Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Information Regulator (South Africa) €30,533 100 % · 3 cases
What for?
by topicWho?
by companyWhen?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €5,224 |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €25,309 |
| Q1 2026 | 0 | – |
| Q2 2026 | 1 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
3 cases
22 May 2026 Central Johannesburg TVET College (CJC)Central Johannesburg TVET College: order after staff vetting reports were mis-sent Order
In September 2022 the public TVET college mistakenly emailed reports verifying the qualifications and criminal records of three employees to other staff, informed neither the regulator nor those affected, and had not registered an information officer. Departing from the view of its Enforcement Committee, the regulator also treated this as impermissible further processing and found breaches of accountability, purpose limitation, security safeguards and the notification duty; on 22 May 2026 it ordered, among other things, registration, notification of the breach, a written apology, a compliance framework and POPIA training for all staff.
Sensitive personnel records should be filed separately – and even an internal misdirected email is a notifiable security compromise.
Misdirected emails and handling of personnel records
Missing or inadequate training played a role in the decision.
- Authority / court
- Information Regulator (South Africa)
- Area of law
- Data protection · Employee data
- Legal basis
- Sections 8, 15(1), 19(1) und 22(1) Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice nach Section 95 POPIA
- Action
- Order
- Status of proceedings
- unknown
- Sector
- Public sector
- Mitigating circumstances
- The college recalled the email two days later, informed staff of the error and took action against those responsible; according to the regulator, this did not relieve it of the duty to notify.
- Published
- 2 Jun 2026
- Information Regulator: Enforcement Notice (Section 95 POPIA) – Central Johannesburg TVET College, dated 22 May 2026 (redacted) Decision of an authority
- Information Regulator Media Statement, 02 June 2026: Information Regulator issues enforcement notices for the contraventions of POPIA and PAIA by public and private bodies Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
13 Nov 2025 Blouberg Local MunicipalityInformation Regulator: ZAR 500,000 against Blouberg municipality over personnel data online €25,309
The municipality had processed personal information of a former employee which was exposed on the internet; the Information Regulator treated this as a gross violation of privacy and issued an enforcement notice. Because the municipality did not implement the corrective instructions, an administrative fine of ZAR 500,000 followed; as it did not pay, the Regulator has initiated court proceedings to recover the amount.
Personnel data remains protected after employees leave; ignoring regulatory orders risks a heavy fine and recovery proceedings.
Protecting personnel data of former employees
- Authority / court
- Information Regulator (South Africa)
- Area of law
- Data protection · Employee data
- Legal basis
- Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice und Infringement Notice
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 13 Nov 2025
Original amount 500,000 ZAR, converted at the ECB reference rate of 13 Nov 2025.
- Information Regulator: Media briefing – high-level cases on POPIA and PAIA (13.11.2025) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
13 Nov 2024 Electoral Commission of South Africa (IEC)Information Regulator: ZAR 100,000 against the Electoral Commission after candidate list leak €5,224
After candidate lists for the 2024 elections were released without authorisation, the Information Regulator found inadequate organisational safeguards and issued an enforcement notice on 10 September 2024. Because the Electoral Commission did not demonstrate compliance within the deadline (31 days), an infringement notice with an administrative fine of ZAR 100,000 followed.
After a data breach, remediation alone is not enough; compliance must also be demonstrated to the regulator on time, and missed deadlines lead straight to a fine.
Implementing regulatory remediation orders after a data leak
- Authority / court
- Information Regulator (South Africa)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice und Infringement Notice
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 13 Nov 2024
Original amount 100,000 ZAR, converted at the ECB reference rate of 13 Nov 2024.
Checked against the official source on 4 Oct 2026 · Direct link