FACT SHEET: HANDLING OF SECURITY COMPROMISES
Cybersecurity Classified by Officially
Fact Sheet: Handling Of Security Compromises
What is a security compromise?
POPIA does not define a security compromise. In brief, a security compromise, also known as a data breach in other jurisdictions, is a compromise in the security, confidentiality, integrity or availability of personal information, leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, processing or access to personal information. This can lead to harm being suffered by data subjects.
What are some examples of security compromises?
Security compromises can occur in a variety of ways, viz.
- Accidentally – viz. sending an email containing personal information of a data subject to an unintended recipient, losing paperwork or devices which contain unprotected personal information;
- Deliberately – viz. cyber-security attacks, employee fraud or mischief;
- Incidentally viz. theft, rioting, hijacking where personal information is not the target of the activity;
- Negligently – viz. failing to use appropriate technical and organisational measures to secure personal information such as not using encryption, sharing passwords, leaving personal information unattended.
Do I have to report low risk security compromises?
Yes. POPIA does not have a threshold for reporting of security compromises. All security compromises must be reported by the responsible party irrespective of the deemed level of risk. The reporting requirement is mandatory. Responsible parties do not have a discretion regarding when or if to report a security compromise nor in respect of notifying affected data subjects.
Who should report a security compromise?
This is an extract. The publication continues at the source.
Read the original at the source: https://inforegulator.org.za/2025/08/19/fact-sheet-handling-of-security-compromises/?utm_source=rss&utm_medium=rss&utm_campaign=fact-sheet-handling-of-security-compromises
Officially imported this from Information Regulator South Africa’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Information Regulator South Africa — imported from official source
- Official source
- https://inforegulator.org.za/feed/ RSS
- Imported
- September 24, 2026 11:30
- Versions
- 1 recorded
- Identity
https://inforegulator.org.za/?p=15851