HomeBlogWhat to Do When You Have a Data Breach in South Africa (POPIA Response Plan)

What to Do When You Have a Data Breach in South Africa (POPIA Response Plan)

Who to notify, what the notice must contain, and what to do in the first 24 hours. POPIA requires reporting as soon as reasonably possible after discovery.

A breach is broader than being hacked

Section 22 is triggered where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person. That covers far more than a cyber attack:

  • A spreadsheet of customer details emailed to the wrong address
  • A laptop or phone with client records stolen from a car
  • An ex-employee still holding access to a shared inbox
  • A misconfigured folder or storage bucket left publicly readable
  • A supplier telling you their systems were compromised, when your data was on them

The everyday, human version is much more common than the dramatic one, and it carries the same obligation.

First, contain it

Before any notification, stop the bleeding:

  • Disconnect or isolate affected systems
  • Change credentials and revoke tokens and third-party access
  • If information went to a wrong recipient, ask them to delete it and confirm, and record that you did
  • Preserve evidence. Do not wipe logs or rebuild servers before anyone has looked. You will need them, and destroying them looks bad
  • Start a written timeline from the moment of discovery. It is the backbone of everything that follows

Then work out what actually went

The scope determines what you have to say, so establish what categories of information were involved, roughly how many people, whether it was encrypted, whether the exposure is ongoing, and whether any of it was special personal information under section 26 or information about children under section 34. Those raise the stakes considerably.

Notify the Regulator, and the people affected

Section 22 requires notification to both the Information Regulator and the affected data subjects, as soon as reasonably possible after discovering the compromise.

POPIA sets no 72 hour deadline. That is a GDPR rule, and it does not apply here. But "as soon as reasonably possible" is not an invitation to take your time, and a long unexplained gap between discovery and notification is exactly what an investigation focuses on.

Notification may be delayed only in narrow circumstances: where a public body responsible for detecting offences, or the Regulator itself, determines that notifying would impede a criminal investigation. You do not get to delay because the news is embarrassing or because you would rather wait for the full forensic report.

What the notice to data subjects must contain

This is where copied templates go wrong, because they reproduce the GDPR's content list rather than POPIA's. Section 22(5) requires enough information for the person to protect themselves, and specifically:

  • A description of the possible consequences of the compromise
  • A description of the measures you have taken or intend to take to address it
  • A recommendation of what the data subject should do to mitigate the effects
  • If known to you, the identity of the unauthorised person who may have accessed or acquired the information

Note what is not on that list. POPIA does not require you to tell data subjects the approximate number of people affected, which is a GDPR requirement that appears in many South African templates.

How you may communicate it

A point that catches small businesses out in the other direction: you are not obliged to reach every person individually. The notice must be in writing and communicated in at least one of these ways:

  • Mailed to the data subject's last known physical or postal address
  • Emailed to their last known email address
  • Placed in a prominent position on your website
  • Published in the news media
  • As directed by the Regulator

So if your records are incomplete, or the affected group is large and poorly identified, a prominent notice on your website is a lawful route. Direct email remains the better choice when you can do it, because it is what a regulator and a customer would both expect, but the Act gives you options when you genuinely cannot.

Then fix what let it happen

Section 19 requires appropriate, reasonable technical and organisational measures, including identifying reasonably foreseeable risks and verifying that safeguards are effective. After an incident, that verification obligation is not theoretical.

  • Address the specific cause, and write down what you changed
  • Review access: who had it, who needed it, and who still has it after leaving
  • If a supplier was involved, revisit your section 21 operator agreement, which should already oblige them to tell you immediately
  • Keep the incident record. Being able to show a considered response is worth more than claiming it never happened

A note on proportion

You will read that a mishandled breach means fines and prison. That overstates it. Failing to notify is a compliance failure that can lead to an investigation and, if you then ignore an enforcement notice, to an administrative fine. The offences carrying imprisonment are things like obstructing the Regulator or unlawfully dealing in account numbers, not a late notification. POPIA fines and penalties sets out the actual ladder.

The more realistic consequences are civil: under section 99 a data subject may claim damages whether or not there was intent or negligence, and they do not need the Regulator to act first.

Which is the argument for handling it properly rather than quietly. A business that contains an incident, tells people promptly, and explains what it fixed is in a much better position than one that hoped nobody would notice.

POPIA Ready generates a privacy policy that sets out how you handle personal information, a PAIA manual and five other documents, free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at August 2026, not legal advice. A live incident involving special personal information, children's data or a large affected group deserves immediate professional advice.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Your WhatsApp Messages Are Records You Must Keep for Five Years

Read article →

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →