{"id":3791,"date":"2026-03-06T08:24:13","date_gmt":"2026-03-06T08:24:13","guid":{"rendered":"https:\/\/itlawco.com\/?p=3791"},"modified":"2026-03-06T08:35:10","modified_gmt":"2026-03-06T08:35:10","slug":"information-regulator-2026-27-annual-performance-plan","status":"publish","type":"post","link":"https:\/\/itlawco.com\/fr\/information-regulator-2026-27-annual-performance-plan\/","title":{"rendered":"Information Regulator 2026\/27 Annual Performance Plan"},"content":{"rendered":"\n\t\t<div id=\"fws_6a9ffe0de659d\"  data-column-margin=\"default\" data-midnight=\"dark\"  class=\"wpb_row vc_row-fluid vc_row\"  style=\"padding-top: 0px; padding-bottom: 0px; \"><div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\"><div class=\"inner-wrap row-bg-layer\" ><div class=\"row-bg viewport-desktop\"  style=\"\"><\/div><\/div><\/div><div class=\"row_col_wrap_12 col span_12 dark left\">\n\t<div  class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \"  data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\" >\n\t\t<div class=\"vc_column-inner\" >\n\t\t\t<div class=\"wpb_wrapper\">\n\t\t\t\t\n\t<div class=\"wpb_raw_code wpb_raw_html wpb_content_element\" >\n\t\t<div class=\"wpb_wrapper\">\n\t\t\t<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>South Africa Information Regulator 2026\/27 \u2014 Article Overview<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Playfair+Display:wght@400;700;900&family=Source+Sans+3:wght@300;400;600;700&family=Source+Serif+4:ital,wght@0,400;0,600;1,400&display=swap\" rel=\"stylesheet\">\n<style>\n  :root {\n    --navy:   #1A3C5E;\n    --steel:  #2E75B6;\n    --teal:   #1A7A6E;\n    --gold:   #C8922A;\n    --red:    #B03A2E;\n    --mist:   #EBF4FA;\n    --fog:    #F4F7F9;\n    --ink:    #1C1C2E;\n    --mid:    #3D4A5A;\n    --rule:   #D0D8E0;\n    --white:  #FFFFFF;\n  }\n\n  * { box-sizing: border-box; margin: 0; padding: 0; }\n\n  body {\n    font-family: 'Source Sans 3', sans-serif;\n    background: #F0F3F6;\n    color: var(--ink);\n    min-height: 100vh;\n    padding: 40px 24px 60px;\n  }\n\n  \/* \u2500\u2500 MASTHEAD \u2500\u2500 *\/\n  .masthead {\n    max-width: 1100px;\n    margin: 0 auto 10px;\n    display: flex;\n    align-items: center;\n    gap: 14px;\n    opacity: 0;\n    animation: fadeUp 0.6s ease forwards;\n  }\n  .masthead-logo {\n    font-family: 'Playfair Display', serif;\n    font-size: 13px;\n    font-weight: 700;\n    letter-spacing: 0.12em;\n    color: var(--steel);\n    text-transform: uppercase;\n    border-right: 1px solid var(--rule);\n    padding-right: 14px;\n  }\n  .masthead-tag {\n    font-size: 11px;\n    letter-spacing: 0.08em;\n    color: #8A97A6;\n    text-transform: uppercase;\n  }\n\n  \/* \u2500\u2500 TITLE BLOCK \u2500\u2500 *\/\n  .title-block {\n    max-width: 1100px;\n    margin: 0 auto 36px;\n    border-left: 5px solid var(--navy);\n    padding-left: 22px;\n    opacity: 0;\n    animation: fadeUp 0.6s 0.1s ease forwards;\n  }\n  .title-block h1 {\n    font-family: 'Playfair Display', serif;\n    font-size: clamp(20px, 2.4vw, 28px);\n    font-weight: 900;\n    color: var(--navy);\n    line-height: 1.25;\n    margin-bottom: 8px;\n  }\n  .title-block .standfirst {\n    font-family: 'Source Serif 4', serif;\n    font-size: 13.5px;\n    font-style: italic;\n    color: var(--mid);\n    line-height: 1.6;\n    max-width: 820px;\n  }\n\n  \/* \u2500\u2500 CENTRAL TENSION BANNER \u2500\u2500 *\/\n  .tension-banner {\n    max-width: 1100px;\n    margin: 0 auto 32px;\n    background: var(--navy);\n    border-radius: 4px;\n    padding: 18px 28px;\n    display: flex;\n    align-items: center;\n    gap: 0;\n    opacity: 0;\n    animation: fadeUp 0.6s 0.2s ease forwards;\n    position: relative;\n    overflow: hidden;\n  }\n  .tension-banner::before {\n    content: '';\n    position: absolute;\n    inset: 0;\n    background: repeating-linear-gradient(\n      -45deg,\n      transparent,\n      transparent 18px,\n      rgba(255,255,255,0.025) 18px,\n      rgba(255,255,255,0.025) 36px\n    );\n  }\n  .tension-pole {\n    flex: 1;\n    text-align: center;\n    position: relative;\n    z-index: 1;\n  }\n  .tension-pole .pole-label {\n    font-size: 10px;\n    letter-spacing: 0.14em;\n    text-transform: uppercase;\n    color: rgba(255,255,255,0.5);\n    margin-bottom: 4px;\n  }\n  .tension-pole .pole-value {\n    font-family: 'Playfair Display', serif;\n    font-size: 18px;\n    font-weight: 700;\n    color: #FFFFFF;\n  }\n  .tension-vs {\n    font-family: 'Playfair Display', serif;\n    font-size: 22px;\n    font-weight: 900;\n    color: var(--gold);\n    padding: 0 32px;\n    position: relative;\n    z-index: 1;\n    flex-shrink: 0;\n  }\n\n  \/* \u2500\u2500 STATS ROW \u2500\u2500 *\/\n  .stats-row {\n    max-width: 1100px;\n    margin: 0 auto 32px;\n    display: grid;\n    grid-template-columns: repeat(5, 1fr);\n    gap: 10px;\n    opacity: 0;\n    animation: fadeUp 0.6s 0.3s ease forwards;\n  }\n  .stat-card {\n    background: var(--white);\n    border-radius: 4px;\n    padding: 16px 14px;\n    border-top: 3px solid var(--steel);\n    text-align: center;\n  }\n  .stat-card.danger { border-top-color: var(--red); }\n  .stat-card.gold   { border-top-color: var(--gold); }\n  .stat-card.teal   { border-top-color: var(--teal); }\n  .stat-card.mid    { border-top-color: var(--mid); }\n  .stat-num {\n    font-family: 'Playfair Display', serif;\n    font-size: clamp(18px, 2vw, 26px);\n    font-weight: 900;\n    color: var(--navy);\n    line-height: 1;\n    margin-bottom: 5px;\n  }\n  .stat-label {\n    font-size: 10.5px;\n    color: #6A7A8A;\n    line-height: 1.4;\n    letter-spacing: 0.02em;\n  }\n\n  \/* \u2500\u2500 MAIN GRID \u2500\u2500 *\/\n  .main-grid {\n    max-width: 1100px;\n    margin: 0 auto 32px;\n    display: grid;\n    grid-template-columns: 1fr 1fr 1fr;\n    grid-template-rows: auto auto;\n    gap: 12px;\n  }\n\n  .section-card {\n    background: var(--white);\n    border-radius: 4px;\n    overflow: hidden;\n    opacity: 0;\n    animation: fadeUp 0.5s ease forwards;\n  }\n  .section-card:nth-child(1) { animation-delay: 0.35s; }\n  .section-card:nth-child(2) { animation-delay: 0.42s; }\n  .section-card:nth-child(3) { animation-delay: 0.49s; }\n  .section-card:nth-child(4) { animation-delay: 0.56s; }\n  .section-card:nth-child(5) { animation-delay: 0.63s; }\n  .section-card:nth-child(6) { animation-delay: 0.70s; }\n\n  .card-header {\n    padding: 13px 16px 10px;\n    display: flex;\n    align-items: flex-start;\n    gap: 10px;\n    border-bottom: 1px solid var(--rule);\n  }\n  .card-num {\n    font-family: 'Playfair Display', serif;\n    font-size: 28px;\n    font-weight: 900;\n    line-height: 1;\n    flex-shrink: 0;\n    margin-top: 2px;\n  }\n  .card-title-block {}\n  .card-section-label {\n    font-size: 9.5px;\n    letter-spacing: 0.12em;\n    text-transform: uppercase;\n    margin-bottom: 3px;\n    font-weight: 600;\n  }\n  .card-title {\n    font-family: 'Playfair Display', serif;\n    font-size: 14px;\n    font-weight: 700;\n    line-height: 1.3;\n    color: var(--ink);\n  }\n\n  .card-body { padding: 14px 16px 16px; }\n\n  .finding {\n    display: flex;\n    gap: 8px;\n    margin-bottom: 10px;\n    align-items: flex-start;\n  }\n  .finding-dot {\n    width: 6px;\n    height: 6px;\n    border-radius: 50%;\n    flex-shrink: 0;\n    margin-top: 5px;\n  }\n  .finding-text {\n    font-size: 12px;\n    color: var(--mid);\n    line-height: 1.55;\n  }\n  .finding-text strong {\n    color: var(--ink);\n    font-weight: 600;\n  }\n\n  \/* verdict pills *\/\n  .verdict-row {\n    display: flex;\n    gap: 6px;\n    flex-wrap: wrap;\n    margin-top: 12px;\n    padding-top: 10px;\n    border-top: 1px solid var(--rule);\n  }\n  .verdict-pill {\n    font-size: 9.5px;\n    font-weight: 700;\n    letter-spacing: 0.08em;\n    text-transform: uppercase;\n    padding: 3px 8px;\n    border-radius: 2px;\n    color: white;\n  }\n\n  \/* colour themes per section *\/\n  .theme-enforcement .card-num { color: var(--steel); }\n  .theme-enforcement .card-section-label { color: var(--steel); }\n  .theme-enforcement .finding-dot { background: var(--steel); }\n  .theme-enforcement .verdict-pill { background: var(--steel); }\n\n  .theme-capacity .card-num { color: var(--red); }\n  .theme-capacity .card-section-label { color: var(--red); }\n  .theme-capacity .finding-dot { background: var(--red); }\n  .theme-capacity .verdict-pill { background: var(--red); }\n\n  .theme-reform .card-num { color: var(--gold); }\n  .theme-reform .card-section-label { color: var(--gold); }\n  .theme-reform .finding-dot { background: var(--gold); }\n  .theme-reform .verdict-pill { background: var(--gold); }\n\n  .theme-ai .card-num { color: var(--teal); }\n  .theme-ai .card-section-label { color: var(--teal); }\n  .theme-ai .finding-dot { background: var(--teal); }\n  .theme-ai .verdict-pill { background: var(--teal); }\n\n  .theme-dual .card-num { color: var(--navy); }\n  .theme-dual .card-section-label { color: var(--navy); }\n  .theme-dual .finding-dot { background: var(--navy); }\n  .theme-dual .verdict-pill { background: var(--navy); }\n\n  .theme-awareness .card-num { color: #6A5ACD; }\n  .theme-awareness .card-section-label { color: #6A5ACD; }\n  .theme-awareness .finding-dot { background: #6A5ACD; }\n  .theme-awareness .verdict-pill { background: #6A5ACD; }\n\n  \/* \u2500\u2500 FINE COMPARISON STRIP \u2500\u2500 *\/\n  .fine-strip {\n    max-width: 1100px;\n    margin: 0 auto 12px;\n    background: var(--white);\n    border-radius: 4px;\n    padding: 18px 20px;\n    opacity: 0;\n    animation: fadeUp 0.5s 0.75s ease forwards;\n  }\n  .fine-strip-title {\n    font-size: 10px;\n    letter-spacing: 0.12em;\n    text-transform: uppercase;\n    font-weight: 700;\n    color: #8A97A6;\n    margin-bottom: 14px;\n  }\n  .fine-bars {\n    display: flex;\n    flex-direction: column;\n    gap: 9px;\n  }\n  .fine-bar-row {\n    display: flex;\n    align-items: center;\n    gap: 12px;\n  }\n  .fine-bar-label {\n    font-size: 11.5px;\n    font-weight: 600;\n    color: var(--mid);\n    width: 170px;\n    flex-shrink: 0;\n  }\n  .fine-bar-track {\n    flex: 1;\n    height: 22px;\n    background: var(--fog);\n    border-radius: 2px;\n    position: relative;\n    overflow: hidden;\n  }\n  .fine-bar-fill {\n    height: 100%;\n    border-radius: 2px;\n    display: flex;\n    align-items: center;\n    padding-left: 8px;\n    font-size: 10.5px;\n    font-weight: 700;\n    color: white;\n    white-space: nowrap;\n    transition: width 1.2s cubic-bezier(0.4,0,0.2,1);\n  }\n\n  \/* \u2500\u2500 BREACH TIMELINE \u2500\u2500 *\/\n  .timeline-strip {\n    max-width: 1100px;\n    margin: 0 auto 32px;\n    background: var(--white);\n    border-radius: 4px;\n    padding: 18px 20px;\n    opacity: 0;\n    animation: fadeUp 0.5s 0.82s ease forwards;\n  }\n  .timeline-title {\n    font-size: 10px;\n    letter-spacing: 0.12em;\n    text-transform: uppercase;\n    font-weight: 700;\n    color: #8A97A6;\n    margin-bottom: 16px;\n  }\n  .timeline-chart {\n    display: flex;\n    align-items: flex-end;\n    gap: 14px;\n    height: 100px;\n  }\n  .bar-col {\n    display: flex;\n    flex-direction: column;\n    align-items: center;\n    gap: 5px;\n    flex: 1;\n  }\n  .bar-val {\n    font-family: 'Playfair Display', serif;\n    font-size: 12px;\n    font-weight: 700;\n    color: var(--navy);\n  }\n  .bar-body {\n    width: 100%;\n    border-radius: 2px 2px 0 0;\n    transition: height 1s ease;\n    min-height: 4px;\n  }\n  .bar-year {\n    font-size: 10px;\n    color: #8A97A6;\n    font-weight: 600;\n    letter-spacing: 0.04em;\n  }\n  .bar-note {\n    font-size: 9px;\n    color: #8A97A6;\n    text-align: center;\n    line-height: 1.3;\n  }\n\n  \/* \u2500\u2500 CONCLUSION BANNER \u2500\u2500 *\/\n  .conclusion-banner {\n    max-width: 1100px;\n    margin: 0 auto 28px;\n    background: var(--navy);\n    border-radius: 4px;\n    padding: 24px 28px;\n    display: grid;\n    grid-template-columns: 1fr 1fr 1fr;\n    gap: 20px;\n    opacity: 0;\n    animation: fadeUp 0.5s 0.88s ease forwards;\n    position: relative;\n    overflow: hidden;\n  }\n  .conclusion-banner::after {\n    content: '';\n    position: absolute;\n    right: -40px;\n    top: -40px;\n    width: 200px;\n    height: 200px;\n    border-radius: 50%;\n    border: 40px solid rgba(255,255,255,0.04);\n  }\n  .concl-item {\n    position: relative;\n    z-index: 1;\n  }\n  .concl-label {\n    font-size: 9.5px;\n    letter-spacing: 0.13em;\n    text-transform: uppercase;\n    color: rgba(255,255,255,0.45);\n    margin-bottom: 6px;\n    font-weight: 600;\n  }\n  .concl-text {\n    font-family: 'Source Serif 4', serif;\n    font-size: 13px;\n    color: rgba(255,255,255,0.9);\n    line-height: 1.55;\n  }\n  .concl-text strong {\n    color: #FFFFFF;\n    font-weight: 600;\n  }\n\n  \/* \u2500\u2500 PULL QUOTE \u2500\u2500 *\/\n  .pull-quote-bar {\n    max-width: 1100px;\n    margin: 0 auto 28px;\n    border-left: 4px solid var(--teal);\n    padding: 8px 0 8px 20px;\n    opacity: 0;\n    animation: fadeUp 0.5s 0.94s ease forwards;\n  }\n  .pull-quote-bar blockquote {\n    font-family: 'Source Serif 4', serif;\n    font-style: italic;\n    font-size: 15px;\n    color: var(--mid);\n    line-height: 1.6;\n  }\n  .pull-quote-bar cite {\n    font-size: 11px;\n    color: #8A97A6;\n    font-style: normal;\n    display: block;\n    margin-top: 6px;\n    letter-spacing: 0.04em;\n  }\n\n  \/* \u2500\u2500 LEGEND \u2500\u2500 *\/\n  .legend {\n    max-width: 1100px;\n    margin: 0 auto;\n    display: flex;\n    gap: 20px;\n    flex-wrap: wrap;\n    opacity: 0;\n    animation: fadeUp 0.5s 1s ease forwards;\n    padding-top: 4px;\n  }\n  .legend-item {\n    display: flex;\n    align-items: center;\n    gap: 6px;\n    font-size: 10.5px;\n    color: #7A8A9A;\n    letter-spacing: 0.04em;\n  }\n  .legend-dot {\n    width: 8px;\n    height: 8px;\n    border-radius: 50%;\n    flex-shrink: 0;\n  }\n\n  \/* \u2500\u2500 ANIMATIONS \u2500\u2500 *\/\n  @keyframes fadeUp {\n    from { opacity: 0; transform: translateY(16px); }\n    to   { opacity: 1; transform: translateY(0); }\n  }\n\n  @media (max-width: 800px) {\n    .stats-row { grid-template-columns: repeat(3, 1fr); }\n    .main-grid { grid-template-columns: 1fr 1fr; }\n    .conclusion-banner { grid-template-columns: 1fr; }\n    .tension-vs { padding: 0 16px; }\n  }\n  @media (max-width: 560px) {\n    .stats-row { grid-template-columns: repeat(2, 1fr); }\n    .main-grid { grid-template-columns: 1fr; }\n  }\n<\/style>\n<\/head>\n<body>\n\n<!-- MASTHEAD -->\n<div class=\"masthead\">\n  <div class=\"masthead-logo\">ITLawCo<\/div>\n  <div class=\"masthead-tag\">Data Protection &amp; Privacy \u00b7 Visual Overview<\/div>\n<\/div>\n\n<!-- TITLE -->\n<div class=\"title-block\">\n  <h1>South Africa Information Regulator 2026\/27 Annual Performance Plan:<br>Enforcement, Capacity, and What It Means for POPIA Compliance<\/h1>\n  <p class=\"standfirst\">Visual overview of key findings, statistics, structural tensions, and implications from the stakeholder consultation session, 5 March 2026.<\/p>\n<\/div>\n\n<!-- CENTRAL TENSION -->\n<div class=\"tension-banner\">\n  <div class=\"tension-pole\">\n    <div class=\"pole-label\">The Mandate<\/div>\n    <div class=\"pole-value\">Regulate data protection for 61 million people across all sectors<\/div>\n  <\/div>\n  <div class=\"tension-vs\">vs<\/div>\n  <div class=\"tension-pole\">\n    <div class=\"pole-label\">The Reality<\/div>\n    <div class=\"pole-value\">~130 staff \u00b7 1 location \u00b7 R10,000,000 maximum fine \u00b7 2 vacancies<\/div>\n  <\/div>\n<\/div>\n\n<!-- STATS ROW -->\n<div class=\"stats-row\">\n  <div class=\"stat-card danger\">\n    <div class=\"stat-num\">2,898<\/div>\n    <div class=\"stat-label\">Security compromises received in 2025\/26 (in-year) \u2014 up from 202 in 2021\/22<\/div>\n  <\/div>\n  <div class=\"stat-card gold\">\n    <div class=\"stat-num\">14%<\/div>\n    <div class=\"stat-label\">Estimated share of CIPC-registered companies with a registered information officer<\/div>\n  <\/div>\n  <div class=\"stat-card\">\n    <div class=\"stat-num\">R10m<\/div>\n    <div class=\"stat-label\">Maximum POPIA administrative fine \u2014 \u2248 \u20ac500,000; GDPR ceiling is \u20ac20 million<\/div>\n  <\/div>\n  <div class=\"stat-card teal\">\n    <div class=\"stat-num\">70%<\/div>\n    <div class=\"stat-label\">Of the South African public unaware the Information Regulator exists (2023 survey)<\/div>\n  <\/div>\n  <div class=\"stat-card mid\">\n    <div class=\"stat-num\">35<\/div>\n    <div class=\"stat-label\">Sectoral assessments conducted since 2021 \u2014 banks, telcos, government, retail, HE<\/div>\n  <\/div>\n<\/div>\n\n<!-- MAIN GRID \u2014 6 SECTIONS -->\n<div class=\"main-grid\">\n\n  <!-- 1. ENFORCEMENT -->\n  <div class=\"section-card theme-enforcement\">\n    <div class=\"card-header\">\n      <div class=\"card-num\">1<\/div>\n      <div class=\"card-title-block\">\n        <div class=\"card-section-label\">Enforcement Picture<\/div>\n        <div class=\"card-title\">Extraordinary Numbers,<br>Modest Tools<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"card-body\">\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Security compromises have increased <strong>fifteenfold<\/strong> in under five years \u2014 driven by both genuine cyber threats and a reporting normalisation effect.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>1,320 open matters<\/strong> in the current year reflect capacity strain, not lack of regulatory will.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Completed enforcement: <strong>Lancet Labs<\/strong> (R200k imposed &amp; paid; below the R10m ceiling), <strong>FT RAMS<\/strong> (civil recovery), <strong>WhatsApp<\/strong> (settlement), <strong>Dept of Justice<\/strong> (R5m fine, contested).<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">CEO publicly acknowledged the Regulator <strong>\"struggles with responsiveness\"<\/strong> \u2014 a significant admission from an enforcement body.<\/div>\n      <\/div>\n      <div class=\"verdict-row\">\n        <span class=\"verdict-pill\">15\u00d7 breach increase<\/span>\n        <span class=\"verdict-pill\">APP targets: 50\/70%<\/span>\n      <\/div>\n    <\/div>\n  <\/div>\n\n  <!-- 2. CAPACITY -->\n  <div class=\"section-card theme-capacity\">\n    <div class=\"card-header\">\n      <div class=\"card-num\">2<\/div>\n      <div class=\"card-title-block\">\n        <div class=\"card-section-label\">Institutional Capacity<\/div>\n        <div class=\"card-title\">The Structural Story<br>the Session Told<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"card-body\">\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Only <strong>69,040 information officers<\/strong> registered against ~490,000 CIPC-active companies. Compliance rate: approximately <strong>14%<\/strong>, nearly 5 years post-enforcement.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>130 staff, 1 location<\/strong> (Gauteng), no regional offices \u2014 regulating every public and private body in a nation of 61 million people.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Two <strong>panel vacancies<\/strong> remain unfilled; Parliament occupied with ad hoc police corruption committee.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Independent practitioners note enforcement profile is <strong>stronger than complaint resolution record<\/strong> \u2014 a growing frustration.<\/div>\n      <\/div>\n      <div class=\"verdict-row\">\n        <span class=\"verdict-pill\">Resource gap<\/span>\n        <span class=\"verdict-pill\">86% non-compliance<\/span>\n      <\/div>\n    <\/div>\n  <\/div>\n\n  <!-- 3. REFORM -->\n  <div class=\"section-card theme-reform\">\n    <div class=\"card-header\">\n      <div class=\"card-num\">3<\/div>\n      <div class=\"card-title-block\">\n        <div class=\"card-section-label\">Legislative Reform<\/div>\n        <div class=\"card-title\">What the Amendments<br>Must Address<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"card-body\">\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>POPIA amendments in draft<\/strong>: moving from \"correct and remedy\" towards direct fines for intentional non-compliance. Requires parliamentary passage \u2014 no confirmed timeline.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>OUTsurance test case<\/strong> before Enforcement Committee: does a telephone call constitute \"electronic communication\"? Outcome affects 250+ DMASA members.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>Section 60 bottleneck<\/strong>: DMASA code submitted twice, returned twice. Code assessment capacity needs addressing in amendments.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>Gated-access code<\/strong> in advanced development \u2014 covers biometrics, CCTV, visitor logs at ~5 million residents' estates.<\/div>\n      <\/div>\n      <div class=\"verdict-row\">\n        <span class=\"verdict-pill\">PAJA risk<\/span>\n        <span class=\"verdict-pill\">Parliament uncertain<\/span>\n      <\/div>\n    <\/div>\n  <\/div>\n\n  <!-- 4. AI -->\n  <div class=\"section-card theme-ai\">\n    <div class=\"card-header\">\n      <div class=\"card-num\">4<\/div>\n      <div class=\"card-title-block\">\n        <div class=\"card-section-label\">AI Governance<\/div>\n        <div class=\"card-title\">A Gap That Cannot<br>Comfortably Persist<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"card-body\">\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>Section 71<\/strong> (automated decision-making) is structurally analogous to GDPR Article 22 \u2014 but has received <strong>no published guidance, cases, or enforcement position<\/strong> from the Regulator.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">EU AI Act entered application <strong>February 2025<\/strong>. SA companies with EU operations are already subject to its obligations.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Facial recognition at gated estates = <strong>biometric special personal information<\/strong> (Section 26) \u2014 heightened protection, explicit consent required. No guidance published.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>PIA guidance note planned<\/strong> for 2026\/27 \u2014 the right vehicle for AI risk integration, if drafted with AI use cases explicitly in scope.<\/div>\n      <\/div>\n      <div class=\"verdict-row\">\n        <span class=\"verdict-pill\">Section 71 unused<\/span>\n        <span class=\"verdict-pill\">PIA note due 2026\/27<\/span>\n      <\/div>\n    <\/div>\n  <\/div>\n\n  <!-- 5. DUAL MANDATE -->\n  <div class=\"section-card theme-dual\">\n    <div class=\"card-header\">\n      <div class=\"card-num\">5<\/div>\n      <div class=\"card-title-block\">\n        <div class=\"card-section-label\">Governance Architecture<\/div>\n        <div class=\"card-title\">The Dual Mandate &amp;<br>Its International Distinction<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"card-body\">\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">South Africa is among <strong>very few jurisdictions<\/strong> where a single body administers both data protection (POPIA) and access to information (PAIA) \u2014 enabling cross-referencing impossible for separate regulators.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>Matric results appeal<\/strong>: does an exam number require parental consent for publication? SC\u00c1 hearing 12 March 2026. Defines the PAIA\/POPIA boundary.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\"><strong>WhatsApp settlement<\/strong> terms undisclosed. 25 million SA users affected. Regulator should consider publishing reasoning as precedent.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Enforcement Committee <strong>jurisprudence being codified<\/strong> \u2014 a published decision archive (like ICO\/DPC) would materially advance legal certainty.<\/div>\n      <\/div>\n      <div class=\"verdict-row\">\n        <span class=\"verdict-pill\">Globally unusual model<\/span>\n        <span class=\"verdict-pill\">SCA appeal live<\/span>\n      <\/div>\n    <\/div>\n  <\/div>\n\n  <!-- 6. AWARENESS -->\n  <div class=\"section-card theme-awareness\">\n    <div class=\"card-header\">\n      <div class=\"card-num\">6<\/div>\n      <div class=\"card-title-block\">\n        <div class=\"card-section-label\">Public Awareness<\/div>\n        <div class=\"card-title\">The 70% Problem<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"card-body\">\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">2023 survey: only <strong>30% of the South African public<\/strong> had heard of the Information Regulator. Approximately <strong>43 million people<\/strong> unaware of the body protecting their data rights.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Awareness concentrated among <strong>tertiary-educated, employed, digitally connected<\/strong> citizens. Rural and lower-income communities \u2014 most vulnerable \u2014 near-negligible awareness.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">EduCom outreach spans <strong>7 provinces<\/strong>: Free State, KZN, Mpumalanga, North West, Northern Cape. Social media is now the primary stakeholder information channel.<\/div>\n      <\/div>\n      <div class=\"finding\">\n        <div class=\"finding-dot\"><\/div>\n        <div class=\"finding-text\">Structural cause: <strong>1 location, 11 official languages, vast digital divide<\/strong>. No APP target addresses the 70% gap at scale.<\/div>\n      <\/div>\n      <div class=\"verdict-row\">\n        <span class=\"verdict-pill\">43m unaware<\/span>\n        <span class=\"verdict-pill\">Structural gap<\/span>\n      <\/div>\n    <\/div>\n  <\/div>\n\n<\/div>\n\n<!-- FINE COMPARISON STRIP -->\n<div class=\"fine-strip\">\n  <div class=\"fine-strip-title\">Maximum Administrative Fine \u2014 Comparative Framework (scaled to GDPR ceiling)<\/div>\n  <div class=\"fine-bars\" id=\"fineBars\">\n    <div class=\"fine-bar-row\">\n      <div class=\"fine-bar-label\">South Africa (POPIA)<\/div>\n      <div class=\"fine-bar-track\">\n        <div class=\"fine-bar-fill\" id=\"bar-za\" style=\"width:0%;background:#2E75B6;\">R10,000,000 \u2248 \u20ac500,000 (fixed ceiling)<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"fine-bar-row\">\n      <div class=\"fine-bar-label\">Brazil (LGPD)<\/div>\n      <div class=\"fine-bar-track\">\n        <div class=\"fine-bar-fill\" id=\"bar-br\" style=\"width:0%;background:#1A7A6E;\">2% of SA revenue, cap R$50m per infringement<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"fine-bar-row\">\n      <div class=\"fine-bar-label\">United Kingdom (UK GDPR)<\/div>\n      <div class=\"fine-bar-track\">\n        <div class=\"fine-bar-fill\" id=\"bar-uk\" style=\"width:0%;background:#C8922A;\">\u00a317.5 million (tiered)<\/div>\n      <\/div>\n    <\/div>\n    <div class=\"fine-bar-row\">\n      <div class=\"fine-bar-label\">European Union (GDPR)<\/div>\n      <div class=\"fine-bar-track\">\n        <div class=\"fine-bar-fill\" id=\"bar-eu\" style=\"width:0%;background:#1A3C5E;\">\u20ac20 million or 4% global turnover (tiered, whichever higher)<\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n<\/div>\n\n<!-- BREACH TIMELINE -->\n<div class=\"timeline-strip\">\n  <div class=\"timeline-title\">Security Compromise Notifications Received \u2014 2021\/22 to 2025\/26 (in-year)<\/div>\n  <div class=\"timeline-chart\" id=\"breachChart\">\n    <div class=\"bar-col\">\n      <div class=\"bar-val\">202<\/div>\n      <div class=\"bar-body\" data-h=\"7\" style=\"background:#2E75B6;height:0px;\"><\/div>\n      <div class=\"bar-year\">2021\/22<\/div>\n      <div class=\"bar-note\">Year 1 of enforcement powers<\/div>\n    <\/div>\n    <div class=\"bar-col\">\n      <div class=\"bar-val\">590<\/div>\n      <div class=\"bar-body\" data-h=\"20\" style=\"background:#2E75B6;height:0px;\"><\/div>\n      <div class=\"bar-year\">2022\/23<\/div>\n      <div class=\"bar-note\"><\/div>\n    <\/div>\n    <div class=\"bar-col\">\n      <div class=\"bar-val\">1,727<\/div>\n      <div class=\"bar-body\" data-h=\"60\" style=\"background:#C8922A;height:0px;\"><\/div>\n      <div class=\"bar-year\">2023\/24<\/div>\n      <div class=\"bar-note\"><\/div>\n    <\/div>\n    <div class=\"bar-col\">\n      <div class=\"bar-val\">2,374<\/div>\n      <div class=\"bar-body\" data-h=\"82\" style=\"background:#B03A2E;height:0px;\"><\/div>\n      <div class=\"bar-year\">2024\/25<\/div>\n      <div class=\"bar-note\"><\/div>\n    <\/div>\n    <div class=\"bar-col\">\n      <div class=\"bar-val\">2,898<\/div>\n      <div class=\"bar-body\" data-h=\"100\" style=\"background:#B03A2E;height:0px;\"><\/div>\n      <div class=\"bar-year\">2025\/26<\/div>\n      <div class=\"bar-note\">In-year \u00b7 not complete<\/div>\n    <\/div>\n  <\/div>\n<\/div>\n\n<!-- CONCLUSION BANNER -->\n<div class=\"conclusion-banner\">\n  <div class=\"concl-item\">\n    <div class=\"concl-label\">What is achievable<\/div>\n    <div class=\"concl-text\">Enforcement targets are <strong>reachable if complaint volumes stabilise<\/strong> and the CMS performs as designed. The monitoring exercise is credible if responsible parties respond honestly.<\/div>\n  <\/div>\n  <div class=\"concl-item\">\n    <div class=\"concl-label\">What is uncertain<\/div>\n    <div class=\"concl-text\">POPIA amendments require <strong>parliamentary passage with no confirmed timeline<\/strong>. Without them, the third-term Regulator (2027\u20132032) inherits the R10,000,000 fine ceiling unchanged.<\/div>\n  <\/div>\n  <div class=\"concl-item\">\n    <div class=\"concl-label\">What cannot be regulated away<\/div>\n    <div class=\"concl-text\">The 70% awareness gap, the 86% IO non-registration, and the AI governance silence are <strong>political and fiscal problems<\/strong>, not regulatory ones. The Regulator can advocate. It cannot compel Parliament.<\/div>\n  <\/div>\n<\/div>\n\n<!-- PULL QUOTE -->\n<div class=\"pull-quote-bar\">\n  <blockquote>\"All persons are empowered to assert their right to privacy and their right of access to information. That is the change we want to make.\"<\/blockquote>\n  <cite>\u2014 Advocate Pansy Tlakula, Chairperson, Information Regulator \u00b7 5 March 2026<\/cite>\n<\/div>\n\n<!-- LEGEND -->\n<div class=\"legend\">\n  <div class=\"legend-item\"><div class=\"legend-dot\" style=\"background:#2E75B6;\"><\/div>Enforcement<\/div>\n  <div class=\"legend-item\"><div class=\"legend-dot\" style=\"background:#B03A2E;\"><\/div>Capacity constraints<\/div>\n  <div class=\"legend-item\"><div class=\"legend-dot\" style=\"background:#C8922A;\"><\/div>Legislative reform<\/div>\n  <div class=\"legend-item\"><div class=\"legend-dot\" style=\"background:#1A7A6E;\"><\/div>AI governance<\/div>\n  <div class=\"legend-item\"><div class=\"legend-dot\" style=\"background:#1A3C5E;\"><\/div>Dual mandate<\/div>\n  <div class=\"legend-item\"><div class=\"legend-dot\" style=\"background:#6A5ACD;\"><\/div>Public awareness<\/div>\n  <div class=\"legend-item\" style=\"margin-left:auto;font-size:10px;color:#AAB;\">ITLawCo \u00b7 Data Protection Desk \u00b7 5 March 2026<\/div>\n<\/div>\n\n<script>\n  \/\/ Animate breach chart bars on load\n  window.addEventListener('load', () => {\n    setTimeout(() => {\n      document.querySelectorAll('.bar-body').forEach(bar => {\n        bar.style.transition = 'height 1s cubic-bezier(0.4,0,0.2,1)';\n        bar.style.height = bar.dataset.h + 'px';\n      });\n    }, 900);\n\n    \/\/ Fine bars\n    const fineWidths = { 'bar-za': '2.5', 'bar-br': '12', 'bar-uk': '87.5', 'bar-eu': '100' };\n    setTimeout(() => {\n      Object.entries(fineWidths).forEach(([id, w]) => {\n        const el = document.getElementById(id);\n        if (el) {\n          el.style.transition = 'width 1.2s cubic-bezier(0.4,0,0.2,1)';\n          el.style.width = w + '%';\n        }\n      });\n    }, 1000);\n  });\n<\/script>\n<\/body>\n<\/html>\n\t\t<\/div>\n\t<\/div>\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p><em>A public consultation on the 2026\/27 Annual Performance Plan revealed an enforcement body that has come a long way in a decade and an organisation under genuine strain. Breach notifications have increased fifteenfold in five years, the fine ceiling sits at a fraction of GDPR levels, fewer than one in five companies has registered an information officer, and the Regulator\u2019s own CEO publicly acknowledged it struggles to respond promptly. The ambitions are real and so are the constraints.<\/em><\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>Who should read this article?<\/h2>\n<p>This analysis is written for professionals operating at the intersection of law, technology, and governance. Role-specific relevance is as follows:<\/p>\n<table width=\"602\">\n<tbody>\n<tr>\n<td width=\"187\"><strong>Data protection lawyers<\/strong><\/td>\n<td width=\"415\">POPIA enforcement precedents, proposed amendments, PAJA constitutional risk, WhatsApp settlement implications, and the OUTsurance telemarketing test case.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><strong>Compliance officers<\/strong><\/td>\n<td width=\"415\">Information officer registration obligations (Section 55), the monitoring exercise, the forthcoming PIIA guidance note, and the gated-access code of conduct.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><strong>Regulators &amp; policymakers<\/strong><\/td>\n<td width=\"415\">Comparative fine regime analysis, dual-mandate governance architecture, AI\/Section 71 gap, and the resource-versus-mandate structural constraint.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><strong>Technologists &amp; AI teams<\/strong><\/td>\n<td width=\"415\">Section 71 automated decision-making rights, biometric special personal information under Section 26, AI Act cross-border obligations, and PIIA\/DPIA alignment.<\/td>\n<\/tr>\n<tr>\n<td width=\"187\"><strong>Civil society &amp; public bodies<\/strong><\/td>\n<td width=\"415\">The 70% public awareness gap, outreach programme reach, information officer obligations for public bodies, and PAIA access rights.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>Key statistics at a glance<\/h2>\n<table width=\"602\">\n<tbody>\n<tr>\n<td width=\"120\"><strong>Metric<\/strong><\/td>\n<td width=\"127\"><strong>Figure<\/strong><\/td>\n<td width=\"127\"><strong>Period \/ Source<\/strong><\/td>\n<td width=\"228\"><strong>Significance<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Security compromise notifications<\/td>\n<td width=\"127\">2,898 (in-year)<\/td>\n<td width=\"127\">2025\/26, to 5 Mar 2026<\/td>\n<td width=\"228\">Fifteenfold increase since 2021\/22<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Finalised security compromises<\/td>\n<td width=\"127\">1,578<\/td>\n<td width=\"127\">2025\/26 to date<\/td>\n<td width=\"228\">1,320 open; capacity gap<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Simple complaints (active caseload)<\/td>\n<td width=\"127\">1,681<\/td>\n<td width=\"127\">As at 1 Apr 2025<\/td>\n<td width=\"228\">Target: 70% resolved in 3 months<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Complex complaints (active caseload)<\/td>\n<td width=\"127\">373<\/td>\n<td width=\"127\">As at 1 Apr 2025<\/td>\n<td width=\"228\">Target: 50% resolved in 12 months<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Registered information officers<\/td>\n<td width=\"127\">69,040<\/td>\n<td width=\"127\">5 Mar 2026<\/td>\n<td width=\"228\">~14% of ~490,000 CIPC-active companies<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Sectoral assessments conducted<\/td>\n<td width=\"127\">35<\/td>\n<td width=\"127\">2021\u20132026<\/td>\n<td width=\"228\">Banks, telcos, govt, retail, higher ed<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Maximum administrative fine (POPIA)<\/td>\n<td width=\"127\">R200,000 to date (\u2248 \u20ac10,000)<\/td>\n<td width=\"127\">Fixed statutory ceiling<\/td>\n<td width=\"228\">vs GDPR \u20ac20m \/ 4% global turnover<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Public awareness of IR existence<\/td>\n<td width=\"127\">30%<\/td>\n<td width=\"127\">2023 public opinion survey<\/td>\n<td width=\"228\">70% of SA public unaware<\/td>\n<\/tr>\n<tr>\n<td width=\"120\">Staff headcount<\/td>\n<td width=\"127\">~130<\/td>\n<td width=\"127\">5 Mar 2026<\/td>\n<td width=\"228\">Single Gauteng location; no regional offices<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>The enforcement picture: Extraordinary numbers, modest tools<\/h2>\n<h3>A fifteenfold increase in five years<\/h3>\n<p>In 2021, the first full year that the South African <a href=\"https:\/\/inforegulator.org.za\/\">Information Regulator<\/a>\u2019s enforcement powers were operational, it received 202 security compromise notifications. By the 2024\/25 financial year that figure had reached 2,374. In the current year\u20142025\/26, not yet complete\u2014the in-year total already stands at 2,898.<\/p>\n<p>From 202 to 2,898 in under five years is a roughly fifteenfold increase. It is one of the most striking data points in South African regulatory governance, and it was presented at a public stakeholder session in Mpumalanga on 5 March 2026 with almost no interpretive framing.<\/p>\n<p>The increase almost certainly reflects two distinct phenomena operating simultaneously.<\/p>\n<ol>\n<li>The first is a genuine deterioration in the South African data security environment. A May 2025 report by Independent Online cited cybersecurity analysts to the effect that cyber attacks now represent a greater economic risk to South African organisations than load shedding,\u00a0 a comparison that, in the South African context, is striking.<\/li>\n<li>The second is a reporting normalisation effect: as POPIA\u2019s breach notification obligations (Section 22) become better understood and the Regulator\u2019s own awareness campaigns bring more organisations into the compliance ecosystem, incidents that would previously have gone unreported are now being disclosed.<\/li>\n<\/ol>\n<p>Advocate Tsehpo Boikanyo, the Regulator\u2019s POPIA executive, acknowledged this dynamic at the session. The two effects are not mutually exclusive, but they have quite different policy implications: one signals a security crisis requiring urgent industry intervention; the other signals a compliance culture beginning to take root. The Regulator did not attempt to disaggregate them, and stakeholders were not invited to interrogate the distinction.<\/p>\n<h3>How South Africa Ccmpares to peer regulators<\/h3>\n<p>For context: the UK <a href=\"https:\/\/ico.org.uk\/\">Information Commissioner\u2019s Office (ICO)<\/a> receives approximately 14,000 to 16,000 breach reports annually across an economy roughly three times the size of South Africa\u2019s by GDP. Ireland\u2019s <a href=\"https:\/\/www.dataprotection.ie\/en\">Data Protection Commission<\/a>\u2014whose jurisdiction encompasses the European headquarters of most major US technology companies\u2014received around 7,000 breach notifications in 2024. South Africa\u2019s in-year total of 2,898, for an economy at a much earlier stage of regulatory maturity, is not obviously out of proportion. What is striking is the rate of change, which suggests the reporting infrastructure is still being built rather than operating at steady state.<\/p>\n<blockquote><p>\nWe are not where we should be. We are pushing that we should be a responsive organisation. I must be honest about that.\n<\/p><\/blockquote>\n<p>Against this volume, the Regulator has finalised 1,578 of the current year\u2019s compromises. The gap\u20141,320 open matters at the current run rate\u2014is a function of institutional capacity rather than regulatory will. CEO Mosalanyane Mosala did not obscure this. His admission that the Regulator \u201cstruggles with responsiveness\u201d is, for an enforcement body whose deterrent effect depends substantially on the credibility of its follow-through, a significant statement. A regulator that cannot process breach notifications within a reasonable timeframe cannot credibly signal to the market that non-compliance carries consequences.<\/p>\n<h3>The fine ceiling problem<\/h3>\n<p>The deterrence question has a second dimension the session surfaced but did not adequately address: the maximum administrative fine available under POPIA is R10,000,000. In absolute terms, this is the equivalent of approximately \u20ac520,000 at current exchange rates.<\/p>\n<table width=\"602\">\n<tbody>\n<tr>\n<td width=\"201\"><strong>Jurisdiction \/ Framework<\/strong><\/td>\n<td width=\"201\"><strong>Maximum Administrative Fine<\/strong><\/td>\n<td width=\"201\"><strong>Basis<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"201\">South Africa (POPIA)<\/td>\n<td width=\"201\">R10,000,000 (\u2248 \u20ac520,000)<\/td>\n<td width=\"201\">Fixed ceiling<\/td>\n<\/tr>\n<tr>\n<td width=\"201\">European Union (GDPR)<\/td>\n<td width=\"201\">\u20ac20 million or 4% global turnover<\/td>\n<td width=\"201\">Tiered, higher of two<\/td>\n<\/tr>\n<tr>\n<td width=\"201\">United Kingdom (UK GDPR)<\/td>\n<td width=\"201\">\u00a317.5 million<\/td>\n<td width=\"201\">Tiered<\/td>\n<\/tr>\n<tr>\n<td width=\"201\">Brazil (LGPD)<\/td>\n<td width=\"201\">2% of Brazilian revenue, cap R$50m<\/td>\n<td width=\"201\">Per-infringement<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The <a href=\"https:\/\/www.itweb.co.za\/article\/inforeg-exposes-popia-violators-as-data-breaches-mount\/kLgB17ezby5M59N4\">Lancet Laboratories<\/a> matter\u2014concerning the mishandling of sensitive health information\u2014resulted in a payment of R200,000. <a href=\"https:\/\/inforegulator.org.za\/wp-content\/uploads\/2020\/07\/FT-RAMS-CONSULTING-ENFORCEMENT-NOTICE-210224_Redacted.pdf\">FT Rams<\/a> declined to pay its fine at all, presumably calculating that litigation was commercially rational.<\/p>\n<p>Adv Boikanyo disclosed that the Regulator is processing draft amendments to POPIA with one stated objective: moving away from the current \u201ccorrect and remedy\u201d framework under which a responsible party is typically afforded an opportunity to remediate a contravention before an infringement notice is issued\u2014towards a regime of more direct consequences for intentional non-compliance.<\/p>\n<p>This is a meaningful reform signal, but it requires careful analysis of two distinct questions the session conflated:<\/p>\n<ol>\n<li>first, whether the prior remediation step should be removed or curtailed; and<\/li>\n<li>second, whether the fine ceiling itself should be raised.<\/li>\n<\/ol>\n<p>These are separable questions with different legal and political trajectories, and the Regulator has not publicly confirmed which it will address, or both.<\/p>\n<p>The constitutional dimension also warrants attention. The current remediation-first framework exists in part because of the <a href=\"https:\/\/www.gov.za\/documents\/promotion-administrative-justice-act\">Promotion of Administrative Justice Act (PAJA)<\/a> and Section 33 of the Constitution, which guarantee procedurally fair administrative action. A regime moving directly to financial penalty will need to demonstrate its procedural safeguards satisfy the PAJA standard or face challenge from well-resourced responsible parties. The WhatsApp and Department of Justice matters already indicate that the Regulator\u2019s enforcement decisions attract legal challenge; a more aggressive fine regime will attract more of it.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>Institutional capacity: The structural story the session told<\/h2>\n<h3>The information officer registration gap<\/h3>\n<p>The most revealing data point of the entire session was not the security compromise figures. It was a number mentioned in passing: 69,040 information officers are currently registered with the Regulator.<\/p>\n<p>The Companies and Intellectual Property Commission (CIPC) maintains approximately 490,000 active company registrations. The Regulator\u2019s own figures therefore imply that roughly 14% of South African registered companies have complied with their Section 55 POPIA obligation to register an information officer, nearly five years after enforcement powers came into force on 1 July 2021. If one includes close corporations and other legal persons with POPIA obligations, the compliance rate may be lower still.<\/p>\n<p>This is not a marginal compliance gap but a structural one. It raises a question the session did not address: what does the Regulator intend to do about the 86% of registrable entities that have not complied with the most basic administrative obligation the legislation imposes?<\/p>\n<h3>130 people, one location, one national mandate<\/h3>\n<p>The Regulator employs approximately 130 people, operates from a single base in Gauteng with no regional offices, and\u2014at the time of the session\u2014had been operating without physical premises for a period, planning to return on 16 March 2026. An organisation of 130 people with a single location is being asked to regulate the data protection behaviour of every public body, every private company, and every other juristic person in a country of 61 million people. The structural gap between mandate and capacity is the defining constraint of the Regulator\u2019s current position.<\/p>\n<p>CEO Mosala addressed governance structures at length: the Section 49 committees, the Enforcement Committee, the audit and risk oversight mechanisms. But these are internal accountability instruments rather than solutions to the capacity constraint. The more important question, which the session did not answer, is whether the National Treasury\u2019s fiscal envelope for the Regulator will expand materially in the third planning term beginning 2027, and whether Parliament will fill the two current vacancies in time to provide continuity into the new term.<\/p>\n<blockquote><p>\nIf you can\u2019t do big things in life, do small things but do them in a big way. That\u2019s where excellence comes in for us.\n<\/p><\/blockquote>\n<h3>APP targets and the responsiveness standard<\/h3>\n<p>The 2026\/27 APP targets for complaint resolution\u201450% of complex complaints within 12 months, 70% of simple complaints within 3 months\u2014are improvements on current performance but fall well short of the standard that data subjects seeking timely redress would consider adequate.<\/p>\n<p>The GDPR\u2019s Article 78 right to an effective judicial remedy specifically contemplates that data subjects may go directly to court where a supervisory authority has not handled a complaint \u201cwithin three months\u201d. South Africa\u2019s comparable provisions impose no equivalent procedural discipline on the Regulator\u2019s responsiveness. Mosala\u2019s frank self-assessment was given in the spirit of transparency. But transparency about a deficit is not the same as a plan to address it.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>Legislative reform: What the amendments will and must address<\/h2>\n<h3>Direct marketing: The OUTsurance test case<\/h3>\n<p>The Regulator\u2019s position on direct marketing is clear: telephone calls fall within the statutory definition of \u201celectronic communications\u201d, bringing telemarketing calls squarely within POPIA\u2019s opt-in consent regime. Responsible parties, including members of the <a href=\"https:\/\/dmasa.org\/\">Direct Marketing Association of South Africa (DMASA)<\/a>, dispute this interpretation.<\/p>\n<p>The test case involving OUTsurance, currently before the Enforcement Committee, will produce a determination that either validates the Regulator\u2019s position or requires legislative clarification. Either outcome is significant: agreement creates a compliance obligation affecting hundreds of South African businesses overnight; disagreement requires parliamentary amendment. DMASA CEO David Dickens noted that his organisation\u2019s 250-plus members are ready to implement guidance once it arrives.<\/p>\n<h3>The Section 60 code of conduct bottleneck<\/h3>\n<p>Approved codes of conduct have the potential to be powerful compliance instruments, allowing industry bodies to develop sector-specific standards with regulatory endorsement. DMASA has submitted a code of conduct twice, receiving it back with revision requests on both occasions. The slow progress of the DMASA code\u2014the largest such submission received to date\u2014suggests that the Regulator\u2019s code assessment capacity is a bottleneck the amendments should explicitly address. The Regulator confirmed at the session that it will return to physical premises on 16 March 2026 and invited fresh submissions immediately.<\/p>\n<h3>Gated-access code of conduct<\/h3>\n<p>The Regulator is developing a code to regulate access control systems\u2014biometrics, CCTV, vehicle registration readers, visitor logs\u2014at residential estates, business parks, and other gated establishments. Approximately five million South Africans live in gated residential developments. The code will address transparency obligations, retention limits, and safeguards against misuse or over-collection of personal information. Adv Boikanyo indicated it is in advanced development; its publication will be a meaningful addition to the POPIA compliance landscape.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>The AI question: A governance gap the regulator has not yet addressed<\/h2>\n<h3>Thirty seconds that deserve a full policy programme<\/h3>\n<p>The most intellectually important exchange of the session lasted approximately thirty seconds. Wanani Sitsula, representing the <a href=\"https:\/\/www.cgso.org.za\/\">Consumer Goods and Services Ombud<\/a>, asked the Regulator what plans it has to mitigate the risks associated with AI. No specific programme was announced. The question was noted, and the session moved on.<\/p>\n<p>This is a governance gap that cannot comfortably persist. The European Union\u2019s AI Act entered its first phase of application in February 2025, prohibiting a list of unacceptable AI practices and imposing obligations on providers and deployers of high-risk AI systems. South African companies with EU-facing operations are already subject to its obligations.<\/p>\n<h3>Section 71: POPIA\u2019s unused automated decision-making provision<\/h3>\n<p>More immediately, POPIA already contains provisions directly relevant to automated decision-making. Section 71 provides that a data subject has the right not to be subject to a decision that results in legal or similarly significant consequences where that decision is based solely on automated processing of personal information, unless the responsible party can establish a lawful ground and has taken steps to safeguard the data subject\u2019s legitimate interests.<\/p>\n<p>The right articulated by Section 71 is structurally analogous to Article 22 of the GDPR. But unlike the GDPR, which has generated substantial regulatory guidance from the European Data Protection Board and national supervisory authorities, Section 71 of POPIA has received almost no regulatory elaboration in South Africa. There is no guidance note, no case study, no published enforcement position.<\/p>\n<p>As AI-driven credit scoring, automated insurance underwriting, algorithmic hiring tools, and predictive policing applications become more prevalent in the South African market, the Regulator\u2019s silence on Section 71 is an increasingly significant gap. It is also a gap with immediate commercial implications: responsible parties deploying AI systems have no authoritative regulatory reference point against which to assess their POPIA compliance exposure.<\/p>\n<h3>AI, biometrics, and the special personal information regime<\/h3>\n<p>The interaction between AI governance and the Regulator\u2019s mandate extends beyond automated decisions. The processing of training data for AI models raises purpose limitation questions under POPIA\u2019s Condition 2. Facial recognition systems, in active deployment at the access-controlled estates the Regulator\u2019s proposed gated-access code seeks to regulate, involve the processing of biometric information: a category of \u201cspecial personal information\u201d under Section 26, attracting heightened protection and explicit consent requirements. The intersection of AI system deployment and POPIA\u2019s special category regime has not been addressed in any published Regulator guidance.<\/p>\n<h3>The PIA guidance note as an AI governance vehicle<\/h3>\n<p>Adv Boikanyo confirmed that the Regulator intends to publish a guidance note on <a href=\"https:\/\/itlawco.com\/piias-under-popia\/\">Personal Information Impact Assessments (PIIAs)<\/a> in the coming financial year. A well-designed PIIA framework would provide a vehicle for integrating AI risk assessment into POPIA compliance programmes, analogous to the EU\u2019s DPIA requirements under GDPR Article 35. The Regulator would be well-advised to draft its PIIA guidance with AI use cases explicitly in scope. The legislative and conceptual architecture for addressing AI risk already exists within POPIA; what is missing is the regulatory will and capacity to deploy it.<\/p>\n<p>A note of balance is warranted here. AI governance is a domain in which regulators globally are still developing coherent frameworks. The EU AI Act itself has only recently entered application, and its interaction with the GDPR remains contested in several member states. It would be unreasonable to expect the South African Regulator\u2014with 130 staff and a contested enforcement budget\u2014to have produced a comprehensive AI governance framework in advance of jurisdictions with far greater resources. The reasonable expectation is that Section 71 guidance and PIIA-AI integration are treated as priorities in the 2026\/27 financial year, not deferred to the next planning cycle.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>Governance architecture: The dual mandate and its international distinction<\/h2>\n<h3>Why the dual-mandate model is globally unusual<\/h3>\n<p>Advocate Lebogang Stroom, a member of the Regulator, observed almost in passing: South Africa is, globally, among a small group of jurisdictions that vest both access to information and data protection oversight in a single institution. Most countries have either a data protection commissioner or an access to information commissioner, not both. The South African model, in which PAIA and POPIA are administered by the same body, enables a form of cross-referencing that structurally separate regulators cannot perform.<\/p>\n<p>This matters in practice. When a requestor seeks access to information that contains the personal information of a third party, PAIA\u2019s grounds for refusal and POPIA\u2019s processing conditions interact directly. When journalists seek to publish personal information in the public interest, POPIA\u2019s Section 7 exclusion for journalistic purposes operates alongside PAIA\u2019s access obligations. When government bodies deny access to information, the question of whether that denial is itself a data protection issue can only be coherently addressed by an institution that holds both mandates.<\/p>\n<h3>The matric results case: The dual mandate in court<\/h3>\n<p>The matric results litigation is the live demonstration of this tension. The Department of Basic Education publishes examination results in a format the Regulator argues requires parental consent, on the basis that an examination number constitutes personal information. The Department argues that publication is a legitimate exercise of its public function. At first instance, the court found for the Department. The Regulator is seeking leave to appeal to the Supreme Court of Appeal, with a hearing listed for 12 March 2026. The outcome will define the boundary between the two statutes in one of its most practically consequential configurations.<\/p>\n<h3>The WhatsApp settlement and the case for published precedent<\/h3>\n<p>The WhatsApp settlement\u2014currently being reduced to a court order\u2014raises questions under both POPIA (lawful processing conditions) and PAIA (user access rights). The substantive terms have not been disclosed, but given WhatsApp\u2019s reach of an estimated 25 million South African users, any compliance undertakings agreed carry significant precedent weight. Other jurisdictions\u2019 regulators have sought to ensure that WhatsApp enforcement decisions produce published precedent. The South African Regulator should consider whether the same approach is warranted here. A settlement reduced to a court order without published reasoning provides little guidance to the 490,000 other responsible parties operating under POPIA.<\/p>\n<h3>Codifying jurisprudence: An essential next step<\/h3>\n<p>Adv Stroom noted that the Regulator is actively working to analyse and codify the jurisprudence emerging from its Enforcement Committee. Legal certainty for responsible parties depends on consistent, published, and reasoned decisions. If the Regulator\u2019s internal analysis leads to a published compendium of enforcement decisions\u2014analogous to the ICO\u2019s published enforcement case register or the Irish DPC\u2019s decision archive\u2014it would meaningfully advance South Africa\u2019s data protection culture. This is work the 2026\/27 planning year should deliver.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>Public awareness: The 70% problem<\/h2>\n<p>Acting EduCom Executive Nomzamo Zondi opened her presentation with a real-time audience poll. Of approximately 38 respondents at a stakeholder session attended predominantly by compliance officers, lawyers, and regulated entities, 14 (roughly 37%) reported that they did not feel well-informed about the Regulator\u2019s programmes and activities. If 37% of a professionally engaged stakeholder audience lacks adequate information, the figures for the general public are unsurprisingly starker.<\/p>\n<p>The Regulator\u2019s 2023 public opinion survey found that only 30% of the South African public had heard of the Information Regulator at all. The remaining 70% (approximately 43 million people) were unaware of the existence of the body responsible for protecting their personal information and promoting their right of access to information. Awareness was concentrated among tertiary-educated, employed, and digitally connected citizens. Among rural, lower-income, and less-educated communities\u2014precisely those most vulnerable to data exploitation and institutional information gatekeeping\u2014awareness was near-negligible.<\/p>\n<p>This is not a criticism of the EduCom division, which has pursued an outreach programme across seven provinces with evident energy: Free State, KwaZulu-Natal, Mpumalanga, North West, and Northern Cape have all been reached in the past year, with a deliberate focus on district municipalities far from the Regulator\u2019s Gauteng base. NGOs and NPOs have been cultivated as community intermediaries. Social media presence has grown to the point where it is the primary channel through which stakeholders report receiving Regulator communications.<\/p>\n<p>The 70% awareness gap is, however, a structural problem with a structural cause: the Regulator is a single-location organisation with 130 staff and a national awareness mandate. The arithmetic of reaching a general population of 61 million, without regional offices and in a country with eleven official languages and vast digital access disparities, makes the 70% gap the most durable structural challenge the Regulator faces. No APP target addresses it at scale.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>What the year ahead holds: Assessing whether the ambition is credible<\/h2>\n<p>The Information Regulator\u2019s 2026\/27 Annual Performance Plan is, by the standards of a ten-year-old institution that started from nothing, a serious document. The enforcement record comprises 35 sectoral assessments, four completed enforcement matters, a WhatsApp settlement, and a Supreme Court appeal in progress. It represents genuine institutional achievement. The monitoring exercise, the PIIA guidance note, the gated-access code, and the proposed POPIA amendments all signal a regulator that is actively developing its regulatory toolkit rather than standing still.<\/p>\n<p>The question the session should have been asked to answer, but was not, is whether the 2026\/27 ambitions are achievable given the structural constraints the Regulator itself disclosed. The answer, assessed candidly, is: partially and unevenly.<\/p>\n<p>The enforcement targets are achievable if the complaints management system performs as intended and investigator headcount grows modestly. They are not achievable if the current rate of complaint volume increase continues without a corresponding increase in investigative capacity. The monitoring exercise is a credible proactive tool, but its effectiveness depends on responsible parties responding honestly to self-certification requests. The Regulator\u2019s own acknowledgment that paper compliance is widespread suggests it will not always get honest answers.<\/p>\n<p>The legislative reform agenda is the most uncertain variable. POPIA amendments require parliamentary passage. The portfolio committee on Justice and Constitutional Development is, by Chairperson Adv Tlakula\u2019s account, currently occupied with the ad hoc committee on police corruption and has not found time to fill two Regulator vacancies. There is no indication that POPIA amendment legislation will be prioritised in the 2026 parliamentary calendar. If the amendments are not passed before the end of the second term of members in November 2026, the third-term Regulator will inherit both the reform agenda and the structural fine ceiling without the legislative tools to address them.<\/p>\n<p>The broader picture that the session revealed, without quite stating, is this: South Africa has built a data protection institution that is now recognisably functioning. It has enforcement powers, a complaints system, an outreach programme, and a governance architecture. What it lacks and what no Annual Performance Plan can substitute for is the resource base proportionate to its mandate, a fine regime with genuine deterrent effect, and the legislative updates that five years of operational experience have shown are necessary. Those are ultimately political and fiscal decisions, not regulatory ones. The Regulator can recommend, advocate, and demonstrate need, but it cannot compel Parliament to act.<\/p>\n<blockquote><p>\nAll persons are empowered to assert their right to privacy and their right of access to information. That is the change we want to make.\n<\/p><\/blockquote>\n<p>That is the right ambition. It is also an ambition that, on the evidence of the session, requires more than an ambitious Annual Performance Plan to achieve. It requires a Parliament willing to modernise the legislative framework, a Treasury willing to fund the institutional capacity, and a compliance culture among responsible parties that the Regulator is still, by its own account, working to build. In Human Rights Month, in the year of the South African Constitution\u2019s thirtieth anniversary, that is not a counsel of despair, but an accurate description of the work that remains.<\/p>\n<\/div>\n\n\n\n\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<h2>FAQs<\/h2>\n<\/div>\n\n\n\n<div class=\"toggles \" data-br=\"none\" data-starting=\"default\" data-style=\"default\"><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0de9862\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0de9862\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>How many security breaches has the Information Regulator received?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0de9862\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0de9862\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>The Regulator has received 2,898 security compromise notifications in the 2025\/26 financial year to date (as at 5 March 2026), compared to 202 in 2021\/22, 590 in 2022\/23, 1,727 in 2023\/24, and 2,374 in 2024\/25. This represents a roughly fifteenfold increase in under five years, reflecting both genuine increases in cyber threats and a reporting normalisation effect as POPIA\u2019s breach notification obligations (Section 22) become better understood.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0de9cd9\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0de9cd9\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Are South African companies required to register an information officer under POPIA?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0de9cd9\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0de9cd9\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes. Section 55 of POPIA requires all responsible parties (organisations that process personal information) to register an information officer with the Information Regulator. As at 5 March 2026, only 69,040 information officers are registered against an estimated 490,000 CIPC-active companies, implying a compliance rate of approximately 14%. Failure to register is a contravention of POPIA.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0dea137\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0dea137\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>Does POPIA have an automated decision-making provision equivalent to GDPR Article 22?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0dea137\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0dea137\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>Yes. Section 71 of POPIA provides that a data subject has the right not to be subject to a decision producing legal or similarly significant consequences based solely on automated processing of personal information, unless the responsible party establishes a lawful ground and implements adequate safeguards. However, unlike the GDPR, Section 71 has received almost no published regulatory guidance from the Information Regulator. No guidance note, enforcement position, or case study has been published as at March 2026.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0dea592\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0dea592\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What is the status of the Information Regulator\u2019s case against WhatsApp?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0dea592\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0dea592\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>The Information Regulator and WhatsApp have signed a settlement agreement concerning WhatsApp\u2019s privacy policy as applied in the South African market. As at 5 March 2026, the settlement is being reduced to a court order. The substantive terms have not been publicly disclosed. Given WhatsApp\u2019s estimated 25 million South African users, the compliance undertakings in the settlement carry significant market-wide implications.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0dea9df\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0dea9df\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What is the status of the POPIA amendment process?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0dea9df\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0dea9df\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>The Information Regulator has prepared a first draft of proposed POPIA amendments, which are still being processed internally. Key objectives include moving away from the current \u201ccorrect and remedy\u201d enforcement framework and introducing more direct consequences for intentional non-compliance. The draft must undergo parliamentary passage. Given that the portfolio committee on Justice and Constitutional Development is currently occupied with other matters, there is no confirmed timeline for introduction of amendment legislation.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0deae21\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0deae21\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What is South Africa\u2019s dual-mandate model for information regulation?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0deae21\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0deae21\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>South Africa is among a small group of jurisdictions globally in which a single institution administers both data protection (POPIA) and access to information (PAIA) law. The Information Regulator holds both mandates, enabling cross-referencing between the right to privacy and the right of access to information that structurally separate regulators in most other countries cannot perform. This is directly relevant in matters such as the matric results litigation, the WhatsApp settlement, and third-party personal information in PAIA requests.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0deb290\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0deb290\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>How does the Information Regulator\u2019s 2026\/27 APP define its performance targets?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0deb290\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0deb290\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>The 2026\/27 APP sets the following key targets for the POPIA division: 50% of complex complaints investigated and resolved within 12 months; 70% of simple complaints investigated and resolved within 3 months; 70% of simple complaints resolved through conciliation and mediation. These represent improvements on current performance but fall short of the three-month supervisory authority response standard contemplated by GDPR Article 78.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0deb6e7\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0deb6e7\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>What is the Information Regulator\u2019s position on AI risk?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0deb6e7\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0deb6e7\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>As at 5 March 2026, the Regulator has not published any guidance on AI risk, automated decision-making under Section 71, or the processing of AI training data under Condition 2 (purpose limitation) of POPIA. A guidance note on Privacy Impact Assessments (PIAs) is planned for the 2026\/27 financial year. ITLawCo considers this the appropriate vehicle for integrating AI risk assessment into POPIA compliance programmes, analogous to DPIA requirements under GDPR Article 35.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><div class=\"toggle default\" data-inner-wrap=\"true\"><h3 class=\"toggle-title\"><a href=\"#\" id=\"toggle-button-6a9ffe0debb27\" role=\"button\" aria-expanded=\"false\" aria-controls=\"toggle-panel-6a9ffe0debb27\" class=\"toggle-heading\"><i role=\"presentation\" class=\"fa fa-plus\"><\/i>When does the Information Regulator\u2019s second term of office end?<\/a><\/h3><div id=\"toggle-panel-6a9ffe0debb27\" role=\"region\" aria-labelledby=\"toggle-button-6a9ffe0debb27\"><div class=\"inner-toggle-wrap\">\n<div class=\"wpb_text_column wpb_content_element \" >\n\t<p>The second term of office of the current members of the Information Regulator ends in November 2026. The 2026\/27 APP is the final Annual Performance Plan of the second term. The third term (2027\u20132032) will bring a fresh five-year strategic cycle. Two vacancies on the five-member panel currently remain unfilled, pending Parliamentary Committee action.<\/p>\n<\/div>\n\n\n\n<\/div><\/div><\/div><\/div>\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n\t\t<div id=\"fws_6a9ffe0dec109\"  data-column-margin=\"default\" data-midnight=\"dark\"  class=\"wpb_row vc_row-fluid vc_row\"  style=\"padding-top: 0px; padding-bottom: 0px; \"><div class=\"row-bg-wrap\" data-bg-animation=\"none\" data-bg-animation-delay=\"\" data-bg-overlay=\"false\"><div class=\"inner-wrap row-bg-layer\" ><div class=\"row-bg viewport-desktop\"  style=\"\"><\/div><\/div><\/div><div class=\"row_col_wrap_12 col span_12 dark left\">\n\t<div  class=\"vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding inherit_tablet inherit_phone \"  data-padding-pos=\"all\" data-has-bg-color=\"false\" data-bg-color=\"\" data-bg-opacity=\"1\" data-animation=\"\" data-delay=\"0\" >\n\t\t<div class=\"vc_column-inner\" >\n\t\t\t<div class=\"wpb_wrapper\">\n\t\t\t\t\n\t<div class=\"wpb_raw_code wpb_raw_html wpb_content_element\" >\n\t\t<div class=\"wpb_wrapper\">\n\t\t\t<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n  <meta charset=\"UTF-8\" \/>\n  <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" \/>\n\n  <!-- \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\n       PRIMARY META\n  \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550 -->\n  <title>South Africa Information Regulator 2026\/27 Annual Performance Plan: Enforcement, Capacity, and What It Means for POPIA Compliance | ITLawCo<\/title>\n\n  <meta name=\"description\"\n        content=\"Analysis of the South African Information Regulator's 2026\/27 Annual Performance Plan consultation. Covers POPIA enforcement statistics, the R10,000,000 fine ceiling, information officer registration gaps, AI governance under Section 71, PAIA\/POPIA dual mandate, and proposed legislative amendments. Essential reading for data protection lawyers, compliance officers, and regulators operating in or monitoring the South African market.\" \/>\n\n  <meta name=\"keywords\"\n        content=\"Information Regulator South Africa, POPIA compliance 2026, POPIA enforcement, Annual Performance Plan 2026 2027, PAIA, data protection South Africa, information officer registration, POPIA fine, Section 71 automated decision-making, AI governance South Africa, POPIA amendments, OUTsurance telemarketing, WhatsApp POPIA, matric results POPIA, GDPR comparison South Africa\" \/>\n\n  <meta name=\"author\"        content=\"ITLawCo Data Protection Desk\" \/>\n  <meta name=\"robots\"        content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n  <meta name=\"language\"      content=\"en-ZA\" \/>\n  <meta name=\"geo.region\"    content=\"ZA\" \/>\n  <meta name=\"geo.placename\" content=\"South Africa\" \/>\n\n  <link rel=\"canonical\" href=\"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/\" \/>\n\n  <!-- \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\n       OPEN GRAPH\n  \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550 -->\n  <meta property=\"og:type\"               content=\"article\" \/>\n  <meta property=\"og:site_name\"          content=\"ITLawCo\" \/>\n  <meta property=\"og:title\"              content=\"South Africa Information Regulator 2026\/27 Annual Performance Plan: Enforcement, Capacity, and What It Means for POPIA Compliance\" \/>\n  <meta property=\"og:description\"        content=\"Analysis of the South African Information Regulator's 2026\/27 APP consultation. Covers enforcement statistics, the R10m fine ceiling, IO registration gaps, AI governance under Section 71, and proposed POPIA amendments.\" \/>\n  <meta property=\"og:url\"                content=\"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/\" \/>\n  <meta property=\"og:image\"              content=\"https:\/\/itlawco.com\/assets\/images\/constitutional-court-johannesburg-hero.jpg\" \/>\n  <meta property=\"og:image:alt\"          content=\"Constitutional Court of South Africa, Johannesburg \u2014 seat of constitutional rights to privacy and access to information\" \/>\n  <meta property=\"og:image:width\"        content=\"1200\" \/>\n  <meta property=\"og:image:height\"       content=\"630\" \/>\n  <meta property=\"og:locale\"             content=\"en_ZA\" \/>\n  <meta property=\"article:published_time\" content=\"2026-03-05T00:00:00+02:00\" \/>\n  <meta property=\"article:modified_time\"  content=\"2026-03-05T00:00:00+02:00\" \/>\n  <meta property=\"article:author\"         content=\"https:\/\/itlawco.com\/about\/data-protection-desk\" \/>\n  <meta property=\"article:section\"        content=\"Regulatory Analysis\" \/>\n  <meta property=\"article:tag\"            content=\"POPIA\" \/>\n  <meta property=\"article:tag\"            content=\"Information Regulator\" \/>\n  <meta property=\"article:tag\"            content=\"Data Protection South Africa\" \/>\n  <meta property=\"article:tag\"            content=\"PAIA\" \/>\n  <meta property=\"article:tag\"            content=\"AI Governance\" \/>\n\n  <!-- \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\n       TWITTER \/ X CARD\n  \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550 -->\n  <meta name=\"twitter:card\"        content=\"summary_large_image\" \/>\n  <meta name=\"twitter:site\"        content=\"@ITLawCo\" \/>\n  <meta name=\"twitter:creator\"     content=\"@ITLawCo\" \/>\n  <meta name=\"twitter:title\"       content=\"South Africa Information Regulator 2026\/27 APP: Enforcement, Capacity, and What It Means for POPIA Compliance\" \/>\n  <meta name=\"twitter:description\" content=\"Breach notifications up fifteenfold. 86% of companies without a registered information officer. R10m fine ceiling \u2014 but fines imposed at 2% of that. A close reading of the Regulator's 2026\/27 Annual Performance Plan consultation.\" \/>\n  <meta name=\"twitter:image\"       content=\"https:\/\/itlawco.com\/assets\/images\/constitutional-court-johannesburg-hero.jpg\" \/>\n  <meta name=\"twitter:image:alt\"   content=\"Constitutional Court of South Africa, Johannesburg\" \/>\n\n  <!-- \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\n       JSON-LD STRUCTURED DATA\n       Schema types used:\n         1. NewsArticle          \u2014 primary article entity\n         2. LegalScholarlyArticle \u2014 secondary type overlay\n         3. FAQPage              \u2014 10 FAQ pairs\n         4. BreadcrumbList       \u2014 site navigation\n         5. Organization         \u2014 publisher entity\n         6. Dataset (inline)     \u2014 key statistics\n  \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550 -->\n\n  <!-- \u2500\u2500 1 & 2. NewsArticle + LegalScholarlyArticle \u2500\u2500 -->\n  <script type=\"application\/ld+json\">\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@graph\": [\n      {\n        \"@type\": [\"NewsArticle\", \"ScholarlyArticle\"],\n        \"@id\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#article\",\n        \"headline\": \"South Africa Information Regulator 2026\/27 Annual Performance Plan: Enforcement, Capacity, and What It Means for POPIA Compliance\",\n        \"alternativeHeadline\": \"South Africa's Data Watchdog: Ambition, Capacity, and the Gap Between Them\",\n        \"description\": \"Analysis of the South African Information Regulator's 2026\/27 Annual Performance Plan consultation held on 5 March 2026. Covers POPIA enforcement statistics, the R10,000,000 fine ceiling, information officer registration compliance (estimated 14%), AI governance under Section 71, the PAIA\/POPIA dual mandate, and proposed legislative amendments.\",\n        \"abstract\": \"The South African Information Regulator held its 2026\/27 Annual Performance Plan stakeholder consultation on 5 March 2026 in Mpumalanga. Security compromise notifications have increased fifteenfold since enforcement powers came into force in 2021. Approximately 86% of CIPC-registered companies have not registered an information officer under Section 55 of POPIA. The maximum administrative fine under POPIA is R10,000,000, compared to the GDPR ceiling of \u20ac20 million or 4% of global turnover. The Regulator is processing draft POPIA amendments and a Privacy Impact Assessment guidance note. Section 71 (automated decision-making) has received no published regulatory guidance. This analysis evaluates whether the Regulator's stated ambitions are achievable given its structural constraints.\",\n        \"url\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/\",\n        \"mainEntityOfPage\": {\n          \"@type\": \"WebPage\",\n          \"@id\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/\"\n        },\n        \"image\": {\n          \"@type\": \"ImageObject\",\n          \"url\": \"https:\/\/itlawco.com\/assets\/images\/constitutional-court-johannesburg-hero.jpg\",\n          \"caption\": \"Constitutional Court of South Africa, Johannesburg \u2014 seat of constitutional rights to privacy and access to information\",\n          \"width\": 1200,\n          \"height\": 630,\n          \"representativeOfPage\": true\n        },\n        \"datePublished\": \"2026-03-05T00:00:00+02:00\",\n        \"dateModified\":  \"2026-03-05T00:00:00+02:00\",\n        \"author\": {\n          \"@type\": \"Organization\",\n          \"name\": \"ITLawCo Data Protection Desk\",\n          \"url\": \"https:\/\/itlawco.com\/about\/data-protection-desk\",\n          \"description\": \"ITLawCo's specialist desk covering POPIA compliance, PAIA administration, African data governance, and comparative privacy law.\"\n        },\n        \"publisher\": {\n          \"@type\": \"Organization\",\n          \"@id\": \"https:\/\/itlawco.com#organization\",\n          \"name\": \"ITLawCo\",\n          \"url\": \"https:\/\/itlawco.com\",\n          \"logo\": {\n            \"@type\": \"ImageObject\",\n            \"url\": \"https:\/\/itlawco.com\/assets\/images\/itlawco-logo.png\",\n            \"width\": 300,\n            \"height\": 60\n          },\n          \"sameAs\": [\n            \"https:\/\/www.linkedin.com\/company\/itlawco\",\n            \"https:\/\/twitter.com\/ITLawCo\"\n          ]\n        },\n        \"inLanguage\": \"en-ZA\",\n        \"isAccessibleForFree\": true,\n        \"license\": \"https:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/\",\n        \"keywords\": [\n          \"Information Regulator South Africa\",\n          \"POPIA compliance\",\n          \"Annual Performance Plan 2026 2027\",\n          \"POPIA enforcement\",\n          \"POPIA fine ceiling\",\n          \"information officer registration\",\n          \"Section 71 automated decision-making\",\n          \"AI governance South Africa\",\n          \"POPIA amendments\",\n          \"PAIA POPIA dual mandate\",\n          \"OUTsurance telemarketing\",\n          \"WhatsApp POPIA settlement\",\n          \"matric results POPIA appeal\",\n          \"Privacy Impact Assessment South Africa\",\n          \"data protection Africa\",\n          \"GDPR comparison\"\n        ],\n        \"about\": [\n          {\n            \"@type\": \"Thing\",\n            \"name\": \"Information Regulator (South Africa)\",\n            \"sameAs\": \"https:\/\/www.wikidata.org\/wiki\/Q55673888\"\n          },\n          {\n            \"@type\": \"Legislation\",\n            \"name\": \"Protection of Personal Information Act 4 of 2013 (POPIA)\",\n            \"jurisdiction\": \"South Africa\",\n            \"legislationType\": \"Act of Parliament\"\n          },\n          {\n            \"@type\": \"Legislation\",\n            \"name\": \"Promotion of Access to Information Act 2 of 2000 (PAIA)\",\n            \"jurisdiction\": \"South Africa\",\n            \"legislationType\": \"Act of Parliament\"\n          }\n        ],\n        \"mentions\": [\n          { \"@type\": \"Person\",  \"name\": \"Advocate Pansy Tlakula\",   \"jobTitle\": \"Chairperson, Information Regulator\" },\n          { \"@type\": \"Person\",  \"name\": \"Mosalanyane Mosala\",        \"jobTitle\": \"Chief Executive Officer, Information Regulator\" },\n          { \"@type\": \"Person\",  \"name\": \"Advocate Tsepo Bukanyo\",   \"jobTitle\": \"Executive: POPIA Division, Information Regulator\" },\n          { \"@type\": \"Person\",  \"name\": \"Advocate Lebogang Stroom\", \"jobTitle\": \"Member, Information Regulator\" },\n          { \"@type\": \"Person\",  \"name\": \"Nomsamo Zondi\",            \"jobTitle\": \"Acting Executive: Education and Communication, Information Regulator\" },\n          { \"@type\": \"Person\",  \"name\": \"Glenn Zulu\",               \"jobTitle\": \"Chief Financial Officer, Information Regulator\" },\n          { \"@type\": \"Organization\", \"name\": \"Direct Marketing Association of South Africa (DMASA)\" },\n          { \"@type\": \"Organization\", \"name\": \"Consumer Goods and Services Ombud\" },\n          { \"@type\": \"Organization\", \"name\": \"OUTsurance\" },\n          { \"@type\": \"Organization\", \"name\": \"WhatsApp\" },\n          { \"@type\": \"Organization\", \"name\": \"Lancet Laboratories\" },\n          { \"@type\": \"Organization\", \"name\": \"Department of Basic Education, South Africa\" },\n          { \"@type\": \"Organization\", \"name\": \"Department of Justice and Constitutional Development, South Africa\" }\n        ],\n        \"citation\": [\n          {\n            \"@type\": \"Legislation\",\n            \"name\": \"Regulation (EU) 2016\/679 (GDPR)\",\n            \"url\": \"https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj\"\n          },\n          {\n            \"@type\": \"Legislation\",\n            \"name\": \"Regulation (EU) 2024\/1689 (EU AI Act)\",\n            \"url\": \"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32024R1689\"\n          },\n          {\n            \"@type\": \"Legislation\",\n            \"name\": \"UK GDPR and Data Protection Act 2018\",\n            \"url\": \"https:\/\/www.legislation.gov.uk\/ukpga\/2018\/12\/contents\"\n          },\n          {\n            \"@type\": \"Legislation\",\n            \"name\": \"Lei Geral de Prote\u00e7\u00e3o de Dados (LGPD), Lei n\u00ba 13.709\/2018\",\n            \"url\": \"https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2015-2018\/2018\/lei\/l13709.htm\"\n          }\n        ],\n        \"isPartOf\": {\n          \"@type\": \"Periodical\",\n          \"name\": \"ITLawCo \u2014 Data Protection & Privacy\",\n          \"url\": \"https:\/\/itlawco.com\/za\/\"\n        },\n        \"articleSection\": \"Regulatory Analysis\",\n        \"articleBody\": \"The South African Information Regulator held its 2026\/27 Annual Performance Plan stakeholder consultation on 5 March 2026. The session revealed an enforcement body under genuine structural strain: security compromise notifications have increased fifteenfold since 2021; approximately 86% of CIPC-registered companies lack a registered information officer; and the CEO publicly acknowledged the Regulator struggles with responsiveness. The maximum administrative fine under POPIA is R10,000,000, compared to the GDPR ceiling of \u20ac20 million or 4% of global turnover. Fines imposed to date have been set at R200,000 \u2014 2% of the available maximum. Draft POPIA amendments are in preparation but require parliamentary passage with no confirmed timeline. Section 71 of POPIA (automated decision-making) has received no published regulatory guidance. A Privacy Impact Assessment guidance note is planned for 2026\/27. The Regulator's dual mandate over both POPIA and PAIA is globally unusual and enables cross-referencing that structurally separate regulators cannot perform.\",\n        \"wordCount\": 6800,\n        \"timeRequired\": \"PT22M\",\n        \"educationalLevel\": \"Professional\",\n        \"audience\": {\n          \"@type\": \"Audience\",\n          \"audienceType\": \"Data protection lawyers, compliance officers, regulators, policymakers, technologists, AI governance professionals\"\n        },\n        \"accessibilityFeature\": [\n          \"alternativeText\",\n          \"tableOfContents\",\n          \"structuredNavigation\",\n          \"readingOrder\"\n        ],\n        \"accessibilityHazard\": \"none\",\n        \"accessMode\": [\"textual\", \"visual\"],\n        \"accessModeSufficient\": [\"textual\"]\n      }\n    ]\n  }\n  <\/script>\n\n  <!-- \u2500\u2500 3. FAQPage \u2500\u2500 -->\n  <script type=\"application\/ld+json\">\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"FAQPage\",\n    \"mainEntity\": [\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What is the maximum fine the South African Information Regulator can impose under POPIA?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The maximum administrative fine under POPIA is R10,000,000, approximately \u20ac500,000 at current exchange rates. This is a fixed statutory ceiling, compared to the GDPR's tiered maximum of \u20ac20 million or 4% of global annual turnover. To date, the Regulator has imposed fines significantly below this ceiling \u2014 notably R200,000 in the Lancet Laboratories and FTRMS matters. The Regulator is processing draft POPIA amendments that may address the enforcement regime more broadly, but no revised ceiling has been proposed publicly.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"How many security breaches has the South African Information Regulator received?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The Regulator received 2,898 security compromise notifications in the 2025\/26 financial year to date (as at 5 March 2026), compared to 202 in 2021\/22, 590 in 2022\/23, 1,727 in 2023\/24, and 2,374 in 2024\/25. This represents a roughly fifteenfold increase in under five years, reflecting both genuine increases in cyber threats and a reporting normalisation effect as POPIA's breach notification obligations (Section 22) become better understood.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"Are South African companies required to register an information officer under POPIA?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Yes. Section 55 of POPIA requires all responsible parties \u2014 organisations that process personal information \u2014 to register an information officer with the Information Regulator. As at 5 March 2026, only 69,040 information officers are registered against an estimated 490,000 CIPC-active companies, implying a compliance rate of approximately 14%. Failure to register is a contravention of POPIA.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"Does POPIA have an automated decision-making provision equivalent to GDPR Article 22?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Yes. Section 71 of POPIA provides that a data subject has the right not to be subject to a decision producing legal or similarly significant consequences based solely on automated processing of personal information, unless the responsible party establishes a lawful ground and implements adequate safeguards. However, unlike the GDPR, Section 71 has received almost no published regulatory guidance from the Information Regulator. No guidance note, enforcement position, or case study has been published as at March 2026.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What is the status of the Information Regulator's case against WhatsApp?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The Information Regulator and WhatsApp have signed a settlement agreement concerning WhatsApp's privacy policy as applied in the South African market. As at 5 March 2026, the settlement is being reduced to a court order. The substantive terms have not been publicly disclosed. Given WhatsApp's estimated 25 million South African users, the compliance undertakings in the settlement carry significant market-wide implications.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What is the status of the POPIA amendment process in 2026?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The Information Regulator has prepared a first draft of proposed POPIA amendments, which are still being processed internally. Key objectives include moving away from the current 'correct and remedy' enforcement framework and introducing more direct consequences for intentional non-compliance. The draft must undergo parliamentary passage. Given that the portfolio committee on Justice and Constitutional Development is currently occupied with other matters, there is no confirmed timeline for introduction of amendment legislation.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What is South Africa's dual-mandate model for information regulation?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"South Africa is among a small group of jurisdictions globally in which a single institution administers both data protection (POPIA) and access to information (PAIA) law. The Information Regulator holds both mandates, enabling cross-referencing between the right to privacy and the right of access to information that structurally separate regulators in most other countries cannot perform. This is directly relevant in matters such as the matric results litigation, the WhatsApp settlement, and third-party personal information in PAIA requests.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What are the Information Regulator's performance targets for 2026\/27?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The 2026\/27 Annual Performance Plan sets the following key targets for the POPIA division: 50% of complex complaints investigated and resolved within 12 months; 70% of simple complaints investigated and resolved within 3 months; 70% of simple complaints resolved through conciliation and mediation. These represent improvements on current performance but fall short of the three-month supervisory authority response standard contemplated by GDPR Article 78.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"What is the Information Regulator's position on AI risk and governance?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"As at 5 March 2026, the Regulator has not published any guidance on AI risk, automated decision-making under Section 71, or the processing of AI training data under Condition 2 (purpose limitation) of POPIA. A guidance note on Privacy Impact Assessments (PIAs) is planned for the 2026\/27 financial year. ITLawCo considers this the appropriate vehicle for integrating AI risk assessment into POPIA compliance programmes, analogous to DPIA requirements under GDPR Article 35. The EU AI Act entered its first phase of application in February 2025; South African companies with EU-facing operations are already subject to its obligations.\"\n        }\n      },\n      {\n        \"@type\": \"Question\",\n        \"name\": \"When does the Information Regulator's second term of office end?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"The second term of office of the current members of the Information Regulator ends in November 2026. The 2026\/27 Annual Performance Plan is the final plan of the second term. The third term (2027\u20132032) will bring a fresh five-year strategic cycle. Two vacancies on the five-member panel currently remain unfilled, pending action by the Parliamentary Committee on Justice and Constitutional Development.\"\n        }\n      }\n    ]\n  }\n  <\/script>\n\n  <!-- \u2500\u2500 4. BreadcrumbList \u2500\u2500 -->\n  <script type=\"application\/ld+json\">\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"BreadcrumbList\",\n    \"@id\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#breadcrumb\",\n    \"itemListElement\": [\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 1,\n        \"name\": \"ITLawCo\",\n        \"item\": \"https:\/\/itlawco.com\"\n      },\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 2,\n        \"name\": \"South Africa\",\n        \"item\": \"https:\/\/itlawco.com\/za\/\"\n      },\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 3,\n        \"name\": \"Data Protection & Privacy\",\n        \"item\": \"https:\/\/itlawco.com\/category\/data-protection\/\"\n      },\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 4,\n        \"name\": \"Regulatory Analysis\",\n        \"item\": \"https:\/\/itlawco.com\/category\/regulatory-analysis\/\"\n      },\n      {\n        \"@type\": \"ListItem\",\n        \"position\": 5,\n        \"name\": \"South Africa Information Regulator 2026\/27 Annual Performance Plan\",\n        \"item\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/\"\n      }\n    ]\n  }\n  <\/script>\n\n  <!-- \u2500\u2500 5. Organization (Publisher) \u2500\u2500 -->\n  <script type=\"application\/ld+json\">\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"Organization\",\n    \"@id\": \"https:\/\/itlawco.com#organization\",\n    \"name\": \"ITLawCo\",\n    \"url\": \"https:\/\/itlawco.com\",\n    \"description\": \"ITLawCo is a specialist publication covering data protection, privacy law, technology governance, and regulatory affairs across Africa and internationally.\",\n    \"logo\": {\n      \"@type\": \"ImageObject\",\n      \"url\": \"https:\/\/itlawco.com\/assets\/images\/itlawco-logo.png\",\n      \"width\": 300,\n      \"height\": 60\n    },\n    \"contactPoint\": {\n      \"@type\": \"ContactPoint\",\n      \"email\": \"editorial@itlawco.com\",\n      \"contactType\": \"editorial\",\n      \"availableLanguage\": \"en\"\n    },\n    \"sameAs\": [\n      \"https:\/\/www.linkedin.com\/company\/itlawco\",\n      \"https:\/\/twitter.com\/ITLawCo\"\n    ],\n    \"publishingPrinciples\": \"https:\/\/itlawco.com\/editorial-policy\",\n    \"ethicsPolicy\":         \"https:\/\/itlawco.com\/ethics-policy\",\n    \"correctionsPolicy\":    \"https:\/\/itlawco.com\/corrections-policy\",\n    \"verificationFactCheckingPolicy\": \"https:\/\/itlawco.com\/fact-checking-policy\"\n  }\n  <\/script>\n\n  <!-- \u2500\u2500 6. Dataset \u2014 Key Statistics \u2500\u2500 -->\n  <script type=\"application\/ld+json\">\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"Dataset\",\n    \"name\": \"South Africa Information Regulator \u2014 Key Statistics 2021\u20132026\",\n    \"description\": \"Key quantitative data points from the Information Regulator's 2026\/27 Annual Performance Plan stakeholder consultation, 5 March 2026.\",\n    \"url\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#statistics\",\n    \"datePublished\": \"2026-03-05\",\n    \"creator\": {\n      \"@type\": \"Organization\",\n      \"name\": \"ITLawCo Data Protection Desk\"\n    },\n    \"license\": \"https:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/\",\n    \"variableMeasured\": [\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Security compromise notifications received \u2014 2021\/22\",\n        \"value\": 202,\n        \"unitText\": \"notifications\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Security compromise notifications received \u2014 2022\/23\",\n        \"value\": 590,\n        \"unitText\": \"notifications\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Security compromise notifications received \u2014 2023\/24\",\n        \"value\": 1727,\n        \"unitText\": \"notifications\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Security compromise notifications received \u2014 2024\/25\",\n        \"value\": 2374,\n        \"unitText\": \"notifications\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Security compromise notifications received \u2014 2025\/26 (in-year to 5 March 2026)\",\n        \"value\": 2898,\n        \"unitText\": \"notifications\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Registered information officers\",\n        \"value\": 69040,\n        \"unitText\": \"registrations\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Estimated CIPC-active companies\",\n        \"value\": 490000,\n        \"unitText\": \"companies\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Estimated information officer registration compliance rate\",\n        \"value\": \"14%\",\n        \"unitText\": \"percentage\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Maximum administrative fine \u2014 POPIA\",\n        \"value\": 10000000,\n        \"unitCode\": \"ZAR\",\n        \"unitText\": \"South African Rand\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Maximum administrative fine \u2014 GDPR (fixed component)\",\n        \"value\": 20000000,\n        \"unitCode\": \"EUR\",\n        \"unitText\": \"Euro\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Active simple complaints \u2014 as at 1 April 2025\",\n        \"value\": 1681,\n        \"unitText\": \"complaints\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Active complex complaints \u2014 as at 1 April 2025\",\n        \"value\": 373,\n        \"unitText\": \"complaints\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Sectoral assessments conducted \u2014 2021 to 2026\",\n        \"value\": 35,\n        \"unitText\": \"assessments\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Public awareness of Information Regulator existence \u2014 2023 survey\",\n        \"value\": \"30%\",\n        \"unitText\": \"percentage of South African general public\"\n      },\n      {\n        \"@type\": \"PropertyValue\",\n        \"name\": \"Regulator staff headcount\",\n        \"value\": 130,\n        \"unitText\": \"employees (approximate)\"\n      }\n    ]\n  }\n  <\/script>\n\n  <!-- \u2500\u2500 7. WebPage (supporting entity) \u2500\u2500 -->\n  <script type=\"application\/ld+json\">\n  {\n    \"@context\": \"https:\/\/schema.org\",\n    \"@type\": \"WebPage\",\n    \"@id\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/\",\n    \"url\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/\",\n    \"name\": \"South Africa Information Regulator 2026\/27 Annual Performance Plan: Enforcement, Capacity, and What It Means for POPIA Compliance\",\n    \"datePublished\": \"2026-03-05T00:00:00+02:00\",\n    \"dateModified\":  \"2026-03-05T00:00:00+02:00\",\n    \"inLanguage\": \"en-ZA\",\n    \"isPartOf\": {\n      \"@type\": \"WebSite\",\n      \"@id\": \"https:\/\/itlawco.com#website\",\n      \"name\": \"ITLawCo\",\n      \"url\": \"https:\/\/itlawco.com\"\n    },\n    \"primaryImageOfPage\": {\n      \"@type\": \"ImageObject\",\n      \"url\": \"https:\/\/itlawco.com\/assets\/images\/constitutional-court-johannesburg-hero.jpg\",\n      \"caption\": \"Constitutional Court of South Africa, Johannesburg\",\n      \"width\": 1200,\n      \"height\": 630\n    },\n    \"speakable\": {\n      \"@type\": \"SpeakableSpecification\",\n      \"cssSelector\": [\".article-standfirst\", \".article-conclusion\", \".faq-answer\"]\n    },\n    \"breadcrumb\": {\n      \"@id\": \"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#breadcrumb\"\n    }\n  }\n  <\/script>\n\n<\/head>\n<body>\n  <!--\n    SCHEMA REFERENCE NOTES FOR DEVELOPMENT TEAM\n    \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\n\n    TYPES IMPLEMENTED\n    \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n    1. NewsArticle + ScholarlyArticle  \u2014 primary content entity\n    2. FAQPage (10 Q&A pairs)          \u2014 featured snippet \/ AI retrieval\n    3. BreadcrumbList (5 levels)       \u2014 navigation signal\n    4. Organization                    \u2014 publisher E-E-A-T signal\n    5. Dataset (16 variables)          \u2014 citable statistics\n    6. WebPage                         \u2014 page-level entity with speakable\n\n    CSS SELECTORS FOR SPEAKABLE SPEC\n    \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n    Ensure the following selectors exist in the page template:\n      .article-standfirst  \u2192 the italic standfirst paragraph\n      .article-conclusion  \u2192 the final analytical paragraph\n      .faq-answer          \u2192 each FAQ answer paragraph\n\n    IMPLEMENTATION CHECKLIST\n    \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n    [ ] Replace all placeholder URLs (www.itlawco.com\/...) with live paths\n    [ ] Upload hero image and confirm URL matches og:image \/ ImageObject\n    [ ] Confirm logo URL and dimensions\n    [ ] Add ISSN once assigned (Article schema issn property)\n    [ ] Wire speakable CSS selectors to template class names\n    [ ] Submit URL to Google Search Console for indexing\n    [ ] Validate all schemas at: https:\/\/validator.schema.org\n    [ ] Validate rich results at: https:\/\/search.google.com\/test\/rich-results\n    [ ] Test Open Graph at: https:\/\/www.opengraph.xyz\n    [ ] Test Twitter Card at: https:\/\/cards-dev.twitter.com\/validator\n    [ ] Run Lighthouse SEO audit post-deployment (target: 100)\n\n    UTM PARAMETERS (for internal link tracking)\n    \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n    ?utm_source=direct&utm_medium=article&utm_campaign=IR-APP-2026-27\n    ?utm_source=newsletter&utm_medium=email&utm_campaign=IR-APP-2026-27\n    ?utm_source=social&utm_medium=linkedin&utm_campaign=IR-APP-2026-27\n\n  -->\n<\/body>\n<\/html>\n\t\t<\/div>\n\t<\/div>\n\n\t\t\t<\/div> \n\t\t<\/div>\n\t<\/div> \n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"South Africa Information Regulator 2026\/27 \u2014 Article Overview ITLawCo Data Protection &amp; Privacy \u00b7 Visual Overview South Africa Information Regulator 2026\/27 Annual Performance Plan:Enforcement, Capacity, and What It Means for...","protected":false},"author":2,"featured_media":3795,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-3791","post","type-post","status-publish","format-standard","has-post-thumbnail","category-data-protection-and-privacy"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Information Regulator 2026\/27 Annual Performance Plan - ITLawCo<\/title>\n<meta name=\"description\" content=\"Analysis of the South African Information Regulator\u2019s 2026\/27 Annual Performance Plan consultation. Essential reading for data protection lawyers, compliance officers, and regulators operating in or monitoring the South African market.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/itlawco.com\/fr\/information-regulator-2026-27-annual-performance-plan\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Information Regulator 2026\/27 Annual Performance Plan - ITLawCo\" \/>\n<meta property=\"og:description\" content=\"Analysis of the South African Information Regulator\u2019s 2026\/27 Annual Performance Plan consultation. Essential reading for data protection lawyers, compliance officers, and regulators operating in or monitoring the South African market.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/itlawco.com\/fr\/information-regulator-2026-27-annual-performance-plan\/\" \/>\n<meta property=\"og:site_name\" content=\"ITLawCo\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-06T08:24:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-06T08:35:10+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero-1024x683.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"683\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Insights team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Insights team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"21 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/\"},\"author\":{\"name\":\"Insights team\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/8d96a4059deb2f2eb4784ac088e92381\"},\"headline\":\"Information Regulator 2026\\\/27 Annual Performance Plan\",\"datePublished\":\"2026-03-06T08:24:13+00:00\",\"dateModified\":\"2026-03-06T08:35:10+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/\"},\"wordCount\":13283,\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png\",\"articleSection\":[\"Data protection and privacy\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/\",\"name\":\"Information Regulator 2026\\\/27 Annual Performance Plan - ITLawCo\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png\",\"datePublished\":\"2026-03-06T08:24:13+00:00\",\"dateModified\":\"2026-03-06T08:35:10+00:00\",\"description\":\"Analysis of the South African Information Regulator\u2019s 2026\\\/27 Annual Performance Plan consultation. Essential reading for data protection lawyers, compliance officers, and regulators operating in or monitoring the South African market.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/#primaryimage\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png\",\"width\":1536,\"height\":1024,\"caption\":\"Visual representation of the Information Regulator\u2019s 2026\\\/27 Annual Performance Plan, highlighting enforcement priorities, institutional capacity, and the evolving expectations for POPIA compliance.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/information-regulator-2026-27-annual-performance-plan\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/itlawco.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Information Regulator 2026\\\/27 Annual Performance Plan\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#website\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"name\":\"ITLawCo\",\"description\":\"Fast, fearless legal\",\"publisher\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/itlawco.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#organization\",\"name\":\"ITLawCo\",\"url\":\"https:\\\/\\\/itlawco.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"contentUrl\":\"https:\\\/\\\/itlawco.com\\\/wp-content\\\/uploads\\\/2024\\\/06\\\/Logo-prsm@4x.png\",\"width\":2854,\"height\":2883,\"caption\":\"ITLawCo\"},\"image\":{\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/itlawco\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/itlawco.com\\\/#\\\/schema\\\/person\\\/8d96a4059deb2f2eb4784ac088e92381\",\"name\":\"Insights team\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4996c37241203a3a636f0f91613256083b171a20f932f67a4cc401862d4e62b6?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4996c37241203a3a636f0f91613256083b171a20f932f67a4cc401862d4e62b6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4996c37241203a3a636f0f91613256083b171a20f932f67a4cc401862d4e62b6?s=96&d=mm&r=g\",\"caption\":\"Insights team\"},\"url\":\"https:\\\/\\\/itlawco.com\\\/fr\\\/author\\\/support\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Information Regulator 2026\/27 Annual Performance Plan - ITLawCo","description":"Analysis of the South African Information Regulator\u2019s 2026\/27 Annual Performance Plan consultation. Essential reading for data protection lawyers, compliance officers, and regulators operating in or monitoring the South African market.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/itlawco.com\/fr\/information-regulator-2026-27-annual-performance-plan\/","og_locale":"fr_FR","og_type":"article","og_title":"Information Regulator 2026\/27 Annual Performance Plan - ITLawCo","og_description":"Analysis of the South African Information Regulator\u2019s 2026\/27 Annual Performance Plan consultation. Essential reading for data protection lawyers, compliance officers, and regulators operating in or monitoring the South African market.","og_url":"https:\/\/itlawco.com\/fr\/information-regulator-2026-27-annual-performance-plan\/","og_site_name":"ITLawCo","article_published_time":"2026-03-06T08:24:13+00:00","article_modified_time":"2026-03-06T08:35:10+00:00","og_image":[{"width":1024,"height":683,"url":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero-1024x683.png","type":"image\/png"}],"author":"Insights team","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Insights team","Dur\u00e9e de lecture estim\u00e9e":"21 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#article","isPartOf":{"@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/"},"author":{"name":"Insights team","@id":"https:\/\/itlawco.com\/#\/schema\/person\/8d96a4059deb2f2eb4784ac088e92381"},"headline":"Information Regulator 2026\/27 Annual Performance Plan","datePublished":"2026-03-06T08:24:13+00:00","dateModified":"2026-03-06T08:35:10+00:00","mainEntityOfPage":{"@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/"},"wordCount":13283,"publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"image":{"@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png","articleSection":["Data protection and privacy"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/","url":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/","name":"Information Regulator 2026\/27 Annual Performance Plan - ITLawCo","isPartOf":{"@id":"https:\/\/itlawco.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#primaryimage"},"image":{"@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#primaryimage"},"thumbnailUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png","datePublished":"2026-03-06T08:24:13+00:00","dateModified":"2026-03-06T08:35:10+00:00","description":"Analysis of the South African Information Regulator\u2019s 2026\/27 Annual Performance Plan consultation. Essential reading for data protection lawyers, compliance officers, and regulators operating in or monitoring the South African market.","breadcrumb":{"@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#primaryimage","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2026\/03\/information-regulator-2026-27-annual-performance-plan-enforcement-capacity-popia-compliance-hero.png","width":1536,"height":1024,"caption":"Visual representation of the Information Regulator\u2019s 2026\/27 Annual Performance Plan, highlighting enforcement priorities, institutional capacity, and the evolving expectations for POPIA compliance."},{"@type":"BreadcrumbList","@id":"https:\/\/itlawco.com\/information-regulator-2026-27-annual-performance-plan\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/itlawco.com\/"},{"@type":"ListItem","position":2,"name":"Information Regulator 2026\/27 Annual Performance Plan"}]},{"@type":"WebSite","@id":"https:\/\/itlawco.com\/#website","url":"https:\/\/itlawco.com\/","name":"ITLawCo","description":"Rapide, sans peur, juridique","publisher":{"@id":"https:\/\/itlawco.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/itlawco.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/itlawco.com\/#organization","name":"ITLawCo","url":"https:\/\/itlawco.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/","url":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","contentUrl":"https:\/\/itlawco.com\/wp-content\/uploads\/2024\/06\/Logo-prsm@4x.png","width":2854,"height":2883,"caption":"ITLawCo"},"image":{"@id":"https:\/\/itlawco.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/itlawco\/"]},{"@type":"Person","@id":"https:\/\/itlawco.com\/#\/schema\/person\/8d96a4059deb2f2eb4784ac088e92381","name":"Insights team","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/4996c37241203a3a636f0f91613256083b171a20f932f67a4cc401862d4e62b6?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4996c37241203a3a636f0f91613256083b171a20f932f67a4cc401862d4e62b6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4996c37241203a3a636f0f91613256083b171a20f932f67a4cc401862d4e62b6?s=96&d=mm&r=g","caption":"Insights team"},"url":"https:\/\/itlawco.com\/fr\/author\/support\/"}]}},"_links":{"self":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3791","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/comments?post=3791"}],"version-history":[{"count":6,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3791\/revisions"}],"predecessor-version":[{"id":3799,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/posts\/3791\/revisions\/3799"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media\/3795"}],"wp:attachment":[{"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/media?parent=3791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/categories?post=3791"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itlawco.com\/fr\/wp-json\/wp\/v2\/tags?post=3791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}