A POPIA security compromise notification is the formal alert your business must send to the Information Regulator and to affected individuals whenever personal information may have been accessed or acquired without authorisation — and, unlike Europe's GDPR, South African law sets no minimum size threshold before that obligation kicks in.

Whether you run a simple business website collecting enquiry-form data or a database with thousands of customer records, a qualifying incident triggers the same legal duties under Section 22 of the Protection of Personal Information Act. Getting the process wrong — including missing the mandatory eServices portal introduced in 2025 — can result in fines, enforcement notices, and personal liability for your Information Officer.

South Africa's Information Regulator received 2,374 security compromise notifications in the 2024/25 financial year, averaging 284 a month, with a 40% year-on-year increase in the early months of 2025/26. That volume reflects enforcement maturity: the Regulator is no longer waiting for organisations to self-correct.

Understanding website and data compliance obligations in full is the starting point; this guide covers the POPIA breach notification requirements specifically — what goes where, in what form, and with what content.

Quick Answer

A POPIA security compromise notification is a mandatory report submitted to South Africa's Information Regulator via the eServices portal (eservices.inforegulator.org.za) and a separate written notice sent to every affected data subject. It must be filed as soon as reasonably possible after discovery — no minimum-size threshold applies, and there is no 72-hour window equivalent to GDPR. The notification to data subjects must include the consequences of the breach, the measures you are taking, recommended protective steps, and a contact point for questions.

Is your website handling breach response correctly?

Send us your current incident response setup and we will show you exactly where the gaps are before the Regulator finds them for you.

Get a Free Compliance Review

What Qualifies as a Data Breach Under South African Law?

A "security compromise" under POPIA is any event that results in the unauthorised access to, or acquisition, use, loss, damage, or destruction of personal information held by your organisation. The definition is deliberately broad: it covers a hacked website, a staff member emailing a customer list to the wrong address, a stolen laptop containing unencrypted records, an unauthorised database export, or a third-party supplier's system being breached where your customer data was stored.

Personal information itself is equally broad — it includes names, ID numbers, contact details, financial records, biometric data, health information, and any other information that can identify a living person. If your website collects booking forms, contact details, or payment references, and those records are accessed by an unauthorised party, that qualifies.

Common triggers for SA businesses:
  • WordPress or WooCommerce site compromised through an unpatched plugin
  • Shared hosting account hacked, exposing multiple clients' data
  • Staff forwarding client spreadsheets to personal email addresses
  • CRM or email marketing platform credentials exposed in a phishing attack
  • Third-party payment processor or API suffering a breach while holding your customers' data

If your business uses an operator (a third-party service provider that processes personal information on your behalf), Section 21(2) of POPIA requires that operator to notify you immediately upon discovering a compromise. Your obligation to notify the Regulator and data subjects is then triggered from the point you become aware, not the point your operator becomes aware. Building that requirement into supplier contracts is a preparedness step, not an optional extra.

The No-Threshold Reporting Rule Every Responsible Party Must Know

South Africa's Information Regulator is explicit: POPIA contains no minimum severity threshold for reporting security compromises. Every qualifying breach — regardless of the number of records affected, the sensitivity of the data, or the perceived risk to individuals — must be reported to the Regulator and to the affected data subjects.

Key Point

There is no "small breach" exemption in POPIA. If one unauthorised person accessed the personal details of even a single data subject, the Section 22 notification obligation applies. This is a materially different position from the EU's GDPR, which allows organisations to assess risk before deciding whether to notify regulators.

The timing standard is "as soon as reasonably possible after the discovery of the compromise." The security compromise notification South Africa framework does not impose a 72-hour window equivalent to the GDPR. What it does require is that you do not wait for a forensic investigation to conclude before filing — you report on what you know and update the notification as further details emerge.

The only permitted delays are a documented law enforcement need (where notification might compromise a criminal investigation) or the time strictly necessary to determine the scope of the breach and restore system integrity.

Discovery timing matters practically. The Information Regulator's own guidance states notification should occur "as soon as it is reasonably sure that a security compromise has occurred" — meaning once you have reasonable grounds to conclude unauthorised access took place, not only after your IT team formally declares a confirmed breach. Website uptime and security monitoring that detects anomalies quickly is therefore also a compliance tool, not just an operational one.

How to Submit a POPIA Security Compromise Notification to the Information Regulator

From 1 April 2025, all security compromise notifications to the Information Regulator must be submitted through the official eServices portal — filing by email or using the old PDF Form SCN1 is no longer the accepted primary method. Organisations that have not yet registered portal access should do so before they need it: an incident is the wrong time to troubleshoot login credentials.

The notification form is structured in five parts:

Form PartWhat It Covers
Part AResponsible party details (your organisation's registered name, address, sector)
Part BInformation Officer details — name, contact, registration number with the Regulator
Part CSecurity compromise specifics: what happened, when, how many data subjects affected, categories of personal information involved, identity of the unauthorised party if known
Part DMeasures taken or intended: containment steps, systems restored, remedial actions planned
Part EDeclaration of accuracy by the Information Officer or authorised signatory

A registered Information Officer must submit the Section 22 POPIA notification. If your business has not yet registered its Information Officer with the Information Regulator, that registration step is itself a compliance obligation — and its absence will be noted in any enforcement review. The Regulator uses the notification data to monitor trends, direct further investigation, and issue compliance notices where remediation is insufficient.

Preparation Steps — Before a Breach Occurs

Register portal access at eservices.inforegulator.org.za and keep credentials current. Name your Information Officer and a deputy with after-hours contacts. Include a clause in all supplier contracts requiring operators to notify you immediately of any compromise. Draft a data-subject notification template in plain language before you need it under pressure.

What Affected Data Subjects Must Be Told

The data subject notification under Section 22 must give people enough information to take meaningful protective action — it is not a legal document for your file, it is a practical alert written for the person whose information was exposed.

Section 22(5) sets out the minimum content. The table below maps the statutory requirement to what that means in practice:

What the law requiresWhat to actually write
Description of the possible consequences of the compromisePlain-language explanation of what could happen: identity theft risk, fraudulent account access, phishing attempts using exposed details
Measures the responsible party has taken or intends to takeSpecific actions: systems isolated, passwords reset, affected accounts suspended, forensic investigation underway
Recommended steps data subjects can take to mitigate adverse effectsChange your password, enable two-factor authentication, check your bank statements, consider a fraud alert with your bank
Identity of the unauthorised person, if knownInclude if known; omit if unknown — do not speculate
Contact point for further informationNamed individual or dedicated email/phone for queries, not a generic info@ address

Delivery of the data subject notification may be by postal mail, email to the last known address, prominent placement on your website, or publication in news media. If your website is used as the notification channel, the Information Regulator's guidance suggests maintaining the notice for 30 to 90 days — a general guideline based on how likely affected individuals are to visit the site within that window.

If the identities of the affected data subjects cannot be established at all, the data subject notification requirement does not apply; the Regulator notification still does.

POPIA compliance sits alongside other website obligations. If your site collects personal data through contact forms or bookings, POPIA email compliance and cookie consent obligations form part of the same compliance picture — breach notification is what kicks in when those protections have been circumvented.

Good: A property management firm discovers its booking system was accessed by an unauthorised party. Within two days of confirming the breach, it emails all affected tenants in plain English explaining what data was exposed (names, contact details, ID numbers), what actions have been taken (access revoked, system patched, investigation ongoing), what tenants should do (monitor credit, change passwords on any sites using the same email address), and providing a direct contact. The Information Officer files the eServices portal notification the same day. The website displays a clear notice for 45 days.
Bad: A retailer's customer database is accessed by an external party. The IT team spends three weeks completing their forensic investigation before anyone files anything. By the time the notification goes out — via a dense legal letter — the Regulator has already received a complaint from an affected customer. The filing arrives late, lacks the required content, and the data subject notification goes to an outdated email list.

Not sure whether your current website setup creates breach exposure?

Tell us about your site's data flows and we will flag the points where unauthorised access is most likely — and where your response plan needs work.

Book a Website Security Review

What Non-Compliance Costs: Real Enforcement Cases

Non-compliance with Section 22 of POPIA can result in administrative fines of up to R10 million under Section 109, criminal penalties of up to 10 years' imprisonment for obstruction, and civil liability to affected data subjects under Section 99. The Information Regulator has moved from issuing advisory guidance to issuing enforcement notices and formal fines.

The most instructive POPIA data breach notification precedent is the Lancet Laboratories case. The Information Regulator found that Lancet had experienced repeated security compromises, failed to implement adequate security measures to prevent further unauthorised access, and failed to notify affected data subjects within a reasonable time under Section 22. An enforcement notice was issued in September 2024.

When Lancet failed to comply, the Regulator imposed a R100,000 fine. The case matters for two reasons: it shows the Regulator will penalise both notification failures and inadequate remediation — organisations that breach and then fail to fix the underlying vulnerability face broader exposure than those whose notification alone was deficient.

Enforcement volume (2024/25 full year, per ITweb / Information Regulator): The Regulator received 2,374 security compromise notifications in the 2024/25 financial year — averaging 284 per month. Early 2025/26 data shows a 40% year-on-year increase. The Regulator has signalled that enforcement action will scale with this growth.

For businesses that operate websites storing customer data — bookings, contact form submissions, account records — the risk is real and not limited to large organisations. The Regulator's 2025 fact sheet makes clear that SMEs are within scope. A website security checklist and a documented incident response plan are the operational layer under your Section 22 obligations.

Why South African Businesses Choose Growth Pulse Media for Web Compliance and Design

Growth Pulse Media builds and maintains websites for South African businesses that have to function as compliant, commercial assets — not liabilities. Dirk van Greuning founded the agency after scaling a large South African ecommerce operation, which means the team understands data flows, third-party integrations, and the operational decisions that create or reduce compliance exposure.

Every site we build is designed with data minimisation in mind: collecting only what is needed, securing what is collected, and documenting what happens when things go wrong.

Our web design services include guidance on privacy policy structures, data processing agreements with hosting and plugin providers, and incident response documentation — the groundwork that makes a Section 22 notification manageable rather than chaotic. We work with a limited number of clients at a time so that every site gets senior-level attention, not a junior checklist pass.

Who This Is NOT For

Not for you if: Your business processes no personal information at all — for example, a purely informational website with no contact forms, no analytics tracking identifiable users, and no ecommerce. POPIA applies only to the processing of personal information; if you genuinely hold none, Section 22 is not triggered.
Not for you if: You are looking for legal advice on a specific breach incident. This guide explains the statutory framework; your Information Officer and a POPIA-specialist attorney should handle live incident response, particularly where law enforcement involvement or litigation risk is present.
Not for you if: You need a full POPIA compliance programme — appointing an Information Officer, conducting a data inventory, drafting a PAIA manual, and building consent workflows. Section 22 notification is one element of a broader compliance structure; this post covers that one element only.
Not for you if: You are operating under a jurisdiction outside South Africa. POPIA applies to responsible parties that process personal information within, or intended to be processed within, the Republic of South Africa. Other jurisdictions have their own notification regimes.

Does your site pass a POPIA readiness check?

Share your website's data collection points with us and we will give you a prioritised list of what to fix before a breach happens — not after.

Request a POPIA Readiness Audit

Frequently Asked Questions

How quickly must a POPIA security compromise notification be filed?

POPIA requires notification "as soon as reasonably possible" after discovery — there is no fixed 72-hour window as in the EU's GDPR. You must report based on available information once you have reasonable grounds to believe a compromise occurred; you do not need to wait for a full forensic investigation to conclude. The only permitted delays are documented law enforcement needs or time strictly necessary to determine scope and restore system integrity.

Does every breach have to be reported, even a small one?

Yes. The Information Regulator has confirmed that POPIA contains no minimum threshold for reporting security compromises. All compromises must be reported by the responsible party regardless of the number of records affected or the perceived risk level. A single unauthorised access to personal information triggers the same Section 22 obligation as a large-scale breach.

Where do I submit the security compromise notification in 2025?

From 1 April 2025, all notifications must be submitted through the Information Regulator's eServices portal at eservices.inforegulator.org.za/compromises/default.aspx. Filing by email or using the old PDF form is no longer the accepted primary method. Your Information Officer must have registered portal access before an incident occurs.

What must the notification to data subjects include?

Under Section 22(5), the data subject notification must include: a description of the possible consequences of the breach; what measures have been or will be taken; recommended protective steps the individual can take; the identity of the unauthorised person if known; and a contact point for further questions. It must be written in plain language, not legal terminology, and delivered via mail, email, website notice, or news media.

What happens if a business fails to notify?

Non-compliance with Section 22 can result in an administrative fine of up to R10 million under Section 109 of POPIA, criminal penalties of up to 10 years for obstruction, and civil liability to affected data subjects under Section 99. In the Lancet Laboratories case, the Regulator found repeated security compromises, failure to implement adequate security measures to prevent further unauthorised access, and failure to notify data subjects — resulting in a R100,000 fine after Lancet failed to comply with an enforcement notice.

Build a Website That Handles Data the Right Way

Growth Pulse Media designs websites for South African businesses that collect, store and process personal information — with security, data minimisation, and incident response built into the architecture from day one. All work is executed in-house by a senior team that understands both the technical and compliance dimensions of operating a business website in South Africa.

No obligation — we'll get back to you within 24 hours.

Talk to Us About Your Website
Dirk van Greuning — Founder, Growth Pulse Media
Dirk van Greuning Founder, Growth Pulse Media

Founder of Growth Pulse Media and a specialist in South African search dominance. Dirk translates his experience in scaling South African businesses into high-velocity digital strategies for B2B and retail leaders. He writes about SEO, lead generation, and paid media from an operator's perspective — prioritising pipeline value over impressions.

Connect on LinkedIn