Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Information Regulator (South Africa) €10,286 100 % · 2 cases
What for?
by action- Fine €10,286 100 % · 2 cases
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q4 2023 | 0 | – |
| Q1 2024 | 0 | – |
| Q2 2024 | 0 | – |
| Q3 2024 | 0 | – |
| Q4 2024 | 1 | €5,224 |
| Q1 2025 | 0 | – |
| Q2 2025 | 0 | – |
| Q3 2025 | 0 | – |
| Q4 2025 | 1 | €5,062 |
| Q1 2026 | 0 | – |
| Q2 2026 | 0 | – |
| Q3 2026 | 0 | – |
| Q4 2026 | 0 | – |
2 cases
13 Nov 2025 Lancet LaboratoriesInformation Regulator: ZAR 100,000 against Lancet Laboratories over unreported data breaches €5,062
An assessment following several security compromises found that the laboratory company had notified neither the Information Regulator nor the affected data subjects. After an enforcement notice that it failed to comply with, it received an infringement notice with an administrative fine of ZAR 100,000, which has since been paid.
Data breaches must be reported both to the regulator and to the data subjects; failing to report several incidents triggers an assessment and sanctions.
Notifying data breaches to the regulator and data subjects
- Authority / court
- Information Regulator (South Africa)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Protection of Personal Information Act 4 of 2013 (POPIA), s. 22
- Action
- Fine
- Status of proceedings
- final
- Sector
- Healthcare
- Published
- 13 Nov 2025
Original amount 100,000 ZAR, converted at the ECB reference rate of 13 Nov 2025.
- Information Regulator: Media briefing – high-level cases on POPIA and PAIA (13.11.2025) Press release of an authority
Checked against the official source on 4 Oct 2026 · Direct link
Report an error
13 Nov 2024 Electoral Commission of South Africa (IEC)Information Regulator: ZAR 100,000 against the Electoral Commission after candidate list leak €5,224
After candidate lists for the 2024 elections were released without authorisation, the Information Regulator found inadequate organisational safeguards and issued an enforcement notice on 10 September 2024. Because the Electoral Commission did not demonstrate compliance within the deadline (31 days), an infringement notice with an administrative fine of ZAR 100,000 followed.
After a data breach, remediation alone is not enough; compliance must also be demonstrated to the regulator on time, and missed deadlines lead straight to a fine.
Implementing regulatory remediation orders after a data leak
- Authority / court
- Information Regulator (South Africa)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice und Infringement Notice
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Public sector
- Published
- 13 Nov 2024
Original amount 100,000 ZAR, converted at the ECB reference rate of 13 Nov 2024.
Checked against the official source on 4 Oct 2026 · Direct link