Use this form to report a personal information security compromise. Your report is recorded in the organisation's breach register for the Information Officer.
Provide as much detail as you can. The Information Officer will assess risk, containment, and notification duties under POPIA Section 22 and EDPB guidance. Do not include unnecessary full personal data of affected individuals in free-text fields.
Record when and how the organisation became aware of the incident (EDPB Art. 33 / POPIA S22).