Protection of Personal Information Act, notification of security compromises
POPIA, s. 22 (notification of security compromises)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 July 2020.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the Information Regulator of a security compromise as soon as reasonably possible after discovering that personal information has been accessed or acquired by an unauthorised person; the Act sets no fixed hour or day limit, only this standard.
- Notify the affected data subject of the same security compromise as soon as reasonably possible after discovery, in writing, unless a law-enforcement body or the Regulator determines that notifying would impede a criminal investigation, or the data subject's identity cannot be established.
- In the notification to the data subject, describe the compromise's likely consequences, the measures you have taken or intend to take to address it, a recommendation of what the data subject should do, and, if known, the identity of the unauthorised person.
- As an operator, notify the responsible party immediately once you have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 22(1) requires a responsible party, where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, to notify both the Information Regulator and the affected data subject, unless the data subject's identity cannot be established.
Section 22(2) fixes the moment the notification is due from the discovery of the compromise: notification must be made as soon as reasonably possible after that discovery, taking into account the legitimate needs of law enforcement and any measures needed to determine the compromise's scope and restore the responsible party's information system.
Section 22(3) lets the responsible party delay only the data subject's notification, and only where a law-enforcement body or the Regulator determines that notifying would impede a criminal investigation; section 22(4) requires the data subject's notification to be in writing, by at least one of several listed channels, and section 22(5) requires it to describe the compromise's likely consequences, the measures taken or proposed to address it, a recommendation for the data subject, and, if known, the unauthorised person's identity.
Section 21(2) separately requires an operator processing personal information for a responsible party to notify that responsible party immediately on the same reasonable grounds.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.