Quick answer
Learn what a POPIA security-compromise notice should contain, which records you can request, how to protect yourself and when to complain.
Key takeaways
- POPIA uses the term “security compromise” when there are reasonable grounds to believe an unauthorised person accessed or acquired personal information.
- Section 22 says notification must occur as soon as reasonably possible after discovery; it does not set a general 72-hour POPIA deadline.
- A notice must describe possible consequences, the organisation's response, recommended protective steps and, if known, the unauthorised person's identity.
- You can request confirmation, access and third-party-access information under section 23, subject to identity proof, possible fees and lawful refusal grounds.
1. Check whether the incident fits POPIA section 22
The familiar phrase “data breach” is wider and less precise than POPIA's statutory test. Section 22 applies where there are reasonable grounds to believe that an unauthorised person accessed or acquired a data subject's personal information.
Personal information can include more than an identity number or password. Depending on the person and context, it may include contact details, account identifiers, financial information, employment records, health information, biometric information, correspondence, location information and opinions about the person. POPIA can also protect information about an identifiable existing juristic person.
A website outage, malware alert or attempted login is not automatically a section 22 security compromise. The event must concern personal information and the statutory access-or-acquisition test. Conversely, a compromise does not need to involve an external hacker. Misaddressed email, unauthorised internal access, a lost file, stolen equipment or disclosure to the wrong recipient may engage POPIA if the test is met.
The responsible party is the body that determines why and how the information is processed. A service provider processing information for it may be an operator. Section 21 requires an operator to notify the responsible party immediately when it has reasonable grounds to believe that relevant personal information was accessed or acquired by an unauthorised person. The responsible party remains responsible for the section 22 notifications.
The legal classification of a disputed incident can require the contract, data flow and technical findings.
2. Know what the notification duty requires
Timing: as soon as reasonably possible, not a fixed 72 hours
Section 22 says the responsible party must notify the Regulator and, subject to the statutory exception, the identifiable affected data subject as soon as reasonably possible after discovering the compromise. The timing may take account of legitimate law-enforcement needs and measures reasonably necessary to determine the scope and restore system integrity.
POPIA does not prescribe a general 72-hour period for this notification. A different statute, code, regulator, industry rule, contract or foreign law may add a separate deadline. Do not import that deadline into POPIA without identifying its source.
The responsible party may delay notice to the data subject only if the Regulator or a public body responsible for preventing, detecting or investigating offences determines that notification will impede a criminal investigation. A business cannot rely on an internal preference for secrecy as though it were that determination.
Form: a written communication through a permitted channel
The notice to the affected person must be in writing. Section 22 allows communication by post to the last known physical or postal address, email to the last known email address, a prominent website placement, publication in the news media or another method directed by the Regulator.
A public website notice may therefore be part of a lawful communication method. Whether it adequately reaches the identifiable affected people and contains the required information remains a fact-specific question.
Content: enough information to take protective measures
The notification must provide sufficient information to allow the person to protect against the possible consequences. It must include:
- a description of the possible consequences;
- the measures the responsible party intends to take or has taken;
- recommendations for measures the data subject can take to reduce possible adverse effects; and
- the identity of the unauthorised person, if known to the responsible party.
The duty is not satisfied merely by saying that “an incident occurred” if that statement gives the reader no meaningful way to understand the possible consequences or protect themselves. At the same time, section 22 does not promise the affected person a full forensic report, privileged advice, security-sensitive detail or the perpetrator's identity when it is not known.
3. Verify the notice before using its links
Criminals can imitate breach notices to collect more information or credentials. Do not assume a message is authentic because it uses an organisation's name, logo or case reference.
Verify it through contact details you obtain independently from the organisation's official website, app, statement or existing contract. Ask the organisation to confirm:
- that the notice is genuine;
- the reference assigned to the incident;
- the authorised contact or information officer handling questions;
- the official page where updates will be published; and
- whether any link or telephone number in the notice belongs to it.
Do not reply with a full identity document, password, one-time PIN, bank credential or new collection of sensitive information unless the lawful need, recipient and secure submission channel have been verified. Adequate identity proof may be required for an access request, but the method should be proportionate and secure.
Keep the original message with its header, envelope or delivery context. Save later versions and updates separately so the sequence remains clear.
4. Ask focused questions about your information
Write to the responsible party or its information officer. Ask questions that connect the incident to your next protective step:
- Which categories of my personal information were involved?
- Which accounts, products, records, devices or periods does the notice concern?
- When did the suspected access or acquisition occur, and when was it discovered?
- Was the information only viewed, or is there evidence it was copied, altered, disclosed, deleted or used?
- Which possible consequences have been identified for these particular data categories?
- What containment and protective measures have been completed, and which are still in progress?
- Which specific measures do you recommend that I take now?
- Was the incident at the responsible party or an operator acting for it?
- What update schedule and reference should I use for further correspondence?
- If the unauthorised person is known, what identity information can lawfully be provided under section 22?
Separate what the organisation knows from what it is still investigating. Do not ask it to confirm that information was “stolen” if the evidence currently supports only access, and do not accept “no evidence of misuse” as proof that access or acquisition did not occur.
Ask for written answers. Preserve unanswered questions and changing explanations without editing earlier correspondence.
5. Use your access and correction rights precisely
Confirmation and access under section 23
After providing adequate proof of identity, a data subject may ask a responsible party to confirm, free of charge, whether it holds personal information about that person.
The person may also request the record or a description of the personal information and information about the identity of all third parties, or categories of third parties, who have or have had access to it. The response must be within a reasonable time, at any prescribed fee, in a reasonable manner and format, and in a generally understandable form.
This is not an unrestricted right to every incident record. POPIA applies relevant PAIA grounds for refusing access, and the organisation may require a fee estimate or deposit for the access service where permitted. A well-scoped request identifies the person, account or relationship, the relevant record categories and the period.
The Information Regulator's PAIA page links its current guide and forms and specifically says the guide assists people seeking their personal information under section 23. Use the responsible party's PAIA manual and information-officer details when available.
Correction, deletion and restriction
Section 24 allows a data subject to request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully. It also permits a request to destroy or delete a record the responsible party is no longer authorised to retain. The Regulator publishes Form 2 for this purpose.
Deletion is not automatic merely because a compromise occurred. The responsible party may still be required or authorised to keep records for a lawful purpose, a legal duty, a contract, proof or another applicable retention basis. If the parties cannot agree on a correction, section 24 provides for a requested indication to be attached to the information in the circumstances described there.
POPIA also provides for restriction of processing in specified section 14 circumstances, including while contested accuracy is verified or where information must be maintained for proof. The correct request depends on the record and why it is still needed.
Objection is not a universal erasure tool
Section 11(3) permits objections on reasonable grounds in specified processing situations, and the Regulator publishes Form 1. It does not create an unrestricted right to stop every processing activity. Identify the organisation's stated processing basis, the purpose and the particular grounds before relying on an objection.
6. Match protective action to the exposed information
A generic instruction to “change your password” is not enough for every incident. Use the categories confirmed or reasonably suspected.
Login and recovery information
- Change affected passwords from a trusted device and replace reused passwords on other services.
- End unfamiliar sessions and review recovery email addresses, telephone numbers and authentication methods.
- Enable strong multi-factor authentication where available.
- Preserve security alerts and account histories before they disappear.
Banking or payment information
- Contact the institution through a verified channel and obtain a fraud or dispute reference.
- Ask which instruments, beneficiaries, cards or digital-banking access can be blocked or monitored.
- Preserve statements, alerts and disputed-transaction records.
Identity and account-opening information
- Watch for unfamiliar account, credit, SIM, service or account-recovery activity.
- Keep every alert and correspondence showing attempted impersonation.
- Use the relevant provider, bank, credit and criminal-reporting routes if misuse appears.
Health, biometric, child or other sensitive records
Passwords can be changed; health history and biometric characteristics usually cannot. Ask what exact data and copies were involved, who received them if known, whether further disclosure is continuing and what controls now limit access. Treat information about children, safety, health, criminal allegations or intimate matters as an early legal-review trigger.
Do not publish the breached data to prove it exists. Send only the minimum necessary evidence through a verified complaint, provider or legal channel.
7. Build a clean incident and loss record
Create one chronology containing:
- the original notice and every update;
- the date and method by which each communication arrived;
- the exposed-data categories described by the organisation;
- your questions, the organisation's answers and unanswered items;
- password, account and provider actions taken, without recording the new passwords themselves;
- bank, platform, insurer, credit, SAPS and Regulator reference numbers;
- suspicious communications or transactions after the compromise;
- direct expenses and financial losses, supported by invoices and statements;
- time-sensitive court, contract, policy or complaint dates identified by an adviser; and
- any health, safety, employment or reputational consequence supported by contemporaneous records.
Record facts, not assumptions. A later phishing email may be relevant, but timing alone does not prove it resulted from this compromise. Keep possible connections labelled as unconfirmed until evidence supports them.
8. When to complain to the Information Regulator
The Information Regulator's current complaints page says a person can lodge a general POPIA complaint for matters including unauthorised sharing, failure to secure personal information, or failure to respond to a correction, deletion or objection request. It directs users to register on the eServices portal and submit the complaint there.
Before submitting, organise:
- your full details and secure contact method;
- the responsible party's correct legal identity and contact details;
- the notice and incident reference;
- a short chronology;
- the POPIA duty or request you say was not met;
- your correspondence with the organisation;
- the response or proof that no response arrived; and
- focused supporting records with unnecessary third-party personal information redacted.
A complaint can lead to pre-investigation, conciliation, investigation, referral or another action allowed by POPIA. The Regulator may also decide not to take further action in the circumstances set out in the Act. Filing a complaint does not guarantee an enforcement notice, compensation or immediate protective relief.
Do not confuse a responsible party's security-compromise notification with your complaint. Since 1 April 2025, the Regulator says responsible parties must submit section 22 notifications through eServices. An affected person who alleges a POPIA violation uses the complaint service.
9. Use parallel routes for their own purpose
A single event may require several tracks:
- report suspected fraud, unlawful access, extortion or other crime through the appropriate SAPS route;
- report unauthorised banking or payment activity to the institution immediately;
- use an applicable ombud, code-of-conduct or sector complaint only after checking its scope and any first-step requirements;
- notify an insurer in the manner and time required by the policy;
- use platform recovery or takedown channels where accounts or content are involved; and
- obtain urgent legal advice where safety, publication, dismissal, blackmail, intimate material or irreversible transactions are involved.
A POPIA complaint examines interference with personal-information protection. It is not a criminal case, a bank recall, a credit correction or an urgent interdict. Suspected criminal conduct may also need a separate SAPS complaint and evidence-preservation process.
10. When a privacy lawyer may be useful
Obtain advice early when:
- the notice is missing, delayed or too vague to permit meaningful protection;
- the affected records involve children, health, biometrics, criminal allegations, intimate information or safety;
- a responsible party and operator dispute responsibility;
- information was transferred across borders or disclosed to many recipients;
- records may disappear or urgent preservation is required;
- a regulator, police, bank, insurer, employer or platform process overlaps;
- you face material financial or non-financial loss;
- the organisation refuses a focused access, correction, restriction or deletion request;
- urgent court relief may be necessary; or
- you are considering a damages claim.
Section 99 permits a data subject—or the Regulator at the data subject's request—to institute a civil action for damages in a court with jurisdiction for a breach described in section 73, whether or not the responsible party intended the breach or was negligent. The section also provides defences and identifies possible just-and-equitable awards. It does not make payment automatic after every security compromise.
The facts, causation, loss, defences, evidence, correct defendant, jurisdiction, procedure and time limits require individual analysis. Do not assume a Regulator complaint suspends a court deadline, or that an internal promise to investigate preserves a claim.
The lawyer directory and law-firm directory support comparison for privacy-law work; they do not recommend a provider or guarantee suitability.
Questions to take to a first consultation
- Which POPIA duties are engaged by the facts we can prove?
- Is the organisation the responsible party, an operator or both for different data?
- What information should be requested now, and through section 23, PAIA or another process?
- Which evidence needs preservation before a complaint or letter is sent?
- Is urgent relief needed to stop continuing disclosure or misuse?
- Which Regulator, criminal, bank, insurer, labour or court routes can run together?
- What loss and causation evidence would a section 99 claim require?
- Which deadlines apply, and what action actually preserves each right?
- What scope, assumptions, fees and next decision point will be recorded in the mandate?
FAQs
Does POPIA require notice within 72 hours?
No general 72-hour deadline appears in section 22. The responsible party must notify as soon as reasonably possible after discovering the compromise, taking account of the considerations in that section. Other laws, codes, contracts or foreign rules may impose separate deadlines.
Must the organisation tell me exactly who accessed my data?
The section 22 notice must include the unauthorised person's identity if it is known to the responsible party. It does not require the organisation to invent an identity or disclose every investigative record. Ask what is known, what remains under investigation and when the next update will be provided.
Can I demand that all my information be deleted?
Not automatically. Section 24 supports correction or deletion for specified problems and deletion of records the responsible party is no longer authorised to retain. A lawful duty, contract, proof requirement or other permitted retention basis may still apply.
Can I ask who had access to my personal information?
Section 23 allows a properly identified data subject to request the record or description of their personal information and information about the identity of third parties, or categories of third parties, who have or have had access. Fees and PAIA refusal grounds may apply.
Does a security-compromise notice mean I will receive compensation?
No. A notice records a statutory security-compromise process; it does not by itself decide breach, causation, loss, defences or an award. Section 99 creates a civil route in the circumstances it describes, but every proposed claim requires fact-specific assessment.
Where do I lodge a POPIA complaint now?
The Information Regulator's current complaints page directs users to create an eServices profile and submit the complaint through the portal. Keep the submission reference and a complete copy of the complaint and attachments.
Related Lexuno paths
Source notes
- Department of Justice: Protection of Personal Information Act 4 of 2013
- South African Government: Protection of Personal Information Act 4 of 2013
- Information Regulator: POPIA guidance
- Information Regulator: Complaints
- Information Regulator: eServices
- Information Regulator: POPIA forms
- Information Regulator: PAIA guidance and forms
Legal note
This article is general legal information for South African readers. It is not legal advice. Speak to a qualified legal professional about your specific facts before taking action.

