One Email. Three Violations. A Wake-Up Call from the Information Regulator.

South Africa’s Information Regulator has issued a formal Enforcement Notice against Central Johannesburg TVET College — and the story behind it should make every South African employer sit up straight.

Here’s what happened.

The college was placed under administration to address governance failures. As part of that process, employees’ credentials were verified — qualifications checked, criminal records assessed. Entirely legitimate. Then, in the middle of communicating finance policies to her team, the Acting CFO accidentally attached those personal verification reports to the email. It went to staff who had no business seeing it. The email was recalled two days later. An internal investigation was launched. Corrective action was taken against the person responsible.

The Regulator still issued an Enforcement Notice, you can view this here.

Why? Because internal clean-up is not the same as legal compliance.

Three violations were confirmed. First, sharing those reports — even by accident — with people who weren’t authorised to see them is unlawful further processing under section 15 of POPIA. The law doesn’t have an “honest mistake” exemption. Second, the college had no adequate security safeguards to prevent this kind of thing happening — no access controls, no segregated file systems, no organisational measures. That’s a section 19 violation. Third, and this is the one that catches almost everyone off guard: when personal information is accessed by an unauthorised person, you are legally required to formally notify the Information Regulator and the affected individuals. Sending an internal “oops” email does not count. The college never notified the Regulator. That’s a section 22 violation.

And underneath all of it: no registered Information Officer. No foundation.

What the Regulator ordered and the clock that’s now ticking:

Within 31 days: register the Information Officer, notify the Regulator and affected employees of the breach, issue a written apology distributed company-wide, and submit the Compliance Framework.

Within 60 days: disciplinary action against the responsible employee.

Within 90 days: POPIA training for all staff, with proof.

Failure to comply isn’t a fine. It’s a criminal offence carrying up to ten years’ imprisonment.

What this means for your organisation

You don’t need a sophisticated cyberattack to be found in breach of POPIA. A shared folder with the wrong permissions. A misaddressed email. A WhatsApp group that includes the wrong people. These are breaches. And they trigger real legal obligations you need to be ready to execute on, fast.

The three questions every organisation should be able to answer today:

  1. Is your Information Officer registered with the Regulator?
  2. Do you have an Incident Response Policy that includes a section 22 notification process?
  3. Is your POPIA Compliance Framework documented, operational, and evidenced?

If the answer to any of those is “we’re working on it”, now is the time.

Contact us at popi@labournet.com