MEDIA BRIEFING ADDRESS BY ADV PANSY TLAKULA
CHAIRPERSON OF THE INFORMATION REGULATOR
(ON BEHALF OF THE MEMBERS OF THE INFORMATION REGULATOR)
13 NOVEMBER 2025
Good morning to all media houses joining us here today, and to those participating virtually via our YouTube live stream. Thank you for taking the time to be part of this important briefing.
Today, we will provide updates on the work of the Information Regulator (Regulator), the developments on high-profile cases under the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA), as well as other key matters.
I would like to acknowledge the presence of my colleagues, the Members of the Regulator, Adv Lebogang Stroom, Mr Mfana Gwala, and Alison Tilley in absentia, as well as the Executive team led by our CEO, Mr Mosalanyane Mosala.
This session comes at a significant time as we commemorate twenty-five (25) years of PAIA, a law that promotes transparency, good governance, and accountability. Enacted in 2000, PAIA remains a cornerstone of our open democracy.
This milestone also reminds us of our unique dual mandate as the Regulator. We are among the few regulators globally that are entrusted with regulating both the right to privacy through POPIA and the right of access to information through PAIA.
In light of this reflection, we would like to provide an update on a few PAIA and POPIA cases that are currently being litigated on, those where we have issued Enforcement Notices and Infringement Notices, and those that are under investigation.
We will start with litigation matters.
LITIGATION MATTERS
We have a few POPIA and PAIA matters which are before the courts. In terms of POPIA, we are glad that some matters are being tested in court because POPIA is still a relatively new legislation. These matters are critical in shaping jurisprudence on POPIA and the right to data privacy in general.
Information Regulator v Minister of Basic Education
This is a recent court case that relates to the publication of the annual matric results. An Enforcement Notice had been issued against the Department of Basic Education (DBE) on 18 November 2024 following a finding from an assessment of how the DBE processes the personal information of learners who sit for matriculation exams. The assessment found that the DBE’s practices were in violation of the POPIA provisions, particularly the manner of publication of the results, which the Regulator deems likely to compromise the personal information of learners.
The Enforcement Notice had ordered the DBE to provide an undertaking “that it will not publish the results of the 2024 matriculants in the newspapers” within 31 days from the date on which the order was served. It also ordered that the department “must not publish the results for the 2024 matriculants in newspapers and must make these results available to the learners using methods that are compliant with POPIA.”
However, the DBE did not comply with the Enforcement Notice, thus forcing the Regulator to issue an Infringement Notice against DBE, in which it ordered the DBE to pay an administrative fine of R5 million following its failure to comply with the Enforcement Notice.
In January 2025, the Regulator approached the Pretoria High Court to make an application on an urgent basis for an interdict against the publication of the matriculation results (case: Information Regulator v Minister of Basic Education and Others (150121/2024) [2025] ZAGPPHC 2 (8 January 2025)). The application was dismissed and placed on the ordinary roll.
The matter was not heard on its merits. In the meantime, the DBE had served papers on the Regulator in an action to appeal the decision of the Regulator, and the matter was argued in the High Court (Gauteng Division, Pretoria) on 27–28 October 2025. Judgment was reserved.
Department of Justice and Constitutional Development (DOJ&CD) v Information Regulator
This concerns a 2021 security compromise at the DOJ&CD. After issuing the Enforcement and Infringement Notices, where the DOJ&CD were to pay a five (5) million rand fine, the Department challenged this in court. The matter is pending a hearing.
WhatsApp LLC v Information Regulator
This case stems from WhatsApp’s amended Privacy Policy as applicable in South Africa. The Regulator issued an Enforcement Notice after its assessment found that WhatsApp’s 2021 Privacy Policy update violated POPIA. While WhatsApp LLC had initiated legal action to review the decision of the Regulator and have it set aside, we are happy to announce that WhatsApp LLC and the Regulator have resolved the matter through a settlement agreement. In terms of this Settlement Agreement, which will be made a court order, WhatsApp LLC has agreed to introduce a number of enhancements to the transparency information that it makes available to South African users.
Swartkops Sea Salt (Pty) Ltd and Another v Information Regulator and Others
This matter involves an Enforcement Notice under PAIA compelling disclosure of certain records. These records relate to proof of whether the inhabitants living in the area where the Applicants are operating a salt mine benefited as a result of these operations. Swartkops Sea Salt is challenging the Enforcement Notice in court, and the Regulator is opposing the matter. The matter is now before the courts, awaiting a hearing date.
POPIA MATTERS
Infringement Notices issued
We issued three (3) Infringement Notices to the bodies that had failed to comply with the Enforcement Notices served to them in terms of section 95 POPIA, and have thereby contravened POPIA. Responsible parties must note that non-compliance with an Enforcement Notice is an offence, and we do not take this lightly as the Regulator. The Infringement Notices now issued compel the institutions to pay administrative fines as determined by the Regulator. The following Infringement Notices were issued:
Blouberg Municipality
An Enforcement Notice was issued against the Blouberg Municipality following it being found to have grossly violated the right to privacy (as it relates to the protection of personal information) of its former employee. The municipality processed the personal information of a former employee, whose personal information was exposed on the internet.
They failed to adhere to the corrective instructions in the Enforcement Notice; hence, they were liable to pay a fine of five hundred thousand rands (R500 000).
The Municipality failed to pay the administrative fine, and as such, the Regulator has initiated court proceedings wherein the Regulator is seeking to recover the amount of the administrative fine payable by the infringer.
Lancet Laboratories
Lancet Laboratories was also issued an Enforcement Notice, following a compliance assessment conducted on the body.
The assessment had been brought about by the number of security compromises (data breaches) that they had experienced. The company failed to comply with the requirement of notifying the Regulator about the security compromises as required by section 22 of POPIA. What was also of grave concern was that the body did not notify the data subjects affected by the security compromise.
Lancet Laboratories was compelled, through the Infringement Notice, to pay a fine of one hundred thousand (R100 000) following their failure to comply with the Enforcement Notice. We confirm that the fine has been duly paid by Lancet Laboratories.
FT Rams Consulting
FT Rams, a company against whom a direct marketing complaint had been received and investigated by the Regulator, failed to comply with the Enforcement Notice issued following the investigation. An Infringement Notice with an administrative fine of one hundred thousand rands (R100 000) was then issued. FT Rams, like Blouberg Municipality, also failed to pay the administrative fine, and as such, the Regulator has initiated court proceedings to recover the amount owed by the infringer.
The rate of security compromise incidents
In the 2024/25 financial year, two thousand, three hundred and seventy-four (2374) security compromise incidents (data breaches) were reported, with an average of one hundred and ninety-eight (198) notifications per month.
From the beginning of this financial year, April 2025 to date, one thousand nine hundred and forty-seven (1947) compromises were reported, with an average of two hundred and eighty-four (284) notifications received per month, demonstrating an increase of forty percent (40%) in reported security compromises.
The Regulator continues to be deeply concerned about the increased number of compromise incidents occurring in the country and calls on both the public and private sectors to make the requisite investments into developing and maintaining appropriate technical and organisational measures to secure the integrity and confidentiality of personal information in their possession.
Amended POPIA Regulations
On 17 April 2025, the amended POPIA Regulations came into effect. The amendments place stricter measures on responsible parties to comply with the provisions of POPIA and subsequently enhance the right to privacy for data subjects (to whom the personal information relates).
Furthermore, the amendments place stricter rules on direct marketing practices in so far as the processing of personal information is concerned.
These include the requirement for responsible parties to put in place multiple mechanisms for data subjects to seamlessly object to the processing of their personal information.
The requirements also include a stipulation that, in the instance where direct marketing is done via telephone, it must be recorded, and the records should be made available to a data subject on request. The Regulations compel the responsible parties to improve their compliance frameworks so as to track, handle, and manage objections in an effective manner.
PAIA MATTERS
Enforcement Notices
The Regulator has issued the following Enforcement Notices:
Organisation Undoing Tax Abuse v Road Traffic Management Corporation
The non-governmental organisation, the Organisation Undoing Tax Abuse (OUTA), had requested records from the Road Traffic Management Corporation (RTMC) regarding the composition of the fees published in the RTMC Regulations on 14 January 2022. The information request was not released to OUTA, and the organisation submitted a PAIA complaint to the Regulator. The Regulator subsequently issued an Enforcement Notice setting aside the decision of the RTMC to deny access to the requested information. The RTMC failed to comply with the Enforcement Notice. Following this, the Regulator has registered the matter with the SAPS for criminal investigation into the contravention of PAIA by the Information Officer of the RTMC.
Pieter-Louis Myburgh v The State Security Agency (SSA)
Mr Pieter-Louis Myburgh (an investigative journalist) requested records from the State Security Agency (SSA) regarding certain disbursements incurred by the SSA for a service provider between 2015 and 2019. Mr Myburgh did not receive the records requests and submitted a PAIA complaint to the Regulator. The Regulator determined that SSA had failed to prove that the release of information would compromise national security and ongoing criminal investigation as had been claimed by the SSA, and, therefore, issued an Enforcement Notice against the SSA directing that they disclose the records. The SSA failed to comply with the Enforcement Notice and the Regulator registered a criminal complaint against the former Acting Director-General with the SAPS for the contravention of the SSA with PAIA.
Kudung CPA case
In August 2025, we issued an Enforcement Notice against the Kudung Communal Property Association. This came after the association had been embroiled in several disputes about transparency, governance, and management. A complaint was lodged with the Regulator due to the deemed refusal of access to the records held by the association. The complainant had made a request for records such as all financial books, invoices, and receipts pertaining to financial transactions and all contracts, as well as attendance registers of the Association’s general meetings and other records.
The Regulator found that the association had failed to demonstrate that access to the requested records can be withheld based on the grounds for refusal provided for in PAIA, specifically sections 66 and 68 of PAIA. Therefore, the Regulator instructed the body to release all the records requested by the complainant within thirty-one (31) days from the date the Enforcement Notice was issued. The association did not respond to the instructions in the Enforcement Notice, even though we had issued a monitoring notice after their thirty-one (31) days had lapsed, which they also ignored. Therefore, we have now embarked on the process of opening a criminal case with the South African Police Services.
Nigel Lawrence, Samuel Williams and Michel Consalves v Oceana Empowerment Trust
The former employees of Oceana Empowerment Trust (the Trust) had requested access to information regarding the Oceana Group Black Employee Share Trust in which they are employee beneficiaries.
The Trust disclosed some of the records, but denied access to others on the basis that the requestors had not shown how the information requested was needed to exercise or protect other rights, as is required when making requests held by a private body.
The Regulator set aside the decision of the information officer and ordered the release of the up-to-date list of beneficiaries and all documents relating to the sourcing of R292 million, more specifically any agreements and/or documents pertaining to any loan or capital contributions.
Warren Thompson v the South African Receiver of Revenue
Mr Warren Thompson is an investigative journalist who had made a request for the individual tax returns (ITR12) for the former State President, Mr Jacob Gedleyihlekisa Zuma, for the years from 2010 to 2018.
Additionally, he requested access to information regarding assessments conducted by SARS into Mr Zuma’s tax affairs, including all relevant correspondence between SARS and Mr Zuma. SARS refused access to information on the basis of the exemption from disclosure of SARS records provided for in PAIA (section 35(1)), and also the claim that some of the records requested did not exist.
Following an exhaustive investigation, the Regulator has found that SARS was not justified in denying access to the requested records and directed that Mr Zuma’s tax returns, assessments, records of correspondence, among others, be released to the requester.
On-going high-profile Investigations
The Democratic Alliance (DA) v Gauteng Premier complaint
The Regulator is currently conducting an investigation involving the Office of the Premier of Gauteng Province following a complaint submitted by the Democratic Alliance (DA) regarding access to one hundred and seventy-seven (177) forensic investigation reports. Although some reports have been disclosed since the commencement of the investigation, the investigation continues in relation to the outstanding reports.
Digital Platform Transparency: Google LLC and Meta Inc.
We are currently in a battle with multinational Big Tech companies and owners of digital platforms such as Google LLC and Meta Inc. on the question of the jurisdiction of PAIA. The issue of jurisdiction has arisen as a result of these companies’ refusal of access to the records that they hold on the basis that PAIA does not apply extraterritorially (that is to say, beyond the limits of South Africa’s borders) despite them conducting business in the Republic.
The complainants had requested access to the records relating to the classification of elections, risk assessments concerning South Africa’s electoral integrity, and the application of global policies to local contexts within these entities.
We are of the firm view that PAIA applies to foreign persons or companies doing business with South Africans and those who live in it, even if they are physically located elsewhere. To resolve this sticky question, we have sought a legal opinion on jurisdictional issues on our enforcement powers in relation to entities domiciled abroad but doing business in South Africa.
Compliance assessments and outcomes
Last year, we conducted eighty (80) own-initiative PAIA compliance assessments across public and private sectors, including social media companies, Parliament, provincial legislatures, constitutional bodies, and medical aid schemes.
Key findings were that many bodies still fail to make PAIA manuals publicly accessible, which is a criminal offence, and it hinders the public’s right to information.
Non-submission of PAIA annual reports remains a widespread problem, undermining transparency and accountability. The annual reports are essential because they provide information on the number of requests for access to information received, and access granted or denied, amongst other access to information activities. They are critical for the Regulator to carry out its obligation to monitor and enforce compliance with PAIA.
Generally, there was a slight improvement in the submission of the 2024/2025 PAIA annual reports by both public and private bodies when compared with the year 2023/2024.
There was a significant increase in submissions by private bodies, from which we received ninety-one thousand, and ninety-six (91 096) reports, whereas in the previous year we received only thirty-four thousand, four hundred and sixty (34 460).
In the year 2024/2025, public bodies’ submissions increased to forty-one point six-six percent (41.66%) compared to the previous year, where thirty-three percent (33%) of reports were received. Out of eight hundred and fifty-three (853) public bodies, three hundred and fifty-eight (358) public bodies had submitted reports to the Regulator. A grave concern remains with TVET colleges, where out of fifty (50) colleges, only six (6) submitted, which is a dismal six percent (6%) submission.
Municipalities are also a source of concern. Out of two hundred and fifty-seven (257) municipalities, only sixty (69) submitted their annual reports, making it a twenty-seven percent (27%) submission.
There was also a decline in the submission of reports by the Provincial Government Business Enterprises. Their submission was at twenty-eight percent (28%), a decline from the previous year, which was at thirty-three percent (33%).
In our recent session with public and private bodies at the International Day for Universal Access to Information event that we hosted in Durban on 29 September 2025, we had robust engagements with the bodies on their obligation to comply with PAIA.
We informed them that we are in the process of developing proposals for reforming PAIA to make it fit for purpose in the digital era and to strengthen our enforcement powers, including the ability to impose sanctions and administrative fines on those who contravene the law.
DIGITISATION OF THE REGULATORS’ SERVICE PLATFORMS
I want to assure the members of the public that we are working tirelessly to improve our service delivery to the public and stakeholders, and we remain committed to the process of innovation and the state of constant improvement.
However, we acknowledge the challenge of limited capacity and resources amid growing demand for our services. As awareness of rights, particularly the right to privacy, continues to rise, so does the volume of complaints and queries we receive.
In the 2023/24 financial year, we received a total of one thousand and forty-four (1044) POPIA complaints, whereas in the 2024/25 financial year, we received one thousand and fifty-five (1355) POPIA complaints. From April 2025 to date, we have received 988 complaints. The total number of complaints has increased by approximately thirty-four percent (34%) compared to the same period last year. To address this, we have embarked on a robust digital transformation journey to enhance efficiency, accessibility, and responsiveness.
We are proud to announce the following solutions that we have made available to the public to enhance their experience of accessing the services of the Regulator:
iSupport
As an institution that adopted the value of responsiveness as one of the pillars of its service delivery efforts, we have introduced the iSupport service, which is a query-management system to improve turnaround times. Historically, we received queries through multiple fragmented channels, including email, telephone, social media, and walk-ins. This resulted in significant inefficiencies, delays, and challenges in tracking, categorisation, follow-ups, and reporting. The platform consolidates all enquiries into a single platform, generating tickets, effective tracking, and allocation for timely resolution, monitored through defined workflow stages.
Security compromise reporting system
With the surge in security compromises experienced by both public and private bodies, and subsequently receiving the reports manually, it was prudent that we introduce a Security Compromise Reporting System. It digitises the reporting and management of security compromises by responsible parties. Previously, responsible parties were required to download a form from the website, complete it manually, and email it to the Regulator. This service now enables secure, structured submissions. This has streamlined reporting and reduced administrative burden.
POPIA Complaints Submission System
Our key milestone is the POPIA Complaints Submission System, which we recently launched in October 2025, enabling members of the public to submit complaints directly on the eServices platform against any individual or responsible party who violates their right to privacy (as it relates to the protection of personal information). The platform has two (2) complaint categories, namely general POPIA complaints and direct marketing complaints, each managed through a structured workflow that automatically guides processing through assessment, escalation, resolution, and closure. This service is aimed at simplifying public access, improving transparency, ensuring standardised handling of matters, and significantly reducing administrative burden while strengthening the protection of personal information rights. As we test and improve the system, we will very soon introduce the same mechanism for PAIA complaints.
ACCOLADES AND AWARDS
These major milestones in our approach to service delivery are to be attributed to the leadership and hard work of our award-winning Chief Information Officer (CIO), Mr Tando Luyaba, working together with his team in developing these systems.
We are proud of the work done by the CIO, which gives meaning to the Regulator’s vision for modernisation and service innovation.
This has been evident with the many accolades he has been bestowed. The most recent achievements include:
- being awarded the Public Sector CIO of the Year Award, by ITWeb. The award recognises excellence in public-sector technology leadership and digital transformation, demonstrating exceptional vision in driving ICT modernisation, strengthening service delivery, and advancing data governance within the public sector.
- the Regulator being also recognised at the GovTech Digital Public Service Awardsand awarded the Digital Governance Award, First Runner-Up, and the Digital Partnerships Award, First Runner-Up.
These are but a few amongst the many global and local awards the CIO has obtained.
These awards affirm our commitment to leveraging technology for better governance, stronger data protection, and improved public service delivery.
CONCLUSION
We truly appreciate the feedback and constant reminder by the public that we are a human rights organisation and that we must improve our processes and systems so we can ensure that their rights are protected and promoted.
Thank you for your attention and continued support of our commitment to promote transparency and protecting personal information.




