What Protection of Personal Information Act (Act 4 of 2013): Section 22 - Notification of security compromises requires
Organizations must notify the Information Regulator and affected data subjects as soon as reasonably possible after discovering a security compromise involving personal information.
Pillar: Data Protection & Privacy · Authority: Information Regulator South Africa · Version: 1.0.0 · Last updated:
Primary source: https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013popi.pdf
SHA-256 integrity: 2dd5ae71e67ad398b3057bff22485b638da1919c0bdda8458eb26c28da42c5fa
Primary Citations — 7 traced to source
- Section 22, paragraph 1: Where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person, the responsible party must notify the Regulator and the data subject.
- Section 22, paragraph 2: The notification must be made as soon as reasonably possible after the discovery of the compromise, taking into account the legitimate needs of law enforcement or any measures reasonably necessary to determine the scope of the compromise and to restore the integrity of the responsible party's information system.
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/za-popia-section-22-notification-security-compromises.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/za-popia-section-22-notification-security-compromises.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/za-popia-section-22-notification-security-compromises
- Back to registry: Browse all 10,090 compliance nodes