How to Handle a Data Breach Under POPIA.

A practical response guide for South African business owners and compliance managers.

Published: 24 August 2026  |  By AOLC

A data breach is not just a technical problem — it is a legal and reputational crisis that starts a clock the moment your systems are compromised. Under the Protection of Personal Information Act (POPIA), South African businesses have specific obligations when personal information is lost, stolen, or accessed without authorisation. Those obligations are time-bound, and failing to meet them can result in fines of up to R10 million or criminal prosecution under Section 107.

The good news is that a structured response — one you plan before anything goes wrong — dramatically reduces the damage. Whether the breach was a ransomware attack, a phishing compromise, a lost laptop, or an accidental email to the wrong recipient, the steps are largely the same. This guide walks you through exactly what to do, step by step.

Under Section 22 of POPIA, once you become aware of a security compromise involving personal information, you are required to notify the Information Regulator and affected data subjects "as soon as reasonably possible" — not after your legal team has finished deliberating.

What Counts as a Data Breach Under POPIA.

POPIA defines a security compromise broadly: it is the unauthorised access to, or acquisition, interference, modification, destruction, disclosure, or use of personal information. This covers a wide range of incidents that many South African businesses would not immediately recognise as reportable breaches:

If you are uncertain whether an incident meets the threshold, treat it as a reportable breach and document your reasoning. The cost of unnecessary caution is a few hours of administration. The cost of missing a required notification is far greater.

R10M

Maximum fine the Information Regulator can impose for a POPIA violation. Section 107 also allows for up to 10 years' imprisonment for the most serious offences.

Your First 72 Hours — What to Do.

While POPIA does not prescribe a specific time window (the European GDPR uses 72 hours), the "as soon as reasonably possible" language means you need to move quickly — days, not weeks. The moment you suspect a breach, activate the following steps:

Tip

Start your breach log the moment you discover the incident. Record the discovery date and time, every action taken, and who made each decision. The Information Regulator may request this log as part of its investigation — it also demonstrates that you responded in good faith.

Notifying the Information Regulator.

Section 22 of POPIA requires the responsible party — that is, the business or organisation that collected and holds the personal information — to notify the Information Regulator of South Africa. The Regulator is contactable at inforeg.org.za and accepts notifications by email (complaints.IR@justice.gov.za) or through its online portal.

Your notification to the Regulator must include:

You may submit an initial notification before all details are known, and follow up with a supplementary report as the investigation progresses. Do not delay the initial notification waiting for a complete picture.

48h

Target window to make your initial notification to the Information Regulator after discovery. Follow up with additional detail as your investigation progresses.

Notifying the People Affected.

Alongside notifying the Regulator, POPIA requires you to notify the affected data subjects — the real people whose information was compromised. This is often the harder conversation. You may not want to alarm clients or employees unnecessarily, but delayed notification exposes them to harm they cannot protect themselves against, and it exposes you to greater legal risk.

Notifications to affected data subjects must include:

Notification can be made by email, letter, SMS, or a prominent notice on your website if the number of affected people makes individual outreach impractical. If you cannot reach some data subjects directly, the Regulator may allow a general public notice.

Do not wait until your investigation is complete before telling affected individuals. An honest, partial notification with a commitment to provide further updates is far better — legally and ethically — than silence while your legal team deliberates for two weeks.

What You Must Document.

Good record-keeping serves two purposes in a breach response: it demonstrates to the Regulator that you acted appropriately, and it gives your own team the information needed to prevent a recurrence. Your breach log should capture:

Retain this documentation for at least three years. If the Regulator investigates, this record is your primary evidence of a good-faith response.

After the Breach — Preventing the Next One.

Once the immediate crisis is contained and notifications are complete, the real work begins. Every breach is a window into a gap in your controls — and that gap almost certainly still exists. A thorough post-incident review should answer three questions: How did this happen? What would have stopped it? What do we change now?

Common improvements South African businesses make after a breach:


Breach Response Checklist.

Use this checklist to guide your response the moment a breach is suspected:

Tip

Do not wait for a breach to find out whether you have a response plan. Run a tabletop exercise with your team — walk through a hypothetical phishing incident and see where the process breaks down. An hour of planning now is worth far more than a week of crisis management later.

Get Ahead of Your Next Breach.

Our team can assess your data protection posture, build a breach response plan, and help you close the gaps before the Information Regulator comes knocking.

Book a Security Assessment

← Back to Blog