A POPIA security compromise notification is the formal alert your business must send to the Information Regulator and to affected individuals whenever personal information may have been accessed or acquired without authorisation — and, unlike Europe's GDPR, South African law sets no minimum size threshold before that obligation kicks in.
Whether you run a simple business website collecting enquiry-form data or a database with thousands of customer records, a qualifying incident triggers the same legal duties under Section 22 of the Protection of Personal Information Act. Getting the process wrong — including missing the mandatory eServices portal introduced in 2025 — can result in fines, enforcement notices, and personal liability for your Information Officer.
South Africa's Information Regulator received 2,374 security compromise notifications in the 2024/25 financial year, averaging 284 a month, with a 40% year-on-year increase in the early months of 2025/26. That volume reflects enforcement maturity: the Regulator is no longer waiting for organisations to self-correct.
Understanding website and data compliance obligations in full is the starting point; this guide covers the POPIA breach notification requirements specifically — what goes where, in what form, and with what content.
Quick Answer
A POPIA security compromise notification is a mandatory report submitted to South Africa's Information Regulator via the eServices portal (eservices.inforegulator.org.za) and a separate written notice sent to every affected data subject. It must be filed as soon as reasonably possible after discovery — no minimum-size threshold applies, and there is no 72-hour window equivalent to GDPR. The notification to data subjects must include the consequences of the breach, the measures you are taking, recommended protective steps, and a contact point for questions.
Jump to a Section
Is your website handling breach response correctly?
Send us your current incident response setup and we will show you exactly where the gaps are before the Regulator finds them for you.
Get a Free Compliance ReviewWhat Qualifies as a Data Breach Under South African Law?
A "security compromise" under POPIA is any event that results in the unauthorised access to, or acquisition, use, loss, damage, or destruction of personal information held by your organisation. The definition is deliberately broad: it covers a hacked website, a staff member emailing a customer list to the wrong address, a stolen laptop containing unencrypted records, an unauthorised database export, or a third-party supplier's system being breached where your customer data was stored.
Personal information itself is equally broad — it includes names, ID numbers, contact details, financial records, biometric data, health information, and any other information that can identify a living person. If your website collects booking forms, contact details, or payment references, and those records are accessed by an unauthorised party, that qualifies.
- WordPress or WooCommerce site compromised through an unpatched plugin
- Shared hosting account hacked, exposing multiple clients' data
- Staff forwarding client spreadsheets to personal email addresses
- CRM or email marketing platform credentials exposed in a phishing attack
- Third-party payment processor or API suffering a breach while holding your customers' data
If your business uses an operator (a third-party service provider that processes personal information on your behalf), Section 21(2) of POPIA requires that operator to notify you immediately upon discovering a compromise. Your obligation to notify the Regulator and data subjects is then triggered from the point you become aware, not the point your operator becomes aware. Building that requirement into supplier contracts is a preparedness step, not an optional extra.
The No-Threshold Reporting Rule Every Responsible Party Must Know
South Africa's Information Regulator is explicit: POPIA contains no minimum severity threshold for reporting security compromises. Every qualifying breach — regardless of the number of records affected, the sensitivity of the data, or the perceived risk to individuals — must be reported to the Regulator and to the affected data subjects.
Key Point
There is no "small breach" exemption in POPIA. If one unauthorised person accessed the personal details of even a single data subject, the Section 22 notification obligation applies. This is a materially different position from the EU's GDPR, which allows organisations to assess risk before deciding whether to notify regulators.
The timing standard is "as soon as reasonably possible after the discovery of the compromise." The security compromise notification South Africa framework does not impose a 72-hour window equivalent to the GDPR. What it does require is that you do not wait for a forensic investigation to conclude before filing — you report on what you know and update the notification as further details emerge.
The only permitted delays are a documented law enforcement need (where notification might compromise a criminal investigation) or the time strictly necessary to determine the scope of the breach and restore system integrity.
Discovery timing matters practically. The Information Regulator's own guidance states notification should occur "as soon as it is reasonably sure that a security compromise has occurred" — meaning once you have reasonable grounds to conclude unauthorised access took place, not only after your IT team formally declares a confirmed breach. Website uptime and security monitoring that detects anomalies quickly is therefore also a compliance tool, not just an operational one.
How to Submit a POPIA Security Compromise Notification to the Information Regulator
From 1 April 2025, all security compromise notifications to the Information Regulator must be submitted through the official eServices portal — filing by email or using the old PDF Form SCN1 is no longer the accepted primary method. Organisations that have not yet registered portal access should do so before they need it: an incident is the wrong time to troubleshoot login credentials.
The notification form is structured in five parts:
| Form Part | What It Covers |
|---|---|
| Part A | Responsible party details (your organisation's registered name, address, sector) |
| Part B | Information Officer details — name, contact, registration number with the Regulator |
| Part C | Security compromise specifics: what happened, when, how many data subjects affected, categories of personal information involved, identity of the unauthorised party if known |
| Part D | Measures taken or intended: containment steps, systems restored, remedial actions planned |
| Part E | Declaration of accuracy by the Information Officer or authorised signatory |
A registered Information Officer must submit the Section 22 POPIA notification. If your business has not yet registered its Information Officer with the Information Regulator, that registration step is itself a compliance obligation — and its absence will be noted in any enforcement review. The Regulator uses the notification data to monitor trends, direct further investigation, and issue compliance notices where remediation is insufficient.
Preparation Steps — Before a Breach Occurs
Register portal access at eservices.inforegulator.org.za and keep credentials current. Name your Information Officer and a deputy with after-hours contacts. Include a clause in all supplier contracts requiring operators to notify you immediately of any compromise. Draft a data-subject notification template in plain language before you need it under pressure.
What Affected Data Subjects Must Be Told
The data subject notification under Section 22 must give people enough information to take meaningful protective action — it is not a legal document for your file, it is a practical alert written for the person whose information was exposed.
Section 22(5) sets out the minimum content. The table below maps the statutory requirement to what that means in practice:
| What the law requires | What to actually write |
|---|---|
| Description of the possible consequences of the compromise | Plain-language explanation of what could happen: identity theft risk, fraudulent account access, phishing attempts using exposed details |
| Measures the responsible party has taken or intends to take | Specific actions: systems isolated, passwords reset, affected accounts suspended, forensic investigation underway |
| Recommended steps data subjects can take to mitigate adverse effects | Change your password, enable two-factor authentication, check your bank statements, consider a fraud alert with your bank |
| Identity of the unauthorised person, if known | Include if known; omit if unknown — do not speculate |
| Contact point for further information | Named individual or dedicated email/phone for queries, not a generic info@ address |
Delivery of the data subject notification may be by postal mail, email to the last known address, prominent placement on your website, or publication in news media. If your website is used as the notification channel, the Information Regulator's guidance suggests maintaining the notice for 30 to 90 days — a general guideline based on how likely affected individuals are to visit the site within that window.
If the identities of the affected data subjects cannot be established at all, the data subject notification requirement does not apply; the Regulator notification still does.
POPIA compliance sits alongside other website obligations. If your site collects personal data through contact forms or bookings, POPIA email compliance and cookie consent obligations form part of the same compliance picture — breach notification is what kicks in when those protections have been circumvented.
Not sure whether your current website setup creates breach exposure?
Tell us about your site's data flows and we will flag the points where unauthorised access is most likely — and where your response plan needs work.
Book a Website Security ReviewWhat Non-Compliance Costs: Real Enforcement Cases
Non-compliance with Section 22 of POPIA can result in administrative fines of up to R10 million under Section 109, criminal penalties of up to 10 years' imprisonment for obstruction, and civil liability to affected data subjects under Section 99. The Information Regulator has moved from issuing advisory guidance to issuing enforcement notices and formal fines.
The most instructive POPIA data breach notification precedent is the Lancet Laboratories case. The Information Regulator found that Lancet had experienced repeated security compromises, failed to implement adequate security measures to prevent further unauthorised access, and failed to notify affected data subjects within a reasonable time under Section 22. An enforcement notice was issued in September 2024.
When Lancet failed to comply, the Regulator imposed a R100,000 fine. The case matters for two reasons: it shows the Regulator will penalise both notification failures and inadequate remediation — organisations that breach and then fail to fix the underlying vulnerability face broader exposure than those whose notification alone was deficient.
For businesses that operate websites storing customer data — bookings, contact form submissions, account records — the risk is real and not limited to large organisations. The Regulator's 2025 fact sheet makes clear that SMEs are within scope. A website security checklist and a documented incident response plan are the operational layer under your Section 22 obligations.
Why South African Businesses Choose Growth Pulse Media for Web Compliance and Design
Growth Pulse Media builds and maintains websites for South African businesses that have to function as compliant, commercial assets — not liabilities. Dirk van Greuning founded the agency after scaling a large South African ecommerce operation, which means the team understands data flows, third-party integrations, and the operational decisions that create or reduce compliance exposure.
Every site we build is designed with data minimisation in mind: collecting only what is needed, securing what is collected, and documenting what happens when things go wrong.
Our web design services include guidance on privacy policy structures, data processing agreements with hosting and plugin providers, and incident response documentation — the groundwork that makes a Section 22 notification manageable rather than chaotic. We work with a limited number of clients at a time so that every site gets senior-level attention, not a junior checklist pass.
Who This Is NOT For
Does your site pass a POPIA readiness check?
Share your website's data collection points with us and we will give you a prioritised list of what to fix before a breach happens — not after.
Request a POPIA Readiness AuditFrequently Asked Questions
How quickly must a POPIA security compromise notification be filed?
POPIA requires notification "as soon as reasonably possible" after discovery — there is no fixed 72-hour window as in the EU's GDPR. You must report based on available information once you have reasonable grounds to believe a compromise occurred; you do not need to wait for a full forensic investigation to conclude. The only permitted delays are documented law enforcement needs or time strictly necessary to determine scope and restore system integrity.
Does every breach have to be reported, even a small one?
Yes. The Information Regulator has confirmed that POPIA contains no minimum threshold for reporting security compromises. All compromises must be reported by the responsible party regardless of the number of records affected or the perceived risk level. A single unauthorised access to personal information triggers the same Section 22 obligation as a large-scale breach.
Where do I submit the security compromise notification in 2025?
From 1 April 2025, all notifications must be submitted through the Information Regulator's eServices portal at eservices.inforegulator.org.za/compromises/default.aspx. Filing by email or using the old PDF form is no longer the accepted primary method. Your Information Officer must have registered portal access before an incident occurs.
What must the notification to data subjects include?
Under Section 22(5), the data subject notification must include: a description of the possible consequences of the breach; what measures have been or will be taken; recommended protective steps the individual can take; the identity of the unauthorised person if known; and a contact point for further questions. It must be written in plain language, not legal terminology, and delivered via mail, email, website notice, or news media.
What happens if a business fails to notify?
Non-compliance with Section 22 can result in an administrative fine of up to R10 million under Section 109 of POPIA, criminal penalties of up to 10 years for obstruction, and civil liability to affected data subjects under Section 99. In the Lancet Laboratories case, the Regulator found repeated security compromises, failure to implement adequate security measures to prevent further unauthorised access, and failure to notify data subjects — resulting in a R100,000 fine after Lancet failed to comply with an enforcement notice.
Build a Website That Handles Data the Right Way
Growth Pulse Media designs websites for South African businesses that collect, store and process personal information — with security, data minimisation, and incident response built into the architecture from day one. All work is executed in-house by a senior team that understands both the technical and compliance dimensions of operating a business website in South Africa.
No obligation — we'll get back to you within 24 hours.
Talk to Us About Your Website

