Information Regulator: Media briefing on POPIA and PAIA contraventions

Information Regulator: Media briefing on POPIA and PAIA contraventions logo

Summary:
The Information Regulator has held a media briefing, delivering a comprehensive account of its enforcement activities under both the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA). 


Article:

The briefing focused on High-profile cases, Enforcements and Investigations into POPIA and PAIA contraventions.

The briefing also marked a significant institutional milestone: 2026 is the Regulator’s 10-year anniversary, having been formally established in December 2016, and 5 years since the enforcement provisions of POPIA commenced.

Key Developments include:

  • Enforcement Notices Under POPIA
  • POPIA Fines Imposed
  • Ongoing POPIA Matters and Investigations
  • PAIA Annual Report Compliance
  • Direct Marketing and Spam Calls
  • Security Compromises (over 8000 since 2021)
  • Proposed Legislative Amendments
  • New Digital Platforms
  • Proactive Monitoring

The following practical conclusions were drawn from the briefing:

  • Heightened enforcement activity: The Regulator is demonstrably moving beyond awareness-raising and into active enforcement. Organisations should treat compliance with POPIA and PAIA as a matter of immediate operational priority, not a project for next quarter.
  • Security compromise preparedness: With over 1,220 security compromise notifications received in fewer than 5 months (and a projected 3,000 by year end), organisations must ensure they have robust incident response plans in place, including the ability to comply with section 22 notification obligations in a timely manner.
  • Direct marketing compliance: Organisations that engage in direct marketing, particularly via telephone, should urgently review their practices against the Regulator’s stated position on consent requirements and opt-out mechanisms.
  • PAIA annual report submissions: Both public and private bodies should ensure they submit PAIA annual reports as required under sections 32 and 83 of PAIA. While compliance rates have improved (to approximately 49% for public bodies), they remain unacceptably low, and the Regulator’s express intention to seek stronger enforcement powers means that non-compliance is likely to attract consequences in the near future.
  • Anticipate legislative change: The proposed amendments to both POPIA and PAIA, including the move towards immediate fines, signal a shift towards a more punitive enforcement regime. Organisations should begin preparing for a stricter compliance environment now, rather than waiting for the legislation to catch up.

The message from the Regulator is unambiguous: the era of soft enforcement is over.

Click here to download the media statement:

https://www.polity.org.za/article/the-regulator-is-watching-new-enforcement-signals-for-popia-and-paia-compliance-2026-09-01 

Relevance to Auditors, Independent Reviewers & Accountants:

  • POPIA and PAIA are more pieces of legislation that your clients must comply with, and which you must assess compliance with.  If they don’t comply with the relevant laws and regulations, you have certain reporting obligations in terms of NOCLAR (NOn-Compliance with Laws And Regulations) – this could include reporting to management, qualifying your audit opinion, reporting a Reportable Irregularity, etc.
  • As an auditor, accountant and independent reviewer, you need to consider updated information that is published by the Information Regulator (as they are responsible for POPIA and PAIA in SA) – especially as it relates to operational functionalities, and other relevant information of interest.
  • As an employer, you also need to comply with POPIA and PAIA in your workplace.

Relevance to Your clients:

  • Both private and public bodies have a duty to comply with POPIA and PAIA, and directors have to fulfil their duties accordingly, otherwise they could be held liable.
  • Your clients need to consider updated information that is published by the Information Regulator (as they are responsible for POPIA and PAIA in SA) – especially as it relates to operational functionalities, and other relevant information of interest.

There are not comments for this article at the moment, check back later.
You must be logged in to add a comment, log in now.

Explore Smarty