POPIA Fines: Up to R10 Million or 10 Years in Prison (2026)
What the Information Regulator can actually impose, which offences carry prison time, and what enforcement has looked like in practice since 2021.
Fines do not arrive out of nowhere
Most writing about POPIA penalties leads with R10 million and leaves the impression that a data breach produces a fine. That is not how the Act works, and understanding the actual sequence is more useful than the headline number, because it tells you where you can still fix things.
Enforcement runs as a ladder:
- A complaint or a breach notification reaches the Information Regulator, or it acts on its own initiative.
- The Regulator investigates or assesses, and may issue an information notice requiring you to provide material.
- If it finds interference with the protection of personal information, it issues an enforcement notice, telling you what to do or stop doing, by when.
- If you fail to comply with that enforcement notice, you commit an offence, and the Regulator may serve an infringement notice carrying an administrative fine.
The fine attaches to ignoring the Regulator, not to the underlying mistake. A business that responds properly to an enforcement notice does not reach the fine stage. That is the single most important thing on this page.
The R10 million administrative fine
Section 109 governs administrative fines, and the maximum is R10 million. The infringement notice must set out the particulars of the alleged offence and the amount.
Two features are worth knowing. First, you may elect to be tried in court instead, within 30 days of the notice being served, rather than paying. Second, if you neither pay nor elect trial, the Regulator can file a certified statement with a court, which then has the effect of a civil judgment against you.
R10 million is a ceiling, not a going rate. The Regulator must consider the circumstances, and the only administrative fine issued to date came in well below it.
What has actually happened since 2021
Honest answer: less than the scare articles suggest, and the one landmark case did not end the way the Regulator wanted.
In November 2024 the Regulator issued an enforcement notice to the Department of Basic Education over the publication of matric results in newspapers, requiring an undertaking that it would not publish the 2024 results that way. The department did not give the undertaking within the 31 days allowed, and in December 2024 the Regulator served an infringement notice carrying a R5 million administrative fine, the first under POPIA.
That is where most articles stop. The story continued. The matter went on review, and in December 2025 the High Court set aside both the enforcement notice and the R5 million fine. The Regulator has sought leave to appeal, so the position is not settled.
Two conclusions follow, and they pull in different directions. The Regulator is willing to use its powers against a large public body, and the ladder from enforcement notice to fine is real rather than theoretical. But the enforcement record remains thin, the first fine did not survive a court challenge, and anyone telling you that POPIA fines are routinely landing on small businesses is selling something.
The realistic exposure for a small business is not a R10 million fine. It is a complaint you have to answer, a breach you have to report, and a customer or a corporate client who asks for documents you do not have.
Criminal offences, and the two tiers
POPIA also creates offences, with penalties in section 107 split into two tiers. The split is counterintuitive, and most summaries get it backwards.
Up to 10 years imprisonment, a fine, or both, for the more serious offences, which include:
- Obstructing the Regulator, or hindering it in the performance of its duties (section 100)
- Failing to comply with an enforcement notice (section 103(1))
- Certain offences by witnesses in Regulator proceedings (section 104(2))
- Unlawful acts in connection with an account number, by a responsible party (section 105(1)) or by a third party (section 106(1), (3) and (4)), which covers knowingly or recklessly obtaining, disclosing, procuring or selling account numbers
Up to 12 months imprisonment, a fine, or both, for the lesser offences, which include:
- Breach of confidentiality by a person acting for the Regulator (section 101)
- Obstructing the execution of a warrant (section 102)
- Failing to comply with an information notice, as opposed to an enforcement notice (section 103(2))
- Other offences by witnesses (section 104(1)), and section 59
Note where account numbers sit. Unlawfully obtaining or selling account numbers is in the ten year tier, alongside obstructing the Regulator. Several online summaries file it under the twelve month tier, which understates it considerably. If your business handles bank or card numbers, that is the provision to be aware of.
Who is actually liable
You will read that directors and Information Officers face personal criminal liability for their organisation's non-compliance. That is broader than the Act supports, and worth being precise about.
POPIA's offences attach to conduct. Obstructing the Regulator, ignoring an enforcement notice, or unlawfully dealing in account numbers are things a person does, and a person who does them can be prosecuted. There is no provision making a director criminally liable simply because the company fell short of a condition for lawful processing.
The Information Officer carries real duties under section 55, including encouraging compliance, dealing with requests and working with the Regulator, and must be registered before taking up those duties. Failure to do the job well is a compliance problem for the organisation. It is not, by itself, a route to prison.
Civil damages, which nobody plans for
Section 99 lets a data subject institute civil action for damages, and the Regulator may do so on their behalf. This runs independently of anything the Regulator decides to do about enforcement.
The feature that makes it serious is that the claim may be brought whether or not there was intent or negligence on the part of the responsible party. A defence that you tried your best and it was an honest mistake does not dispose of it. Courts may award damages for patrimonial loss, for non-patrimonial loss such as distress, and aggravated damages.
For most small businesses this is a more realistic risk than an administrative fine, because it does not depend on the Regulator prioritising your case.
What actually brings you to the Regulator's attention
- A complaint. A former employee, a customer who received marketing they did not ask for, or someone whose access request you ignored.
- Your own breach notification. Section 22 obliges you to report certain compromises, and reporting is the right thing to do, but it does put you on the Regulator's radar.
- Publicity. A breach reported in the media invites an own-initiative assessment.
- Being an operator to someone who is being investigated.
Notice that none of these is a random audit. Enforcement is overwhelmingly reactive, which is why the practical priority is having answers ready rather than achieving theoretical perfection.
What this means for a small business
Do not organise your compliance around a R10 million number you will almost certainly never see. Organise it around the three things that actually happen: someone complains, something leaks, or a client asks for your documents.
That means having a privacy notice that describes what you really do, knowing who your Information Officer is and registering them, being able to answer an access request inside 30 days, and having a plan for reporting a breach. If an enforcement notice ever does arrive, comply with it, because that is the step where a manageable problem becomes an expensive one.
For the full obligation list, see POPIA requirements. For the request process, see how to respond to a POPIA access request. For breaches, see your POPIA breach response plan.
POPIA Ready generates a privacy policy, a PAIA manual and five other documents customised to your business, free to preview. The free checklist will show you where you actually stand.
General guidance on South African law as at August 2026, not legal advice. The Department of Basic Education matter was under appeal at the time of writing, and enforcement practice is still developing.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview