GG Notices

Abstract
The South African Information Regulator (IRSA) frequently issues Government Gazette (GG) notices, which serve as critical directives and guidance for legal professionals and organisations navigating the Protection of Personal Information Act (POPIA) and the Promotion of Access to Information Act (PAIA). These notices range from promulgating regulations and codes of conduct to issuing enforcement directives and inviting public comments on draft provisions. Recent developments, including amended POPIA regulations and landmark enforcement notices under PAIA, underscore the Regulator's increasingly proactive stance, necessitating continuous vigilance and proactive compliance measures from all responsible parties to avoid significant penalties and legal repercussions.
Introduction
The landscape of data privacy and access to information in South Africa is dynamically shaped by the pronouncements of the Information Regulator (IRSA). A key mechanism through which the Regulator communicates its directives, regulations, and interpretations is the Government Gazette (GG). These GG notices are not merely administrative formalities; they represent binding legal instruments and crucial guidance that demand immediate attention and action from legal professionals, compliance officers, and responsible parties across all sectors. Failure to monitor and respond to these notices can expose organisations to substantial administrative fines, reputational damage, and even criminal liability under the Protection of Personal Information Act 4 of 2013 (POPIA) and the Promotion of Access to Information Act 2 of 2000 (PAIA).
Background
The Information Regulator (South Africa) is an independent body established under Section 39 of POPIA, tasked with monitoring and enforcing compliance with both POPIA and PAIA. Its mandate extends to ensuring the protection of personal information processed by public and private bodies and upholding the constitutional right of access to information. To fulfil this dual mandate, the Regulator is empowered to issue various forms of notices, including regulations, codes of conduct, and enforcement notices, which are formally published in the Government Gazette. POPIA, which became fully enforceable on 1 July 2021, sets out eight conditions for the lawful processing of personal information, establishing minimum requirements for such processing. Similarly, PAIA gives effect to the constitutional right of access to information held by the state and, in certain circumstances, by private bodies. The legal framework empowers the Regulator to take necessary steps to perform its oversight function, including issuing enforcement notices for non-compliance.
Analysis
Recent GG notices from the Information Regulator highlight a significant shift towards more robust enforcement and structured compliance monitoring. A notable development is the gazetting of amended POPIA regulations on 17 April 2025, which immediately impact critical areas such as the correction or deletion of personal information, direct marketing through unsolicited electronic communications, and complaints procedures. These amendments necessitate a review of existing privacy policies, consent mechanisms, and internal complaints handling processes to ensure alignment with the updated regulatory requirements. Legal practitioners must advise clients to update their data subject request forms and direct marketing opt-out procedures accordingly. Furthermore, the Regulator has demonstrated its willingness to issue binding enforcement notices, as evidenced by the landmark decision against Sibanye-Stillwater on 22 May 2026 under PAIA. This notice compelled the mining company to disclose Social and Labour Plan compliance reports, rejecting arguments of commercial harm and emphasising the public interest in transparency, particularly in the mining sector. This case signals a tougher stance on PAIA compliance for private bodies, requiring them to provide factual evidence rather than mere conjecture when claiming exemptions. The Regulator has also issued enforcement notices under POPIA for data breaches and direct marketing violations, imposing a ZAR 5 million administrative fine on the Department of Justice and Constitutional Development for security lapses and directing FT Rams Consulting to cease unsolicited messages. These actions underscore the severe consequences of non-compliance, which can include administrative fines of up to ZAR 10 million, civil liability, or even imprisonment. Beyond enforcement, the Regulator continues to issue guidance notes on various aspects, such as the processing of special personal information, children's personal information, and direct marketing. While advisory, these notes provide valuable insight into the Regulator's interpretation of POPIA and should inform compliance strategies. Moreover, the Regulator has launched a proactive compliance monitoring exercise, requiring selected organisations to submit comprehensive POPIA compliance reports and supporting documentation within 14 business days. This initiative demands that organisations maintain meticulous records of their compliance measures, including privacy policies, risk registers, incident response plans, and proof of Information Officer registration and training.
Conclusion
The consistent issuance of Government Gazette notices by the Information Regulator serves as a clear indicator of its active role in shaping and enforcing data protection and access to information laws in South Africa. For legal practitioners, the imperative is clear: continuous monitoring of these notices is non-negotiable. The recent amended POPIA regulations and the robust enforcement actions under both POPIA and PAIA signal a heightened regulatory environment where proactive compliance, meticulous record-keeping, and a thorough understanding of the Regulator's expectations are paramount. Organisations must move beyond a tick-box approach to compliance, embedding data privacy and access principles into their operational DNA. Legal advisors should guide clients in conducting regular compliance audits, updating policies in line with new regulations and guidance, and preparing for potential compliance monitoring exercises or enforcement actions. The trend suggests that the Regulator will continue to intensify its oversight, making ongoing vigilance and adaptive compliance strategies essential for all responsible parties.
Citations
- 1.Protection of Personal Information Act 4 of 2013
- 2.Promotion of Access to Information Act 2 of 2000
- 3.GG 41105, GoN 709, 08 Sep 2017 – Protection of Personal Information Act, 2013 (Act. 4 of 2013): Invitation to comment on Draft Regulations relating to the Protection of Personal Information
- 4.GG 42110, RG 10897, GoN 1383, 14 Dec 2018 – Protection of Personal Information Act: Regulations: Information register (English / Afrikaans)
- 5.GG 44459, GeN 209, 16 Apr 2021 – Protection of Personal Information Act: Credit Bureau Association: Codes of Conduct
- 6.GG 53426, GoN 6673, 26 September 2025 – Protection of Personal Information Act 4 of 2013: Regulations relating to the processing of data subject's health or sex life by certain responsible parties
- 7.GG 54594, No. 7416, 30 April 2026: Notice in terms of section 61(2) of the Protection of Personal Information Act, No. 4 of 2013 (POPIA), on the own-initiative code of conduct of the Information Regulator on the processing of personal information at gated accesses in South Africa
- 8.Information Regulator (South Africa) website
- 9.Enforcement notice issued by the Information Regulator against Sibanye-Stillwater (22 May 2026)
- 10.SA Legal Academy: POPIA: amended regulations gazetted and in force (17 April 2025)
- 11.ITLawCo: Enforcement notices issued by South Africa's Information Regulator (November 04 2024)
- 12.Bowmans: South Africa: Information Regulator launches POPIA monitoring exercise
How does this affect your business?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.