POPIA enforcement in 2025: what has changed and what it means for your business
The April 2025 amendments to the POPIA Regulations materially changed three things: the obligations of Information Officers, the process for reporting security breaches, and the mechanism for paying administrative fines. Together, they signal a shift from a compliance-on-paper regime to one with genuine operational teeth.[1]
The three key changes from April 2025
1. Information Officer obligations expanded
The amendments substantially expanded what Information Officers must do. The IO role is no longer a paper appointment (it defaulted to the CEO before any active steps were taken). The April 2025 amendments require active, ongoing oversight of a compliance framework that must be "continuously improved." IOs are now explicitly responsible for ensuring that the organisation's PAIA manual is kept current, that data subject requests are handled within the 30-day window, and that the compliance programme is documented and auditable.[2]
2. Breach reporting now requires the eServices portal
Section 22 of POPIA has always required breach notification to both the Information Regulator and affected data subjects. The April 2025 amendments specify that all security compromise reports must be submitted via the Regulator's eServices portal (launched April 2025). Paper-based or email-based notification is no longer sufficient. Organisations without portal access and an established breach response procedure are now directly non-compliant with the amended regulation.
3. Administrative fine instalments
Fines of up to R10 million per infringement remain unchanged in maximum amount. The amendment introduced the ability to pay administrative fines in instalments - a practical accommodation, not a reduction in exposure. The Regulator retains full discretion on penalty quantum.[3]
The enforcement track record: 2024 into 2025
The Information Regulator issued its first enforcement notice in February 2024 - a direct marketing violation. Through 2024, the Regulator completed over 30 compliance assessments, including assessments targeting specific sectors. Its 2025/2026 annual plan lists enforcement as a top priority, with a stated intention to increase the volume of compliance assessments and the proportion resulting in formal action.[4]
Immediate action checklist
- Register your Information Officer on the eServices portal if not already done
- Obtain eServices portal access for breach reporting
- Write and test a breach response procedure that ends with portal submission
- Review your IO's documented responsibilities - the April 2025 scope is broader than most job descriptions
- Audit data subject request handling: responses must be within 30 days
- Check direct marketing consent records - opt-in only, opt-out removes consent permanently
Frequently asked questions
What triggers an Information Regulator investigation?
Investigations are triggered by complaints from data subjects, referrals, and proactive compliance assessments chosen by the Regulator. A data subject complaint about unsolicited marketing or a failure to respond to an access request within 30 days is a common trigger.
Can I appeal a fine?
Administrative fines can be contested through the Regulator's process and subsequently through the courts. The April 2025 instalment provision applies during the enforcement process, not as a substitute for it.