GOVERNANCE IN 60 SECONDS
The Information Regulator’s latest enforcement signals make data governance, cyber resilience and POPIA assurance immediate board-level concerns.
A Supreme Court of Appeal judgment reinforces that corporate confidentiality under the Companies Act is exceptional, not automatic.
An acting head has been appointed at IDAC while a permanent appointment process proceeds.
Infrastructure South Africa plans quarterly public progress updates on projects in its Construction Book.
UCT research is adding momentum to calls for a binding, rights-based framework for AI governance in South Africa.
Proposed beneficial-owner requirements remain open for comment and could create enhanced governing-body oversight obligations for financial institutions.
HUB ECOSYSTEM UPDATE
The Workplace Experience Mentorship Programme remains active for current Governance Practitioner (NQF 7) and Company Secretarial Route (NQF 8) cohorts. No further intakes are planned for the current cycle. Details on the next intake and upcoming development programmes will be announced through The Hub Briefing.
COMING UP
New development programmes coming soon.
Click here: The Hub Briefing Development Programmes
GOVERNANCE RADAR
Development | Key Update | Status |
|---|---|---|
Justice Minister Mmamoloko Kubayi appointed Advocate Ntuthuzelo Vanara as Acting Head of the Investigating Directorate Against Corruption while a permanent incumbent is appointed. | Interim appointment in effect; institutional independence, capacity and continuity remain matters to monitor. | |
Infrastructure South Africa has committed to quarterly progress updates on projects listed in its Construction Book, including whether projects are proceeding as intended. | New reporting commitment; public sector stakeholders should monitor whether reporting produces meaningful accountability. |
Further reading:
THE GOVERNANCE LENS
Information Regulator: Data Protection Is an Enterprise-Risk Issue
The Information Regulator has described the volume of security-compromise notifications in South Africa as alarming, reporting more than 8,000 data-breach notifications since its establishment and 1,220 reports since April 2026. It has also signalled stronger enforcement under POPIA and PAIA, including enforcement notices, fines and referrals to its Enforcement Committee.
The issue is not confined to technology teams. A breach can create operational disruption, regulatory exposure, litigation risk and loss of stakeholder trust.
The Governance Lens
Boards should receive regular reporting on data breaches, near misses, cyber controls and remediation.
Information officers need authority, resources and clear reporting access to senior management and the board.
Third-party data processors should be assessed through contracts, assurance evidence and incident-response obligations.
Incident-response plans should be tested, including decision-making, notification and stakeholder communications.
Data-protection performance should be integrated into risk, compliance and internal-audit planning.
Corporate Transparency: Confidentiality Must Be Exceptional
The Supreme Court of Appeal confirmed in GUD Holdings (Pty) Ltd v CIPC and Others that the Companies Act’s commitment to corporate transparency will not easily give way to commercial claims of confidentiality. The Court held that confidentiality under section 212 requires specific evidence and should be granted only in exceptional circumstances.
The judgment provides a timely reminder that commercial sensitivity alone is not enough to prevent disclosure where the Companies Act requires transparency.
The Governance Lens
Company secretaries should evaluate confidentiality claims against a documented legal basis, rather than commercial preference.
Boards should distinguish genuinely sensitive information from information that must be disclosed to support transparency and accountability.
Disclosure decisions should be recorded clearly, including the reasons for withholding information where permitted.
Governance policies should align Companies Act disclosure requirements with internal information-classification protocols.
Stakeholder trust is strengthened when organisations explain their disclosure decisions consistently and lawfully.
Further reading:
ITWeb (2026) InfoReg concerned by ‘alarming’ rate of data breaches.
GOVERNANCE INTELLIGENCE
Development | Key Update | Status |
|---|---|---|
South Africa’s AI governance debate is moving from a generic technology discussion to a concrete policy and governance issue. UCT research has added momentum to calls for a binding, constitutional and rights-based framework for AI regulation. | Current policy and governance issue; boards should monitor regulatory developments and strengthen oversight of AI use cases, data, accountability and assurance. | |
The FSCA and Prudential Authority have published a proposed beneficial-owner standard for financial institutions, with enhanced expectations for identifying, verifying, assessing and reporting beneficial owners. | Still current and actionable; boards, company secretaries and compliance functions should assess potential register, oversight and reporting impacts. |
Further reading:
GOVERNANCE RESOURCE DESK
What Happens if a Company Never Appoints a Public Officer?
Who is responsible for appointing a company’s public officer, when must it be done, and what happens when the appointment has been overlooked?
Our latest Governance Resource Desk article breaks down the South African requirements, the governance implications of non-compliance and the practical steps companies can take to regularise the position.
Need help putting it into practice?
The Governance Resource Desk supports organisations with practical governance implementation, including public officer appointments, board and governance documentation, statutory governance processes and related advisory support.
Resource coming soon: The Public Officer Appointment Pack will provide the core documents and practical guidance needed to manage the appointment process.
JOIN THE RESOURCE WAITLIST
Email: [email protected]
RESOURCE OF THE PERIOD
OECD AI Principles
The OECD AI Principles offer an internationally recognised framework for trustworthy AI, covering human rights, transparency, robustness, safety and accountability. Updated in 2024, the resource is useful for organisations beginning to formalise AI governance without waiting for local regulation to become binding.
Practical Benefit
Boards, company secretaries and risk teams can use the principles to test AI policies, assign accountability, strengthen risk registers and frame management reporting on AI use, ethics, privacy, security and stakeholder impact.
Resource:
Additional Resource

One Platform. One GRC Ecosystem.
If this edition was valuable, consider sharing it with a colleague working in governance, company secretarial, risk, compliance or the legal profession.
Until next time,
The Editorial Team
The Hub Briefing

