Petrol 93: Inland R25.94 · Coastal R25.07 /// Petrol 95: Inland R26.10 · Coastal R25.23 /// Diesel 50ppm: Inland R25.17 · Coastal R24.30 /// Illuminating Paraffin: Inland R17.24 · Coastal R16.18 /// Effective 1 JULY 2026
POPIA Isn’t Optional Anymore — Eli Masechaba
Governance & Compliance

POPIA Isn’t Optional Anymore

South Africa’s Information Regulator has stopped waiting for complaints and started going out and checking. Here’s what every SME owner needs to have in place before that knock comes.

Eli Masechaba  |  Business Consultant  |  Wits Business School Alumna

For a long time, POPIA was the law everyone knew about and almost nobody actually operationalised. A privacy policy on the website, a line in the employment contract, and that was that. That era is closing. The Information Regulator has moved from a complaints desk to a proactive watchdog, it has shown it will fine, and the sectors it’s circling first — financial services, insurance, health, retail, telecoms, and the public sector — are exactly where most South African SMEs live. If you handle customer records, staff files, or supplier data, this piece is for you.

R10mMax administrative fine, per contravention
2R5m fines issued to date
10 yrsMax imprisonment, serious offences
Part 01

The Regulator Has Teeth Now

And it’s finally using them.

Outsider Translation

Translation: the Regulator used to only act if someone complained. Now it’s actively auditing businesses whether they’ve complained or not — and it’s started handing out real fines.

The Information Regulator presented its 2025/26 and 2026/27 plan to Parliament’s Portfolio Committee on Justice and Constitutional Development in May 2026, and the message was unambiguous: it is moving away from a purely reactive, complaints-driven model toward its own compliance assessments — proactively checking sectors that hold large volumes of personal information, rather than waiting to be told there’s a problem.

The Regulator’s first big enforcement case is worth understanding properly, because it shows exactly what triggers a fine. The Department of Justice and Constitutional Development suffered a ransomware attack in 2021 after letting its security software licences lapse — a mundane, entirely preventable failure. The Regulator issued an enforcement notice in May 2023 ordering the department to fix its security and prove it had done so. It didn’t comply in time. Only then did the R5 million fine follow, via an infringement notice. That sequence matters: the fine wasn’t for the breach itself — it was for failing to respond properly once the Regulator stepped in. A second R5 million fine has since followed the same pattern, and a R500,000 fine was issued against a municipality on separate grounds. Direct marketing non-compliance and data breach management have both been flagged as priority enforcement areas.

There’s also a new, sector-specific tightening worth knowing about even if it doesn’t apply to your business directly: regulations on the processing of health information came into force on 6 March 2026 with no grace period, giving insurers, medical schemes, employers, and pension funds an explicit, higher bar for handling health data. If your SME touches employee medical information — even something as simple as sick notes or a company wellness benefit — it’s worth checking whether this affects you.

Enforcement Posture: Then vs Now
Pre-2026
2026 Onward
Regulator largely responds to complaints lodged by individuals.
Regulator runs its own proactive compliance assessments, unprompted.
Fines seen as rare, symbolic, aimed at large public bodies.
Fines issued to both public and private entities; enforcement described as increasingly routine.
Non-compliance framed as a legal footnote.
Non-compliance framed as an operational and reputational risk that boards must actively manage.
Part 02

Where SMEs Actually Get Caught Out

It’s rarely the dramatic data breach. It’s the paperwork nobody got around to.

Outsider Translation

Translation: most POPIA problems aren’t hackers — they’re a business that never appointed anyone to be responsible for data, never wrote anything down, and hopes nobody asks.

In practice, the gap between “we have a privacy policy” and “we are actually POPIA compliant” comes down to a handful of concrete, unglamorous requirements. These are the ones I see SMEs miss most often.

The Compliance Gaps The Regulator Keeps Finding

No registered Information Officer

Every business processing personal information is required to have an Information Officer responsible for POPIA (and PAIA) compliance, registered with the Regulator. Many owners either don’t know this obligation exists or assume a website privacy notice covers it. It doesn’t — this is a specific, named-person registration.

No PAIA manual

Alongside POPIA, most organisations are required to have a manual describing how people can request access to information the business holds. This is frequently skipped entirely, and it’s one of the first things an assessment checks for.

Unresolved data subject requests

When a customer or employee asks what data you hold, or asks you to correct or delete it, POPIA expects a timely, documented response — not silence, and not a fee steep enough to discourage the request.

Direct marketing without proper consent

Flagged as a current priority area for the Regulator. If your marketing list wasn’t built with clear, POPIA-compliant consent, every campaign you send is a live exposure, not a growth channel.

No incident response plan

The Department of Justice case shows the pattern clearly: it isn’t the incident itself that draws the heaviest penalty, it’s the absence of adequate security measures and a documented plan to respond when something goes wrong.

The Real Financial Exposure

Administrative fines under POPIA can reach R10 million per contravention, with the amount weighed against factors like how sensitive the information was, how many people were affected, and whether the failure was preventable. For the most serious offences — obstructing the Regulator, or unlawfully disclosing things like account numbers — the penalty can extend to imprisonment of up to 10 years. For an SME, the fine itself is often survivable. The reputational cost of an enforcement notice becoming public rarely is.


Part 03

POPIA Meets King V: A Governance Issue, Not Just A Legal One

The sequel to where we left off with AI and data governance.

Outsider Translation

Translation: your lawyer can keep you POPIA-compliant on paper. What King V is now asking is whether your board actually governs data as a strategic asset — POPIA compliance is the floor, not the whole conversation.

This is where POPIA compliance stops being purely a legal or IT matter and becomes a board-level governance question. King V, the new corporate governance code that took effect for financial years beginning on or after 1 January 2026, dedicates one of its thirteen principles specifically to the governance of data, information, and technology. That’s not a coincidence — it reflects the same shift in expectation that’s driving the Regulator’s more proactive posture: personal information is now treated as something governing bodies must actively steward, not something that sits quietly with the IT department until there’s a problem.

King V isn’t law — it’s a voluntary code, and it applies most directly to larger, JSE-listed entities. But its logic travels downward fast, because banks, insurers, and corporate customers increasingly expect the SMEs in their supply chain to reflect the same standard. If you’re a smaller business hoping to win or keep contracts with larger, more governed clients, being able to show a documented POPIA compliance framework — an appointed Information Officer, a breach response plan, evidence of how you handle data subject requests — is quickly becoming a commercial requirement, not just a defensive one.

Data governance has moved from an IT checkbox to a board-level responsibility — and the businesses that treat it that way now will be the ones with the paper trail when the Regulator, or a client’s due diligence team, comes asking.

Eli Masechaba, Ascentpeak

The Bottom Line

POPIA compliance for a South African SME isn’t about being perfect — it’s about being able to show your work. An appointed Information Officer, a PAIA manual, a documented process for data subject requests, real consent behind your marketing list, and a plan for the day something goes wrong. None of it is exotic. Most of it is a few weeks of proper governance discipline, not a major IT project.

What’s changed in 2026 is the cost of not doing it. The Regulator is checking proactively, the fines are no longer theoretical, and the businesses your SME wants to work with are increasingly asking the same questions the Regulator is. Treating data governance as a board-level responsibility — in the spirit King V now asks of larger organisations — isn’t red tape. It’s how you stay fundable, contractable, and out of an enforcement notice’s way.

Get Your Governance House In Order

Ascentpeak works with South African SME owners and boards to close exactly these gaps — practically, without the jargon.

Eli Masechaba  |  Business Consultant  |  South Africa