The likeliest answer is No. The information regulator has not said anything about naming and shaming responsible parties who have experienced breaches. The information regulator has also said that their office is very keen to cooperate with responsible parties and not necessarily name and shame them.

You should keep in mind that breach notifications are not only addressed to the information regulator, but to data subjects as well. Both notifications would include the same information. Depending on the nature of the breach, and the amount of data subjects you need to notify, it is possible that these notices are reported into the public domain.

Another thing to take note of here, is that in terms where a responsible party, data subject or any other person asks the information regulator to make an assessment in terms of s89 of POPIA, once the assessment has been completed, the Regulator could publish information on the responsible party’s personal information management practices.