South Africa’s Information Regulator now receives roughly 284 data breach notifications a month, and by its own estimate more than 90% of them were preventable, according to reporting in The Star. Most South African small business owners have never registered an Information Officer, do not know what POPIA actually requires when something goes wrong, and have no plan beyond hoping it never happens. This is the plan.
You already have an Information Officer, whether you registered one or not
Under POPIA, every organisation that collects, stores or processes personal information, which covers almost any business with a customer database, an employee list or a supplier contract, must have an Information Officer. If a business has not formally appointed one, the role defaults automatically to the CEO or managing director, regardless of whether they know it or have any privacy programme in place.
Registering the role properly takes under 30 minutes through the Information Regulator’s own portal at inforegulator.bizportal.gov.za, logging in with a CIPC customer code and selecting Information Officer Registration from the services menu. A manual paper form is also available directly from the Information Regulator’s own site, emailed to its registration address. This single, five-minute administrative step is the compliance gap the Regulator most often finds during an investigation, and it is free to close.
What POPIA actually requires when a breach happens
Section 22 of POPIA requires notifying both the Information Regulator and every affected person “as soon as reasonably possible” after discovering a security compromise. That is the actual legal wording, and it is worth being precise about it: POPIA itself does not set a fixed 72-hour deadline the way EU data protection law does. The Regulator’s own 2021 guidance note on security compromises expresses an expectation in that range, but it is guidance, not statute, and the law’s real test is reasonableness given the circumstances, including how long it genuinely takes to establish the scope of what happened.
The notification itself has to do more than simply say a breach happened. Section 22 sets out what it needs to actually contain: a description of the possible consequences for the people affected, the measures the business has taken or plans to take to address the breach, a recommendation of what those people should do to protect themselves, and the identity of the unauthorised person responsible, if that is known. A one-line email saying “we had an incident” does not meet this bar, however fast it goes out.
That distinction matters practically: a business that moves as fast as it reasonably can, and can show its working, is in a very different position to one that simply stays quiet. Notification has to happen regardless of whether the breach was caused by an external hacker, a lost laptop, an employee mistake, or a supplier’s own failure, since POPIA does not distinguish between these when it comes to the notification duty itself.
What actually gets a business fined, and what does not
The Information Regulator has issued two administrative fines of R5 million each so far, out of a legislated maximum of R10 million per contravention. The first, against the Department of Justice and Constitutional Development, followed a 2021 ransomware attack that exposed personal information from more than 1,000 files, after the department let its own security software licences lapse and then failed to act on a formal enforcement notice ordering it to fix the problem, a sequence of events set out in detail by law firm Bowmans. The second, against the Department of Basic Education, was for publishing matric results without consent, one of two government departments BusinessTech reported being fined R5 million each.
A third case shows the same pattern outside a straightforward breach. In September 2024, the Regulator issued WhatsApp with a formal enforcement notice after finding that South African users were given weaker privacy protections than users in Europe, a finding TimesLIVE reported when it became public. WhatsApp was given 60 days to update its privacy policy and processes or face a fine of up to R10 million, imprisonment of up to ten years, or both.
The detail that matters for a small business owner: in every one of these cases, the consequence followed a failure to comply with a corrective enforcement notice, not the original incident itself. The Regulator’s own pattern so far has been to investigate, issue guidance or an enforcement notice, and only fine an organisation that ignores it. A business that has a breach, notifies properly and fixes the underlying problem is in a fundamentally different position to one that gets flagged and does nothing.
The response plan itself
- Contain it first. Change compromised credentials, isolate an affected system, and stop the ongoing exposure before anything else, since the clock on “reasonably possible” starts running from discovery, not from when containment finishes.
- Establish what was actually exposed. Whose data, what categories of information, and how it happened, in enough detail to notify accurately rather than vaguely.
- Notify the Information Regulator via its published breach notification form, including the specific content Section 22 requires: the likely consequences, what the business has done or plans to do about it, and what affected people should do to protect themselves.
- Notify affected individuals directly wherever reasonably possible, in the same detail, since a vague notice technically sent is not the same as a notice that actually lets someone protect themselves.
- Fix the underlying cause and keep a written record of having done so. Given the Regulator’s own enforcement pattern across the Department of Justice, the Department of Basic Education and WhatsApp cases, this step is what actually determines whether a bad day becomes a multi-million-rand problem.
Why this is worth doing before anything goes wrong
South Africa loses an estimated R2.2 billion a year to cyber incidents, according to Interpol figures cited in the same reporting that surfaced the Regulator’s monthly breach numbers. A small business with no IT department is not a smaller target for that reason, it is often a softer one. According to research from cybersecurity firm SureTel, fewer than a third of South African SMEs surveyed recently planned to increase their security budget at all, even as breach costs average around 7% of annual revenue for the businesses that get hit. Data breach management is also one of the Information Regulator’s own stated enforcement priorities for 2026, alongside direct marketing compliance, which means the volume of investigations into exactly this kind of incident is only going up.
Registering an Information Officer and having a written response plan costs nothing but time, and it is the single biggest factor separating a contained, well-handled incident from a regulatory investigation. Our SA Compliance Document Generator can produce a POPIA-ready privacy manual filled in with your own business details, our guide to key business compliance requirements covers where POPIA fits alongside a small business’s other regulatory obligations, and our B-BBEE compliance guide covers the other major compliance exercise most growing SMEs eventually have to get through on a similar kind of deadline pressure.

