Offences and penalties for failing to obtain prior authorisation when required
The prior authorisation requirements under the Protection of Personal Information Act (POPIA) are not merely procedural. Failure to comply constitutes a criminal offence and can also attract substantial administrative penalties. The Act sets out clear consequences for responsible parties that ignore or mishandle the obligation.
Understanding these consequences is essential. The categories of processing that require prior authorisation are already regarded as higher risk. The penalties attached to non-compliance reflect that assessment.
A responsible party that fails to notify the Information Regulator of processing that is subject to prior authorisation commits an offence. On conviction, the responsible party is liable to a fine or to imprisonment for a period not exceeding 12 months, or to both a fine and such imprisonment.
This applies where the organisation proceeds with one of the listed categories of processing — such as the secondary use of unique identifiers with linking, the processing of information on criminal or objectionable conduct on behalf of third parties, credit reporting, or the transfer of special personal information or children’s personal information to a country without adequate protection — without first submitting the required application.
Even where a responsible party has submitted a notification, it may not carry out the processing until the Regulator has completed its investigation or has confirmed that a more detailed investigation will not be conducted. Proceeding with the processing before that point is also an offence.
The same penalties apply: a fine or imprisonment for a period not exceeding 12 months, or both. This rule is designed to preserve the purpose of the prior authorisation mechanism. The Regulator must have an opportunity to examine the lawfulness of the processing before it begins.
If the Regulator investigates and issues a written statement concerning the lawfulness of the processing, the responsible party must comply with it. Failure to do so is a more serious offence. On conviction, the responsible party is liable to a fine or to imprisonment for a period not exceeding 10 years, or to both a fine and such imprisonment.
Where the Regulator finds the processing unlawful, it may also issue an enforcement notice requiring the responsible party to take specified steps, refrain from certain actions, or stop the processing altogether. Ignoring such a notice carries significant legal risk.
In addition to criminal liability, the Information Regulator may impose an administrative fine not exceeding R10 million on a responsible party alleged to have committed any of the offences related to prior authorisation. This provides the Regulator with a civil enforcement route that does not depend on a criminal prosecution.
These penalties apply to real and increasingly common forms of processing. Digital systems that reuse identifiers for secondary purposes, artificial intelligence tools that link data across sources, background screening and fraud prevention services, credit-related processing, and cross-border transfers of health or children’s data can all fall within the prior authorisation categories. Organisations that fail to identify these activities, or that treat the authorisation requirement as optional, expose themselves to material legal and financial risk.
From a governance perspective, the existence of these penalties reinforces the expectations associated with King V. Boards are required to oversee data and technology risks with appropriate accountability. Processing that carries the possibility of criminal liability or multi-million-rand administrative fines is, by definition, processing that requires careful oversight. Evidence that such activities have been identified, assessed and properly authorised supports the demonstration of that accountability.
The most effective way to manage these risks is preventive. Organisations need to map their processing activities against the four categories that trigger prior authorisation, conduct thorough Personal Information Impact Assessments where required, and submit applications in good time. Once an application has been submitted, the processing must remain suspended until the Regulator has completed its process.
Prior authorisation exists to protect data subjects from higher-risk forms of processing. The penalties attached to non-compliance exist to give that protection practical force. Organisations that treat the requirement with the seriousness the law intends are far better placed to avoid the significant consequences of getting it wrong.