Breach notification
Protection of Personal Information Act, notification of security compromises
POPIA, s. 22 (notification of security compromises)Protection of Personal Information Act 4 of 2013, Government Gazette text hosted by the Information Regulator of South Africa
In force since 1 July 2020. Binds public and private bodies.
What this law does
Section 22(1) requires a responsible party, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, to notify both the Information Regulator and the affected data subject, unless the data subject's identity cannot be established.
Section 22(2) fixes the moment the notification is due from the discovery of the compromise: notification must be made as soon as reasonably possible after that discovery, taking into account the legitimate needs of law enforcement and any measures needed to determine the compromise's scope and restore the responsible party's information system.
Section 22(3) lets the responsible party delay only the data subject's notification, and only where a law-enforcement body or the Regulator determines that notifying would impede a criminal investigation; section 22(4) requires the data subject's notification to be in writing, by at least one of several listed channels, and section 22(5) requires it to describe the compromise's likely consequences, the measures taken or proposed to address it, a recommendation for the data subject, and, if known, the unauthorised person's identity.
Section 21(2) separately requires an operator processing personal information for a responsible party to notify that responsible party immediately on the same reasonable grounds.
What it requires