it had fully complied; it had not.
- In April 2025, more than seven months after the deadline, the Department emailed a single audit report. The complainant showed it was not the same report he had independently obtained and sent to the PAIA Division as evidence of non-disclosure.
- The Department’s spokesperson had publicly stated that the internal team had conducted audits “across facilities”, yet the Information Officer deposed to an affidavit in August 2025 stating that only one report existed within the scope of the request. No explanation was offered for the contradiction.
- Purchase orders eventually provided to the complainant in June 2025 turned out to be ones he already held, submitted by him originally as a sample to demonstrate non-compliance, not as the requested records themselves.
The Department’s assertions of compliance were, throughout, uncontroverted denials in the face of specific, documented proof of non-disclosure.
What the Regulator found
The settlement certificate is binding
The Regulator made clear that a Settlement Agreement is not aspirational. It is contractually binding on the parties, and the Department’s repeated, incorrect assertion that it had complied demonstrated a fundamental failure to honour its obligations. The Regulator agreed with the Enforcement Committee that the Department had blatantly disregarded the Settlement Agreement.
The evidentiary burden and bare denial
This enforcement notice presents the evidentiary dynamic in reverse from a typical commercial refusal case. Here, there was no claimed ground of refusal to evaluate; the Department had agreed to disclose everything. The question was whether it had. Against specific, uncontroverted evidence of non-disclosure (known purchase order numbers, a specific audit report the Department never addressed), a bare affidavit asserting compliance was insufficient.
The Regulator found that the Information Officer’s affidavit of August 2025 “does not contain sufficient details and explanations on submissions raised by the Complainant” and that the Department’s failure to explain or respond to the audit report provided by the Complainant as Annexure CD3 was particularly damaging.
Deemed refusal and constitutional duty
The Regulator also recorded that the Department’s original failure to respond to either the requests or the internal appeal was itself a constitutional failure. Under section 11 of PAIA, a public body must grant access to records unless it can establish a ground of refusal. The Department never even attempted that; it simply did not respond. The Regulator described this conduct as unacceptable and noted it left the complainant with no option but to approach the PAIA Division.
The second complaint and procedural observation
When the Department failed to honour the Settlement Certificate, the PAIA Division advised the complainant to lodge a new complaint, which was given reference CI 392/24. The Regulator disagreed with this approach, observing that the Settlement Certificate itself provided that non-compliance would result in referral to the Enforcement Committee. A second complaint was unnecessary procedural duplication. This is a useful operational note for both requesters and the PAIA Division.
The orders
The notice directs the Information Officer to:
- Grant access to all internal audit reports and annexures within the scope of the original request, in full compliance with the Settlement Certificate, accompanied by an index page identifying each report disclosed.
- In the event any report cannot be found or does not exist, depose to an affidavit setting out all steps taken to find it, all communications with those who conducted the search, and confirmatory affidavits from those persons.
- Procure an affidavit from the Department’s spokesperson providing a detailed explanation of statements made publicly about the scope and findings of the audit programme, together with any supporting documents.
- Grant access to the Mamelodi Hospital payment schedule in full compliance with the Settlement Certificate, with a cover page and index, within 15 days.
- In the event any records cannot be found, depose to a similar search affidavit.
- Disclose all records and deliver all affidavits electronically within 15 days.
- Comply with the notice in full within 31 days of receipt.
The spokesperson-affidavit order is notable. It is unusual for an enforcement notice to require a named official to explain public statements, and it reflects the Regulator’s view that the contradiction between the spokesperson’s public acknowledgement of multiple audits and the Information Officer’s sworn statement that only one exists required an explanation, not silence.
What this means for your organisation
For information officers of public bodies
Deemed refusal is not a neutral state; it is a breach of a constitutional obligation. And, it does not disappear when a settlement is later reached. Register your response timelines, respond within the statutory periods under sections 25 and 77 of PAIA, and if records cannot be found, say so formally with a proper search affidavit. Do not simply stay silent.
For compliance and legal teams at government departments
A Settlement Certificate is a binding commitment, enforceable through the Enforcement Committee route. Treating it as a target rather than a deadline, or asserting compliance without being able to demonstrate it, creates compounded exposure. The cost of the settlement process and, now, the enforcement notice, is far greater than prompt disclosure would have been.
For requesters and public-interest litigants
Specific evidence of non-disclosure—e.g., known purchase order numbers, a copy of an undisclosed document—is more powerful before the Regulator than a general complaint about incompleteness. This case shows that an uncontroverted, specific evidential record will defeat a bare denial, even a sworn one.
For journalists and researchers
The access-to-information framework applies equally to public bodies, and the peremptory language of section 11 means that once procedural requirements are met and no ground of refusal is established, disclosure is mandatory, not discretionary. The Brummer and M&G Media constitutional court decisions, cited in this notice, confirm that transparency is a founding constitutional value, and that it is impossible to hold a government accountable that operates in secrecy.
Appeal and consequences
As a PAIA enforcement notice issued against a public body, the Information Officer may apply to court under section 82 for appropriate relief, after notifying the Regulator of that intention within 10 working days and bringing the application within 180 days of receipt. Non-compliance is a criminal offence under section 77K, carrying a fine or up to three years’ imprisonment.
One structural note: the compliance period stated in the notice is 31 days from receipt, but the operative orders for record disclosure and affidavit delivery specify 15 days. These are not reconciled in the notice—the same internal tension visible in the Sibanye-Stillwater enforcement notice of May 2026.
FAQs
What is deemed refusal under PAIA?
Deemed refusal occurs when a public body fails to respond to a PAIA request within the statutory period (generally 30 days under section 25), or when an internal appeal is not decided within the period under section 77(3). The silence is treated as a refusal, entitling the requester to pursue the complaint or court route.
Is a PAIA settlement certificate legally binding?
Yes. A Settlement Certificate issued by the Information Regulator’s PAIA Division following a facilitated settlement under section 77F records the terms agreed between the parties. It is binding on both parties, and failure to comply with it is grounds for referral to the Enforcement Committee without the need for a new complaint.
Does a journalist need to give reasons for a PAIA request to a public body?
No. Under section 11(3) of PAIA, a requester’s right of access to records held by a public body is not affected by the reasons given for the request, or by the information officer’s belief about those reasons. The requester must comply with procedural requirements; the body must then grant access unless it can establish a ground of refusal.
What happens if a public body says it has complied but the requester disputes this?
The Regulator will assess the evidence from both parties. As this notice demonstrates, a bare assertion of compliance—even under oath—will not prevail against specific, uncontroverted evidence of non-disclosure. The body must be able to demonstrate compliance, not merely assert it.
Can the Information Regulator require a named official to explain public statements?
This notice suggests yes, in appropriate circumstances. The Regulator ordered the Department’s spokesperson to provide a sworn explanation of public statements about the audit programme that appeared to contradict the Information Officer’s position. Where public statements by officials bear directly on compliance disputes, the Regulator may require an account.
What are the consequences for non-compliance with a PAIA enforcement notice against a public body?
Non-compliance is a criminal offence under section 77K of PAIA, carrying a fine or imprisonment of up to three years, or both. The aggrieved body may challenge the notice by applying to court under section 82 within 180 days.
This article was prepared by the ITLawCo Information Law team. ITLawCo advises public and private bodies on PAIA, POPIA and information governance in South Africa.
This article is provided for general information and does not constitute legal advice. It discusses a public regulatory decision and publicly available information; no confidential information is disclosed. If your organisation needs to respond to a PAIA request, assess a compliance framework, or navigate an Information Regulator process, ITLawCo would be glad to assist.




