When One Incident Opens the Whole File

The Information Regulator’s 31 August 2026 media briefing set out five years of enforcement work and one clear message for employers: the incident is the trigger, not the finding.

On 31 August 2026 the Information Regulator held a media briefing on its POPIA and PAIA enforcement work. Most coverage will lead with the numbers, and the numbers are worth knowing. The more useful part for any business holding employee information is what the Regulator said about how it decides to act, and what it finds once it starts looking.

The SABS enforcement notice

The Regulator issued an enforcement notice against the South African Bureau of Standards following a significant ransomware attack in 2024. The attack encrypted SABS information systems and severely disrupted its operations.

What matters is what happened next. The Regulator opened its own assessment of the circumstances around the security compromise, and then went further, assessing other compliance areas under POPIA. The findings covered ground well beyond the attack itself:

  • Processing excessive and irrelevant information
  • Inadequate consent mechanisms
  • Weak security safeguards
  • Failure to address known vulnerabilities
  • No incident response plans
  • Failure to inform people how their information was collected

SABS has 90 days from receipt of the notice to revise its policies, conduct personal information impact assessments and implement protective measures.

The Chairperson was explicit that the enforcement action was not taken simply because SABS was the victim of a cyberattack. The Regulator accepts that attacks are increasingly sophisticated and that no organisation can promise it will never be attacked.

That single sentence is the most commercially important line in the whole briefing. The Regulator is not testing whether you were attacked. It is testing what your file looked like when the attack arrived. The briefing closed that section with a warning against organisations that treat the protection of personal information as a tick box exercise rather than an operational requirement that has to be planned for and properly resourced.

The volume behind it

The Regulator has now received over 8 000 security compromise reports in total. Over 1 220 of those came in between 1 April 2026 and the date of the briefing, which is under five months of the current financial year. On that trend it expects to pass 3 000 reported breaches for the year.

It also received over 3 800 complaints in the past year, 10 percent of them relating to direct marketing.

Direct marketing now carries two separate obligations

Two direct marketing matters, involving OUTsurance and MTN, have been referred to the Regulator’s Enforcement Committee. Both turn on the interpretation and application of section 69 of POPIA on unsolicited electronic communications, and the outcomes are expected to bring certainty for everyone sending marketing.

The Regulator also welcomed the recent amendments to the Consumer Protection Act Regulations and the new pre-emptive block register, and then settled a question that has been causing real confusion in marketing teams. Registration on the block register does not displace POPIA. The obligation to obtain consent before sending unsolicited direct marketing still stands on its own.

If your marketing operation has been treating the block register as the compliance answer, it is one half of the answer.

PAIA reporting is being counted, and named

For the 2025/26 cycle, 417 of 853 public bodies submitted PAIA annual reports between 1 April and 30 June 2026, a compliance rate of roughly 52 percent. That is an improvement on the 358 bodies and 33 percent recorded the year before, but the Regulator described the position as still a cause for concern.

Municipalities remain the weakest group. Only 91 of 257 submitted, roughly 35 percent. Political parties, TVET colleges, Schedule 3 entities and major public entities were also named as low compliance groups.

Those figures cover public bodies. Private bodies carry their own annual reporting obligation under section 83(4) of PAIA, on the same 1 April to 30 June window, and a nil return is still a return.

The Regulator also flagged a trend of bodies challenging enforcement notices in court rather than complying with them, naming Sibanye Stillwater and the Johannesburg Stock Exchange among those that have gone on review. In response, the review of PAIA to strengthen the Regulator’s powers to enforce and issue sanctions was described as an apex priority.

Live investigations

The Regulator confirmed it is currently investigating or assessing matters involving the National Credit Regulator, Truecaller, Pick n Pay, the Gauteng Department of e-Government, Land Bank and Standard Bank. These are investigations and assessments to establish whether conduct complies with POPIA. No findings have been made.

What this means if you employ people

Read the SABS findings again and picture a standard HR file.

Employers hold some of the densest personal information in any organisation. Identity numbers, banking details, next of kin, disciplinary records, medical certificates, injury on duty reports, incapacity assessments, payroll history. Most of it is collected because employment law requires it, which is exactly why it is easy to assume it takes care of itself.

The SABS findings map onto that file almost line for line. Is anything being collected that is no longer needed. Can you show what people were told at the point of collection. Is there an incident response plan that someone has actually read. Can you produce the assessment, or does it exist as an intention.

None of those questions require an attack to be asked. They require a request.

If you would prefer to start with a view of your own position first, our Information Compliance team runs a no-charge health check covering Information Officer registration, PAIA manual status, breach readiness and direct marketing consent.