PogoWasRight.org

Menu
  • About
  • Privacy
Menu

South Africa Introduces Mandatory e-Portal Reporting for Data Breaches

Posted on April 16, 2025April 15, 2025 by Dissent

Dan Cooper, Benjamin Haley, Deon Govender, Ahmed Mokdad, and Mosa Mkhize of Covington and Burling write:

On April 7, 2025, South Africa’s Information Regulator announced a new requirement for organizations to report data breaches—referred to under local law as “security compromises”—via an online eServices Portal. The announcement marks a significant procedural shift in how companies must comply with the Protection of Personal Information Act, 2013 (“POPIA”), South Africa’s data protection framework.

The move to a digital platform aligns South Africa with international trends toward streamlined breach reporting mechanisms. For companies that process personal information using means located in South Africa—whether or not they are headquartered in the country—this development highlights the importance of understanding when and how POPIA may apply. Foreign-based companies that rely on South African infrastructure, service providers, or operations to process data should review whether their activities fall within POPIA’s extraterritorial scope.

POPIA and the Concept of a “Security Compromise”

POPIA defines a “security compromise” broadly as any unauthorised access to, or acquisition of, personal information.

Read more at Inside Privacy.

Category: BreachesLawsNon-U.S.

Post navigation

← Privacy on the Map: How States Are Fighting Location Surveillance
Judge Blocks Cities From Defending HHS Abortion Privacy Rule →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

RSS Recent Posts on DataBreaches.net

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy