In May 2026, the Sibanye-Stillwater enforcement notice saw South Africa’s Information Regulator set aside the mining company’s refusal of an access-to-information request and order the records released. The reasoning carries a plain message for any organisation that holds information and fields requests under the Promotion of Access to Information Act 2 of 2000 (PAIA): a commercial-confidentiality claim that rests on assertion rather than evidence will not survive scrutiny, and the Regulator has the statutory power to enforce that finding.

This article explains what happened, why the refusal failed, and what organisations should take from it.

Key takeaways

  • PAIA applies to private bodies, not only the State. Where a record is genuinely required to exercise or protect a right, and no exemption properly applies, access must be granted.
  • The ground of refusal in section 68 of PAIA must be proved with evidence of actual, likely harm. Speculation about reputational or share-price damage is not enough, and a fear that information may be “misunderstood” is not a recognised ground at all.
  • Since 30 June 2021, the Information Regulator can investigate a refusal, decide the merits, and issue a binding enforcement notice under section 77J. Refusing to comply is a criminal offence under section 77K.
  • How an organisation handles a request—what it records, when, and on what basis—shapes whether a later refusal is defensible.

What the case was about

The Centre for Applied Legal Studies (CALS), a research and law clinic linked to the University of the Witwatersrand, requested Sibanye-Stillwater’s annual Social and Labour Plan (SLP) compliance reports for its Eastern and Western Platinum operations, covering 2019 to 2023.

SLPs are the development commitments a mining-right holder makes to surrounding communities and workers: housing, infrastructure, skills, local economic development. The plans themselves are public. Whether a company delivers on them year to year is recorded in the annual compliance reports, which are far less visible.

Sibanye’s deputy information officer refused the request, relying on two commercial information exemptions in PAIA:

  • Section 68(1)(b) — disclosure likely to cause harm to the body’s commercial or financial interests.
  • Section 68(1)(c)(i) — disclosure that could reasonably be expected to put the body at a disadvantage in contractual or other negotiations.

CALS complained to the Regulator. After an investigation by the PAIA Division and a recommendation from the Enforcement Committee, the Regulator set aside the refusal and ordered disclosure against payment of the prescribed fee.

Why the refusal failed

The decision turns on evidence and it is the part most relevant to organisations that refuse requests as a matter of habit.

Access is the default; grounds of refusal are narrow

PAIA begins from the position that access is the rule and refusal the exception. Because the grounds of refusal limit a constitutional right (section 32 of the Constitution), they are read narrowly, and the burden of justifying a refusal sits on the body claiming it and is to be discharged on a balance of probabilities, with evidence that the record actually falls within the exemption.

Speculation is not harm

Sibanye argued that the figures could be read out of context, could create a misleading impression of non-compliance, and could damage its reputation and share price as a listed company. The Regulator treated these as conjecture rather than demonstrated harm. Critically, the concern that information might be misunderstood is not, in itself, a ground of refusal under PAIA.

The “investigate but cannot decide” argument

Sibanye also contended that the Regulator may investigate but not determine whether a record falls within a ground of refusal; that this is for a court alone. The Regulator rejected this as negating its role, pointing to its own enabling provisions: section 77J empowers it to issue an enforcement notice setting aside the decision under complaint, and section 77K makes non-compliance an offence. An aggrieved part’’s remedy is to take the decision on review, not to deny that a decision was competently made.

The standing and authority challenges

The company further attacked the requester’s standing and the authority of the person who lodged the complaint. The Regulator dismissed both noting, among other things, that Sibanye had engaged the request on its merits (citing section 68) rather than questioning authority at the time, which itself signalled satisfaction with the requester’s capacity.

What this means for your organisation

The notice is a compliance lesson dressed as a dispute. The points that travel well beyond mining:

For information officers and legal teams

A ground of refusal is a position you must be able prove, not a label you attach. Quoting the section is not enough. Before refusing on a commercial-harm ground, document the specific, demonstrable harm, and assess whether any part of the record can be severed and released.

For compliance and governance leads

How the request is handled shapes the dispute. Refusing on the merits while later challenging standing, or making bare assertions early and trying to substantiate them only at the Enforcement Committee stage, weakens the position. Build the evidentiary record from the first response.

For executives at listed and regulated companies

The Regulator’s enforcement powers are real, and non-compliance is a criminal offence carrying a fine or up to three years’ imprisonment. Where an organisation makes public-facing commitments—to communities, regulators, or the market—the records evidencing compliance are increasingly hard to shield behind confidentiality.

For ESG and sustainability functions

Disclosure obligations and transparency expectations are converging. Compliance reporting that sits behind an SLP, an environmental authorisation, or a licence condition may be reachable through PAIA even when held by a private company.

What happens next

An enforcement notice is not the last word. A respondent aggrieved by the Regulator’s decision may apply to court for appropriate relief under section 82 of PAIA. To preserve that route, it must notify the Regulator of its intention within ten working days of receiving the notice and bring the application within 180 days. Absent a challenge, the records must be released within the compliance period stated in the notice.

FAQs

Yes, PAIA reaches records held by private bodies, not only the State. A requester must show that the record is required for the exercise or protection of a right; if that is shown and no ground of refusal properly applies, access must be granted.

Only where it can prove the requirements of the relevant ground of refusal. Under section 68, the company must show, on a balance of probabilities, that disclosure is likely to harm its commercial or financial interests, or is reasonably likely to disadvantage it in negotiations. Bare assertions of harm are insufficient.

It is a binding order issued by the Information Regulator under section 77J of PAIA, after considering the Enforcement Committee’s recommendation. It can confirm, amend or set aside the decision complained of, or require the information officer or head of the body to take or refrain from specified action.

Refusing to comply is a criminal offence under section 77K of PAIA, punishable by a fine or imprisonment of up to three years, or both.

Yes, the aggrieved party may apply to a court for appropriate relief under section 82, after notifying the Regulator within ten working days and bringing the application within 180 days of receiving the notice.

The Information Regulator (South Africa). It assumed responsibility for PAIA from the South African Human Rights Commission with effect from 30 June 2021, and holds a dual mandate covering both PAIA and the Protection of Personal Information Act 4 of 2013 (POPIA).

This article is provided for general information and does not constitute legal advice. It discusses a public regulatory decision; no confidential client information is disclosed. If your organisation needs to respond to a PAIA request, test a proposed refusal, or review its access-to-information and privacy governance, ITLawCo would be glad to assist. Contactez-nous.