Information Regulator Escalates Formal Enforcement Under POPIA and PAIA
Brought to you by SA Accounting Academy: The Information Regulator has delivered an account of its active investigations, compliance notices, and administrative enforcement actions under the Protection of Personal Information Act, No. 4 of 2013 (POPIA) and the Promotion of Access to Information Act, No. 2 of 2000 (PAIA).
In terms of sections 89 through 109 of POPIA and sections 77A through 77K of PAIA, the Information Regulator possesses statutory mandates to investigate complaints, issue binding enforcement notices, and impose administrative fines of up to R10 million for non-compliance. Marking five years since the commencement of POPIA’s enforcement provisions and ten years since the Regulator’s formal establishment, the briefing signaled an end to transitional accommodation and discretionary tolerance for non-compliant public and private bodies.
Key Enforcement Focus Areas
The Regulator’s active enforcement agenda prioritises the following compliance failures:
- Unlawful direct marketing: Contraventions of section 69 of POPIA, focusing on electronic marketing conducted without prior consent or valid opt-in mechanisms;
- Security compromises and breach notifications: Failure to implement appropriate, reasonable technical and organizational measures under section 19 of POPIA, as well as failure to notify the Regulator and affected data subjects without undue delay under section 22;
- Information Officer compliance: Operating without registered Information Officers or Deputies, or failing to operationalise mandatory compliance frameworks under section 55 of POPIA; and
- PAIA manual and access refusals: Failure to compile, maintain, and publish updated PAIA manuals, or unlawfully refusing requests for access to records.
Click here to read the analysis of new enforcement signals published via Polity.
What this means for you, your business, or your clients
- For yourself: If appointed as an Information Officer or Deputy Information Officer, ensure your registration with the Regulator is current and that internal standard operating procedures for data subject access requests are fully operational.
- For your business: Audit internal data protection safeguards immediately under section 19 of POPIA, update your PAIA section 51 manual, and ensure an active, documented incident response procedure is in place for section 22 security compromise notifications.
- For your clients: Advise corporate clients—particularly those engaging in direct electronic marketing or handling large volumes of special personal information—that the Regulator is issuing formal infringement notices and monetary penalties without preliminary warnings, requiring immediate cessation of non-consensual processing.
Originally published at https://accountingacademy.co.za/news/read/information-regulator-media-briefing-on-popia-and-paia-contraventions






