Information Regulator sounds alarm over data breaches

Posted on Leave a comment

The Information Regulator has described the rate of security compromises in South Africa as “very alarming”, saying it has received more than 8 000 notifications to date.

At its media briefing on 31 August 2026, the Regulator said more than 1 220 security compromises had been reported since 1 April, less than five months into the 2026/27 financial year. It projected that notifications could exceed 3 000 by the end of the financial year.

Some organisations do not report security compromises, meaning the notifications received by the Regulator may not reflect the full extent of such incidents.

The briefing also pointed to a broader shift towards more proactive oversight. In addition to reporting new enforcement and investigative matters, the Regulator said it is requiring organisations to demonstrate their compliance with the Protection of Personal Information Act (POPIA), seeking stronger enforcement powers under the Promotion of Access to Information Act (PAIA), and pursuing matters that could clarify the application of POPIA to telephone marketing and learners’ information.

Chairperson Pansy Tlakula (pictured) said the consequences of a security compromise can extend beyond the exposure of personal information. Depending on its severity, a compromise can disrupt essential services, damage institutional credibility, undermine public confidence, and have significant economic consequences.

The Regulator’s assessments have identified inadequate security controls, employee negligence or human error, weak passwords, malware and ransomware attacks, and phishing among the causes of security compromises.

Tlakula acknowledged that cyberattacks are becoming increasingly sophisticated and that no organisation can guarantee it will never be attacked.

Cyberattacks do not excuse compliance failures

The Regulator’s response to a significant ransomware attack on the South African Bureau of Standards (SABS) in 2024 illustrates the compliance issues it considers following a security compromise. The attack encrypted the SABS’s information systems and severely disrupted its operations.

The incident prompted a regulator-initiated assessment of the security compromise and the SABS’s broader compliance with POPIA. The Regulator emphasised that the enforcement action was not taken simply because SABS had been the victim of a cyberattack, but because the assessment identified deficient data-protection and security practices.

The Regulator found that the SABS had contravened several of POPIA’s conditions for the lawful processing of personal information. The contraventions included processing excessive or irrelevant information, inadequate consent mechanisms, weak security safeguards, failure to address known vulnerabilities, a lack of incident-response plans, and failure to inform data subjects about how their personal information was collected.

The SABS was directed to improve its security and data-protection practices within 90 days of receiving the enforcement notice. The required measures include revising its policies, conducting thorough personal information impact assessments, and implementing security measures to protect the personal information it processes.

Fines, litigation, and investigations

The SABS matter was one of several enforcement and investigative matters highlighted by the Regulator. It also provided an update on administrative fines issued under its POPIA enforcement powers.

The Department of Justice and the Department of Basic Education were each issued with R5 million fines, although both matters became the subject of litigation. The Department of Justice matter remains before the courts.

The other fines disclosed at the briefing were R100 000 against the Electoral Commission, which has been paid; R100 000 against Lancet Laboratories, which has also been paid; and R500 000 against Blouberg Local Municipality.

The municipality challenged the fine in court, and the amount was reduced to R250 000.

The R5m fine previously imposed on the Department of Basic Education formed part of the enforcement and infringement notices set aside by the High Court in December 2025. The Court dismissed the Regulator’s application for leave to appeal in June 2026.

The Regulator has since approached the Supreme Court of Appeal, maintaining that the case raises important questions about the application of POPIA to learners’ information.

It also provided an update on investigations and assessments involving public and private-sector organisations. These include the National Credit Regulator, Truecaller, Pick n Pay, the Gauteng Department of E-Government, Land Bank, and Standard Bank.

The investigations and assessments are intended to establish whether the organisations’ conduct or practices comply with POPIA and, where appropriate, may result in findings and recommendations.

The briefing also covered referrals from the Judicial Commission of Inquiry into Criminality, Political Interference, and Corruption in the Criminal Justice System, chaired by Justice Mbuyiseli Madlanga.

A referral received in February 2026 concerned the alleged unlawful processing of personal information by Imogen Mashazi, the former city manager of the Ekurhuleni Metropolitan Municipality. The Regulator said it had completed an own-initiative investigation and referred the matter to its Enforcement Committee.

Further referrals received from the Commission on 4 August 2026 concern Major-General Lesetja Senona, Vusimuzi Matlala, Linda Gxasheka, and Sergeant Fannie Nkosi. The Regulator said investigations into these matters are under way and declined to comment on their merits pending completion.

Direct marketing

Direct marketing was another area of concern highlighted by the Regulator. It said it had received more than 3 800 complaints during the previous year, 10% of which related to direct marketing.

The Regulator said the complaints reflected continuing concern among data subjects about the use of their personal information for marketing purposes, particularly through electronic communications.

Two direct-marketing matters, involving OUTsurance and MTN, have been referred to the Enforcement Committee. The Regulator said they raise important questions about the interpretation and application of section 69 of POPIA, which regulates direct marketing by means of electronic communication.

The matters involve direct marketing by telephone. Tlakula said the Regulator’s position that telephone calls constitute electronic communications for the purposes of POPIA remains contested by the direct-marketing sector.

The outcomes could clarify the Regulator’s enforcement approach and may provide a route for its interpretation to be tested in court.

Section 69 generally prohibits direct marketing by means of electronic communication unless the data subject has consented or the person is an existing customer and the statutory requirements are met. These include restrictions on the products or services that may be marketed and requirements to give the customer reasonable opportunities to object.

The Regulator welcomed recent amendments to the Consumer Protection Act regulations aimed at curbing unsolicited marketing communications, including spam calls. It said the pre-emptive block register is an important additional measure but emphasised that registration on the register does not displace obligations imposed by POPIA.

The Regulator has engaged with the National Consumer Commission to identify areas in which the two institutions can work together on public awareness and the handling of complaints relating to unwanted electronic communications.

Proposed legislative changes

The Regulator also highlighted weaknesses in the legislative framework that it wants to address. It said PAIA does not provide enforcement mechanisms comparable to those available under POPIA when an information officer fails to comply with an enforcement notice.

Under the current framework, the Regulator said it must open a criminal case against an information officer who fails to comply with an enforcement notice requiring information to be released or another specified action to be taken.

It said this creates practical difficulties, including because police officials may be unfamiliar with offences involving non-compliance with PAIA enforcement notices.

The Regulator is pursuing amendments that would provide enforcement mechanisms similar to those available under POPIA. It has also approached Parliament in connection with the Judicial Matters Amendment Bill, proposing that it be empowered to release information that it has ordered an institution to disclose if the institution fails to comply within 180 days.

The Regulator also expressed concern that bodies are increasingly seeking judicial review of PAIA enforcement notices instead of releasing the requested information. It identified Sibanye-Stillwater and the JSE among the bodies that have challenged its decisions.

Tlakula also identified what she described as a weakness in POPIA’s enforcement regime. She said that, after the Regulator finds a contravention and issues an enforcement notice, the responsible party is given a period in which to comply with the notice or challenge it in court.

According to Tlakula, the Regulator cannot subsequently impose an administrative fine if the party complies within that period.

PAIA compliance remains a concern

The Regulator also reported continuing concerns about compliance with PAIA, particularly among public bodies.

For the 2025/26 reporting cycle, 417 of the 853 public bodies required to submit annual reports did so between 1 April and 30 June 2026. This represents a compliance rate of about 49%.

The Regulator described this as an improvement on the 358 submissions recorded in 2024/25. However, slightly more than half of public bodies failed to meet their reporting obligations during the latest cycle.

The annual reports provide statistics on how bodies process access-to-information requests, including the number of requests received and granted, compliance with statutory timeframes, and the handling of internal appeals.

Compliance by municipalities was particularly concerning. Only 91 of the country’s 257 municipalities submitted PAIA annual reports, a compliance rate of approximately 35%.

The Regulator said this was troubling because municipalities are the sphere of government closest to the public and play a central role in service delivery. Access to information at local-government level enables communities to hold municipalities accountable, monitor the use of public funds, and participate meaningfully in decisions affecting their daily lives.

The Regulator also identified low compliance among political parties, TVET colleges, and certain categories of public entities.

It said the Public Protector had not submitted information concerning PAIA-related complaints lodged with that office. Under section 84(b) of PAIA, the Regulator’s annual report to the National Assembly must include particulars about the number and nature of complaints lodged with the Public Protector and their outcomes.

The Regulator said its compliance assessments indicated that some public and private bodies disregard its recommendations because they perceive PAIA as lacking sufficiently effective enforcement consequences. Strengthening its enforcement and sanctioning powers under the Act therefore remains a priority.

More proactive monitoring

The Regulator is also taking a more proactive approach to monitoring compliance with POPIA. Its POPIA division has begun sending letters to responsible parties requiring them to demonstrate how they comply with the Act, rather than waiting for a complaint or potential contravention before conducting an assessment.

The Regulator said the exercise had already identified serious compliance problems in some environments. Where shortcomings are identified, it informs the responsible party of the areas requiring attention and the provisions with which it may need to ensure compliance.

Its assessments also indicated that POPIA compliance was generally higher in the private sector than in the public sector. The Regulator attributed this partly to the established compliance functions within many private-sector organisations.

It said compliance should be embedded throughout an organisation rather than remaining solely the responsibility of an information officer or compliance function.

The Regulator is also expanding its digital services. These include online complaint and compliance-management systems, portals for exemption and prior-authorisation applications, and a centralised system for directing general enquiries to the appropriate division.

It said the platforms are intended to improve accessibility, service delivery, and regulatory effectiveness.

The Regulator cautioned organisations against treating the protection of personal information as a “tick-box exercise”. It said compliance must be embedded throughout an organisation and supported by adequate operational attention and resources.

Its move towards proactive monitoring means organisations may increasingly be required to demonstrate their compliance before a complaint or suspected contravention arises.

 

Leave a Reply

Your email address will not be published. Required fields are marked *