KZN citrus exporter — POPIA + EU buyer audit
A KwaZulu-Natal citrus exporter handling EU buyer data and POPIA-regulated seasonal worker records faced an Information Regulator enquiry after a phishing-led breach exposed roughly 1,800 worker ID numbers. The §22 clock and a parallel EU buyer audit demand both began the same week.
Senior-led 72-hour forensic engagement, POPIA gap remediation against the eight conditions, and an EU GDPR cross-border addendum (Chapter V transfer mechanism) for the buyer relationship.
POPIA §22 notification accepted by the Information Regulator with no enforcement order. EU buyer audit closed favourably. Full POPIA-aligned ISMS in place within 9 weeks; export relationship retained.