South Africa2023Data ProtectionCybercrime

za-ir-2023-doj · Information Regulator of South Africa

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Holding
The Information Regulator imposed a R5 million administrative fine on the Department of Justice and Constitutional Development for failing to comply with an enforcement notice, having found the Department in breach of its security-safeguard obligations under sections 19 and 22 of POPIA, specifically, its failure to renew antivirus, intrusion-detection and SIEM licences, which contributed to a 2021 ransomware breach that compromised personal information.
Why this case matters

The first administrative fine ever issued under POPIA, marking the point at which the Information Regulator's enforcement powers became operative in practice. It establishes that inadequate technical security measures, including a failure to maintain basic software protections, will be treated as a sanctionable breach of POPIA's security-safeguards provisions, and that public bodies are not exempt. It set the benchmark for subsequent South African enforcement activity.

Instruments cited
Related cases
Entry history
Entry history
  1. 24 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from Information Regulator media statement (3 - 4 July 2023)