Most South African businesses have thought about how to prevent a breach. Far fewer have thought about the hours immediately after one — and that’s where POPIA bites. Section 22 of the Protection of Personal Information Act turns a security incident into a legal reporting obligation, and the clock starts the moment you have reasonable grounds to believe someone unauthorised has accessed personal information.
It doesn’t take a sophisticated attack to trigger it. A compromised mailbox, a laptop stolen from a car, a misdirected spreadsheet of client details, or a ransomware infection on the file server all count.
What POPIA calls a “security compromise”
The Act deliberately casts a wide net. If personal information you hold — about customers, employees, learners, suppliers — has been accessed or acquired by an unauthorised person, that is a security compromise. Two points catch businesses out:
- Suspicion is enough. The trigger is reasonable grounds to believe a compromise has occurred. You do not get to wait until you have proven it beyond doubt.
- There is no harm threshold in the text. Unlike some overseas regimes, POPIA does not exempt incidents simply because you judge the risk to individuals to be low. Assume it is reportable and work from there.
If you use an outsourced provider that processes information on your behalf — a payroll bureau, a cloud platform, an IT partner — they are an operator under POPIA and must notify you immediately when they become aware of a compromise. The obligation to report onward still sits with you.
The first hours: contain, then document
Before anyone drafts a notification, two things matter more than anything else.
Contain the incident. Isolate affected machines, force password resets, revoke active sessions and tokens, and pull the compromised mailbox or account out of reach. Resist the urge to wipe and rebuild immediately — you may destroy the evidence you need to work out what was actually taken.
Start an incident log. Record the time you became aware, who was told, what you did, and when. This log is what demonstrates that you acted reasonably, and it becomes the backbone of your notification. Reconstructing it from memory two weeks later is a miserable exercise with no upside.
Notifying the Information Regulator
POPIA requires notification to the Regulator as soon as reasonably possible after discovery. It does not name a fixed number of hours, but “we were busy” is not a defence — the only recognised reasons for delay are the legitimate needs of law enforcement, or the time genuinely needed to determine the scope of the compromise and restore your systems.
The Regulator has published a prescribed Security Compromise Notification Form for this purpose, and using it matters: notifications submitted in another format risk being treated as non-compliant. The form asks for the responsible party and information officer details, the date of the incident and the date of reporting, an explanation for any delay, the nature of the compromise, the number of people affected, and how you intend to notify them. Download the current version directly from the Information Regulator’s website when you need it, rather than relying on a copy saved months ago.
Notifying the people affected
The second obligation is the one businesses dread, and the one that most determines whether you keep your customers. Notification to affected individuals must be in writing, and POPIA accepts delivery by post, email, or a prominent notice on your website, among other routes.
The notice must contain enough detail for someone to actually protect themselves. In practice that means:
- A plain description of what happened and what information was involved.
- The possible consequences for them.
- What you have done and are doing in response.
- Specific recommended actions — change these passwords, watch for these scam calls, verify banking details by phone before paying.
- The identity of the responsible party, if you know it.
You may only hold back notification to individuals where a public body or the Regulator determines that telling them would impede a criminal investigation. That decision is not yours to make unilaterally.
Why silence is the expensive option
POPIA carries administrative fines running into millions of rand, alongside civil claims from affected data subjects. But in most real incidents the regulatory penalty is not the biggest number on the page. The larger costs are downtime, the follow-on fraud that lands on your clients while nobody knew to be careful, and the reputational damage of a breach that surfaces through rumour rather than through you.
Businesses that notify quickly and clearly are routinely forgiven. Businesses that quietly hoped it would go away are not.
Getting ready before it happens
- Appoint and register your information officer. By default this is the CEO, owner or equivalent — and registration with the Regulator is a legal requirement, not an optional extra.
- Write a one-page incident response plan. Who is called first, who can authorise shutting systems down, who talks to clients, who completes the form. One page that people actually read beats a policy nobody opens.
- Know what data you hold and where. You cannot report the scope of a breach if you have never mapped your own information.
- Keep audit logs and retain them. Mailbox and file-access logs are how you distinguish “a mailbox was accessed” from “these 3 000 client records were downloaded” — and the difference determines who you have to notify.
- Test your restores. Ransomware becomes a reportable disaster or a bad afternoon depending entirely on whether your backups work. The 3-2-1 backup rule is the place to start.
- Cut off the common entry point. The overwhelming majority of compromises we see begin with a credential harvested by email. Multi-factor authentication on every mailbox, and a team trained to recognise modern phishing, removes most of the risk.
We help South African businesses put the technical controls, logging and response plans in place that make a breach survivable — and manageable when it happens. This article is general guidance rather than legal advice; for a formal POPIA compliance opinion, speak to an attorney. If you’d like a practical assessment of where your business is exposed, get in touch.
