What happened

South Africa's Information Regulator has spent 2026 issuing enforcement notices to public and private bodies — including a notice against the Central Johannesburg TVET College in May and further notices in August. But the most instructive case is the Regulator's own-initiative assessment of the South African Bureau of Standards following its ransomware attack.

The finding was notable for its shape: the incident was a security failure, but the contraventions were mostly about governance. The Regulator cited the SABS for processing excessive or irrelevant information, inadequate consent mechanisms, insufficient security safeguards, and failing to tell data subjects how their information was collected. With POPIA's penalty ceiling at R10 million, the era of treating compliance as a paperwork exercise is over.

Why it matters to your business

The SABS finding establishes a pattern every business should sit with: you can be breached through no great fault of your own and still be found wanting on what you collected, why you kept it, and whether anyone was told. Ransomware is the trigger — governance is the finding.

Enforcement is also no longer reserved for large institutions. The Regulator's 2026 notices span public and private bodies, and every breached organisation becomes a potential assessment target the moment it files a notification — which, as we covered last week, over 8,000 organisations have now done.

What you should do

Minimise what you hold. Data you don't retain can't be breached or flagged as excessive. Audit what you collect and why.

Fix the basics the Regulator cites most: security safeguards, consent records, and clear privacy notices.

Pair compliance with protection. POPIA-aligned email archiving and compliance reporting — included in managed bundles like Complete Managed Protection — turn an audit from a scramble into a formality.

Treat ransomware readiness as a governance issue, not just an IT one. Boards and owners should be asking for evidence of tested backups and incident plans.

Source: MSC Incorporation / Werksmans Attorneys