POPIA enforcement is shifting from guidance to consequence

The Information Regulator has confirmed that enforcement action under POPIA is moving beyond education and into sanctions, including enforcement notices and administrative fines. Recent guidance has reinforced expectations around lawful processing, security safeguards, and operator oversight. In Minister of Justice and Constitutional Development v Prince, the Constitutional Court confirmed that statutory compliance obligations must be interpreted purposively. For scaling technology businesses, this sharpens the need for enforceable data processing agreements, incident response procedures, and documented accountability.

What changes when a regulator stops educating

The practical difference between an educative and an enforcing regulator is the value of documentation. During an education phase, demonstrating intent is usually sufficient. Once sanctions are in play, the question becomes what can be evidenced, and evidence has to have existed before the incident rather than been assembled after it.

This is where operator oversight tends to fail. Most businesses can name their operators. Considerably fewer can produce a current agreement for each, show what was actually assessed before appointment, or evidence that the oversight described in the agreement has ever been exercised.

What to check

  • Whether every operator processing personal information has a current, signed agreement, including ones onboarded by teams outside procurement.
  • Whether incident response procedures have been tested, or only written.
  • Whether the security safeguards described in operator agreements have been verified since signature.
  • Whether accountability decisions are documented contemporaneously, rather than reconstructed when questioned.

Where this lands in the contract

Enforceable is doing real work in this context. An operator agreement that describes obligations without any mechanism to verify them provides limited protection once a regulator asks what oversight was actually exercised. The provisions that matter are the ones that can be acted on: audit rights that are exercisable in practice, notification periods short enough to meet the regulator’s expectations upstream, and sub-operator consent that is required rather than assumed.

Newsletter Form

Subscribe to our Newsletter and  receive the latest news and updates.