POPIA Was Never Just a Privacy Policy — King V Just Made That Official
Your Information Officer registration and your board’s AI oversight duties are now the same conversation. Here’s what changed, and what your SME needs to do about it before the Regulator asks first.
If you read our piece on King V’s data and technology governance principle, you’ll remember the core message: boards can no longer treat data, IT, and AI as a background technical function — it’s now a governing-body duty with your name on it. What we didn’t spell out then is how directly that duty collides with an Act you probably already have a folder for: POPIA. In 2026, the Information Regulator stopped treating POPIA as a slow-burn awareness campaign and started issuing enforcement notices. If your business processes any personal information — and if you have customers, employees, or a WhatsApp number, it does — this is the piece that connects the two.
Why This Is a Sequel, Not a Separate Topic
Two compliance conversations that used to run on parallel tracks just merged.
POPIA tells you the legal rules for handling personal information. King V’s data and technology principle tells your board it’s personally on the hook for making sure those rules — plus your AI tools — are actually governed properly, not just written into a policy nobody reads.
King V, effective for financial years starting on or after 1 January 2026, elevated data, information and technology into what most commentators describe as Principle 10 — a standalone strategic pillar rather than a line item buried under risk management. Its scope is explicit: governing bodies must oversee IT, data governance, cyber resilience, and increasingly, artificial intelligence, with the same seriousness they apply to financial oversight. A handful of commentators number it differently, so if your board pack cites a specific principle number, it’s worth cross-checking against your own King V application register rather than assuming.
POPIA is the legal substance that sits underneath that principle. King V tells your board that it must govern data responsibly; POPIA tells you how — the eight lawful processing conditions, the Information Officer obligation, the breach notification timelines. An SME that has quietly filed away its POPIA privacy policy and never looked at it again is, functionally, already out of step with what King V now expects of governance — even if you’re not a listed company bound by King V’s disclosure requirements. The Regulator’s enforcement pattern in 2026 makes that gap expensive rather than theoretical.
What the Regulator Is Actually Chasing in 2026
This year’s enforcement priorities, in plain terms.
The Information Regulator has moved from “let’s raise awareness” to “show us your paperwork.” It’s now sending formal compliance notices and following through with fines when businesses ignore them.
Since late 2025, the Information Regulator has run a structured compliance monitoring exercise, issuing formal notices requiring organisations to demonstrate — with documentation — how they comply with POPIA. This is a shift from complaint-driven investigation to proactive audit. Two entities have already been hit with R5 million fines for failing to comply with enforcement notices, and the Regulator has flagged direct marketing and data breach management as priority enforcement areas for 2025 and 2026.
Information Officer registration
Every responsible party must register an Information Officer with the Regulator. This remains one of the most commonly missed obligations among SMEs — many assume a privacy policy on the website is enough. It isn’t.
Breach notification via the eServices portal
Since April 2025, data breach notifications must be lodged through the Regulator’s online portal. Notifications by email or letter no longer satisfy the process requirement, and incomplete or delayed portal submissions are treated as compliance failures in themselves.
Direct marketing controls
Following regulatory amendments, unsolicited electronic marketing without proper consent is a specifically flagged enforcement priority — relevant to any SME running email or WhatsApp marketing campaigns.
Health and sensitive personal information
New regulations governing health-related personal information were finalised in March 2026, tightening requirements for any business — healthcare, insurance, HR departments handling medical certificates — that touches this category of data.
PAIA manuals and annual reporting
The Promotion of Access to Information Act, long treated as POPIA’s quieter sibling, now carries its own annual reporting deadline (30 June) and is an increasing enforcement focus in its own right.
Where AI Governance and POPIA Actually Overlap
If your business uses AI tools on customer or employee data, this is the part that applies to you directly.
Feeding customer data into an AI tool — a chatbot, a scoring model, an automated marketing system — is “processing” under POPIA. King V now expects your board to be able to explain how that processing is governed, not just that it happens.
King V’s information governance principle explicitly extends board oversight to emerging technology, including AI — requiring governing bodies to ensure AI is deployed with human oversight, transparency, fairness, privacy and accountability designed in, not bolted on afterward. That list maps almost exactly onto POPIA’s existing lawful processing conditions: purpose specification, further processing limitation, data subject participation, and security safeguards.
In practice, this means an SME experimenting with an AI-powered CRM, a recruitment screening tool, or a customer service chatbot needs to ask the same questions POPIA has always required — what personal information is going in, whether the data subject consented to that specific use, how long it’s retained, and who’s accountable if it leaks — and now needs to be able to show a governing body (even an informal one, for a smaller business) that those questions were actually asked before deployment, not after a complaint.
The Gap Most SMEs Don’t Realise They Have
Information Officer registration is free and takes under half an hour online — yet it remains one of the most overlooked obligations in the South African SME market. If yours isn’t registered, it’s the fastest, lowest-cost fix available before anything else on this list.
Regulatory pressure is increasing, and many organisations are not equipped for it.
Industry Compliance Commentary, 2026The Bottom Line
POPIA and King V’s data governance principle used to feel like they belonged to different conversations — one legal, one boardroom. In 2026 they’re the same conversation, and the Information Regulator’s enforcement pattern is making that expensive to ignore. You don’t need to be a JSE-listed company bound by King V’s disclosure rules to feel the consequences of getting this wrong; you just need to be processing personal information, which almost every SME is.
The good news is that the fixes are largely foundational, not exotic: register your Information Officer, document what you can already show a Regulator if asked, and treat any new AI tool as a data processing decision that needs the same scrutiny as anything else touching customer or employee information. Get that right, and you’re not just compliant — you’re ahead of most of the market.

