On 1 September the Information Regulator confirmed active POPIA investigations into Standard Bank, Pick n Pay, Land Bank, the National Credit Regulator, Truecaller and the Gauteng Department of e-Government. The IEC and Lancet Laboratories have each paid administrative fines. A municipal fine of half a million rand was reduced by a court to two hundred and fifty thousand.
Read the list again. That is a cadence, not a warning shot.
For most of POPIA's life boards have treated it as a paperwork exercise. Sign the operator agreement, tick the impact assessment, file the breach notification within the window. The Regulator has now shifted from guidance to enforcement, and the names it is willing to say out loud are the biggest banks, retailers and public bodies in the country. That changes the risk calculus for every board that has outsourced a core process to a third party and assumed the contract would carry the exposure.
It will not. POPIA fines land on the responsible party first. The supplier's failure becomes your headline.
The contract was never the control
The comfortable fiction of the last decade was that vendor risk could be transferred through legal language. Indemnities, liability caps, right-to-audit clauses, ISO attestations attached as annexures. Procurement teams built spreadsheets of these clauses and called the spreadsheet a programme.
None of that stops a breach at a payroll bureau, a call centre, a data analytics partner or a cloud-hosted HR platform. And none of it stops the Regulator naming you as the responsible party when the records that leaked were about your customers, your employees or your pensioners.
The Pick n Pay and Standard Bank investigations have not concluded. What matters is that they are open, they are named, and the Regulator is prepared to say so publicly at a briefing. That is the reputational exposure boards should be modelling now, not after the finding lands.
Micro, meso, macro
At the micro level the question is unglamorous but urgent. Which supplier contracts actually specify encryption at rest, breach notification timelines that match POPIA's requirement to notify as soon as reasonably possible after discovery of a compromise, and evidence obligations that survive the supplier going quiet? Most South African enterprise contract libraries were written before the Regulator started naming firms. They need a line-by-line review, not a template refresh.
At the meso level the shift is from annual vendor questionnaires to continuous monitoring. A supplier that passed a due diligence review in March can be compromised in September and the enterprise will not know until customers do. Third-party risk platforms that rate supplier attack surfaces continuously, and quantify the financial exposure of each relationship, are no longer a nice-to-have. They are how a CISO answers the board question that is coming: which of our suppliers would survive being named next?
At the macro level the Regulator is establishing a fine cadence. Two hundred and fifty thousand rand from a municipality via a court. One hundred thousand rand each from the IEC and Lancet. These figures are small relative to the maximum POPIA allows, but the trajectory matters more than the amount. Enforcement bodies build muscle case by case, and early fines in a new regime tend to sit well below the ceiling the statute permits.
What boards should ask this quarter
Three questions belong on the next risk committee agenda.
First, which of our top twenty suppliers hold personal information of our customers or staff, and when did we last see evidence, not assurance, of their security posture? Assurance is a signed form. Evidence is a current external assessment of their attack surface, patch discipline and breach history.
Second, if the Regulator opened an investigation into us tomorrow because of a supplier breach, what would our incident response file look like? Contract, DPIA, monitoring logs, notification workflow. If any of those are missing or stale, that gap is the finding.
Third, who owns third-party cyber risk in this organisation. Not procurement, not legal, not the CISO alone. If the answer is unclear, the answer is nobody.
The stance
Vendor risk transfer through contracts is over. The Regulator has said so with its choice of investigation targets, and the fines already paid confirm the direction of travel. Boards that continue to treat POPIA as a compliance exercise administered by legal will be the ones explaining to customers why their data left through a supplier they had never independently assessed.
Detection is not protection. Containment is. And containment starts at the edge of your supplier estate, not the edge of your own network.

