The PAIA annual report submission window closed on 30 June 2026. If your organisation did not submit, you are not alone — the Information Regulator’s own figures show fewer than a third of public bodies submitted in the most recent reporting cycle, and private body compliance was lower still.
Low compliance rates are not the same as low enforcement risk. The Regulator’s 2025/2026 Annual Performance Plan signals a distinctly tougher posture under both PAIA and POPIA, and a missed submission is the first thing an inspector looks for.
What the Information Regulator does after the deadline
Unlike CIPC or the Compensation Fund, which apply an automatic financial penalty the moment a deadline passes, the Regulator’s process for a missed PAIA submission is not a fine. It is an investigation.
Step 1 — compliance assessment. The Regulator can start what it calls an own-initiative assessment against organisations that did not submit. No complaint from a member of the public is needed; its own records of who submitted are enough to trigger it.
Step 2 — inspection. An assessment can include a physical inspection of premises and a review of documents relating to your PAIA and POPIA compliance. Inspectors check whether your Information Officer is registered, whether your PAIA manual is current, whether you keep a section 17 register, and whether you have a working process for handling information requests.
Step 3 — enforcement notice. Where the assessment finds non-compliance, the Regulator issues an enforcement notice requiring you to put it right within a set period. This is the step that matters most: both R5 million POPIA fines issued to date were for failing to comply with an enforcement notice, not for the underlying breach.
Step 4 — penalties. Section 107 of POPIA provides for administrative fines, criminal prosecution, or both, for non-compliance with an enforcement notice, with a maximum administrative fine of R10 million. That provision sits in POPIA rather than PAIA, which matters less than it sounds — the two regimes are assessed together.
The POPIA compounding risk
This is the consequence most organisations underestimate. A missed PAIA report does not sit in isolation. It gives the Regulator a reason to look at your wider information-governance framework under POPIA.
The Regulator’s own language is that PAIA and POPIA are two sides of the same coin. An organisation that cannot show basic PAIA compliance — report submitted, Information Officer registered, manual current — invites the inference that its POPIA position is no better.
In sectors where client trust depends on data governance — financial services, healthcare, legal, accounting — the reputational side of a POPIA investigation lands harder than the fine.
What to do right now
Check that your Information Officer is registered. It is the prerequisite for everything else: you cannot submit a PAIA annual report at all unless your Information Officer is registered and linked to the organisation on the Regulator’s portal. Registration is free and takes under 30 minutes at inforegulator.bizportal.gov.za. Our Information Officer registration guide walks through it.
Understand that you probably cannot submit late. Unlike COIDA, where the portal accepts late Returns of Earnings year-round, the PAIA reporting window is fixed. The window for the 2025/2026 cycle — covering 1 April 2025 to 31 March 2026 — closed on 30 June 2026. The next opens on 1 April 2027 and closes on 30 June 2027, covering 1 April 2026 to 31 March 2027.
Start your request register now. Whether or not you can file for the closed cycle, you must keep an ongoing register of every information request received under PAIA: who asked, when, what for, how you responded, and the outcome. That register is the source document for the next report. Reconstructing a year of it in May is how reports end up wrong.
Bring your PAIA manual up to date. Every private body must have one, describing what records it holds, how to request access, and who to contact — and it must be publicly accessible, which for most businesses means on the website. Inspectors have been finding outdated manuals and, in particular, outdated request forms: the old Form A is no longer compliant, and requests must use a form corresponding to Form 2 under the 2021 PAIA Regulations.
Use the gap. There are months between now and 1 April 2027. An organisation that walks into an assessment with a registered Information Officer, a current manual and a maintained register has very little to remediate, even having missed a deadline.
Where this is heading
The Regulator is moving from reacting to complaints towards auditing proactively. Its 2025/2026 plan sets out an intention to pursue PAIA amendments that strengthen enforcement powers, to mandate use of the eServices portal for breach notifications, and to run its own audits rather than waiting to be told.
For anyone who missed the 2026 deadline, the useful response is not to hope it goes unnoticed. It is to get the foundations in place so that when an assessment does arrive, there is very little to find.
ClearComply tracks the PAIA and POPIA deadlines alongside your CIPC and COIDA ones, and sends reminders before each falls due. The work itself — Information Officer registration, a PAIA manual, the annual report — is done by a specialist firm we match you with; we do not file it ourselves. You can see where your company stands at CIPC at clearcomply.co.za/check, free and without signing up.
For what the PAIA annual report is and how it is submitted, see our PAIA annual report guide. For the year-round picture across both laws, see our PAIA and POPIA compliance guide.
Sources: Information Regulator of South Africa, 2025/2026 Annual Performance Plan, presented to the Parliamentary Portfolio Committee on 5 May 2026. Werksmans Attorneys commentary on the 2025/26 APP. Moonstone Information Refinery, “PAIA deadline opens as Regulator tightens oversight”, April 2026. Bowmans, “South Africa: PAIA reporting season is here”, April 2026. POPIA section 107 administrative penalty provisions.