Article
The Bot In The Room: Does Automated Access Trigger POPIA's Breach Notification?
South African data protection law requires organisations to notify regulators and affected individuals when personal information is accessed or acquired by unauthorised persons, but what exactly constitutes "access," "acquisition," or "reasonable grounds to believe" a breach has occurred? This analysis examines these undefined legal concepts through the lens of established cybersecurity frameworks and digital forensics practices, exploring how they apply to modern cyber-attacks and automated tools in the co
ENS