Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific, Middle East and Africa: 2,033 cases from 44 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
–Total of monetary amounts (0 cases with an amount)
–Largest single case
–Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Information Regulator (South Africa) – 0 % · 1 case

What for?

by area of law

All areas of law

  1. Data protection – 0 % · 1 case

Who?

by company
  1. Blouberg Local Municipality €25,309 83 % · 1 case
  2. Electoral Commission of South Africa (IEC) €5,224 17 % · 1 case
  3. Central Johannesburg TVET College (CJC) – 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20260–
Q2 20261–
Q3 20260–
Q4 20260–

1 case

22 May 2026 Central Johannesburg TVET College (CJC)Central Johannesburg TVET College: order after staff vetting reports were mis-sent South AfricaEmployee data Order

In September 2022 the public TVET college mistakenly emailed reports verifying the qualifications and criminal records of three employees to other staff, informed neither the regulator nor those affected, and had not registered an information officer. Departing from the view of its Enforcement Committee, the regulator also treated this as impermissible further processing and found breaches of accountability, purpose limitation, security safeguards and the notification duty; on 22 May 2026 it ordered, among other things, registration, notification of the breach, a written apology, a compliance framework and POPIA training for all staff.

What organisations can take from it

Sensitive personnel records should be filed separately – and even an internal misdirected email is a notifiable security compromise.

Relevance to training and awareness

Misdirected emails and handling of personnel records

Missing or inadequate training played a role in the decision.

Authority / court
Information Regulator (South Africa)
Area of law
Data protection · Employee data
Legal basis
Sections 8, 15(1), 19(1) und 22(1) Protection of Personal Information Act 4 of 2013 (POPIA); Enforcement Notice nach Section 95 POPIA
Action
Order
Status of proceedings
unknown
Sector
Public sector
Mitigating circumstances
The college recalled the email two days later, informed staff of the error and took action against those responsible; according to the regulator, this did not relieve it of the duty to notify.
Published
2 Jun 2026

Checked against the official source on 4 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial