The POPI Act the Act, section by section, free PAIA Guide ↗
The POPI Act / Sections / Section 22
Section 22

Notification of security compromises

Chapter 3 · Conditions for Lawful Processing · Condition 7, Security Safeguards

(1) Where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person, the responsible party must notify— (a) the Regulator; and (b) subject to subsection (3), the data subject, unless the identity of such data subject cannot be established.

(2) The notification referred to in subsection (1) must be made as soon as reasonably possible after the discovery of the compromise, taking into account the legitimate needs of law enforcement or any measures reasonably necessary to determine the scope of the compromise and to restore the integrity of the responsible party's information system.

(3) The responsible party may only delay notification of the data subject if a public body responsible for the prevention, detection or investigation of offences or the Regulator determines that notification will impede a criminal investigation by the public body concerned.

(4) The notification to a data subject referred to in subsection (1) must be in writing and communicated to the data subject in at least one of the following ways: (a) Mailed to the data subject's last known physical or postal address; (b) sent by e-mail to the data subject's last known e-mail address; (c) placed in a prominent position on the website of the responsible party; (d) published in the news media; or (e) as may be directed by the Regulator.

(5) The notification referred to in subsection (1) must provide sufficient information to allow the data subject to take protective measures against the potential consequences of the compromise, including— (a) a description of the possible consequences of the security compromise; (b) a description of the measures that the responsible party intends to take or has taken to address the security compromise; (c) a recommendation with regard to the measures to be taken by the data subject to mitigate the possible adverse effects of the security compromise; and (d) if known to the responsible party, the identity of the unauthorised person who may have accessed or acquired the personal information.

(6) The Regulator may direct a responsible party to publicise, in any manner specified, the fact of any compromise to the integrity or confidentiality of personal information, if the Regulator has reasonable grounds to believe that such publicity would protect a data subject who may be affected by the compromise.

breach notificationcondition 7security compromiseRegulator
Beyond the text

What this means for your estate

  • This is the section that turns a CCTV hack, a stolen visitor-log spreadsheet, or an access-control database breach into a formal legal deadline, subsection (2)'s “as soon as reasonably possible” is not a grace period to investigate quietly first; the notification obligation starts at reasonable suspicion, not confirmed proof.
  • Both the Regulator and affected residents have to be told (subsection (1)), notifying only one of the two doesn't satisfy this section.
  • Subsection (5) sets specific content requirements for the notice itself, a generic “we had a security incident” email doesn't meet the bar; it needs consequences, remedial steps taken, and recommended actions for the affected resident.
Relevant tool

PopiGuard's Breach Register walks you through the s.22 notification requirements step by step, Regulator and data subject, on the clock, with the right content.

See PopiGuard for estates →
Frequently asked
Who has to be told if there's a data breach, the Regulator, the people affected, or both? ▾

Both. Section 22(1) requires notifying the Information Regulator and, unless their identity can't be established, the data subjects whose information was accessed or acquired without authorisation.

How quickly must a breach be reported under POPIA? ▾

Section 22(2) requires notification “as soon as reasonably possible” after discovering the compromise, though it does allow that timing to account for genuine law-enforcement needs or the work required to determine the scope of the breach.