This wizard helps Information Officers determine if a security compromise requires mandatory notification to the Regulator under Section 77 of the Protection of Personal Information Act (POPIA).
Note: Under POPIA, notification must occur as soon as reasonably possible after the discovery of the compromise, taking into account the legitimate needs of law enforcement or any measures reasonably necessary to determine the scope of the compromise and restore the integrity of the information system.
Section 77(1) mandatory triggers.
Are there reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by an unauthorised person?
Estimating risk to the data subjects.
Given the nature of the data compromised (e.g. sensitive financial info, identifiers, biometrics), is it likely that the compromise will result in a high risk to the data subject’s rights and freedoms?
POPIA requires notification whenever there are "reasonable grounds" of unauthorised access, regardless of the severity level, but risk severity dictates the urgency and communication strategy.
Capture essential information for the notification letter.
The assessment indicates a notification is required. Below is a draft to be used as a starting point.
Based on your answers, a notification under Section 77 of POPIA is not mandatory at this stage.
Section 77 only triggers when there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.