South Africa's Information Regulator Is Getting More Assertive on POPIA
South Africa's Information Regulator commenced a formal POPIA monitoring exercise in February 2026, continuing an escalation that started with its first direct-marketing enforcement notice in 2024. The Regulator has since published a Guidance Note on Direct Marketing, amended POPIA's regulations, and issued two R5 million administrative fines - both for organisations that failed to comply with earlier enforcement notices, not for the original underlying violations.
A track record that's no longer theoretical
Enforcement notices to date have named a broad mix of organisations: the South African Police Service, the Department of Justice and Constitutional Development, Dis-Chem Pharmacies, the Department of Basic Education, and - notably - WhatsApp, cited in April 2025 for applying weaker privacy terms to South African users than to European users under the same product. Administrative fines under POPIA can reach R10 million, and the most serious offences carry criminal penalties of up to 10 years' imprisonment.
What this means for South African operators, and firms serving SA clients
- Direct marketing and data breach management are the Regulator's stated priority enforcement areas for 2025 and 2026 - audit consent and opt-out flows specifically, not just general data handling.
- The pattern in enforcement notices shows the Regulator escalating hardest against organisations that ignore an initial notice, not necessarily against the size of the original breach - responsiveness to the Regulator matters as much as the underlying control gap.
- The WhatsApp case is a useful benchmark: applying a lower privacy standard to South African users than you apply elsewhere is now an identified enforcement risk, not a grey area.
For insurance, fintech, and gaming operators handling South African policyholder, customer, or player data, a formal monitoring exercise means the Regulator is actively looking, not just waiting for complaints. Now is a reasonable time to confirm your Information Officer registration is current and your breach notification process actually matches what POPIA requires.
Sources
Have a security question of your own?
Talk to a Security Expert →