Verified data-protection context · South Africa / Information Regulator POPIA 2022/2023–2024/2025
South Africa Information Regulator POPIA security-compromise notification and enforcement context
Market context — not industry-specific evidence
Information Regulator South Africa annual reports (2023/2024 and 2024/2025) state that the Information Regulator received 590 POPIA security compromise notifications in the 2022/2023 financial year, 1,727 in the 2023/2024 financial year, and 2,374 in the 2024/2025 financial year. The Information Regulator also issued 5 enforcement notices in respect of POPIA investigations and assessments in the 2024/2025 financial year. These figures are reported under the Information Regulator's POPIA / personal-information protection mandate and must not be presented as confirmed compromises, successful attacks, or all cyber incidents in South Africa. Year-to-year growth in notification volume may reflect regulatory maturity, awareness growth, portal changes, and changes in notification behaviour — not only changes in underlying attack volume.
POPIA security-compromise notifications received — South Africa 2022/2023 to 2024/2025
- 2022/2023 financial year — 590 POPIA security compromise notifications received
- 590
- Unit
- security compromise notifications received by the Information Regulator in the 2022/2023 financial year
- Period
- South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context.
- Scope
- South Africa Information Regulator POPIA security-compromise notification context
- 2023/2024 financial year — 1,727 POPIA security compromise notifications received
- 1,727
- Unit
- security compromise notifications received by the Information Regulator in the 2023/2024 financial year
- Period
- South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context.
- Scope
- South Africa Information Regulator POPIA security-compromise notification context
- 2024/2025 financial year — 2,374 POPIA security compromise notifications received
- 2,374
- Unit
- security compromise notifications received by the Information Regulator in the 2024/2025 financial year
- Period
- South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context.
- Scope
- South Africa Information Regulator POPIA security-compromise notification context
Source: Information Regulator South Africa, annual reports for 2023/2024 and 2024/2025 financial years. Notifications received under the Information Regulator's POPIA mandate.
South Africa Information Regulator POPIA security-compromise notification context only. The 590, 1,727, and 2,374 values are security compromise notifications received by the Information Regulator for the stated financial years and must not be presented as confirmed compromises, confirmed breaches, successful attacks, unique affected organisations, unique affected data subjects, or all cyber incidents in South Africa. Year-to-year growth in notification volume may reflect regulatory maturity, awareness growth, portal changes, and notification behaviour changes and must not be presented as proof that actual national cyberattack volume increased at the same rate.
Enforcement notices issued in respect of POPIA investigations and assessments — South Africa 2024/2025
- 5 enforcement notices issued in respect of POPIA investigations and assessments in the 2024/2025 financial year
- 5
- Unit
- enforcement notices issued in respect of POPIA investigations and assessments in the 2024/2025 financial year
- Period
- South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context.
- Scope
- South Africa Information Regulator POPIA security-compromise notification context
Source: Information Regulator SA Annual Report for the year ended 31 March 2025.
South Africa Information Regulator POPIA enforcement context only. The 5 enforcement notices value refers to enforcement notices issued in respect of POPIA investigations and assessments in the 2024/2025 financial year and must not be presented as five resolved incidents, five confirmed cyberattacks, five certified organisations, or five protected organisations.
Source: Information Regulator South Africa, Annual Report for the year ended 31 March 2025, 2025
Scope: Information Regulator South Africa, Annual Report for 2023/24 Financial Year and Annual Report for the year ended 31 March 2025. The 590, 1,727, and 2,374 values are security compromise notifications received by the Information Regulator for the stated financial years and must not be presented as confirmed compromises, confirmed breaches, successful attacks, unique affected organisations, unique affected data subjects, criminal case counts, or all cyber incidents in South Africa. These metrics are reported under the Information Regulator's POPIA mandate and must not be presented as general cybersecurity incidents, a national cyber incident registry, or a South African CSIRT incident registry. Year-to-year increases in notification volumes may reflect regulatory maturity, awareness growth, portal changes, and changes in notification behaviour — not only changes in underlying attack volume. The 5 enforcement notices value refers to enforcement notices issued in respect of POPIA investigations and assessments in 2024/2025 and must not be presented as five resolved incidents, five confirmed cyberattacks, five certified organisations, or five protected organisations. Do not present any admitted indicator as total South African cybercrime prevalence, total business incident prevalence, hidden incident prevalence, all-sector incident rate, breached-organisation count, resolved incident count, protected-organisation count, compliance achievement, certification, proof of security, or guaranteed protection.
Methodology: Official Information Regulator South Africa annual report statistics published under the Information Regulator's POPIA / personal-information protection mandate. This source covers the 2024/2025 financial year (2,374 notifications and 5 enforcement notices). The 2,374 value is security compromise notifications received by the Information Regulator in the 2024/2025 financial year and must not be presented as confirmed compromises, confirmed breaches, successful attacks, unique affected organisations, unique affected data subjects, or criminal case counts. These metrics are reported under the Information Regulator's POPIA mandate and must not be presented as general cybersecurity incidents or all cyber incidents in South Africa. Year-to-year increases in notification volumes may reflect regulatory maturity, awareness growth, portal changes, and changes in notification behaviour — not only changes in underlying attack volume. Do not present any increase as proof that actual national cyberattack volume increased at the same rate. The 5 enforcement notices metric refers to enforcement notices issued in respect of POPIA investigations and assessments in the 2024/2025 financial year and must not be presented as five resolved incidents, five confirmed cyberattacks, five certified organisations, or five protected organisations. Do not present any admitted indicator as a national cyber incident registry, South African CSIRT incident registry, confirmed cyberattack count, total South African cybercrime prevalence, total business incident prevalence, hidden incident prevalence, all-sector incident rate, breached-organisation count, resolved incident count, protected-organisation count, compliance achievement, certification, proof of security, or guaranteed protection.
Accessible data table
| Metric | Value | Source | Scope | Reporting period |
|---|---|---|---|---|
| 2022/2023 financial year — 590 POPIA security compromise notifications received | 590 security compromise notifications received by the Information Regulator in the 2022/2023 financial year | Information Regulator South Africa, Annual Report for the year ended 31 March 2025, 2025 | South Africa Information Regulator POPIA security-compromise notification context | South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context. |
| 2023/2024 financial year — 1,727 POPIA security compromise notifications received | 1,727 security compromise notifications received by the Information Regulator in the 2023/2024 financial year | Information Regulator South Africa, Annual Report for the year ended 31 March 2025, 2025 | South Africa Information Regulator POPIA security-compromise notification context | South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context. |
| 2024/2025 financial year — 2,374 POPIA security compromise notifications received | 2,374 security compromise notifications received by the Information Regulator in the 2024/2025 financial year | Information Regulator South Africa, Annual Report for the year ended 31 March 2025, 2025 | South Africa Information Regulator POPIA security-compromise notification context | South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context. |
| 5 enforcement notices issued in respect of POPIA investigations and assessments in the 2024/2025 financial year | 5 enforcement notices issued in respect of POPIA investigations and assessments in the 2024/2025 financial year | Information Regulator South Africa, Annual Report for the year ended 31 March 2025, 2025 | South Africa Information Regulator POPIA security-compromise notification context | South Africa Information Regulator 2024/2025 financial year POPIA security-compromise notification and enforcement-notice context. |
