Insights / POPIA · Enforcement & Penalties
Data Privacy Insight · Celagenix® Academy

The Information Regulator: How POPIA Enforcement Actually Works, and What the R10 Million Cap Really Means

An information notice is not a fine, and there is no turnover-percentage penalty in South African law. Understanding the POPIA enforcement ladder is the difference between panic and a plan.

In short: POPIA enforcement runs through a defined Chapter 10 pathway - complaint or own initiative, investigation, an information notice (a request, not a fine), the Enforcement Committee, and an enforcement notice under section 95. Only failure to comply with that enforcement notice opens the section 109 administrative fine, which is capped at a fixed ten million rand, not a percentage of turnover. POPIA runs three separate consequence tracks: administrative (s109), criminal (sections 100 to 106, penalties on conviction under s107), and civil (s99). A responsible party has 30 days to appeal an administrative fine under section 97. The first POPIA administrative fine - R5 million against the Department of Justice and Constitutional Development in July 2023 - followed exactly this pathway.

A responsible party’s compliance lead opens an envelope from the Information Regulator. She reads the words “information notice” and her stomach drops. She calls the chief financial officer and says the Regulator has fined the company. Within the hour the board is convened, a provision is discussed, and someone asks whether they must pay ten percent of last year’s turnover. None of that is true. No fine has been issued. No turnover formula exists anywhere in South African law. What has actually landed on her desk is a request, not a penalty - and the difference between those two things is the difference between panic and a proportionate response.

Who the Regulator actually is

The Information Regulator is established under section 39 of POPIA as an independent body, subject only to the Constitution and the law, and accountable to the National Assembly. That independence matters, because enforcement decisions cannot be leaned on by a minister or a regulated party. Two features are worth holding onto. First, the Regulator has a dual mandate: it enforces both POPIA and the Promotion of Access to Information Act (PAIA). The same body that polices how you protect personal information also polices how you grant access to it. Second, it is a juristic person with its own powers, not a division of a government department. The correspondence it sends carries specific legal meaning depending on which power it is exercising - and knowing which power is in play is the whole game.

The pathway begins with a complaint

The enforcement ladder in Chapter 10 has a defined shape, and it almost never begins with a fine. It begins with information reaching the Regulator, either through a complaint lodged under section 74 by a data subject or any person, or through the Regulator acting on its own initiative. From there the Regulator may conduct a pre-investigation and then a full investigation, with real teeth at this stage: it can summon people, administer oaths, and require the production of records. But investigation is a fact-finding phase, not a punishment. The Act deliberately front-loads inquiry so that consequences, when they come, rest on established facts rather than assumption.

The information notice - not a fine

One of the Regulator’s early instruments is the information notice: a formal, written request compelling a responsible party to furnish specified information within a stated period. It is exactly what the opening scenario got wrong. An information notice is not a determination of guilt, it is not a fine, and it does not by itself impose any monetary liability. The correct response is to treat it seriously, meet the deadline, and answer completely - because failing to comply with a lawful notice is itself an offence - but the correct emotional register is composure, not crisis. A responsible party that understands the ladder reads an information notice as an invitation to demonstrate compliance, not as a sentence already passed.

The Enforcement Committee

Where a matter warrants it, the Regulator refers it to the Enforcement Committee, appointed under section 50, whose role is to consider matters referred to it and make recommendations to the Regulator. It is an important structural safeguard, because it separates the body that investigates from the body that weighs the evidence and recommends an outcome. The Committee does not itself issue the final instrument; it recommends, and the Regulator then acts. This deliberate distance between investigation, deliberation and the final enforcement step is what gives the process its procedural fairness.

The enforcement notice - the instrument that bites

The instrument that genuinely bites is the enforcement notice, issued under section 95. Acting on the Committee’s recommendation, the Regulator can direct a responsible party to take specified steps, or to stop doing something, within a set period - to cease a processing activity, to remediate a failure, or to comply with a condition it has breached. This is the operative order the earlier envelope only felt like. And here is the hinge point for consequences: it is failure to comply with an enforcement notice that opens the door to the section 109 administrative fine. The fine does not fall from the sky on first contact. It follows a failure to obey a binding order that itself followed investigation and recommendation.

Three tracks that do not mix

POPIA creates three distinct consequence tracks, and a given failure may attract one or more, but they operate on different logic. The administrative track under section 109 is the infringement notice and administrative fine that follow non-compliance with an enforcement notice. The criminal track, sections 100 to 106, creates actual offences - such as obstructing the Regulator, breaching confidentiality provisions, or failing to comply with a notice - prosecuted through the ordinary criminal courts, not imposed by the Regulator. The civil track under section 99 lets a data subject institute a civil action for damages for a breach, whether or not there was intent or negligence. Administrative, criminal, civil: three doors, three different keys. When you map a scenario, the first question is which door, or doors, the failure actually opens.

The section 109 fine and the fixed cap

Here is the correction that matters most for anyone trained on European rules. Under section 109, when a responsible party fails to comply, the Regulator may issue an infringement notice with an administrative fine - and that fine is capped at a fixed rand figure, a maximum of ten million rand. It is not a percentage of turnover. There is no “ten million rand or ten percent of annual turnover, whichever is greater” formula in South African law; that construction is imported straight from the GDPR and is simply wrong here. So when a board asks what the maximum administrative exposure is, the honest, precise answer is a fixed statutory ceiling, not a turnover-linked number that could balloon without limit.

Penalties on conviction

The criminal side stays distinct. Section 107 sets the penalties a court may impose on conviction for the offences in sections 100 to 106, in two bands: a more serious band carrying a fine or imprisonment for a period not exceeding ten years, or both, and a lesser band carrying a fine or imprisonment for a period not exceeding twelve months, or both. Which band applies depends on which offence was committed. The crucial discipline is never to describe these as something the Regulator hands down. The Regulator does not convict anyone - criminal liability runs through the prosecuting authority and the courts. The Regulator’s own monetary instrument is the administrative fine under section 109.

The appeal clock

Timing is where the GDPR instinct does its final damage. Section 97 governs appeals and objections, and it sets two different clocks that must never be conflated. A responsible party that wishes to appeal against an administrative fine has 30 days to do so. A complainant, or a data subject dissatisfied with certain outcomes, works to a longer window of 180 days. Notice the asymmetry: 30 days for the responsible party, 180 days for the complainant. The European “180 days” figure that floats around in training material is not the responsible party’s appeal window, and treating it as such can cost an organisation its right to challenge a fine entirely. If you take one operational fact into your diary system, make it this: the moment an administrative fine lands, a 30-day clock starts.

What precision buys you

The first administrative fine under POPIA is a useful anchor for all of this. It was issued to the Department of Justice and Constitutional Development - five million rand, in July 2023 - following exactly this kind of failure to comply with an enforcement notice. Precision here is not pedantry. It is the difference between advising a board to provision for a phantom turnover-percentage penalty and advising it to answer an information notice on time; between missing a 30-day appeal window and preserving your organisation’s rights. Carry the pathway, hold the fixed cap, keep the three tracks apart, and watch the appeal clock - and the next envelope that lands on your desk will not produce panic. It will produce a plan.

Also available - the free POPIA Compliance Assessment

Would an information notice find you ready?

The free POPIA Compliance Assessment helps your organisation gauge how well it could answer the Information Regulator - before an envelope arrives. No email required to start. Enrolment in Celagenix® Academy unlocks the full learning unit this article is drawn from.

Take the free POPIA Compliance Assessment

Frequently asked questions

Is an information notice from the Information Regulator a fine?

No. An information notice is a formal written request compelling a responsible party to furnish specified information within a stated period. It is not a determination of guilt, not a fine, and it imposes no monetary liability by itself. It should be answered fully and on time - failing to comply with a lawful notice is itself an offence - but it signals a fact-finding stage, not a penalty.

Is the POPIA administrative fine a percentage of turnover?

No. Under section 109 the administrative fine is capped at a fixed maximum of ten million rand. There is no “ten million rand or a percentage of annual turnover, whichever is greater” formula in South African law - that construction is imported from the GDPR and does not apply to POPIA.

When can the Information Regulator impose an administrative fine?

Only after a defined pathway: a complaint under section 74 or the Regulator acting on its own initiative, investigation, referral to the Enforcement Committee (section 50), and an enforcement notice under section 95. It is failure to comply with that enforcement notice that opens the section 109 administrative fine - the fine does not arise on first contact.

What are the three consequence tracks under POPIA?

Administrative (section 109 infringement notice and fine following non-compliance with an enforcement notice); criminal (offences in sections 100 to 106, with penalties on conviction under section 107 of up to ten years or twelve months imprisonment depending on the band, imposed by the courts, not the Regulator); and civil (section 99, a data subject’s action for damages, with or without intent or negligence). A single failure may open one or more of these doors.

How long do you have to appeal a POPIA administrative fine?

A responsible party has 30 days to appeal an administrative fine under section 97. A complainant or dissatisfied data subject works to a longer 180-day window. The 180-day figure common in European training material is not the responsible party’s appeal window, and treating it as such can forfeit the right to challenge a fine.

← Back to Insights