What a POPIA penalty actually is
"R10 million fine" gets repeated so often it's treated as a flat penalty every violation triggers. It isn't. Two separate provisions get conflated. Section 109(2)(c) caps an administrative fine at R10 million per infringement notice - a ceiling, not a default. Section 107 is the distinct criminal provision, carrying up to 10 years' imprisonment for the most serious offences, such as failing to comply with an enforcement notice. The two are mutually exclusive: the Regulator may not impose an administrative fine where the responsible party has been criminally charged on the same facts, and no prosecution may follow once such a fine has been paid. In practice every fine issued to date has followed an ignored enforcement notice, with amounts ranging from R100,000 to R5 million - the largest being R5 million against the Department of Justice and R5 million against the Department of Basic Education. The amount reflects the severity, duration, and response to the specific breach.[1]
How enforcement actually reaches a fine
Enforcement rarely starts with a fine. It typically follows this sequence: a complaint or the Regulator's own investigation, an assessment, an enforcement notice requiring specific remedial steps within a set period, and - only if the notice is ignored or the non-compliance is severe - an administrative fine or referral for prosecution. Businesses that respond to an enforcement notice and remediate promptly rarely escalate to the fine stage.[2]
What actually triggers Regulator attention
| Trigger | Why it escalates |
|---|---|
| Unreported data breach | Failure to notify via the eServices portal is itself a separate contravention |
| No Information Officer registered | A baseline, checkable compliance failure - easy for the Regulator to identify |
| Repeated or public complaints | Pattern of non-compliance weighs against the responsible party |
| No remedial action after a notice | Escalates from notice to fine stage |
| Processing without a lawful basis | Core contravention of ss. 9–12 - the conditions for lawful processing |
What changed in April 2025
The 2025 amendments expanded Information Officer obligations, made eServices portal breach reporting mandatory rather than optional, and introduced instalment payment options for administrative fines - a signal the Regulator expects fines to become a more routinely used enforcement tool, not a rare last resort.[1]
Frequently asked questions
Can a small business actually be fined R10 million?
The ceiling applies regardless of business size - POPIA has no small-business exemption. In practice, fine amounts scale with the severity and scope of the contravention, but the exposure is real for any business holding personal information, not just large enterprises.[3]
Does fixing the issue after a complaint help?
Yes. Prompt, documented remediation in response to an enforcement notice is the strongest mitigating factor available. Ignoring a notice is what typically moves a case from "notice" to "fine."