Data Security & Breach Notification
Protection of Personal Information Act, 2013 — notification of security compromises
South Africa · July 1, 2020 (s. 22 commencement); enforcement from July 1, 2021
South Africa has no materiality threshold. Where there are reasonable grounds to believe that an unauthorised person has unlawfully accessed or acquired personal information, s. 22 requires notifying BOTH the Information Regulator and the affected data subjects — even a single record, and even where no harm is likely. That makes POPIA more reportable than almost every other regime in this dataset, and a business filtering incidents through a GDPR-style risk test will systematically under-report in South Africa. Notification must be as soon as reasonably possible after discovery, subject only to the legitimate needs of law enforcement or of determining the scope of the compromise and restoring system integrity — no fixed hour count. The Regulator publishes a prescribed form that must be used. Non-compliance with s. 22 is an interference with the protection of personal information under s. 73.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.