The Information Regulator recently marked ten years since establishment, and five since they began enforcement. The latest briefing from Adv. Pansy Tlakula, held 31 August 2026, provides some important compliance lessons for community schemes, its trustees and directors, and managing agents. Throughout this session I kept wondering how much of this compliance lands squarely in our world in terms of the personal information we handle daily. 

The Regulator confirmed that to date they have received over 8 000 reported security compromises, with more than 1 500 since April alone. Should this trend hold, the Regulator is projecting over 3 000 breaches by year-end. 

What are some of the known causes for security compromises?  

These should be familiar to anyone running a community scheme office: 

  • weak passwords, 
  • human error, 
  • phishing, and 
  • old/out-dated infrastructure.

The Regulator highlighted a specific matter following a 2024 ransomware attack on data held by South African Police Service (“SAPS”). Here SAPS was found guilty of excessive processing, weak consent practices, poor security safeguards, and failing to report the breach and/or tell the people affected. SAPS now has 90 days, from receiving the notice, to fix its policies, run proper impact assessments, and put real safeguards in place. 

I know what you thinking, (1) this is a public-sector case, it doesnt affect me (2) if SAPS cant get it right, how can we be expected to, and (3) when the Regulator has these big breaches to deal with why would they be worrying about my small scheme. 

While these questions are valid, the takeaway lesson should be that date breaches and investigations from the Information Regulator are not sector-specific. If a national policing agency can be found short on the basics, a scheme running its records off a shared spreadsheet and an old server is not exempt from the same scrutiny.

It goes without saying that every community scheme holds personal information and in terms of the Protection of Personal Information Act 4 of 2013 (“POPIA”), trustees and managing agents are automatically deemed a “responsible party”, whether they signed up for the additional duty or not. 

Some examples of personal information a scheme and is managing agent has access to: 

  • Owner details
  • Tenant records
  • ID numbers
  • Banking details of the scheme
  • Banking details of the member, and  
  • Visitor logs. 

What’s relevant in terms of a community scheme?

  1. Direct marketing and unsolicited communications About 10% of the complaints received last year were related to unsolicited marketing. If you as a trustee, managing agent and/or even an owner in the scheme sends marketing-style communication which is beyond ordinary scheme business, without consent,  that process is definitely worth a review.
  2. PAIA Compliance and information requests Remember that owners in a sectional title scheme are automatically granted permission to access certain information in terms of the Sectional Titles Schemes Management Act 8 of 2011. POPIA does still apply to these requests, and a body corporate cannot ask for PAIA to be followed. It’s worth noting that the Regulator is now treating failure to respond to information requests. Again a process that deserves a review when it comes to your scheme.  

In practical terms, the Information Regulator’s latest briefing means that trustees and managing agents should review how their community scheme collects, stores, accesses and protects personal information.

5 tips to ensure that trustees and managing agents are POPIA compliant

  1. Know what personal information the community scheme holds, and where it lives. Owner and tenant registers, visitor logs, financial records, correspondence. If you can’t list it, you can’t protect it.
  2. Check the basics before anything fancier. Passwords, access controls, who can see what. Most of the incidents the regulator is dealing with started with something ordinary, not something exotic.
  3. Have processes in place in order to deal with requests to access information of the members.
  4. Have an actual plan for what happens if something goes wrong. POPIA requires you to notify the Regulator and affected data subjects when there’s a breach. Waiting to figure that out after the fact is how a bad day becomes a legal problem.
  5. Treat compliance as more than a box to tick. The regulator said this outright in the briefing: they want to see a culture of compliance, not paperwork produced to look the part.

Conclusion | Compliance starts with awareness  

None of this needs to be alarming for community schemes. It does however need to be taken seriously, and someone in the scheme needs to actually own POPIA compliance. While most schemes are somewhat compliant, it’s always advisable to review the relevant manuals, records and/or processes and in the event that your scheme is not yet compliant at all, now would be a sensible time to start.

Frequently asked questions about POPIA and community schemes

  • Does POPIA apply to body corporates?
    Yes. Body corporates and other community schemes process personal information and therefore need to comply with POPIA where applicable.
  • What personal information does a community scheme typically hold?
    This can include owner and tenant details, ID numbers, contact information, financial information, visitor records and correspondence.
  • What should a scheme do if personal information is compromised?
    A scheme should have an incident-response process and assess its notification obligations to the Information Regulator and affected data subjects. 
  • Are trustees responsible for POPIA compliance?
    Trustees, alongside the body corporate and managing agent, play an important governance role in ensuring that the body corporate has appropriate processes and safeguards in place.
  • Must each scheme develop its own POPIA manual?
    Yes, it will be adopted by the body corporate at an Annual or Special General Meeting, setting out conditions for accessing and dissemination of information. That’s become a practical requirement, not optional.

Contact us today on 061 536 3138 or at info@tvdmconsultants.com if you have any questions on the above.

Watch the full media briefing here: The Information Regulator briefs members of the media on key POPIA and PAIA matters

The Information Regulator recently marked ten years since establishment, and five since they began enforcement. The latest briefing from Adv. Pansy Tlakula, held 31 August 2026, provides some important compliance lessons for community schemes, its trustees and directors, and managing agents. Throughout this session I kept wondering how much of this compliance lands squarely in our world in terms of the personal information we handle daily. 

The Regulator confirmed that to date they have received over 8 000 reported security compromises, with more than 1 500 since April alone. Should this trend hold, the Regulator is projecting over 3 000 breaches by year-end. 

What are some of the known causes for security compromises?  

These should be familiar to anyone running a community scheme office: 

  • weak passwords, 
  • human error, 
  • phishing, and 
  • old/out-dated infrastructure.

The Regulator highlighted a specific matter following a 2024 ransomware attack on data held by South African Police Service (“SAPS”). Here SAPS was found guilty of excessive processing, weak consent practices, poor security safeguards, and failing to report the breach and/or tell the people affected. SAPS now has 90 days, from receiving the notice, to fix its policies, run proper impact assessments, and put real safeguards in place. 

I know what you thinking, (1) this is a public-sector case, it doesnt affect me (2) if SAPS cant get it right, how can we be expected to, and (3) when the Regulator has these big breaches to deal with why would they be worrying about my small scheme. 

While these questions are valid, the takeaway lesson should be that date breaches and investigations from the Information Regulator are not sector-specific. If a national policing agency can be found short on the basics, a scheme running its records off a shared spreadsheet and an old server is not exempt from the same scrutiny.

It goes without saying that every community scheme holds personal information and in terms of the Protection of Personal Information Act 4 of 2013 (“POPIA”), trustees and managing agents are automatically deemed a “responsible party”, whether they signed up for the additional duty or not. 

Some examples of personal information a scheme and is managing agent has access to: 

  • Owner details
  • Tenant records
  • ID numbers
  • Banking details of the scheme
  • Banking details of the member, and  
  • Visitor logs. 

What’s relevant in terms of a community scheme?

  1. Direct marketing and unsolicited communications About 10% of the complaints received last year were related to unsolicited marketing. If you as a trustee, managing agent and/or even an owner in the scheme sends marketing-style communication which is beyond ordinary scheme business, without consent,  that process is definitely worth a review.
  2. PAIA Compliance and information requests Remember that owners in a sectional title scheme are automatically granted permission to access certain information in terms of the Sectional Titles Schemes Management Act 8 of 2011. POPIA does still apply to these requests, and a body corporate cannot ask for PAIA to be followed. It’s worth noting that the Regulator is now treating failure to respond to information requests. Again a process that deserves a review when it comes to your scheme.  

In practical terms, the Information Regulator’s latest briefing means that trustees and managing agents should review how their community scheme collects, stores, accesses and protects personal information.

5 tips to ensure that trustees and managing agents are POPIA compliant

  1. Know what personal information the community scheme holds, and where it lives. Owner and tenant registers, visitor logs, financial records, correspondence. If you can’t list it, you can’t protect it.
  2. Check the basics before anything fancier. Passwords, access controls, who can see what. Most of the incidents the regulator is dealing with started with something ordinary, not something exotic.
  3. Have processes in place in order to deal with requests to access information of the members.
  4. Have an actual plan for what happens if something goes wrong. POPIA requires you to notify the Regulator and affected data subjects when there’s a breach. Waiting to figure that out after the fact is how a bad day becomes a legal problem.
  5. Treat compliance as more than a box to tick. The regulator said this outright in the briefing: they want to see a culture of compliance, not paperwork produced to look the part.

Conclusion | Compliance starts with awareness  

None of this needs to be alarming for community schemes. It does however need to be taken seriously, and someone in the scheme needs to actually own POPIA compliance. While most schemes are somewhat compliant, it’s always advisable to review the relevant manuals, records and/or processes and in the event that your scheme is not yet compliant at all, now would be a sensible time to start.

Frequently asked questions about POPIA and community schemes

  • Does POPIA apply to body corporates?
    Yes. Body corporates and other community schemes process personal information and therefore need to comply with POPIA where applicable.
  • What personal information does a community scheme typically hold?
    This can include owner and tenant details, ID numbers, contact information, financial information, visitor records and correspondence.
  • What should a scheme do if personal information is compromised?
    A scheme should have an incident-response process and assess its notification obligations to the Information Regulator and affected data subjects. 
  • Are trustees responsible for POPIA compliance?
    Trustees, alongside the body corporate and managing agent, play an important governance role in ensuring that the body corporate has appropriate processes and safeguards in place.
  • Must each scheme develop its own POPIA manual?
    Yes, it will be adopted by the body corporate at an Annual or Special General Meeting, setting out conditions for accessing and dissemination of information. That’s become a practical requirement, not optional.

Contact us today on 061 536 3138 or at info@tvdmconsultants.com if you have any questions on the above.

Watch the full media briefing here: The Information Regulator briefs members of the media on key POPIA and PAIA matters

STC_wsi
Author: STC_wsi

No thanks

©2018 Created and Maintained by WSI

CONTACT US

Get in touch! Send us an email and we'll get back to you, asap.

Sending

Log in with your credentials

Forgot your details?