Skip to content
Close Menu
ConvictionConviction
  • Home
  • Law & Justice
  • Special Reports
  • Opinion
  • Ask The Expert
  • Get In Touch

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Husband ordered to pay R106,211 monthly maintenance or face jail time

July 23, 2026

Lawyers face the music for poor court papers in asylum case, ordered to repay client

July 23, 2026

Two common mistakes can sink CSOS disputes before hearings begin

July 23, 2026
Facebook X (Twitter) Instagram
Trending
  • Husband ordered to pay R106,211 monthly maintenance or face jail time
  • Lawyers face the music for poor court papers in asylum case, ordered to repay client
  • Two common mistakes can sink CSOS disputes before hearings begin
  • Only one of four WhatsApp allegations against Harmony Gold found defamatory
  • Augmenting apartheid memory through art, exhibition and lived experience
  • Labour Court stops municipal disciplinary hearing over AI citation concerns
  • Court approves surrogacy where second wife carries child for first wife under customary law
  • Judge dismisses bid to suspend attorneys over R23 million dispute, citing unfair investigation
Facebook X (Twitter) Instagram
ConvictionConviction
Sonneblom
  • Home
  • Law & Justice
  • Special Reports
  • Opinion
  • Ask The Expert
  • Get In Touch
ConvictionConviction
Home » TVET college ordered to apologise for sharing personal information of employees
Regulatory Law

TVET college ordered to apologise for sharing personal information of employees

Information Regulator finds Central Johannesburg TVET College breached multiple provisions of POPIA after employees' verification reports were circulated to unauthorised staff.
Kennedy MudzuliBy Kennedy MudzuliJune 3, 2026Updated:June 3, 2026No Comments
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Central Johannesburg TVET College has been ordered to apologise after employees' personal information was shared with unauthorised staff in breach of POPIA.
Share
Facebook Twitter LinkedIn Pinterest Email
  • Central Johannesburg TVET College unlawfully shared employees' personal information with staff who were not authorised to see it.
  • The Information Regulator told the college to apologise, inform the affected employees and improve how it follows POPIA rules.
  • If the college does not follow the Enforcement Notice, it could face criminal penalties such as a fine or even jail time.

Central Johannesburg TVET College has been ordered to apologise to employees after the Information Regulator found that it unlawfully shared personal information contained in employee verification reports with staff members who were not authorised to access the information.

The Enforcement Notice, issued on 22 May 2026, followed complaints by three employees whose personal information was disclosed during an internal governance process. The Regulator concluded that the college had breached several provisions of the Protection of Personal Information Act (POPIA), including requirements relating to accountability, further processing of information, security safeguards and the reporting of security compromises.

How the information was shared

The matter arose while the college was under administration and attempting to address governance concerns. Employees were required to declare interests and undergo verification of their qualifications and criminal records.

According to the findings, the personal information was collected through verification reports for the purpose of assessing employee qualifications and strengthening governance within the institution. However, the reports were later mistakenly included in a folder containing finance policies and distributed to various employees by email.

The Regulator found that the sharing of the reports amounted to further processing of personal information that was incompatible with the purpose for which the information had originally been collected.

The notice records that the administrator later recalled the email and informed employees that the documents had been distributed in error. Despite those efforts, the Regulator found that the disclosure had already occurred and that unauthorised employees had gained access to the information.

The Regulator found, "The sharing of these reports with other employees who were not involved in the strengthening of governance of the institution, albeit by mistake, was incompatible with the purpose for which the personal information in the Verification Reports was collected."

Accountability failures identified

The Regulator also found that the college had failed to register its Information Officer and deputy information officers as required by POPIA.

According to the notice, this failure demonstrated a lack of accountability and weakened the institution's ability to ensure compliance with data protection obligations.

The Regulator found, "The Responsible Party does not comply with the condition of accountability by failing to register the Information Officer with the Regulator and to designate deputy information officer(s) and register them with the Regulator."

The notice further concluded that the college had failed to implement adequate organisational measures to safeguard personal information. The fact that verification reports were stored together with unrelated policy documents contributed to the unlawful disclosure. The Regulator found, "The Responsible Party violated Section 19(1) of POPIA."

Failure to report the security compromise

A further finding related to the college's failure to notify both the Information Regulator and the affected employees after the security compromise occurred.

The Regulator found that once unauthorised employees gained access to the verification reports, the college became legally obliged to report the compromise. Although the college sent an internal email acknowledging the error and launched an investigation, it did not formally notify either the Regulator or the affected employees in the manner required by POPIA.

The notice records, "Neither the Regulator nor the complainants were informed of the security compromise."

The Regulator added that the internal communication and investigation did not remove the institution's legal obligations under the Act.

Orders issued against the college

The college has been directed to register its Information Officer and deputy information officers and provide proof of registration to the Regulator.

It must also notify the affected employees and the Regulator of the security compromise, submit a written apology to the complainants, circulate the apology to employees and publish it through its communication channels.

The Enforcement Notice further requires the college to take action against the employee responsible for unlawfully sharing the information, develop or submit a POPIA compliance framework and conduct awareness and training programmes for staff.

The Regulator warned that non-compliance with the Enforcement Notice constitutes an offence under POPIA.

The notice states that a responsible party that fails to comply with an Enforcement Notice is liable upon conviction to a fine, imprisonment for a period not exceeding 10 years, or both.

Conviction.co.za

Get your news on the go. Click here to follow the Conviction WhatsApp channel.

Central Johannesburg TVET College Data Protection Information Regulator POPIA Privacy law
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Kennedy Mudzuli

Multiple award-winner with passion for news and training young journalists. Founder and editor of Conviction.co.za

Related Posts

Judge dismisses bid to suspend attorneys over R23 million dispute, citing unfair investigation

July 22, 2026

A decade of income protection payments declared an error despite earlier promises

July 22, 2026

LPC rejects Teffo reinstatement rumours as charge sheet suggests acquittal on all six charges

July 21, 2026
Leave A Reply Cancel Reply

Prove your humanity: 0   +   1   =  

Subscribe to our newsletter:
Top Posts

Making sectional title rules that work: A practical guide

January 17, 2025

Protection order among the consequences of trespassing in an ‘Exclusive Use Area’

December 31, 2024

Between a rock and a foul-smelling place

November 27, 2024

Irregular levy increases, mismanagement, and legal threats in a sectional title scheme

June 2, 2025
Don't Miss
Family Law
4 Mins Read

Husband ordered to pay R106,211 monthly maintenance or face jail time

By Kennedy MudzuliJuly 23, 20264 Mins Read

The High Court in Durban ruled that a husband who reduced his court-ordered maintenance payments without approval must pay the full amount or face a suspended 60-day prison sentence.

Lawyers face the music for poor court papers in asylum case, ordered to repay client

July 23, 2026

Two common mistakes can sink CSOS disputes before hearings begin

July 23, 2026

Only one of four WhatsApp allegations against Harmony Gold found defamatory

July 23, 2026
Stay In Touch
  • Facebook
  • Twitter
  • WhatsApp
Demo
About Us
About Us

Helping South Africans to navigate the legal landscape; providing accessible legal information; and giving a voice to those seeking justice.

Facebook X (Twitter) YouTube WhatsApp Twitch RSS
Latest posts

Making sectional title rules that work: A practical guide

January 17, 2025

Protection order among the consequences of trespassing in an ‘Exclusive Use Area’

December 31, 2024

Between a rock and a foul-smelling place

November 27, 2024
OUR PICKS

Judge dismisses bid to suspend attorneys over R23 million dispute, citing unfair investigation

July 22, 2026

Wedding rehearsal or workplace protest? Judge rules in favour of singing mineworkers

July 21, 2026

Mpumalanga records highest initiation death toll, prompting CRL Rights Commission inquiry

July 21, 2026
© 2026 Conviction.
  • Home
  • Law & Justice
  • Special Reports
  • Opinion
  • Ask The Expert
  • Get In Touch

Type above and press Enter to search. Press Esc to cancel.

Powered by
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by