Records & POPIA
POPIA Breach Notification Tracking
Tracking of personal-information security compromises and the timeliness of notifications to the Regulator.
Why breach-notification timeliness is a legal duty
POPIA requires that security compromises affecting personal information be reported to the Information Regulator and affected data subjects as soon as reasonably possible, and delay or non-notification carries enforcement and reputational consequences. Tracking each compromise and the timeliness of its notification is essential to discharge the responsible party's obligations. AuditPro Core tracks personal-information breaches and notification timeliness so the Information Officer can act within the statutory expectation.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Incidents (year)
19
▲ 4 vs prior year
Reportable breaches
7
Notified within 72h
5 of 7
71%
Data subjects affected
8,420
Breach incidents by quarter
Reportable breaches
| Ref | Cause | Affected | Regulator notified |
|---|---|---|---|
| PB-07 | Misdirected email | 320 | Within 72h |
| PB-11 | Lost device | 1840 | Within 72h |
| PB-14 | Ransomware | 5200 | Late (9 days) |
| PB-18 | Unauthorised access | 1060 | Within 72h |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Notification is mandatory and prompt
Where there are reasonable grounds to believe personal information has been accessed by an unauthorised person, both the Regulator and affected data subjects must be notified as soon as reasonably possible. The duty is triggered by reasonable belief, not by certainty.
The clock starts at discovery
Timeliness is measured from when the compromise is discovered, so detection and internal escalation directly affect compliance. Slow internal reporting consumes the available notification window.
Records evidence the response
Maintaining a breach register with dates, scope and actions demonstrates that the institution responded appropriately. The register is the institution's defence if the response is questioned.
How AuditPro Core Bridges the Gap
- Breach register: AuditPro Core records each compromise with discovery date, scope and affected data subjects.
- Timeliness tracking: notification dates are measured against discovery to flag delays.
- Workflow escalation: open breaches are routed to the Information Officer with required actions tracked.
- Traceability: the complete record supports any Regulator engagement or audit review.
Key Takeaways
- Notify the Regulator and data subjects as soon as reasonably possible.
- Timeliness is measured from discovery, so detection speed counts.
- Reasonable belief, not certainty, triggers the duty.
- A maintained breach register evidences a compliant response.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
