Close Menu
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact

Subscribe to Updates

Get the latest technology news from TechFinancials News about FinTech, Tech, Business, Telecoms and Connected Life.

What's Hot

Why Bitcoin and XRP Holders Are Rethinking Income in 2026—and What Comes Next

2026-01-23

How Local Leaders Can Shift Their Trajectory In 2026

2026-01-23

The EX60 Cross Country: Built For The “Go Anywhere” Attitude

2026-01-23
Facebook X (Twitter) Instagram
Trending
  • Why Bitcoin and XRP Holders Are Rethinking Income in 2026—and What Comes Next
Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp RSS
TechFinancials
  • Homepage
  • News
  • Cloud & AI
  • ECommerce
  • Entertainment
  • Finance
  • Opinion
  • Podcast
  • Contact
TechFinancials
Home»Opinion»The Notification of Data Breaches in SA Will Soon be Required by Law 
Opinion

The Notification of Data Breaches in SA Will Soon be Required by Law 

ContributorBy Contributor2017-04-20No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

By Darryl Bernstein, partner in Baker McKenzie’s Disputes and ITC Practice Groups in Johannesburg

According to the Gemalto Breach Level Index, released in March 2017, South Africa experienced nine reported security breaches in 2016. Across Africa, 45.2 million records were stolen in 2016, compared with 38.5 million in 2015. Africa had 17 data breaches in total, compared with six in 2015.

It was not the rise in security breaches that caused the most alarm, however. Gemalto noted in the survey that the delay in disclosing or identifying security breaches was the most concerning factor. In March 2017 Ster-Kinekor in South Africa announced that its website had been hacked a year prior, in 2016 exposing personal information in over 6-million accounts.

Legislation around data protection and privacy in South Africa is currently awaiting implementation. The Protection of Personal Information Act, 2013 (POPIA) was enacted in 2013. Once implemented, it is expected to change the way businesses approach the protection of customer and employee data and how they will have to report on data security breaches.

POPIA seeks to bring South Africa in line with international data protection laws by regulating the processing of the information of natural and juristic persons and placing more onerous obligations on “responsible parties” that process such information. However, only certain sections of the Act have commenced. These sections relate specifically to the establishment of the Information Regulator, who was appointed in December 2016.

The enactment of the Act itself, largely based on similar EU data protection legislation, is the most significant development in the South African privacy landscape. The timeline for the commencement of the entire Act is, however, still unclear. Given the limited transitional period of one year provided for compliance, coupled with potentially severe penalties, businesses in South Africa have already commenced implementing initiatives to comply with the prescriptive principles under the Act.

The notification of security compromises is governed by POPIA, where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person, the responsible party will have to notify the Information Regulator, as well as the data subject, unless that person’s identify cannot be established.

The notification will have to be made as soon as reasonably possible after the discovery of the compromise, considering the needs of law enforcement or any measures necessary to determine the scope of the compromise and to restore the integrity of the responsible party’s information system. The responsible party may only delay notification of the data subject if a public body responsible for the prevention, detection or investigation of offences or the Information Regulator determines it will impede a criminal investigation.

The notification must be in writing and must be communicated either via email or posted to the data subject’s last known address. The notification could also be placed in a prominent position on the website of the responsible party, published in the media; or as directed by the Information Regulator.

The notification must provide sufficient information to allow the data subject to take protective measures against the potential consequences of the compromise. This includes providing a description of the possible consequences of the data breach and how they will affect the data subject.

It should also include a description of the measures taken by the responsible party intends to address the security breach, as well as a recommendation on what measures the data subject should take to mitigate the possible adverse effects of the breach. If known to the responsible party, the identity of the unauthorised person who may have accessed or acquired the personal information must also be divulged to the data subject.

In addition, the Information Regulator may direct a responsible party to publicise, in any manner specified, the fact of any compromise to the integrity or confidentiality of personal information, if the she has reasonable grounds to believe that such publicity would protect a data subject affected by the compromise.

An organisation that is involved in a data breach situation may also be subject to an administrative fine, penalty or sanction, or civil actions and/or class actions.

In addition, the revised Cybercrimes and Cybersecurity Bill, which was tabled in the South African National Assembly in February 2017 notes the further obligations of electronic communications service providers and financial institutions when they become aware that their computer systems have involved in a cyber security breach as defined by the Bill. They must, according to the Bill, report such offences to the South African Police Service and preserve any information which may be of assistance in the investigation. Non-compliance with the clause is a criminal offence.

Whether or not compulsory reporting of this nature is a good thing is certainly up for debate. One thing is certain however, in a world where security breaches are a matter of when, not if, the treatment and security of personal information ought to be a matter of top priority for all institutions.

Bernstein and his team recently contributed the South African chapter of the Baker McKenzie Global Privacy Handbook 2017 which outlines privacy and information protection legislation in 58 jurisdictions around the world. More information on the protection of personal information and the processes involved can be found in this guide.

Cybercrimes cybersecurity data protection POPIA security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Contributor

Related Posts

How Local Leaders Can Shift Their Trajectory In 2026

2026-01-23

Directing The Dual Workforce In The Age of AI Agents

2026-01-22

The Productivity Myth That’s Costing South Africa Talent

2026-01-21

The Boardroom Challenge: Governing AI, Data And Digital

2026-01-20

Ransomware: What It Is And Why It’s Your Problem

2026-01-19

Can Taxpayers Lose By Challenging SARS?

2026-01-16

Science Is Best Communicated Through Identity And Culture – How Researchers Are Ensuring STEM Serves Their Communities

2026-01-16

Could ChatGPT Convince You To Buy Something?

2026-01-15

Trust Is The New Currency Of The Digital Economy

2026-01-12
Leave A Reply Cancel Reply

DON'T MISS
Breaking News

Chery SA to Buy Nissan Rosslyn Plant, Save Jobs

In a major development for South Africa’s automotive industry, Nissan and Chery SA have reached…

Directing The Dual Workforce In The Age of AI Agents

2026-01-22

Huawei Says The Next Wave Of Infrastructure Investment Must Include People, Not Only Platforms

2026-01-21

South Africa: Best Starting Point In Years, With 3 Clear Priorities Ahead

2026-01-12
Stay In Touch
  • Facebook
  • Twitter
  • YouTube
  • LinkedIn
OUR PICKS

The EX60 Cross Country: Built For The “Go Anywhere” Attitude

2026-01-23

Why Legal Businesses Must Lead Digital Transformation Rather Than Chase It

2026-01-23

Mettus Launches Splendi App To Help Young South Africans Manage Their Credit Health

2026-01-22

Over R270M In Phuthuma Nathi Dividends Remain Unclaimed

2025-11-27

Subscribe to Updates

Get the latest tech news from TechFinancials about telecoms, fintech and connected life.

About Us

TechFinancials delivers in-depth analysis of tech, digital revolution, fintech, e-commerce, digital banking and breaking tech news.

Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp Reddit RSS
Our Picks

Why Bitcoin and XRP Holders Are Rethinking Income in 2026—and What Comes Next

2026-01-23

How Local Leaders Can Shift Their Trajectory In 2026

2026-01-23

The EX60 Cross Country: Built For The “Go Anywhere” Attitude

2026-01-23
Recent Posts
  • Why Bitcoin and XRP Holders Are Rethinking Income in 2026—and What Comes Next
  • How Local Leaders Can Shift Their Trajectory In 2026
  • The EX60 Cross Country: Built For The “Go Anywhere” Attitude
  • Why Legal Businesses Must Lead Digital Transformation Rather Than Chase It
  • Why Rezor’s Exchange Launch Sets a New Benchmark for Web3 Founders — Rahul Rohit Parikh Story of Determination
TechFinancials
RSS Facebook X (Twitter) LinkedIn YouTube WhatsApp
  • Homepage
  • Newsletter
  • Contact
  • Advertise
  • Privacy Policy
  • About
© 2026 TechFinancials. Designed by TFS Media. TechFinancials brings you trusted, around-the-clock news on African tech, crypto, and finance. Our goal is to keep you informed in this fast-moving digital world. Now, the serious part (please read this): Trading is Risky: Buying and selling things like cryptocurrencies and CFDs is very risky. Because of leverage, you can lose your money much faster than you might expect. We Are Not Advisors: We are a news website. We do not provide investment, legal, or financial advice. Our content is for information and education only. Do Your Own Research: Never rely on a single source. Always conduct your own research before making any financial decision. A link to another company is not our stamp of approval. You Are Responsible: Your investments are your own. You could lose some or all of your money. Past performance does not predict future results. In short: We report the news. You make the decisions, and you take the risks. Please be careful.

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.