HomeRights by ProvinceGauteng › Personal Data Privacy Breach

Personal Data Privacy Breach in Gauteng

The Protection of Personal Information Act (POPIA) protects your personal data in Gauteng. If a company or government body leaks, misuses, or fails to secure your personal information, you can complain to the Information Regulator and may have a claim for damages.

The Law That Protects You

Protection of Personal Information Act 4 of 2013 (POPIA) — Section 19
Responsible parties must implement appropriate security measures to prevent loss, damage, or unlawful access to personal information.
Protection of Personal Information Act 4 of 2013 (POPIA) — Section 22
A responsible party must notify the Information Regulator and the data subject when there are reasonable grounds to believe a security compromise has occurred.
Protection of Personal Information Act 4 of 2013 (POPIA) — Section 99
A data subject may institute a civil action for damages suffered as a result of a breach of the Act.

What To Do — Step by Step

  1. Step 1. As soon as you discover the breach, document what information was exposed and how you found out.

  2. Step 2. Notify your bank, insurance provider, or other relevant institutions if financial or identity information was compromised.

  3. Step 3. Lodge a complaint with the Information Regulator at inforegulator.org.za or 010 023 5207.

  4. Step 4. Request from the responsible party (the company/institution) details of the breach, what data was affected, and what steps they are taking.

  5. Step 5. If you suffered actual harm (identity theft, financial loss), consult an attorney about a civil damages claim under section 99 of POPIA.

  6. Step 6. If identity documents were compromised, apply for a new ID number at Home Affairs and report identity theft to the SAPS.

Frequently Asked Questions

What is the Information Regulator and what can it do in Gauteng?
The Information Regulator is the independent statutory body that enforces POPIA and PAIA. It can investigate complaints, impose administrative fines of up to R10 million, and refer criminal cases to the NPA.
Does POPIA apply to small businesses in Gauteng?
Yes. POPIA applies to any organisation that processes personal information, regardless of size. However, certain exemptions apply to personal or household use.
Can I get compensation for emotional distress from a data breach in Gauteng?
Section 99 of POPIA allows a data subject to claim damages, which could include general damages for distress, anxiety, or reputational harm, in addition to financial losses.

Legal Resources in Gauteng

📋 CCMA: Johannesburg CCMA (011 377 6650) or Pretoria CCMA (012 843 1000)

⚖️ Legal Aid SA: Legal Aid South Africa — Johannesburg (011 877 2000) or Pretoria (012 325 1726)

🏛️ High Court: Gauteng Division of the High Court (Johannesburg: 011 335 0082 | Pretoria: 012 315 0868)

🏢 Magistrates' Courts: Johannesburg, Pretoria, Randburg, Soweto, Midrand, and other magistrates' courts

🏠 Rental Housing Tribunal: Gauteng Rental Housing Tribunal (011 355 4000)

Gauteng has the highest volume of labour disputes, housing evictions, and consumer complaints in the country. Multiple CCMA regional offices serve the province.