Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

4cases from 1 jurisdiction
€35,595Total of monetary amounts (3 cases with an amount)
€25,309Largest single case: Blouberg Local Municipality
€5,224Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Information Regulator (South Africa) €35,595 100 % · 4 cases

What for?

by topic
  1. Employee data €25,309 71 % · 2 cases
  2. Data breaches and data security €10,286 29 % · 2 cases

Who?

by sector

All sectors

  1. Public sector €30,533 86 % · 3 cases
  2. Healthcare €5,062 14 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20241€5,224
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20252€30,371
Q1 20260–
Q2 20261–
Q3 20260–
Q4 20260–

4 cases

22 May 2026 Central Johannesburg TVET College (CJC)Central Johannesburg TVET College: order after staff vetting reports were mis-sent South AfricaEmployee data Order

In September 2022 the public TVET college mistakenly emailed reports verifying the qualifications and criminal records of three employees to other staff, informed neither the regulator nor those affected, and had not registered an information officer. Departing from the view of its Enforcement Committee, the regulator also treated this as impermissible further processing and found breaches of accountability, purpose limitation, security safeguards and the notification duty; on 22 May 2026 it ordered, among other things, registration, notification of the breach, a written apology, a compliance framework and POPIA training for all staff.

What organisations can take from it

Sensitive personnel records should be filed separately – and even an internal misdirected email is a notifiable security compromise.

Relevance to training and awareness

Misdirected emails and handling of personnel records

Missing or inadequate training played a role in the decision.

Authority / court
Information Regulator (South Africa)
Area of law
Data protection · Employee data
Legal basis
Sections 8, 15(1), 19(1) und 22(1) Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice nach Section 95 POPIA
Action
Order
Status of proceedings
unknown
Sector
Public sector
Mitigating circumstances
The college recalled the email two days later, informed staff of the error and took action against those responsible; according to the regulator, this did not relieve it of the duty to notify.
Published
2 Jun 2026

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

13 Nov 2025 Blouberg Local MunicipalityInformation Regulator: ZAR 500,000 against Blouberg municipality over personnel data online South AfricaEmployee data €25,309

The municipality had processed personal information of a former employee which was exposed on the internet; the Information Regulator treated this as a gross violation of privacy and issued an enforcement notice. Because the municipality did not implement the corrective instructions, an administrative fine of ZAR 500,000 followed; as it did not pay, the Regulator has initiated court proceedings to recover the amount.

What organisations can take from it

Personnel data remains protected after employees leave; ignoring regulatory orders risks a heavy fine and recovery proceedings.

Relevance to training and awareness

Protecting personnel data of former employees

Authority / court
Information Regulator (South Africa)
Area of law
Data protection · Employee data
Legal basis
Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice und Infringement Notice
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
13 Nov 2025

Original amount 500,000 ZAR, converted at the ECB reference rate of 13 Nov 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

13 Nov 2025 Lancet LaboratoriesInformation Regulator: ZAR 100,000 against Lancet Laboratories over unreported data breaches South AfricaData breaches and data security €5,062

An assessment following several security compromises found that the laboratory company had notified neither the Information Regulator nor the affected data subjects. After an enforcement notice that it failed to comply with, it received an infringement notice with an administrative fine of ZAR 100,000, which has since been paid.

What organisations can take from it

Data breaches must be reported both to the regulator and to the data subjects; failing to report several incidents triggers an assessment and sanctions.

Relevance to training and awareness

Notifying data breaches to the regulator and data subjects

Authority / court
Information Regulator (South Africa)
Area of law
Data protection · Data breaches and data security
Legal basis
Protection of Personal Information Act 4 of 2013 (POPIA), s. 22
Action
Fine
Status of proceedings
final
Sector
Healthcare
Published
13 Nov 2025

Original amount 100,000 ZAR, converted at the ECB reference rate of 13 Nov 2025.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

13 Nov 2024 Electoral Commission of South Africa (IEC)Information Regulator: ZAR 100,000 against the Electoral Commission after candidate list leak South AfricaData breaches and data security €5,224

After candidate lists for the 2024 elections were released without authorisation, the Information Regulator found inadequate organisational safeguards and issued an enforcement notice on 10 September 2024. Because the Electoral Commission did not demonstrate compliance within the deadline (31 days), an infringement notice with an administrative fine of ZAR 100,000 followed.

What organisations can take from it

After a data breach, remediation alone is not enough; compliance must also be demonstrated to the regulator on time, and missed deadlines lead straight to a fine.

Relevance to training and awareness

Implementing regulatory remediation orders after a data leak

Authority / court
Information Regulator (South Africa)
Area of law
Data protection · Data breaches and data security
Legal basis
Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice und Infringement Notice
Action
Fine
Status of proceedings
unknown
Sector
Public sector
Published
13 Nov 2024

Original amount 100,000 ZAR, converted at the ECB reference rate of 13 Nov 2024.

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial