POPI ACT RESPONSIBILITY TO KEEP CUSTOMER PERSONAL INFORMATION SECURE

Dear Sage City

Do I have a duty towards my customers if someone not only gained illegal access to their personal information but also changed it. This happened in June and Sage can still not explain who did it and how they gained access to sage and there is no audit report that shows it was changed and by which user.

Do I have an obligation in terms of POPIA to disclose this to my effected customers? And currently to secure their information I will have to get a different service provider?

This is serious and I used a sage audit reports in court a while ago claiming that it cannot be incorrect.

Sage reference no HD14673808

I will have to move their companies to quick books