The Information Regulator’s January 2026 enforcement notice against the Johannesburg Stock Exchange (JSE) clarifies how South African law treats access to information, market regulation, privacy, and confidentiality when a private institution performs a public regulatory function.

The key clarification is simple and far-reaching:

If an institution exercises public power, it must be prepared to explain itself.

This article explains what the enforcement notice clarifies, why it matters for regulated markets, and how organisations should adapt their governance and PAIA processes accordingly.

Context: why this enforcement notice matters

In January 2026, South Africa’s Information Regulator reportedly issued an enforcement notice against the JSE following a complaint by Inhlanhla Ventures. The dispute arose after the JSE refused a request under the Promotion of Access to Information Act 2 of 2000 (PAIA) for trading records linked to alleged market manipulation in enX Group Ltd shares during May 2020.

The JSE relied on arguments of confidentiality, privacy, and regulatory sensitivity. The Regulator set aside that refusal and ordered the JSE to restart the PAIA process, including third-party notification and proper consideration of representations.

While fact-specific, the notice provides rare doctrinal clarity on how PAIA applies to exchanges, regulators, and hybrid institutions that perform public functions.

Disclosure under PAIA is the legal default

Clarification

PAIA treats access to information as the rule, not the exception.

The enforcement notice confirms that:

  • refusal grounds must be narrowly construed;
  • the burden of proof lies on the refusing body; and
  • speculative or hypothetical harm does not justify refusal.

Why this matters

In practice, many institutions treat PAIA refusals as routine administrative acts. The notice corrects this drift and re-anchors PAIA as a constitutional accountability mechanism, not a courtesy process.

Public power is determined by function, not corporate form

Clarification

An institution may be private in structure but public in function.

The Regulator confirmed that when the JSE performs market regulation and monitoring functions under the Financial Markets Act, it acts as a public body for PAIA purposes. Trading records held to fulfil those functions are held in the exercise of public power.

Why this matters

This resolves a recurring ambiguity for exchanges, industry regulators, certification bodies, and other hybrid institutions. Accountability follows what you do, not how you describe yourself.

Motive is irrelevant when requesting records from a public body

Clarification

For PAIA requests directed at public bodies, the requester’s motive is legally irrelevant.

The enforcement notice confirms that Inhlanhla Ventures was not required to justify its reasons for seeking access because the JSE was acting as a public body in this context.

Why this matters

Public bodies frequently attempt to import private-body standards to raise the access threshold. The notice makes clear that this is unlawful.

Personal information is not automatically exempt from disclosure

Clarification

PAIA prohibits unreasonable disclosure of personal information, not all disclosure.

The Regulator emphasised that:

  • privacy protects the “inner sanctum” of personal life;
  • business and regulated market activity attracts lower expectations of privacy; and
  • participation in highly regulated markets carries foreseeable disclosure risk.

In the context of alleged market manipulation, the expectation of absolute privacy was found to be unreasonable.

Why this matters

Privacy arguments are often asserted reflexively. The notice restores a contextual, principled privacy analysis, aligned with constitutional jurisprudence.

Confidentiality clauses cannot override PAIA

Clarification

Confidentiality cannot be created by contract to defeat a constitutional right of access.

The enforcement notice confirms that:

  • parties cannot contract out of PAIA;
  • confidentiality clauses do not trump constitutional rights; and
  • confidentiality must itself be justified within PAIA’s framework.

Why this matters

This clarification is critical for financial institutions, platforms, and regulators that rely heavily on contractual secrecy as a governance shield.

Statutory secrecy provisions are subject to PAIA

Clarification

Sector-specific confidentiality provisions apply unless disclosure is required or permitted by law.

The Regulator confirmed that PAIA is such a law. Where PAIA permits disclosure, it prevails.

Why this matters

This prevents the misuse of sectoral legislation as a blanket exemption from access-to-information obligations.

Audi alteram partem is mandatory in PAIA processes

Clarification

Third-party notification and representations are not optional.

Where records may affect third parties:

  • notice must be given;
  • representations must be invited; and
  • submissions must be considered before disclosure.

The JSE’s failure to follow this process did not justify refusal; it demonstrated procedural non-compliance.

Why this matters

The notice confirms that procedural fairness conditions disclosure, but does not negate the right of access.

PAIA is a legitimate accountability tool, not an abuse of process

Clarification

PAIA requests are not aberrations or nuisances.

The Regulator recognised that access-to-information requests are often the only viable mechanism for individuals and entities to understand, challenge, or vindicate their rights in complex regulatory systems.

Why this matters

This reframes PAIA as normal governance infrastructure rather than adversarial disruption.

Why this matters for markets and governance

The enforcement notice does not introduce radical transparency. It introduces legibility.

Markets rely on trust. Trust relies on the credible possibility of scrutiny. A market in which suspicious conduct cannot be examined is not free; it is insulated. Insulation benefits insiders and erodes confidence over time.

By clarifying that regulatory records are inspectable through due process, the Information Regulator strengthens market integrity without interfering in trading activity, price formation, or legitimate commercial strategy.

This is pro-market accountability, not regulatory overreach.

FAQs

No. Disclosure remains conditional, contextual, and procedurally constrained under PAIA.

No. It clarifies the boundary between legitimate confidentiality and unconstitutional secrecy.

No. The reasoning applies to any institution performing public regulatory or monitoring functions.

There is no evidence that credible oversight reduces long-term market participation. Jurisdictions with strong transparency and enforcement regimes consistently attract more durable capital.

How ITLawCo helps organisations respond

Governance challengeHow ITLawCo assists
PAIA exposure for regulators and hybrid bodiesAssess whether functions trigger public-body obligations and redesign PAIA frameworks
Over-reliance on confidentiality or privacyAlign refusal and disclosure decisions with PAIA, POPIA, and constitutional standards
Regulatory record-keeping riskStructure oversight records to be defensible under access-to-information scrutiny
Third-party notice and audi complianceDesign compliant, auditable third-party engagement workflows
Board and executive accountability riskTrain boards and executives on transparency obligations arising from public functions
Dispute-ready PAIA decision-makingPrepare institutions for Regulator investigations and judicial review

ITLawCo advises exchanges, regulators, financial institutions, and complex hybrid organisations on data protection, transparency, and digital governance—helping them treat accountability not as a threat, but as stability. Contact us today.