Two departments nailed with R5 million fines in South Africa

 ·1 Sep 2026

The Information Regulator (IR) fined both the Department of Justice and the Department of Education for breaching the country’s Protection of Private Information (POPI) Act in the past five years.

The POPI Act was enacted in 2020 and, following a grace period, fully came into effect for South Africans in 2021.

The Act imposes strict requirements on businesses and on anyone holding another person’s private information, including how this information can be used and stored.

On 31 August 2026, the IR gave a comprehensive overview of how it has enforced the POPI Act and the Promotion of Access to Information Act (PAIA).

In its briefing, the regulator outlined the largest fines it has imposed for entities which do not comply with POPIA requirements.

The two largest fines were both R5 million for the Department of Justice and the Department of Basic Education.

The Justice Department received its fine following a cyberattack in 2021, which led to the loss of roughly 1,200 files and the compromise of personal information.

The IR, following an investigation, decided that the Department had failed to implement adequate cybersecurity to prevent the attack and the exposure of private information.

The regulator then issued an enforcement notice to the Department of Justice to review its security monitoring and antivirus software, but did not receive a response within the 31-day deadline.

This ultimately led to the R5 million fine being imposed, which the IR recently confirmed remains in dispute due to ongoing legal battles between the two groups.

The second R5 million fine, imposed on the Department of Basic Education for publishing matric results in newspapers, remains in dispute.

The IR has repeatedly argued that publishing grade 12 results in newspapers does not protect personal information, but the courts ruled that the department could continue the practice by using ID numbers.

The dispute has gone through several appeals, but the Department of Basic Education currently has permission from South Africa’s courts to publish the matric results.

Largest fines issued by the Information Regulator for contravening POPIA

EntityFine Status
Department of JusticeR5 millionStill in dispute
Department of Basic EducationR5 millionCurrently before the courts
Independent Electoral Commission (IEC)R100,000Paid
Lancet LaboratoriesR100,000 (approx.)Paid
Bloubergstrand MunicipalityR500,000 (reduced by the court to R250,000)Currently in recovery proceedings

Focus on enforcement

The IR has proposed amendments to both the PAIA and POPIA laws, which would make the acts work as stronger deterrents and give more power to the regulator.

For POPIA, the regulator is considering the proposal of legislative amendments which would move towards immediate fines, instead of providing a compliance window.

It argued that the current 31-day grace period for complying with an enforcement notice limits the deterrent effect of the fines system.

For PAIA, current enforcement systems were considered too weak, as the act has no fines and instead requires the IR to lodge criminal complaints.

The regulator said it is pursuing enforcement programmes equivalent to POPIA, including the ability to release information directly when an order has not been complied with within 180 days.

This follows poor compliance with the PAIA laws, with only 417 of 853 public entities submitting annual reports to the IR.

Werksmans Attorneys directors Ahmore Burger-Smidt and Armand Swart, as well as associate Hlonelwa Lutuli, said the regulator is showing heightened enforcement activity.

They said the IR is moving beyond awareness raising and into active enforcement of both POPIA and PAIA laws.

They said that organisations must ensure they have adequate response plans in place for potential security breaches, including the ability to comply with section 22 notification obligations.

Both public and private bodies must also ensure compliance with PAIA reports, as the regulator looks to clamp down on non-compliance.

“The Regulator’s express intention to seek stronger enforcement powers means that non-compliance is likely to attract consequences in the near future,” Werksmans attorneys said.

“The combination of escalating enforcement action, proactive compliance monitoring, and proposed legislative amendments designed to introduce immediate fines signals a fundamental shift in the South African data protection landscape.”

Show comments
Subscribe to our daily newsletter