What happened

At a briefing on 31 August 2026, Information Regulator chair Pansy Tlakula disclosed that South Africa has now passed 8,000 cumulative data breach notifications — with notifications rising 40% year on year. It is one of the clearest signals yet that breaches are no longer exceptional events for South African organisations; they are routine.

The numbers reflect both a genuine increase in attacks and a maturing reporting culture. Since POPIA's enforcement provisions took effect, notifying the Regulator of a security compromise has moved from best practice to legal obligation — and organisations are feeling that shift.

Why it matters to your business

A 40% annual rise in reported breaches means the probability that your business will face a reportable incident is climbing steadily. Under POPIA, failing to notify the Regulator and affected data subjects of a breach is itself a contravention — separate from the security failure that caused it.

For small and mid-sized businesses, the practical exposure is twofold: the operational damage of the incident itself, and the regulatory and reputational fallout of handling it badly. Companies that can demonstrate reasonable safeguards — encryption, monitored backups, access control and documented response procedures — are in a fundamentally stronger position with the Regulator than those that cannot.

What you should do

Know your notification duty. POPIA requires notification 'as soon as reasonably possible' after a breach. Build this into your incident plan before you need it.

Document your safeguards. If the Regulator comes asking, evidence of managed backups, endpoint protection and monitoring is your defence.

Encrypt everything. Breach impact drops sharply when stolen data is encrypted — encryption at rest and in transit should be non-negotiable.

Test your recovery. A breach that destroys data is very different from one that copies it. Immutable, tested backups turn a catastrophe into an inconvenience.

Source: ITWeb / DSG Market Insights