Key points
- Breach notifications to the Information Regulator rose from 590 in 2022/23 to 2,374 in 2024/25, while its POPIA programme had 20 filled posts.
- Public bodies account for many of the most serious cases: the Justice department, the police, the Electoral Commission and the Department of Basic Education have all fallen short of POPIA’s security or notification duties.
- A fine can follow only a failed enforcement notice, and both R5 million fines issued to government departments have been contested in court.
- Other African legislators should fund regulators before multiplying reports, and let serious breaches be fined directly.
South Africa’s Protection of Personal Information Act (POPIA) is one of the continent’s most closely watched data protection laws. Most of it came into force on 1 July 2020, and every public and private body had to comply by 1 July 2021.1 It is enforced by the Information Regulator, which the Act declares “independent and … subject only to the Constitution and to the law”, and which also enforces the right of access to information.2
Five years of enforcement now give a clear picture. The law’s duties are well drafted. The difficulty lies in what happens after a breach is reported, and above all when the organisation that failed is part of the state. That lesson matters well beyond South Africa, because many African data protection laws are built on the same model.
A rising tide of breach reports
POPIA requires any organisation that suffers a security compromise to notify the Regulator and the people affected “as soon as reasonably possible”.3 Since 1 April 2025 every report must be made through the Regulator’s online portal, and every compromise must be reported “irrespective of the deemed level of risk”.4
The volume has grown quickly. The Regulator received 590 notifications in 2022/23, 1,727 in 2023/24 and 2,374 in 2024/25.5 Between April and mid-November 2025 it received a further 1,947, an average of 284 a month.6
The capacity to act on those reports has not kept pace. In October 2024 the Regulator told Parliament that of 413 approved posts, only 93 were funded. At the end of March 2025 its POPIA programme had 21 funded posts, 20 of them filled, and in 2024/25 it issued five enforcement notices under POPIA.7 Parliament’s justice committee recorded a concern that the Regulator “often learnt about data breaches/security compromises from the media”.8
A notification duty is only as useful as the regulator’s capacity to act on what it is told.
The state as a data controller
The Regulator’s most serious cases have involved public bodies, and they show a pattern.
In September 2021 the Department of Justice and Constitutional Development suffered a security compromise on its IT systems. The Regulator found that about 1,204 files were lost because security licences had not been renewed, and that the Department notified the Regulator “only … after it requested the DoJ & CD to do so”.9 When the Department did not comply with the resulting enforcement notice, the Regulator fined it R5 million in July 2023. The Department challenged the fine in court, and in November 2025 the matter was still awaiting a hearing.10
The police were found in 2023 to have shared the details of sexual assault survivors in WhatsApp groups, and to have made no notification. They complied with the enforcement notice, but in 2024 the Regulator opened a second investigation into a similar leak.11 The Electoral Commission was fined R100,000 after candidate lists leaked before the 2024 elections.12 A public college was found in May 2026 to have failed to notify either the Regulator or the people affected by a breach.13 When Blouberg Local Municipality did not pay a R500,000 fine, the Regulator had to go to court to enforce it, and the High Court halved it to R250,000.14
These cases share an awkward history. When the Regulator fined the Justice department in 2023, it was still operating as a branch of that department. It was listed as a separate public entity only in March 2024, and its financial records for 2024/25 still formed part of the Department’s accounts.15 A regulator that depends on a ministry for its budget and its books is poorly placed to enforce the law against that ministry.
Fines that arrive late, if at all
POPIA’s enforcement machinery is slow by design. An administrative fine of up to R10 million can be imposed only where an offence is alleged, and in practice the offence has been failing to comply with an enforcement notice.16 An enforcement notice is suspended while an appeal is pending unless it is marked urgent, and an appeal to the High Court may re-examine the facts.17 A controller that breaks the law therefore has three chances to delay: before the notice, during the appeal and after the fine.
The Department of Basic Education case shows the result. In November 2024 the Regulator ordered the Department not to publish matric results in newspapers, and in December 2024 fined it R5 million. On 12 December 2025 a full bench of the High Court upheld the Department’s appeal, set aside both notices and ordered the Regulator to pay costs. The court held that publishing results by examination number “does not constitute the processing of personally identifiable information”, and it condoned an appeal filed six days late.18 The High Court refused the Regulator leave to appeal on 3 June 2026, and in August 2026 the matter was before the Supreme Court of Appeal.19
Whatever the final outcome, the case shows how long a contested enforcement can take, and how a regulator that loses a novel argument pays for it. According to a law firm’s account of the Regulator’s August 2026 media briefing, the Regulator itself has said that once an organisation complies within an enforcement notice’s grace period it can no longer be fined, which “limits the deterrent effect”.20
Lessons for South Africa and the continent
South Africa’s experience is not a failure of drafting. It is a failure of design to match enforcement capacity and incentives to the duties the law creates, and it offers practical lessons to every African country building or reforming a data protection regime.
- Fund the regulator before multiplying the reports. Breach notification produces information, not protection. Treasuries and parliaments should fund investigation posts in proportion to the notifications a regulator receives.
- Separate the regulator’s money from the ministries it polices. A data protection authority should have its own budget vote and its own audited accounts, so that it never enforces against the department that funds it.
- Let serious breaches be fined directly. Administrative fines should be available for serious contraventions such as a failure to notify, without first requiring a second failure to obey an enforcement notice. South Africa should amend section 109 of POPIA accordingly.
- Keep urgent orders in force during appeals. Appeals should not suspend orders that protect people from continuing harm, and courts should decide them quickly.
- Make public bodies report on their own compliance. Government departments should publish, each year, the breaches they have notified and the steps they have taken, so that Parliament can hold them to the standard they impose on others.
Notes
-
South African Government News Agency, “Protection of Personal Information Act sections come into effect”, 22 June 2020; Protection of Personal Information Act 4 of 2013, section 114(1). ↩
-
Protection of Personal Information Act 4 of 2013, section 39. ↩
-
Protection of Personal Information Act 4 of 2013, section 22(1) and (2). ↩
-
Information Regulator, media statement on the eServices portal, 7 April 2025; fact sheet on security compromises, August 2025. ↩
-
Information Regulator, Annual Report 2023/24 and Annual Report 2024/25. ↩
-
Information Regulator, media briefing, 13 November 2025. ↩
-
Information Regulator, Annual Report 2024/25, including its reply to the Portfolio Committee of 16 October 2024 and table 3.2.1. ↩
-
Information Regulator, Annual Report 2024/25, recording the committee’s budgetary review of 16 October 2024. ↩
-
Information Regulator, enforcement notice to the Department of Justice and Constitutional Development, 9 May 2023, and media statement, 10 May 2023. ↩
-
Information Regulator, media statement on the infringement notice, 4 July 2023; media briefing, 13 November 2025. ↩
-
Information Regulator, enforcement notice to the South African Police Service, 4 April 2023; media briefing, 26 March 2024. ↩
-
TimesLive, “Regulator issued enforcement notices to IEC, WhatsApp for breach of POPIA”, 11 September 2024; Information Regulator, Annual Report 2024/25. ↩
-
Information Regulator, media statement on enforcement notices to public and private bodies, 2 June 2026. ↩
-
Information Regulator, media statement on Blouberg Local Municipality, 29 April 2026. ↩
-
Information Regulator, Annual Performance Plan 2025/26; Annual Report 2024/25. ↩
-
Protection of Personal Information Act 4 of 2013, sections 103(1) and 109. ↩
-
Protection of Personal Information Act 4 of 2013, sections 95(3) and (4), 97(1) and 98(2). ↩
-
Minister of Basic Education and Another v Information Regulator of South Africa and Others, case 148459/24, High Court, Gauteng Division, Pretoria, 12 December 2025, paragraphs 22 and 66 to 67. ↩
-
Werksmans, “Leave to appeal refused, but questions remain”, 9 June 2026; Information Regulator, media invitation, 26 August 2026. ↩
-
Werksmans, “The Regulator is watching: new enforcement signals for POPIA and PAIA compliance”, 31 August 2026. ↩