PAIA Enforcement Takes a Sharp Turn: Why the Information Regulator's Escalation to SAPS Signals More Than Procedural Non-Compliance

PAIA Enforcement Takes a Sharp Turn: Why the Information Regulator's Escalation to SAPS Signals More Than Procedural Non-Compliance

regulationcompliancegovernancedata

PAIA Enforcement Takes a Sharp Turn: Why the Information Regulator's Escalation to SAPS Signals More Than Procedural Non-Compliance

South Africa's access-to-information regime has entered a new phase. The Information Regulator (IR) has, for the first time on record, escalated several matters of alleged PAIA non-compliance to the South African Police Service for criminal investigation. This shift — involving entities ranging from state agencies to communal bodies — is more than an administrative development. It is a statement of intent: transparency obligations are no longer optional, and persistent non-compliance will now attract consequences that extend beyond corrective notices.

Yet the move also raises crucial questions about regulatory capacity, proportionality, and the broader culture of access to information. It presents an opportunity to reflect on the state of PAIA compliance, why the IR is adopting a firmer stance, and what this means for organisations, information officers, and the public.

A System Under Strain

Since assuming full responsibility for PAIA in 2021, the IR has repeatedly highlighted chronic non-compliance across both public and private bodies. The required Section 32 annual reporting remains under-submitted, many entities still fail to publish or update their PAIA manuals, and most recently, organisations have been criticised for continuing to use outdated request forms that were repealed with the 2021 regulations.

It is unsurprising, then, that the IR has shifted from guidance to enforcement. Its recent communication emphasises that the legally prescribed "Form 2" must be used for PAIA requests and that continued reliance on the old SAHRC-era "Form A" is now expressly treated as a breach of Regulation 7.1. This signals that even technical non-compliance is significant — because accuracy, standardisation, and procedural clarity underpin the effectiveness of access-to-information rights.

Criminal Liability Is No Longer Abstract

PAIA has always contained criminal provisions, but historically they were rarely invoked. Referral to SAPS indicates that the IR now sees criminal enforcement as essential for systemic change.

This raises the stakes for information officers in particular. Their personal accountability — including potential fines or imprisonment — introduces new pressure into a role already tasked with balancing confidentiality, operational demands and legal compliance. It also confronts public bodies with a reality they have traditionally been slow to engage: internal delays, ignored requests, or procedural lapses are no longer administrative irritations; they may now constitute criminal exposure.

For private entities, especially those with lean governance structures, the message is equally clear. Access-to-information obligations apply beyond large corporates and public institutions. Every private body, unless exempt, must maintain up-to-date manuals, handle requests lawfully, and follow the prescribed procedures.

Necessary Intervention or Regulatory Overreach?

The IR's intervention has been welcomed by civil society groups who view strong enforcement as essential to rebuilding South Africa's transparency ecosystem. Given the country's well-documented governance failures and corruption legacy, decisive action is arguably overdue.

However, reliance on criminal enforcement introduces complex challenges:

  • Overburdened enforcement infrastructure

SAPS is already stretched, with low detection and clearance rates across a wide range of criminal categories. It is unclear whether law-enforcement agencies possess the specialist capacity to address procedural access-to-information offences — which are technical, paper-heavy and often time-sensitive.

  • Risk of defensive bureaucracy

Strong enforcement should drive compliance — but it may also lead to highly conservative interpretations of PAIA. Entities may prefer to refuse requests rather than risk procedural faults in disclosure. This would undermine the very transparency PAIA seeks to promote.

  • Potential inequity in enforcement

There is a risk that smaller entities — without dedicated compliance teams — become easier enforcement targets, while large, powerful institutions with complex legal defences continue to evade meaningful accountability.

  • Criminalisation vs behavioural change

Sustainable compliance requires capability, not fear. Training, guidance, clarity and systems support matter as much as enforcement. An over-reliance on criminal sanctions could produce compliance "on paper" without improving the actual culture of disclosure.

A Tougher Regulator in a Tougher Environment

The escalation aligns with a broader regulatory trajectory. The IR's annual reports emphasise expanded enforcement activities, more compulsory compliance assessments, and growing use of subpoena and enforcement notices. It has also advocated for legislative amendments to strengthen PAIA's enforcement architecture and address growing digital-rights challenges.

This is occurring against a backdrop of increasing public impatience with institutional opacity — particularly around procurement, service delivery, and governance failures. In that sense, the IR's actions reflect not only regulatory assertiveness but societal demand.

Where Organisations Must Evolve

To avoid exposure — and more importantly, to foster a functioning transparency culture — organisations should shift from reactive compliance to proactive enablement. Key priorities include:

✓ Formalising information officer duties, with clear accountability and competent resourcing.

✓ Updating PAIA manuals and internal workflows, aligning them with 2021 regulations and emerging IR guidance.

✓ Embedding PAIA into operational practice, rather than treating it as a technical legal function.

✓ Training staff, particularly those in frontline or information-producing roles.

✓ Implementing systems for tracking, logging and responding to requests with evidentiary consistency.

PAIA compliance cannot be reduced to forms and technicalities; it must become part of an organisation's governance DNA

A Moment That Demands Attention — and Balance

The Information Regulator's decision to involve SAPS in PAIA enforcement is a powerful signal that the era of goodwill-based compliance has reached it's conclusion. This approach could significantly strengthen transparency if balanced with support, clarity and proportionate application.

But if criminalisation becomes the dominant tool, the risk is a compliance environment motivated by avoidance rather than accountability — defensive refusals, escalating appeals, and strained relationships with the public.

The challenge, therefore, is twofold: for the Regulator to enforce firmly yet fairly, and for organisations to stop treating access-to-information as an afterthought. PAIA is not a bureaucratic inconvenience; it is a constitutional mechanism for public trust.