The Information Regulator media briefing on 31 August 2026 set out where POPIA and PAIA enforcement now stands: more than 8,000 security compromise notifications since commencement, an enforcement notice against the South African Bureau of Standards, six administrative fines, two direct marketing matters heading for court, and a plan to give PAIA the enforcement powers it has never had.

The Regulator marked ten years since its establishment and five years since POPIA’s enforcement provisions commenced. It used the occasion to say plainly what practitioners have argued for years: the Promotion of Access to Information Act 2 of 2000 (PAIA) gives the Regulator the power to order disclosure, but almost nothing to do when disclosure does not follow. That is the most consequential point made at the briefing, and it is where this article begins.

Key takeaways

  • PAIA’s enforcement gap is now official policy. Acting PAIA Executive Mukelani Dimba confirmed that non-compliance with a PAIA enforcement notice can only be pursued by laying a criminal charge against the information officer, and that the Regulator is drafting amendments to give PAIA enforcement mechanisms equivalent to POPIA’s.
  • A 180-day self-help power is on the table. Through the Judicial Matters Amendment Bill, the Regulator has asked Parliament for the power to release information itself where a body has not complied with a disclosure order within 180 days.
  • Bodies are litigating rather than disclosing. Chairperson Advocate Pansy Tlakula named Sibanye-Stillwater and the Johannesburg Stock Exchange as bodies that have taken the Regulator on review rather than release records.
  • POPIA’s grace period blunts its own fines. Tlakula identified the structural weakness candidly: a responsible party that complies within the period set in an enforcement notice can no longer be fined.
  • A sixth administrative fine surfaced. Alongside the Department of Justice and Constitutional Development, the Department of Basic Education, the IEC, Lancet, and Blouberg, the Regulator disclosed that a R100,000 direct-marketing fine against FT Rams Consulting is being processed under section 109 of POPIA.
  • Security compromise notifications have passed 8,000, with more than 1,220 received since 1 April 2026 and roughly 3,000 projected for the financial year.
  • Public-body PAIA reporting remains poor. 417 of 853 public bodies filed annual reports for 2025/26; only 91 of 257 municipalities did.

What to do about it

  • Information officers and deputies. Registration is not optional, and it is the first thing an assessment looks for. If you have not registered, do it now. If your PAIA manual is not accessible, fix that, too. Tlakula’s illustration was pointed: she asked the person capturing visitor details at the door why he was collecting them and what happened to them afterwards, and he could not answer.
  • Private bodies holding contested records. Reassess any live PAIA refusal that rests on assertion rather than evidence, particularly under section 68. And reassess any strategy that treats a review application as a low-cost delay. The Regulator has named that strategy publicly and is legislating against it.
  • Public bodies and municipalities. Filing the annual report is the cheapest compliance step available, and the Regulator has said it will intensify monitoring and escalate to oversight structures. Non-filing is what draws the compliance assessment that finds everything else.
  • Direct marketers. Do not rely on the argument that telephone calls fall outside section 69. Two matters testing that proposition are before the Enforcement Committee and the Regulator expects the question to be litigated. Registration on the Consumer Protection Act block register does not discharge the POPIA consent obligation.
  • Boards and executives. The recurring finding across the SABS notice, the Central Johannesburg TVET College notice and the assessment programme is structural rather than incidental: no registered information officer, no compliance framework, no training, no incident response plan. Our analysis of the Central Johannesburg TVET College enforcement notice shows how a single misdirected email escalates when the foundations are missing.

Why the PAIA enforcement gap matters

Under section 77J(1) of PAIA, the Regulator may issue an enforcement notice ordering a body to grant access to a record. Section 77J(3) imports subsections (3) to (5) of section 95 of the POPIA, which govern the content and timing of enforcement notices. What it does not import is POPIA’s section 109 infringement-notice machinery, which is the source of the administrative fine.

The consequence is that a PAIA enforcement notice and a POPIA enforcement notice look alike on paper and behave very differently in practice. Ignore a POPIA notice and the Regulator can issue an infringement notice and impose an administrative fine of up to R10 million. Ignore a PAIA notice and the Regulator’s only route is section 77K, which makes refusal to comply an offence carrying a fine or imprisonment of up to three years, or both. That means opening a criminal case against a named information officer.

Dimba described what that looks like in practice. In the State Security Agency matter, where the Regulator had ordered the release of records and the order was not complied with, the Regulator had to open a criminal case against the acting Director-General. His account of the reception at the police station was blunt: the police officials they deal with, in his words, half the time do not know what the Regulator is talking about. These are people handling life-and-death community policing matters, and non-compliance with an enforcement notice does not land.

This is the practical answer to a question that has hung over the Regulator’s PAIA work since it took the function over from the South African Human Rights Commission in 2021. The Regulator’s findings are theoretically enforceable. However, in practice, the enforcement route runs through a charge office.

Tlakula put the same point in a different way on the assessment side. Public and private bodies ignore the recommendations that follow PAIA compliance assessments, she said, because they understand that no punitive consequence flows from them. The review of PAIA to strengthen the Regulator’s power to enforce and to impose sanctions is, in her words, an apex priority.

Review applications as a compliance strategy

The second PAIA theme was newer and, for private bodies, more immediately relevant. The Regulator says it is seeing a pattern in which bodies found to have contravened PAIA challenge the enforcement notice on review rather than release the records.

Tlakula named two: Sibanye-Stillwater and the Johannesburg Stock Exchange.

The Sibanye-Stillwater matter will be familiar. On 22 May 2026 the Regulator set aside the company’s refusal of a request from the Centre for Applied Legal Studies for annual Social and Labour Plan compliance reports covering the Eastern and Western Platinum operations from 2019 to 2023, finding that the reliance on the commercial and financial grounds of refusal in section 68 of PAIA was not supported by evidence of likely harm. We covered that decision in detail in our analysis of the Sibanye-Stillwater enforcement notice.

A review application is, of course, a lawful response to an adverse administrative decision, and nothing in the Regulator’s framing changes that. But the strategic calculus is worth naming. Where the alternative to review is a criminal complaint that may go nowhere, review is close to costless in enforcement terms, and it buys years. That is precisely the incentive structure the proposed amendments are designed to break.

Organisations weighing a review should assume that the arithmetic will not hold for long. If PAIA acquires an administrative-fine mechanism, the cost of an unsuccessful review changes materially.

POPIA’s grace-period problem

Asked about fines, Tlakula went straight to the design flaw. When the Regulator finds a contravention, it issues an enforcement notice setting a period within which the responsible party must comply or challenge the notice. Bodies that comply within that period cannot then be fined. The fine, in other words, only ever reaches those who refuse outright or litigate and lose.

That is an accurate description of the interaction between sections 95 and 109 of POPIA, and it explains a fines ledger that is thinner than five years of enforcement activity might suggest.

Responsible partyFineStatus
Department of Justice and Constitutional DevelopmentR5 millionDisputed, before the courts
Department of Basic EducationR5 millionBefore the courts
Independent Electoral CommissionR100,000Paid
Lancet LaboratoriesR100,000Paid
Blouberg Local MunicipalityR500,000, reduced by the court to R250,000Recovery proceedings
FT Rams ConsultingR100,000 (direct marketing)Being processed under section 109

Two points of detail are worth recording because both have been reported incorrectly elsewhere. The municipality is Blouberg Local Municipality in Limpopo, not a Cape Town entity. And the court reduced the Blouberg fine on the basis that the municipality was a first offender and the amount was too high, which is a poor foundation for the argument that POPIA’s fines are too low to deter.

The Regulator did not, at this briefing, propose replacing the grace period with immediate fines upon a finding of contravention, nor did it invoke the GDPR model. Tlakula identified the weakness and said the Regulator could do better. Those are different things, and practitioners should not attribute the stronger proposal to her.

Security compromises: 8,000 and counting

The Regulator has received more than 8,000 security compromise notifications since POPIA’s enforcement provisions commenced. More than 1,220 have come in since 1 April 2026, which is under five months, and the projection for the financial year is over 3,000.

Advocate Tshepo Boikanyo (Executive: POPIA) identified the recurring causes picked up during assessments: inadequate security controls, employee negligence and human error, weak passwords, malware and ransomware, and phishing. He also acknowledged that the true figure is higher than the reported one, because some responsible parties do not notify at all.

The enforcement notice issued to the South African Bureau of Standards (SABS) in the week before the briefing is the case study. Following the 2024 ransomware attack that encrypted SABS systems and disrupted operations, the Regulator conducted an own-initiative assessment and found contraventions spanning excessive and irrelevant processing, inadequate consent mechanisms, weak security safeguards, failure to address known vulnerabilities, absence of incident response plans, and failure to inform data subjects of collection methods. SABS has 90 days from receipt to revise policies, conduct personal information impact assessments and implement adequate security measures.

Tlakula was careful about the ratio. The enforcement action does not follow from SABS having been attacked. No organisation can guarantee it will never be attacked. It follows from the compliance failures that the assessment exposed. She placed this against the Auditor-General’s findings of ageing infrastructure, compromised security environments, a cybersecurity skills deficit, weak third-party risk management, and under-investment across government.

Her warning was aimed squarely at boards: organisations that treat the protection of personal information as a tick-box exercise, rather than an operational requirement that is planned for and resourced, are the ones that end up in enforcement.

Direct marketing: the telephone question is heading to court

Roughly 10% of the more than 3,800 complaints the Regulator received last year concerned direct marketing.

Two matters have been referred to the Enforcement Committee: OUTsurance and MTN. Both concern telephone marketing, and both put the central interpretive question directly at issue. Section 69 of POPIA regulates direct marketing by means of unsolicited electronic communication. The sector’s position is that a telephone call is not an electronic communication and therefore falls outside section 69. The Regulator disagrees. Tlakula said she expects the question to reach the court through these matters.

She also confirmed the Regulator’s position on the interaction with consumer protection law. The pre-emptive block register created by the recent Consumer Protection Act amendment regulations is welcome, and the Regulator has engaged the National Consumer Commission on joint awareness and complaint handling. But registration on that register does not displace POPIA. The obligation to obtain consent before sending unsolicited direct marketing communication remains.

Advocate Lebogang Stroom noted that despite the Regulator’s guidance note on direct marketing, non-compliance persists, often in the form of repeat conduct by single marketers across large populations, which the Regulator is now consolidating in its handling.

Madlanga Commission referrals

Privacy is intersecting with the criminal justice system. In February 2026, the Judicial Commission of Inquiry into Criminality, Political Interference and Corruption in the Criminal Justice System, chaired by Justice Mbuyiseli Madlanga, referred to the Regulator concerns about the alleged unlawful processing of personal information by Dr Imogen Mashazi, former City Manager of the Ekurhuleni Metropolitan Municipality. The Regulator accepted the referral, initiated an own-initiative investigation under section 76(3) of POPIA, completed it, and has referred the matter to the Enforcement Committee.

Further referrals arrived on 4 August 2026. Investigations have been initiated in relation to Major General Lesetja Senona, Mr Vusimuzi “Vusi” Matlala, Mrs Lindani Mchunu, and Sergeant Fanie Nkosiyabantu. The Regulator will not comment on the merits while those investigations are running.

Section 76(3) is worth noting for its own sake. It allows the Regulator to conduct an investigation on its own initiative, without a complaint. Referrals from a commission of inquiry are a route into that power that we should expect to see used again.

Matric results: the SCA application

The Regulator confirmed it has approached the Supreme Court of Appeal in the matric results litigation, after the High Court set aside its enforcement and infringement notices in December 2025 and refused leave to appeal in June 2026.

Tlakula’s framing is the interesting part. Whatever the outcome, she said, it must be sound in law and provide the Regulator with adequate clarity on the interpretation of POPIA while protecting the rights of every person in South Africa. That is not the language of a litigant confident of victory. It is the language of a regulator that believes the reasoning below was wrong and that the development of POPIA jurisprudence depends on correcting it.

We have argued the same point about the full bench’s approach: resolving the matter by holding that examination numbers are not personal information is a definitional shortcut that avoids the harder and more useful question, which is whether publication with a linking key retained by the department amounts to pseudonymisation rather than anonymisation, and therefore remains within POPIA’s scope.

Other investigations and assessments

The Regulator confirmed live investigations and assessments involving the National Credit Regulator, Truecaller, Pick n Pay, the Gauteng Department of e-Government, the Land Bank, and Standard Bank. It has also run PAIA compliance assessments across Schedule 3A entities, non-profit organisations and real estate agencies, with low compliance observed across the board.

Boikanyo described a shift in method that deserves attention. POPIA ordinarily brings the Regulator to a responsible party’s door because of a complaint or an instance of processing that suggests a contravention. The Regulator has now begun writing to responsible parties across selected industries, requiring them to demonstrate how they comply, without waiting for a complaint. The letters are framed as assistance, and the Regulator writes back, identifying the provisions the body must address. They are nonetheless an assessment by another name, and the first many organisations will hear of the exercise is the letter.

PAIA annual reports: read the raw numbers, not the percentages

For the 2025/26 cycle, reports were received between 1 April and 30 June 2026. Of 853 public bodies, 417 submitted. Of 257 municipalities, 91 submitted. In 2024/25, 358 public bodies submitted.

A caution on the percentages. The Regulator described 417 of 853 as approximately 52% and 358 as 43%. On a denominator of 853, those figures are 48.9% and 42.0%. Back-solving from the stated percentages produces denominators of roughly 802 and 833, so the denominator is not stable across the two figures or against the 853 given in the same passage. The municipal figure is internally consistent: 91 of 257 is 35.4%.

Our advice is to cite the numerators and denominators and leave the percentages alone. The underlying point survives either way: close to half of all public bodies are not meeting a statutory reporting obligation, and the municipal sphere, which is closest to the communities that need access most, is the worst performer.

Other categories flagged as poor performers were political parties, TVET colleges and Schedule 3A and major public entities. The Regulator also said the Public Protector has been failing to submit what it called the section 84(b) report, describing this as a statutory requirement. Strictly, section 84(b)(x) obliges the Regulator to include in its own annual report the number, nature and outcome of access-to-information complaints lodged with the Public Protector, and section 83(3)(h) is the provision under which the Regulator requests that information. The duty to report sits with the Regulator; the Public Protector’s role is to supply the data on request.

If your organisation has not filed, our guide to the PAIA annual report sets out what is required and how to submit.

New digital services

The Regulator has launched a POPIA and PAIA complaints management system, an online POPIA exemption application process, an online prior authorisation application process, and iSupport, a centralised query management platform that routes general enquiries to the relevant division. It has also moved to new premises at 54 Maxwell Drive, Woodmead North Office Park, Johannesburg.

Frequently asked questions

Both are formal orders requiring a body to act. A POPIA enforcement notice under section 95 is backed by the infringement notice and administrative fine regime in section 109, with fines up to R10 million. A PAIA enforcement notice under section 77J imports only subsections (3) to (5) of section 95, not the fine machinery, so non-compliance is pursued as an offence under section 77K of PAIA rather than by fine. The Regulator has confirmed it is seeking amendments to close that gap.

Thirty days. Section 97(1) of POPIA provides for an appeal to the High Court within 30 days of receiving the notice, for the notice to be set aside or varied. Several published reports have given the period as 31 days. It is 30.

On the current framework, not for the processing that is the subject matter of the enforcement notice. The Regulator confirmed that where a responsible party complies within the period set in the notice, no administrative fine follows. That is the grace period the Regulator has identified as a structural weakness, so the position may not hold indefinitely.

No. The Regulator was explicit that registration on the pre-emptive block register does not displace the POPIA obligation to obtain consent before sending unsolicited direct marketing communication.

The Regulator’s position is that they are. Parts of the direct marketing sector argue that a telephone call is not an electronic communication and falls outside section 69. The OUTsurance and MTN matters before the Enforcement Committee put the question in issue, and the Regulator expects it to be decided by a court.

Section 83(4) says the head of a private body “may furnish” information about access requests, and then only if the Regulator asks. The verb is permissive, which is why the question keeps arising. In practice, the Regulator treats submission as expected, uses non-submission as a trigger for compliance assessments, and has said it will escalate. Treat it as mandatory.

Where this leaves things

The Regulator has spent five years demonstrating that it will act. What this briefing added is an admission of where it cannot act, and a legislative plan to fix it.

For anyone advising on access to information, the practical horizon has shifted. The question is no longer whether a PAIA enforcement notice can be safely absorbed. It is how much longer that will be true.

If you need help assessing a PAIA refusal, responding to an enforcement notice, or getting your information officer registration and compliance framework in order, contact ITLawCo.

Sources