Close Menu
    Facebook X (Twitter) Instagram
    • Home
    • Contact Us
    • About Us
    • Privacy Policy
    • Terms Of Service
    • Advertisement
    Tuesday, July 28
    Facebook X (Twitter) Instagram Pinterest Vimeo
    ABS Africa TV
    • Breaking News
    • Trending
    • Africa News
    • World News
    • Features
    • Technology
    • Sports
    • Politics
    • More
      • Culture
      • Lifestyle
      • Travel
      • Business
      • Environment
      • Legal
      • Health
      • Cameroon
      • Ambazonia
      • AfroSingles
      • Environ/Climate
      • Editorial
      • The Leak Magazine
    • Donate
    Subscription
    ABS Africa TV
    Home»Legal»Does Automated Access Trigger POPIA’s Breach Notification?
    Legal

    Does Automated Access Trigger POPIA’s Breach Notification?

    Chris AnuBy Chris AnuJuly 27, 2026No Comments7 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Does Automated Access Trigger POPIA's Breach Notification?
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Post Views: 17

    The Bot In The Room: Does Automated Access Trigger POPIA’s Breach Notification?

    South African data protection law requires organisations to notify regulators and affected individuals when personal information is accessed or acquired by unauthorised persons, but what exactly constitutes “access,” “acquisition,” or “reasonable grounds to believe” a breach has occurred? This analysis examines these undefined legal concepts through the lens of established cybersecurity frameworks and digital forensics practices, exploring how they apply to modern cyber-attacks and automated tools in the co
    South AfricaPrivacy
    To print this article, all you need is to be registered or login on Mondaq.com.
    Article Insights
    Priyanka Raath’s articles from ENS are most popular:

    • in Africa
    • in Africa
    • in Africa
    • with readers working within the Advertising & Public Relations, Banking & Credit and Healthcare industries
    • within Immigration, Media, Telecoms, IT, Entertainment and Criminal Law topic(s)

    Section 22 of the Protection of Personal Information Act, 2013 (“POPIA“) states that organisations must notify the Information Regulator and affected data subjects when “there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person“. But what do these concepts actually mean? POPIA does not define “accessed”, “acquired”, “reasonable grounds to believe”, or “unauthorised person”. Neither the Information Regulator nor the South African courts have clarified them. We must therefore look to established cybersecurity frameworks and digital forensics practices to give these terms meaningful content.

    In this article, we examine these concepts and consider how they apply to modern cyber-attacks, drawing on both POPIA and the Cybercrimes Act, 2020. We do not take a definitive view, but instead, we outline the key considerations organisations should consider when determining whether notification is required.

    Section 22 uses the phrase “accessed or acquired”. These are two separate triggers – you only need to meet one.

    • “Access” means any unauthorised entry into, querying of, or ability to reach personal information. A human does not need to have actually read the data. Forensic signs of access include unusual login activity, privilege escalation, movement into network areas containing personal information, database queries, or data being staged for extraction. The Cybercrimes Act supports this reading — it criminalises “unlawful access” to data and systems, and recognises that access can happen through software, hardware, and automated processes.
    • “Acquisition” sets a higher bar: the unauthorised person must have obtained, copied, downloaded, or taken control of the information. Typical evidence includes outbound data transfers, data appearing on dark-web sites, or ransomware operators publishing proof of theft.

    Because “accessed” and “acquired” are alternatives, an organisation cannot delay notification just because it has not confirmed data was actually taken. Evidence of access alone is enough to trigger the duty to notify.

    If data was staged for extraction but the transfer was stopped, the “accessed” test is likely met even if “acquisition” is unclear. The test is whether there are reasonable grounds to believe access occurred — not forensic certainty.

    Cybersecurity frameworks further reinforce this distinction between access and acquisition, treating the unauthorised transfer of information from a system as conceptually and operationally separate from access to that system. The concept of a “breach” under cybsecurity frameworks are broader than just a “security compromise” under POPIA but still instructive: “the loss of control, compromise, unauthorised disclosure, unauthorised acquisition or a similar occurrence where a person other than an authorised user accesses or potentially accesses personally identifiable information“. This definition is instructive for several reasons. First, it confirms that mere access, or even potential access, is sufficient to constitute a breach. Acquisition is one possible element of the definition but is by no means a prerequisite. Similarly, a data breach has been defined as a cybercrime “where information is accessed or stolen by a cybercriminal without authorisation”, reinforcing the principle that access alone, without theft or exfiltration, is enough to constitute a breach.

    The operational reality of cyberattacks further supports this distinction. Access and exfiltration are separate and sequential phases of an attack. An attacker first gains access to a network or system and only thereafter attempts to exfiltrate data. This sequencing is important to this discussion because many attacks are interrupted between these stages, detected and contained after access has been achieved but before any data has been removed.

    From a digital forensics’ perspective, the artefacts that evidence access are fundamentally different from the artefacts that evidence exfiltration. Access is typically evidenced by login records, privilege escalation logs, database queries, and lateral movement traces. Exfiltration, by contrast, is evidenced by outbound data transfers, data staging for extraction, compression of large datasets and data subsequently appearing on dark-web sites or adversary infrastructure.

    “Reasonable grounds to believe”

    If the available evidence, includingmonitoring, forensics, threat intelligence, or a third-party tip-offwould lead a reasonable person to believe access or acquisition occurred, the notification clock starts. Organisations cannot wait indefinitely for a final forensic report. On the other hand, a blocked attack, failed login, or unpatched vulnerability with no sign of exploitation probably does not meet the threshold.

    “Any unauthorised person” and technology

    An “unauthorised person” is anyone who does not have authority to process the relevant information. This includes individuals, criminal groups, insiders, state-backed hackers, or contractors who exceed their access rights.

    A more complex question is whether automated tools — malware, bots, AI — can themselves be the “person”. We think there is a strong argument that these tools are instruments of an unauthorised person, not persons themselves. The Cybercrimes Act supports this view: it treats unlawful acts using “software or hardware tools” as the responsibility of the person who deployed them.

    Cybersecurity frameworks lend considerable weight to the view that automated tools function as instruments of an unauthorised person rather than as independent actors in their own right. The most comprehensive catalogue of security controls in use globally consistently defines access as being performed by “a user (or a process acting on behalf of a user)”. Automated processes are not treated as autonomous agents under these frameworks, rather, they are regarded as extensions of the human user who initiated or directed them.

    But edge cases exist. What about malware that spreads on its own without ongoing control? Or a self-replicating worm that touches data by accident? Or an AI agent that acts beyond its original instructions? In these situations, the link between a human “person” and the access event is weaker. Organisations will need to assess, on the facts, whether the connection is strong enough to attribute the access to an identifiable person. Reasonable people may disagree. In most cases, this approach avoids an absurd outcome – that because “only” malware accessed a system, no “person” was involved and section 22 does not apply. But each incident must be judged on its own facts.

    Threat-actor toolchains and the kill chain

    Modern cyber attacks use layers of automation: automated scanning to find targets, mass phishing campaigns, tools that map out networks, and high-speed data extraction. The question is not whether a human was present at every step, but whether an unauthorised person started or directed the process that led to the access – and whether that link is close enough on the facts. In a typical ransomware attack, no human actually “reads” the personal information, yet humans have directed every stage. Usually, automation does not break the chain between the person and the breach. But the strength of that chain depends on how much human direction there was, whether the specific data accessed was foreseeable, and how close the link is between what the attacker did and the final access event.

    Section 22 is deliberately broad and technology-neutral, but how it applies will depend on the facts of each case. In most situations, treating automated access as real access — and tools as extensions of the attacker — will best serve POPIA’s purpose of protecting data subjects. This also aligns with the Cybercrimes Act. Until we get clearer guidance from the Regulator or courts, organisations should lean towards a purposive reading of the law. But ultimately, the specific facts, including how much human direction there was and what kind of automated process was involved, will determine whether section 22 applies.

    The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

    Access Automated Does POPIAs trigger
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Chris Anu
    • Website

    Related Posts

    Deep-sea mining talks end without a framework… again

    July 28, 2026

    Trump administration asks US Supreme Court to reinstate mail ballot restrictions: Report

    July 28, 2026

    ChatGPT training was legal and covered by ‘private research’ copyright exception says Indian judge

    July 28, 2026
    Leave A Reply Cancel Reply

    Search
    Latest Post

    Rethinking PANAFEST and EMANCIPATION DAY: Time for Ghana to Reimagine Africa’s homecoming

    July 28, 2026

    Spain wildfire burns campsite to ash, leaving tears and despair

    July 28, 2026

    Zedcrest acquires Leatherback to strengthen global fintech expansion

    July 28, 2026

    Clinicians warn of dangers linked to pre

    July 28, 2026

    Deep-sea mining talks end without a framework… again

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • TikTok
    ABS TV and ABS Network News is a leading Pan-African 24/7 broadcasting network delivering nonstop news, talk shows, lifestyle programs, and digital media content worldwide through Satellite, Streaming Platforms, and Roku TV.
     
    Based in the United States, we connect Africa to the world while empowering creators, journalists, and brands through innovative media and broadcasting services.
    Facebook X (Twitter) Pinterest WhatsApp Instagram

    Our Picks

    Travel

    Rethinking PANAFEST and EMANCIPATION DAY: Time for Ghana to Reimagine Africa’s homecoming

    Spain wildfire burns campsite to ash, leaving tears and despair

    Business

    Zedcrest acquires Leatherback to strengthen global fintech expansion

    Most Popular

    Health

    Clinicians warn of dangers linked to pre

    Legal

    Deep-sea mining talks end without a framework… again

    Lifestyle

    AMVCA-nominated Documentary sparks national reckoning on infertility

    © 2026 Copyright. All Rights Reserved by ABSAFRICATV
    • Privacy Policy
    • Terms of Services

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.