South Africa Information Regulator 2026/27 Annual Performance Plan:
Enforcement, Capacity, and What It Means for POPIA Compliance
Visual overview of key findings, statistics, structural tensions, and implications from the stakeholder consultation session, 5 March 2026.
Modest Tools
the Session Told
Must Address
Comfortably Persist
Its International Distinction
A public consultation on the 2026/27 Annual Performance Plan revealed an enforcement body that has come a long way in a decade and an organisation under genuine strain. Breach notifications have increased fifteenfold in five years, the fine ceiling sits at a fraction of GDPR levels, fewer than one in five companies has registered an information officer, and the Regulator’s own CEO publicly acknowledged it struggles to respond promptly. The ambitions are real and so are the constraints.
Who should read this article?
This analysis is written for professionals operating at the intersection of law, technology, and governance. Role-specific relevance is as follows:
| Data protection lawyers | POPIA enforcement precedents, proposed amendments, PAJA constitutional risk, WhatsApp settlement implications, and the OUTsurance telemarketing test case. |
| Compliance officers | Information officer registration obligations (Section 55), the monitoring exercise, the forthcoming PIIA guidance note, and the gated-access code of conduct. |
| Regulators & policymakers | Comparative fine regime analysis, dual-mandate governance architecture, AI/Section 71 gap, and the resource-versus-mandate structural constraint. |
| Technologists & AI teams | Section 71 automated decision-making rights, biometric special personal information under Section 26, AI Act cross-border obligations, and PIIA/DPIA alignment. |
| Civil society & public bodies | The 70% public awareness gap, outreach programme reach, information officer obligations for public bodies, and PAIA access rights. |
Key statistics at a glance
| Metric | Figure | Period / Source | Significance |
| Security compromise notifications | 2,898 (in-year) | 2025/26, to 5 Mar 2026 | Fifteenfold increase since 2021/22 |
| Finalised security compromises | 1,578 | 2025/26 to date | 1,320 open; capacity gap |
| Simple complaints (active caseload) | 1,681 | As at 1 Apr 2025 | Target: 70% resolved in 3 months |
| Complex complaints (active caseload) | 373 | As at 1 Apr 2025 | Target: 50% resolved in 12 months |
| Registered information officers | 69,040 | 5 Mar 2026 | ~14% of ~490,000 CIPC-active companies |
| Sectoral assessments conducted | 35 | 2021–2026 | Banks, telcos, govt, retail, higher ed |
| Maximum administrative fine (POPIA) | R200,000 to date (≈ €10,000) | Fixed statutory ceiling | vs GDPR €20m / 4% global turnover |
| Public awareness of IR existence | 30% | 2023 public opinion survey | 70% of SA public unaware |
| Staff headcount | ~130 | 5 Mar 2026 | Single Gauteng location; no regional offices |
The enforcement picture: Extraordinary numbers, modest tools
A fifteenfold increase in five years
In 2021, the first full year that the South African Information Regulator’s enforcement powers were operational, it received 202 security compromise notifications. By the 2024/25 financial year that figure had reached 2,374. In the current year—2025/26, not yet complete—the in-year total already stands at 2,898.
From 202 to 2,898 in under five years is a roughly fifteenfold increase. It is one of the most striking data points in South African regulatory governance, and it was presented at a public stakeholder session in Mpumalanga on 5 March 2026 with almost no interpretive framing.
The increase almost certainly reflects two distinct phenomena operating simultaneously.
- The first is a genuine deterioration in the South African data security environment. A May 2025 report by Independent Online cited cybersecurity analysts to the effect that cyber attacks now represent a greater economic risk to South African organisations than load shedding, a comparison that, in the South African context, is striking.
- The second is a reporting normalisation effect: as POPIA’s breach notification obligations (Section 22) become better understood and the Regulator’s own awareness campaigns bring more organisations into the compliance ecosystem, incidents that would previously have gone unreported are now being disclosed.
Advocate Tsehpo Boikanyo, the Regulator’s POPIA executive, acknowledged this dynamic at the session. The two effects are not mutually exclusive, but they have quite different policy implications: one signals a security crisis requiring urgent industry intervention; the other signals a compliance culture beginning to take root. The Regulator did not attempt to disaggregate them, and stakeholders were not invited to interrogate the distinction.
How South Africa Ccmpares to peer regulators
For context: the UK Information Commissioner’s Office (ICO) receives approximately 14,000 to 16,000 breach reports annually across an economy roughly three times the size of South Africa’s by GDP. Ireland’s Data Protection Commission—whose jurisdiction encompasses the European headquarters of most major US technology companies—received around 7,000 breach notifications in 2024. South Africa’s in-year total of 2,898, for an economy at a much earlier stage of regulatory maturity, is not obviously out of proportion. What is striking is the rate of change, which suggests the reporting infrastructure is still being built rather than operating at steady state.
We are not where we should be. We are pushing that we should be a responsive organisation. I must be honest about that.
Against this volume, the Regulator has finalised 1,578 of the current year’s compromises. The gap—1,320 open matters at the current run rate—is a function of institutional capacity rather than regulatory will. CEO Mosalanyane Mosala did not obscure this. His admission that the Regulator “struggles with responsiveness” is, for an enforcement body whose deterrent effect depends substantially on the credibility of its follow-through, a significant statement. A regulator that cannot process breach notifications within a reasonable timeframe cannot credibly signal to the market that non-compliance carries consequences.
The fine ceiling problem
The deterrence question has a second dimension the session surfaced but did not adequately address: the maximum administrative fine available under POPIA is R10,000,000. In absolute terms, this is the equivalent of approximately €520,000 at current exchange rates.
| Jurisdiction / Framework | Maximum Administrative Fine | Basis |
| South Africa (POPIA) | R10,000,000 (≈ €520,000) | Fixed ceiling |
| European Union (GDPR) | €20 million or 4% global turnover | Tiered, higher of two |
| United Kingdom (UK GDPR) | £17.5 million | Tiered |
| Brazil (LGPD) | 2% of Brazilian revenue, cap R$50m | Per-infringement |
The Lancet Laboratories matter—concerning the mishandling of sensitive health information—resulted in a payment of R200,000. FT Rams declined to pay its fine at all, presumably calculating that litigation was commercially rational.
Adv Boikanyo disclosed that the Regulator is processing draft amendments to POPIA with one stated objective: moving away from the current “correct and remedy” framework under which a responsible party is typically afforded an opportunity to remediate a contravention before an infringement notice is issued—towards a regime of more direct consequences for intentional non-compliance.
This is a meaningful reform signal, but it requires careful analysis of two distinct questions the session conflated:
- first, whether the prior remediation step should be removed or curtailed; and
- second, whether the fine ceiling itself should be raised.
These are separable questions with different legal and political trajectories, and the Regulator has not publicly confirmed which it will address, or both.
The constitutional dimension also warrants attention. The current remediation-first framework exists in part because of the Promotion of Administrative Justice Act (PAJA) and Section 33 of the Constitution, which guarantee procedurally fair administrative action. A regime moving directly to financial penalty will need to demonstrate its procedural safeguards satisfy the PAJA standard or face challenge from well-resourced responsible parties. The WhatsApp and Department of Justice matters already indicate that the Regulator’s enforcement decisions attract legal challenge; a more aggressive fine regime will attract more of it.
Institutional capacity: The structural story the session told
The information officer registration gap
The most revealing data point of the entire session was not the security compromise figures. It was a number mentioned in passing: 69,040 information officers are currently registered with the Regulator.
The Companies and Intellectual Property Commission (CIPC) maintains approximately 490,000 active company registrations. The Regulator’s own figures therefore imply that roughly 14% of South African registered companies have complied with their Section 55 POPIA obligation to register an information officer, nearly five years after enforcement powers came into force on 1 July 2021. If one includes close corporations and other legal persons with POPIA obligations, the compliance rate may be lower still.
This is not a marginal compliance gap but a structural one. It raises a question the session did not address: what does the Regulator intend to do about the 86% of registrable entities that have not complied with the most basic administrative obligation the legislation imposes?
130 people, one location, one national mandate
The Regulator employs approximately 130 people, operates from a single base in Gauteng with no regional offices, and—at the time of the session—had been operating without physical premises for a period, planning to return on 16 March 2026. An organisation of 130 people with a single location is being asked to regulate the data protection behaviour of every public body, every private company, and every other juristic person in a country of 61 million people. The structural gap between mandate and capacity is the defining constraint of the Regulator’s current position.
CEO Mosala addressed governance structures at length: the Section 49 committees, the Enforcement Committee, the audit and risk oversight mechanisms. But these are internal accountability instruments rather than solutions to the capacity constraint. The more important question, which the session did not answer, is whether the National Treasury’s fiscal envelope for the Regulator will expand materially in the third planning term beginning 2027, and whether Parliament will fill the two current vacancies in time to provide continuity into the new term.
If you can’t do big things in life, do small things but do them in a big way. That’s where excellence comes in for us.
APP targets and the responsiveness standard
The 2026/27 APP targets for complaint resolution—50% of complex complaints within 12 months, 70% of simple complaints within 3 months—are improvements on current performance but fall well short of the standard that data subjects seeking timely redress would consider adequate.
The GDPR’s Article 78 right to an effective judicial remedy specifically contemplates that data subjects may go directly to court where a supervisory authority has not handled a complaint “within three months”. South Africa’s comparable provisions impose no equivalent procedural discipline on the Regulator’s responsiveness. Mosala’s frank self-assessment was given in the spirit of transparency. But transparency about a deficit is not the same as a plan to address it.
Legislative reform: What the amendments will and must address
Direct marketing: The OUTsurance test case
The Regulator’s position on direct marketing is clear: telephone calls fall within the statutory definition of “electronic communications”, bringing telemarketing calls squarely within POPIA’s opt-in consent regime. Responsible parties, including members of the Direct Marketing Association of South Africa (DMASA), dispute this interpretation.
The test case involving OUTsurance, currently before the Enforcement Committee, will produce a determination that either validates the Regulator’s position or requires legislative clarification. Either outcome is significant: agreement creates a compliance obligation affecting hundreds of South African businesses overnight; disagreement requires parliamentary amendment. DMASA CEO David Dickens noted that his organisation’s 250-plus members are ready to implement guidance once it arrives.
The Section 60 code of conduct bottleneck
Approved codes of conduct have the potential to be powerful compliance instruments, allowing industry bodies to develop sector-specific standards with regulatory endorsement. DMASA has submitted a code of conduct twice, receiving it back with revision requests on both occasions. The slow progress of the DMASA code—the largest such submission received to date—suggests that the Regulator’s code assessment capacity is a bottleneck the amendments should explicitly address. The Regulator confirmed at the session that it will return to physical premises on 16 March 2026 and invited fresh submissions immediately.
Gated-access code of conduct
The Regulator is developing a code to regulate access control systems—biometrics, CCTV, vehicle registration readers, visitor logs—at residential estates, business parks, and other gated establishments. Approximately five million South Africans live in gated residential developments. The code will address transparency obligations, retention limits, and safeguards against misuse or over-collection of personal information. Adv Boikanyo indicated it is in advanced development; its publication will be a meaningful addition to the POPIA compliance landscape.
The AI question: A governance gap the regulator has not yet addressed
Thirty seconds that deserve a full policy programme
The most intellectually important exchange of the session lasted approximately thirty seconds. Wanani Sitsula, representing the Consumer Goods and Services Ombud, asked the Regulator what plans it has to mitigate the risks associated with AI. No specific programme was announced. The question was noted, and the session moved on.
This is a governance gap that cannot comfortably persist. The European Union’s AI Act entered its first phase of application in February 2025, prohibiting a list of unacceptable AI practices and imposing obligations on providers and deployers of high-risk AI systems. South African companies with EU-facing operations are already subject to its obligations.
Section 71: POPIA’s unused automated decision-making provision
More immediately, POPIA already contains provisions directly relevant to automated decision-making. Section 71 provides that a data subject has the right not to be subject to a decision that results in legal or similarly significant consequences where that decision is based solely on automated processing of personal information, unless the responsible party can establish a lawful ground and has taken steps to safeguard the data subject’s legitimate interests.
The right articulated by Section 71 is structurally analogous to Article 22 of the GDPR. But unlike the GDPR, which has generated substantial regulatory guidance from the European Data Protection Board and national supervisory authorities, Section 71 of POPIA has received almost no regulatory elaboration in South Africa. There is no guidance note, no case study, no published enforcement position.
As AI-driven credit scoring, automated insurance underwriting, algorithmic hiring tools, and predictive policing applications become more prevalent in the South African market, the Regulator’s silence on Section 71 is an increasingly significant gap. It is also a gap with immediate commercial implications: responsible parties deploying AI systems have no authoritative regulatory reference point against which to assess their POPIA compliance exposure.
AI, biometrics, and the special personal information regime
The interaction between AI governance and the Regulator’s mandate extends beyond automated decisions. The processing of training data for AI models raises purpose limitation questions under POPIA’s Condition 2. Facial recognition systems, in active deployment at the access-controlled estates the Regulator’s proposed gated-access code seeks to regulate, involve the processing of biometric information: a category of “special personal information” under Section 26, attracting heightened protection and explicit consent requirements. The intersection of AI system deployment and POPIA’s special category regime has not been addressed in any published Regulator guidance.
The PIA guidance note as an AI governance vehicle
Adv Boikanyo confirmed that the Regulator intends to publish a guidance note on Personal Information Impact Assessments (PIIAs) in the coming financial year. A well-designed PIIA framework would provide a vehicle for integrating AI risk assessment into POPIA compliance programmes, analogous to the EU’s DPIA requirements under GDPR Article 35. The Regulator would be well-advised to draft its PIIA guidance with AI use cases explicitly in scope. The legislative and conceptual architecture for addressing AI risk already exists within POPIA; what is missing is the regulatory will and capacity to deploy it.
A note of balance is warranted here. AI governance is a domain in which regulators globally are still developing coherent frameworks. The EU AI Act itself has only recently entered application, and its interaction with the GDPR remains contested in several member states. It would be unreasonable to expect the South African Regulator—with 130 staff and a contested enforcement budget—to have produced a comprehensive AI governance framework in advance of jurisdictions with far greater resources. The reasonable expectation is that Section 71 guidance and PIIA-AI integration are treated as priorities in the 2026/27 financial year, not deferred to the next planning cycle.
Governance architecture: The dual mandate and its international distinction
Why the dual-mandate model is globally unusual
Advocate Lebogang Stroom, a member of the Regulator, observed almost in passing: South Africa is, globally, among a small group of jurisdictions that vest both access to information and data protection oversight in a single institution. Most countries have either a data protection commissioner or an access to information commissioner, not both. The South African model, in which PAIA and POPIA are administered by the same body, enables a form of cross-referencing that structurally separate regulators cannot perform.
This matters in practice. When a requestor seeks access to information that contains the personal information of a third party, PAIA’s grounds for refusal and POPIA’s processing conditions interact directly. When journalists seek to publish personal information in the public interest, POPIA’s Section 7 exclusion for journalistic purposes operates alongside PAIA’s access obligations. When government bodies deny access to information, the question of whether that denial is itself a data protection issue can only be coherently addressed by an institution that holds both mandates.
The matric results case: The dual mandate in court
The matric results litigation is the live demonstration of this tension. The Department of Basic Education publishes examination results in a format the Regulator argues requires parental consent, on the basis that an examination number constitutes personal information. The Department argues that publication is a legitimate exercise of its public function. At first instance, the court found for the Department. The Regulator is seeking leave to appeal to the Supreme Court of Appeal, with a hearing listed for 12 March 2026. The outcome will define the boundary between the two statutes in one of its most practically consequential configurations.
The WhatsApp settlement and the case for published precedent
The WhatsApp settlement—currently being reduced to a court order—raises questions under both POPIA (lawful processing conditions) and PAIA (user access rights). The substantive terms have not been disclosed, but given WhatsApp’s reach of an estimated 25 million South African users, any compliance undertakings agreed carry significant precedent weight. Other jurisdictions’ regulators have sought to ensure that WhatsApp enforcement decisions produce published precedent. The South African Regulator should consider whether the same approach is warranted here. A settlement reduced to a court order without published reasoning provides little guidance to the 490,000 other responsible parties operating under POPIA.
Codifying jurisprudence: An essential next step
Adv Stroom noted that the Regulator is actively working to analyse and codify the jurisprudence emerging from its Enforcement Committee. Legal certainty for responsible parties depends on consistent, published, and reasoned decisions. If the Regulator’s internal analysis leads to a published compendium of enforcement decisions—analogous to the ICO’s published enforcement case register or the Irish DPC’s decision archive—it would meaningfully advance South Africa’s data protection culture. This is work the 2026/27 planning year should deliver.
Public awareness: The 70% problem
Acting EduCom Executive Nomzamo Zondi opened her presentation with a real-time audience poll. Of approximately 38 respondents at a stakeholder session attended predominantly by compliance officers, lawyers, and regulated entities, 14 (roughly 37%) reported that they did not feel well-informed about the Regulator’s programmes and activities. If 37% of a professionally engaged stakeholder audience lacks adequate information, the figures for the general public are unsurprisingly starker.
The Regulator’s 2023 public opinion survey found that only 30% of the South African public had heard of the Information Regulator at all. The remaining 70% (approximately 43 million people) were unaware of the existence of the body responsible for protecting their personal information and promoting their right of access to information. Awareness was concentrated among tertiary-educated, employed, and digitally connected citizens. Among rural, lower-income, and less-educated communities—precisely those most vulnerable to data exploitation and institutional information gatekeeping—awareness was near-negligible.
This is not a criticism of the EduCom division, which has pursued an outreach programme across seven provinces with evident energy: Free State, KwaZulu-Natal, Mpumalanga, North West, and Northern Cape have all been reached in the past year, with a deliberate focus on district municipalities far from the Regulator’s Gauteng base. NGOs and NPOs have been cultivated as community intermediaries. Social media presence has grown to the point where it is the primary channel through which stakeholders report receiving Regulator communications.
The 70% awareness gap is, however, a structural problem with a structural cause: the Regulator is a single-location organisation with 130 staff and a national awareness mandate. The arithmetic of reaching a general population of 61 million, without regional offices and in a country with eleven official languages and vast digital access disparities, makes the 70% gap the most durable structural challenge the Regulator faces. No APP target addresses it at scale.
What the year ahead holds: Assessing whether the ambition is credible
The Information Regulator’s 2026/27 Annual Performance Plan is, by the standards of a ten-year-old institution that started from nothing, a serious document. The enforcement record comprises 35 sectoral assessments, four completed enforcement matters, a WhatsApp settlement, and a Supreme Court appeal in progress. It represents genuine institutional achievement. The monitoring exercise, the PIIA guidance note, the gated-access code, and the proposed POPIA amendments all signal a regulator that is actively developing its regulatory toolkit rather than standing still.
The question the session should have been asked to answer, but was not, is whether the 2026/27 ambitions are achievable given the structural constraints the Regulator itself disclosed. The answer, assessed candidly, is: partially and unevenly.
The enforcement targets are achievable if the complaints management system performs as intended and investigator headcount grows modestly. They are not achievable if the current rate of complaint volume increase continues without a corresponding increase in investigative capacity. The monitoring exercise is a credible proactive tool, but its effectiveness depends on responsible parties responding honestly to self-certification requests. The Regulator’s own acknowledgment that paper compliance is widespread suggests it will not always get honest answers.
The legislative reform agenda is the most uncertain variable. POPIA amendments require parliamentary passage. The portfolio committee on Justice and Constitutional Development is, by Chairperson Adv Tlakula’s account, currently occupied with the ad hoc committee on police corruption and has not found time to fill two Regulator vacancies. There is no indication that POPIA amendment legislation will be prioritised in the 2026 parliamentary calendar. If the amendments are not passed before the end of the second term of members in November 2026, the third-term Regulator will inherit both the reform agenda and the structural fine ceiling without the legislative tools to address them.
The broader picture that the session revealed, without quite stating, is this: South Africa has built a data protection institution that is now recognisably functioning. It has enforcement powers, a complaints system, an outreach programme, and a governance architecture. What it lacks and what no Annual Performance Plan can substitute for is the resource base proportionate to its mandate, a fine regime with genuine deterrent effect, and the legislative updates that five years of operational experience have shown are necessary. Those are ultimately political and fiscal decisions, not regulatory ones. The Regulator can recommend, advocate, and demonstrate need, but it cannot compel Parliament to act.
All persons are empowered to assert their right to privacy and their right of access to information. That is the change we want to make.
That is the right ambition. It is also an ambition that, on the evidence of the session, requires more than an ambitious Annual Performance Plan to achieve. It requires a Parliament willing to modernise the legislative framework, a Treasury willing to fund the institutional capacity, and a compliance culture among responsible parties that the Regulator is still, by its own account, working to build. In Human Rights Month, in the year of the South African Constitution’s thirtieth anniversary, that is not a counsel of despair, but an accurate description of the work that remains.
FAQs
How many security breaches has the Information Regulator received?
The Regulator has received 2,898 security compromise notifications in the 2025/26 financial year to date (as at 5 March 2026), compared to 202 in 2021/22, 590 in 2022/23, 1,727 in 2023/24, and 2,374 in 2024/25. This represents a roughly fifteenfold increase in under five years, reflecting both genuine increases in cyber threats and a reporting normalisation effect as POPIA’s breach notification obligations (Section 22) become better understood.
Are South African companies required to register an information officer under POPIA?
Yes. Section 55 of POPIA requires all responsible parties (organisations that process personal information) to register an information officer with the Information Regulator. As at 5 March 2026, only 69,040 information officers are registered against an estimated 490,000 CIPC-active companies, implying a compliance rate of approximately 14%. Failure to register is a contravention of POPIA.
Does POPIA have an automated decision-making provision equivalent to GDPR Article 22?
Yes. Section 71 of POPIA provides that a data subject has the right not to be subject to a decision producing legal or similarly significant consequences based solely on automated processing of personal information, unless the responsible party establishes a lawful ground and implements adequate safeguards. However, unlike the GDPR, Section 71 has received almost no published regulatory guidance from the Information Regulator. No guidance note, enforcement position, or case study has been published as at March 2026.
What is the status of the Information Regulator’s case against WhatsApp?
The Information Regulator and WhatsApp have signed a settlement agreement concerning WhatsApp’s privacy policy as applied in the South African market. As at 5 March 2026, the settlement is being reduced to a court order. The substantive terms have not been publicly disclosed. Given WhatsApp’s estimated 25 million South African users, the compliance undertakings in the settlement carry significant market-wide implications.
What is the status of the POPIA amendment process?
The Information Regulator has prepared a first draft of proposed POPIA amendments, which are still being processed internally. Key objectives include moving away from the current “correct and remedy” enforcement framework and introducing more direct consequences for intentional non-compliance. The draft must undergo parliamentary passage. Given that the portfolio committee on Justice and Constitutional Development is currently occupied with other matters, there is no confirmed timeline for introduction of amendment legislation.
What is South Africa’s dual-mandate model for information regulation?
South Africa is among a small group of jurisdictions globally in which a single institution administers both data protection (POPIA) and access to information (PAIA) law. The Information Regulator holds both mandates, enabling cross-referencing between the right to privacy and the right of access to information that structurally separate regulators in most other countries cannot perform. This is directly relevant in matters such as the matric results litigation, the WhatsApp settlement, and third-party personal information in PAIA requests.
How does the Information Regulator’s 2026/27 APP define its performance targets?
The 2026/27 APP sets the following key targets for the POPIA division: 50% of complex complaints investigated and resolved within 12 months; 70% of simple complaints investigated and resolved within 3 months; 70% of simple complaints resolved through conciliation and mediation. These represent improvements on current performance but fall short of the three-month supervisory authority response standard contemplated by GDPR Article 78.
What is the Information Regulator’s position on AI risk?
As at 5 March 2026, the Regulator has not published any guidance on AI risk, automated decision-making under Section 71, or the processing of AI training data under Condition 2 (purpose limitation) of POPIA. A guidance note on Privacy Impact Assessments (PIAs) is planned for the 2026/27 financial year. ITLawCo considers this the appropriate vehicle for integrating AI risk assessment into POPIA compliance programmes, analogous to DPIA requirements under GDPR Article 35.
When does the Information Regulator’s second term of office end?
The second term of office of the current members of the Information Regulator ends in November 2026. The 2026/27 APP is the final Annual Performance Plan of the second term. The third term (2027–2032) will bring a fresh five-year strategic cycle. Two vacancies on the five-member panel currently remain unfilled, pending Parliamentary Committee action.





Un commentaire