Skip to content
Close Menu
ConvictionConviction
  • Home
  • Law & Justice
  • Special Reports
  • Opinion
  • Ask The Expert
  • Get In Touch

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Farm for sale advert slammed for misleading jacuzzi, workshop and three-phase power claims

June 3, 2026

TVET college ordered to apologise for sharing personal information of employees

June 3, 2026

Judge calls for investigation into claims of body corporate capture in Maboneng

June 3, 2026
Facebook X (Twitter) Instagram
Trending
  • Farm for sale advert slammed for misleading jacuzzi, workshop and three-phase power claims
  • TVET college ordered to apologise for sharing personal information of employees
  • Judge calls for investigation into claims of body corporate capture in Maboneng
  • Company fails bid to escape contract clause buried in terms and conditions
  • Tribunal dismisses Bogdanov’s PhD defence, upholds 10-year JSE ban
  • South Africa cannot afford to lag while youth nicotine addiction escalates
  • Evicted Durban tenants win urgent court order pending eviction challenge
  • Pension fund withdrawal benefits are determined by rules, not contributions
Facebook X (Twitter) Instagram
ConvictionConviction
Sonneblom
  • Home
  • Law & Justice
  • Special Reports
  • Opinion
  • Ask The Expert
  • Get In Touch
ConvictionConviction
Home » TVET college ordered to apologise for sharing personal information of employees
Regulatory Law

TVET college ordered to apologise for sharing personal information of employees

Information Regulator finds Central Johannesburg TVET College breached multiple provisions of POPIA after employees' verification reports were circulated to unauthorised staff.
Kennedy MudzuliBy Kennedy MudzuliJune 3, 2026Updated:June 3, 2026No Comments
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Central Johannesburg TVET College has been ordered to apologise after employees' personal information was shared with unauthorised staff in breach of POPIA.
Share
Facebook Twitter LinkedIn Pinterest Email
  • Central Johannesburg TVET College unlawfully shared employees' personal information with staff who were not authorised to see it.
  • The Information Regulator told the college to apologise, inform the affected employees and improve how it follows POPIA rules.
  • If the college does not follow the Enforcement Notice, it could face criminal penalties such as a fine or even jail time.

Central Johannesburg TVET College has been ordered to apologise to employees after the Information Regulator found that it unlawfully shared personal information contained in employee verification reports with staff members who were not authorised to access the information.

The Enforcement Notice, issued on 22 May 2026, followed complaints by three employees whose personal information was disclosed during an internal governance process. The Regulator concluded that the college had breached several provisions of the Protection of Personal Information Act (POPIA), including requirements relating to accountability, further processing of information, security safeguards and the reporting of security compromises.

How the information was shared

The matter arose while the college was under administration and attempting to address governance concerns. Employees were required to declare interests and undergo verification of their qualifications and criminal records.

According to the findings, the personal information was collected through verification reports for the purpose of assessing employee qualifications and strengthening governance within the institution. However, the reports were later mistakenly included in a folder containing finance policies and distributed to various employees by email.

The Regulator found that the sharing of the reports amounted to further processing of personal information that was incompatible with the purpose for which the information had originally been collected.

The notice records that the administrator later recalled the email and informed employees that the documents had been distributed in error. Despite those efforts, the Regulator found that the disclosure had already occurred and that unauthorised employees had gained access to the information.

The Regulator found, "The sharing of these reports with other employees who were not involved in the strengthening of governance of the institution, albeit by mistake, was incompatible with the purpose for which the personal information in the Verification Reports was collected."

Accountability failures identified

The Regulator also found that the college had failed to register its Information Officer and deputy information officers as required by POPIA.

According to the notice, this failure demonstrated a lack of accountability and weakened the institution's ability to ensure compliance with data protection obligations.

The Regulator found, "The Responsible Party does not comply with the condition of accountability by failing to register the Information Officer with the Regulator and to designate deputy information officer(s) and register them with the Regulator."

The notice further concluded that the college had failed to implement adequate organisational measures to safeguard personal information. The fact that verification reports were stored together with unrelated policy documents contributed to the unlawful disclosure. The Regulator found, "The Responsible Party violated Section 19(1) of POPIA."

Failure to report the security compromise

A further finding related to the college's failure to notify both the Information Regulator and the affected employees after the security compromise occurred.

The Regulator found that once unauthorised employees gained access to the verification reports, the college became legally obliged to report the compromise. Although the college sent an internal email acknowledging the error and launched an investigation, it did not formally notify either the Regulator or the affected employees in the manner required by POPIA.

The notice records, "Neither the Regulator nor the complainants were informed of the security compromise."

The Regulator added that the internal communication and investigation did not remove the institution's legal obligations under the Act.

Orders issued against the college

The college has been directed to register its Information Officer and deputy information officers and provide proof of registration to the Regulator.

It must also notify the affected employees and the Regulator of the security compromise, submit a written apology to the complainants, circulate the apology to employees and publish it through its communication channels.

The Enforcement Notice further requires the college to take action against the employee responsible for unlawfully sharing the information, develop or submit a POPIA compliance framework and conduct awareness and training programmes for staff.

The Regulator warned that non-compliance with the Enforcement Notice constitutes an offence under POPIA.

The notice states that a responsible party that fails to comply with an Enforcement Notice is liable upon conviction to a fine, imprisonment for a period not exceeding 10 years, or both.

Conviction.co.za

Get your news on the go. Click here to follow the Conviction WhatsApp channel.

Central Johannesburg TVET College Data Protection Information Regulator POPIA Privacy law
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Kennedy Mudzuli

Multiple award-winner with passion for news and training young journalists. Founder and editor of Conviction.co.za

Related Posts

Farm for sale advert slammed for misleading jacuzzi, workshop and three-phase power claims

June 3, 2026

Tribunal dismisses Bogdanov’s PhD defence, upholds 10-year JSE ban

June 3, 2026

Pension fund withdrawal benefits are determined by rules, not contributions

June 2, 2026
Leave A Reply Cancel Reply

Prove your humanity: 6   +   2   =  

Subscribe to our newsletter:
Top Posts

Making sectional title rules that work: A practical guide

January 17, 2025

Protection order among the consequences of trespassing in an ‘Exclusive Use Area’

December 31, 2024

Between a rock and a foul-smelling place

November 27, 2024

Irregular levy increases, mismanagement, and legal threats in a sectional title scheme

June 2, 2025
Don't Miss
Regulatory Law
4 Mins Read

Farm for sale advert slammed for misleading jacuzzi, workshop and three-phase power claims

By Kennedy MudzuliJune 3, 20264 Mins Read

A Property24 farm listing was found to be misleading after claims about workshops, a jacuzzi and backup power could not be verified.

TVET college ordered to apologise for sharing personal information of employees

June 3, 2026

Judge calls for investigation into claims of body corporate capture in Maboneng

June 3, 2026

Company fails bid to escape contract clause buried in terms and conditions

June 3, 2026
Stay In Touch
  • Facebook
  • Twitter
  • WhatsApp
Demo
About Us
About Us

Helping South Africans to navigate the legal landscape; providing accessible legal information; and giving a voice to those seeking justice.

Facebook X (Twitter) YouTube WhatsApp Twitch RSS
Latest posts

Making sectional title rules that work: A practical guide

January 17, 2025

Protection order among the consequences of trespassing in an ‘Exclusive Use Area’

December 31, 2024

Between a rock and a foul-smelling place

November 27, 2024
OUR PICKS

R13,914 debt triggers sale of R380 000 home, transfer halted amid execution flaws

April 20, 2026

Understanding employee rights, workplace protections and grievance resolution in South Africa

June 8, 2025

Dead wife contradiction forces Nedbank to return repossessed Nissan Navara

May 29, 2026
© 2026 Conviction.
  • Home
  • Law & Justice
  • Special Reports
  • Opinion
  • Ask The Expert
  • Get In Touch

Type above and press Enter to search. Press Esc to cancel.

Powered by
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by