
Data breaches are no longer theoretical risks. They are operational realities — and under the Protection of Personal Information Act 4 of 2013 as amended (“POPIA”), the legal and financial consequences of being unprepared are significant.
The Context
The first case against the Department of Justice and Constitutional Development began with an enforcement notice on 9 May 2023 under sections 19 and 22, linked to a 2021 compromise of about 1,204 files and lapsed licenses for antivirus, SIEM, and intrusion detection. This led to the first POPIA fine, a R5 million infringement notice on 3 July 2023. Both notices are challenged in the High Court and were pending as of November 2025. Earlier, on 4 April 2023, the Regulator issued an enforcement notice against the South African Police Service over victim and witness data shared on internal WhatsApp groups and public Facebook pages, violating sections 8 to 11, 15, 19, and 22. That case resulted in remedial orders: notifying data subjects, issuing a public apology, conducting disciplinary investigations, training, and adopting a privacy policy.
The operator cases follow a similar pattern. The Dis-Chem Pharmacies enforcement notice on 31 August 2023 involved a brute-force attack on Grapevine Interactive, affecting about 3.6 to 3.7 million data subjects, and addressed lawful-processing conditions and section 22. No fine was given; remedial orders included a personal information impact assessment, an incident-response plan, and updated operator agreements. The case was closed per the 2023/24 Annual Report. In Lancet Laboratories, a September 2024 enforcement notice for failing to notify the Regulator and data subjects within a reasonable time under section 22 resulted in a R100,000 infringement notice, paid to date without litigation.
Of the total, direct marketing and public-sector publication make up the rest. FT Rams Consulting received its first enforcement notice on 21 February 2024 for sending unsolicited emails despite opt-outs; a R100,000 fine announced on 13 November 2025 remains unpaid, and collection has begun. The Department of Basic Education was served on 18 November 2024 for publishing matric results with exam numbers without consent, fined R5 million on 23 December 2024. That fine was set aside on appeal, but the Regulator seeks to appeal again. Blouberg Local Municipality was fined R500,000 in 2024 for unlawfully publishing a former employee’s information online, announced on 13 November 2025. Despite reports of a R250,000 reduction on review, the fine remains unpaid, and recovery is ongoing.
Two matters illustrate the Regulator’s current stance. The WhatsApp LLC and Meta enforcement notice of 16 April 2025 addressed weaker privacy terms for South African users than EU users, requiring an updated policy, impact assessment, and PAIA compliance within 60 days. A settlement was announced on 13 November 2025, to be court-ordered, with no fine. Recently, the Central Johannesburg TVET College enforcement notice of 22 May 2026 followed a misdirected email revealing employees’ credentials and criminal records, violating sections 8, 15, 19, and 22. It required registering the Information Officer and deputies, notifying data subjects, issuing a written apology, disciplinary action, training, and submitting a POPIA Compliance Framework within 31 days. No fine was reported. The Regulator also issued notices against the IEC, OUTA, the State Security Agency, Kudung CPA, and Oceana Empowerment Trust (unpublished on its website), and separately under PAIA against Sibanye Stillwater and the Gauteng Department of Health.
Four observations: first, enforcement notice, not the fine, is the main tool. second, fines follow non-compliance, not the breach. third, judicial oversight exists: the DBE fine was set aside, and the DoJ&CD fine is contested. fourth, and most helpful, the remedial orders are consistent — registering Information Officers, notifying data subjects, a compliance framework, impact assessment, incident-response plan, revised operator agreements, training, and often a public apology. This list reflects the Regulator’s view of an adequate framework, available before an incident.
The Regulator received 1,727 security-compromise reports in 2024/25 and plans to reconfigure its units to improve handling. Its 2025/26 Performance Plan, presented to Parliament on 5 May 2026, shows a shift from complaint-driven to own-initiative investigations, with 10 ongoing complaint-based and 35 assessments across sectors. Planned outputs include a Guidance Note on transborder data transfers, influenced by the AfCFTA Digital Trade Protocol and AU Digital Transformation Strategy; a draft Code of Conduct on personal info at gated access points, due in 2025/26 with finalisation in 2026/27; and legislative efforts to enhance PAIA powers.
The question is not whether your organisation needs a POPIA compliance framework. It is whether the one you have will hold up when it matters.
Preparing Before a Breach Occurs
The organisations that navigate data breach incidents well are, almost without exception, the ones that prepared long before anything went wrong. A well-constructed compliance programme does not just reduce regulatory risk — it changes the trajectory of an incident entirely.
Our pre-breach services are built around practical legal defensibility, not tick-box compliance.
POPIA Compliance Audits: We assess your data activities, security controls, operator agreements, and governance against POPIA’s eight conditions. You receive a prioritized action plan highlighting the main compliance gaps, not just a theoretical report.
Data Breach Response Plan Drafting: We create bespoke, POPIA-compliant Data Breach Response Plans tailored to your organisation’s size, sector, and risk profile. Each plan includes ten essential components: escalation matrices, triage criteria, evidence preservation procedures, regulator notification templates for the Information Regulator’s e-Services Portal, and plain-language data subject notification drafts.
Operator Agreement Review and Drafting: Most organisations are exposed via their vendors and service providers, not their own systems. We review contracts, identify where Section 21 requirements aren’t met, and redraft agreements to include security obligations, breach notification, subcontracting restrictions, and audit rights as POPIA demands.
Responding When a Breach Has Occurred
When a breach happens, the first 24 to 72 hours define the outcome. Speed, legal precision, and regulatory expertise are not optional — they are the difference between a well-managed incident and an enforcement notice, and between an enforcement notice and a R10 million fine.
Emergency Legal Advice: We offer immediate legal advice on triggering Section 22 notifications, their required content, and managing liability. We advise clients in real time when decisions are urgent.
Information Regulator Notification Drafting: We draft and review your Section 22 notification to the Information Regulator, ensuring it meets requirements and accurately presents your organisation’s response.
Data Subject Notification Drafting: We prepare the plain-language notifications to affected data subjects that Section 22 requires, calibrated to the nature and severity of the specific breach.
Forensic and Legal Privilege Coordination: We work alongside your technical forensic investigators to ensure that legally privileged communications are properly protected and that the forensic process is conducted in a way that supports, rather than undermines, any subsequent legal proceedings.
Civil Liability Assessment and Defence: Where a breach gives rise to civil claims from affected data subjects under Section 99, we advise on your exposure, assess the merits of claims, and represent your organisation in any resulting litigation.
Post-Breach Remediation Advice: Once the immediate crisis is managed, we assist with the root-cause analysis from a legal perspective, update your Data Breach Response Plan to incorporate lessons learned, revise operator agreements, and prepare the post-incident compliance documentation that demonstrates accountability to the regulator.
Contact an expert at SchoemanLaw for all your data privacy compliance and breach response needs.

