POPIA Enforcement South Africa: The Regulator Has Teeth — And It’s Using Them
For the first two years after POPIA became fully enforceable in July 2021, many South African businesses quietly waited to see whether the Information Regulator would actually act. Enforcement notices were issued, but no fines were collected. Some compliance professionals started calling the Regulator a paper tiger.
That window has firmly closed. POPIA enforcement South Africa-wide is now active, escalating, and reaching the courts — and the cases on record offer a clear picture of exactly what gets businesses into trouble.
By the Regulator’s own account at its November 2025 media briefing, Chairperson Adv Pansy Tlakula put it plainly: “The leniency is going to be a thing of the past.” At that point, data breaches were being reported to the Regulator at a rate of 284 per month — a 40% year-on-year increase.
By mid-2026, the 2025/26 financial year had already logged 3,219 breach notifications. The direction of travel is unmistakable.
From Grace Period to Active POPIA Enforcement South Africa
POPIA’s grace period ended on 1 July 2021, and the Regulator spent its first two years issuing enforcement notices and building its enforcement pipeline. What changed between then and now is the willingness to escalate.
Organisations that ignored enforcement notices discovered that the Regulator does not simply issue a second notice — it issues an infringement notice and sets a rand figure.
The critical insight from the full enforcement record is this: in virtually every case where a fine was imposed, the fine was not for the original data protection failure. It was for ignoring the enforcement notice that followed it.
Dis-Chem, TransUnion, and the SA Police Service all received enforcement notices — and all complied, paying nothing. Every rand of every fine issued to date traces back to non-compliance with the notice, not the underlying breach.
That distinction matters for any business owner reading the headlines. POPIA enforcement South Africa does not mean that a single mistake results in a fine.
It means that ignoring the Regulator’s instruction to fix a mistake results in a fine. The enforcement pipeline is designed to give organisations a chance to respond — and the record shows that responding works.
The Cases Every SA Business Owner Should Know

The Department of Justice: South Africa’s First POPIA Fine
In September 2021, the Department of Justice suffered a ransomware attack that took down electronic services across the department — including bail processing, letters of authority, and departmental email. The investigation that followed found that antivirus, Security Information and Event Management (SIEM — the software that monitors your network for threats), and intrusion detection licences had all lapsed in 2020 and were never renewed.
An enforcement notice issued in May 2023 gave the Department 31 days to renew them. The Department missed the deadline.
The result was a R5 million infringement notice — South Africa’s first ever POPIA fine. The Department has contested it in court and the matter is still pending, but the enforcement action stands.
The lesson for any business: letting security software subscriptions lapse is not just an IT oversight. Under Section 19 of POPIA, maintaining adequate security safeguards is a legal obligation.
That obligation extends to keeping those safeguards active and licensed.
Dis-Chem: When Your Supplier’s Problem Becomes Your Problem
In April 2022, a brute-force attack on Dis-Chem’s third-party e-Statement service provider, Grapevine, exposed approximately 3.6 million customer records — names, email addresses, and cell numbers. Dis-Chem reported the breach promptly.
But the investigation found two problems: there was no written contract between Dis-Chem and Grapevine requiring POPIA-compliant security, and the 3.6 million affected customers were never notified.
The Regulator issued an enforcement notice. Dis-Chem complied within 31 days — no fine was imposed.
This case is directly relevant to any business using a CRM, email marketing platform, payroll provider, or payment processor. Under POPIA, the legal term for any supplier who handles personal information on your behalf is an “operator.”
Section 21 requires that your agreement with every operator includes specific provisions requiring them to maintain adequate security. The absence of that contract — not the breach itself — was what the Regulator cited.
A managed IT partner can help you identify which of your suppliers qualify as operators and ensure those contracts are in place before a breach happens.
Blouberg Municipality: The Regulator Will Go to Court
The most recent confirmed enforcement outcome illustrates the end-to-end pipeline. A former Blouberg Municipality employee’s personal information was published on the municipality’s website.
The Regulator issued an enforcement notice. Then an infringement notice for R500,000. Both were ignored.
In April 2026, the Regulator applied to the Polokwane High Court under Section 109(5) of POPIA. The court confirmed a fine — reduced to R250,000 given the limited scope of the breach — but confirmed nonetheless.
This is the first publicly confirmed court enforcement of a POPIA fine in South Africa.
POPIA enforcement South Africa has now completed the full circuit: violation, enforcement notice, infringement notice, High Court application, court judgment. The pipeline is real and the Regulator has demonstrated it will see it through.
The lesson is not that organisations will be pursued over trivial matters — the reduction to R250,000 shows the court will consider context — but that ignoring the Regulator entirely is not a viable strategy.
FT Rams Consulting: Even Small Businesses Are Not Exempt
FT Rams Consulting is not a household name, which is precisely why this case matters. The firm was sending marketing emails to recipients who had not consented — and continued doing so after people opted out.
The Regulator issued the first direct-marketing enforcement notice under Section 69 of POPIA. FT Rams ignored it.
A R100,000 infringement notice followed. The fine remains unpaid, and the Regulator has initiated court proceedings to recover it.
The fine amount is modest. The signal is not.
It confirms that POPIA enforcement South Africa applies regardless of company size, and that marketing emails sent without consent — or sent after an opt-out — are now a fineable offence. There are no SME exemptions written into the Act.
What Changed in April 2025 — And Why It Affects Your Marketing
On 17 April 2025, amended POPIA Regulations (Government Gazette 52523) came into effect immediately. Several changes directly affect how South African businesses can collect marketing consent and handle opt-out requests. You can review the full amendments in MJK Inc’s summary of the 2025 POPIA Regulations amendments.

The most significant change for most SMEs is this: opt-out is explicitly no longer valid consent. The amended regulations close the loophole that some marketers had used — reasoning that because a recipient had not unsubscribed, they had implicitly consented.
That argument no longer holds. If your email marketing currently operates on the basis that people can opt out if they want to, you are now non-compliant.
You need a positive opt-in.
The amendments also expand who can bring a POPIA complaint. Previously, only the affected data subject could complain to the Regulator.
The amended regulations now allow anyone with “sufficient personal interest” — including NGOs, journalists, and activist organisations — to lodge a complaint on behalf of others. Your data practices are more exposed than they were eighteen months ago, and the amendments make it easier for third parties to bring them to the Regulator’s attention.
What the Numbers Say About POPIA Enforcement South Africa
The IBM Cost of a Data Breach Report 2025 puts the average cost of a data breach in South Africa at R44.1 million — down from R53.1 million in 2024, but still more than four times POPIA’s maximum R10 million fine. In the financial sector, the average cost reaches R70.2 million.
These are not fine amounts — they are the total business cost of a breach, including recovery, notification, legal fees, regulatory response, and reputational damage.
POPIA’s R10 million fine ceiling is actually low by international standards. The EU’s GDPR allows fines up to €20 million or 4% of global annual turnover, whichever is higher.
The Information Regulator has publicly signalled its intention to approach Parliament to seek expanded enforcement powers. For now, the maximum fine under POPIA is the floor of what a breach is likely to actually cost — not the ceiling.
The Regulator received 1,355 POPIA complaints in the 2024/25 financial year — a 34% increase over the prior year. Data breach notifications reached 2,374 in that period, climbing to a monthly average of 284 by November 2025.
See the full record in the MJK Inc POPIA Enforcement Tracker. The direction is consistent: more breaches, more complaints, more enforcement.
Waiting to see whether the trend reverses is not a compliance strategy.
Five Things Every SA SME Should Have in Place Right Now
Every POPIA enforcement case on record traces back to a failure in one of the following areas. None of them require a large IT budget. All of them are non-negotiable under the Act:

- Register your Information Officer. This is free and takes approximately 30 minutes through the Regulator’s BizPortal eServices platform. By default, this is the CEO or MD of your business. The Central Johannesburg TVET College received an enforcement notice in May 2026 partly because it had not done this. It is the lowest-hanging fruit in POPIA compliance.
- Have written operator contracts with every supplier who handles personal data. Your CRM, email platform, payroll system, payment processor — each one is a POPIA operator. Each one needs a written agreement requiring them to maintain adequate security. The absence of this contract was central to the Dis-Chem finding.
- Keep your security software active and licensed. The Department of Justice case turned on lapsed antivirus and monitoring licences — not on the ransomware attack itself. Under Section 19, maintaining adequate technical and organisational security measures is a legal requirement, not an IT preference. This is where cybersecurity monitoring earns its keep — licences that don’t lapse because someone else is watching them.
- Have a breach response plan before you need one. Section 22 requires that you report a security compromise to the Regulator and affected individuals within a reasonable time. Lancet Laboratories was fined R100,000 — and paid it — for failing to report multiple security compromises. Having a documented plan, and a managed IT partner who can execute it, is what separates organisations that respond well from those that end up in enforcement notices. This is exactly what breach response planning is designed to cover.
- Fix your marketing consent model. Since April 2025, opt-out is not consent. If your email marketing relies on the absence of an unsubscribe request as evidence of consent, you are now non-compliant. You need a positive opt-in, and telephonic consent calls must be electronically recorded.
POPIA Enforcement South Africa Is Active — The Question Is Whether You’re Ready
The Information Regulator spent its first two years building an enforcement record. It now has one.
Fines have been issued, the courts have confirmed them, and the Regulator has publicly committed to ending the leniency period, as outlined in its November 2025 media statements. POPIA enforcement South Africa is no longer a theoretical risk for businesses that handle personal information — it is an operating reality.
The good news embedded in every case above is that compliance is achievable. Dis-Chem received an enforcement notice and complied within 31 days — no fine.
TransUnion complied — no fine. SAPS complied — no fine. The organisations that ended up in infringement notices and court proceedings were the ones that did nothing.
Having the right technical safeguards, the right documentation, and the right support in place means that if you ever receive an enforcement notice, you have the tools to respond quickly and correctly.
A qualified IT and cybersecurity partner can walk you through exactly where your business stands — across security hygiene, operator contracts, breach response planning, and data handling practices.
If you’re not certain your business is covered, the time to find out is before the Regulator asks. A security audit is the fastest way to get that clarity.
Ready to Find Out Where You Stand?
Wired IT’s IT Strategy, Audit & Consultancy service gives you a clear picture of your current POPIA posture — what’s in place, what’s missing, and what needs to change.
It’s not about generating a report that collects dust. It’s about knowing your risk before it becomes a notification.
Request a POPIA Compliance Review
Want to talk it through first? Get in touch with the Wired IT team here — no obligation, just a conversation with someone who understands the South African compliance landscape.