The Salary Spreadsheet Just Went to the Whole Company: Data Breach Steps
It happens in one click: the payroll spreadsheet goes to ‘All Staff’ instead of the bookkeeper, or a laptop with unencrypted salary data disappears from a car. Under POPIA that is a data breach β a security compromise of personal information β and it comes with defined duties: contain, assess, notify, document, prevent. The employers who survive these incidents are the ones with a plan before they need it. Here is that plan, sized for a small business.

- βSalaries, ID numbers and bank details are personal information β a leak is a POPIA data breach.
- βFirst 48 hours: contain, recall what you can, assess scope, and preserve evidence.
- βNotify the Information Regulator and affected data subjects where the breach meets the threshold.
- βDocument everything β your response record matters as much as the fix.
- βMost payroll breaches are process failures: access too wide, no send-check, no encryption.
Why the salary spreadsheet is a data breach
POPIA defines a compromise broadly: any unauthorised access to, or acquisition of, personal information. A payroll file carries the full set β names, ID numbers, bank accounts, salaries, tax references β so its disclosure to people with no business seeing it is squarely a breach, whether it travelled by email, lost device or snooping colleague. Intent does not matter; the accident is still a compromise. Employee monitoring and internal-access questions that often surface alongside are covered in the employee monitoring guide.
The breach clock matters because POPIA expects notification ‘as soon as reasonably possible’ where there are reasonable grounds to believe personal information was compromised. Panicking quietly for three weeks is not a strategy the Act accommodates.
Data breach first response: the 48-hour checklist
- βContain: recall the email, disable the link, revoke access, recover the device β stop the spread first.
- βAssess: whose data, what fields, how many people, how far did it travel? Write it down with timestamps.
- βDecide notification: if there are reasonable grounds to believe a compromise occurred, notify the Information Regulator and the affected data subjects without unreasonable delay.
- βPreserve: keep the evidence β sent items, access logs, the file itself β for the Regulator and your own defence.
- βCommunicate internally: one spokesperson, one consistent message to staff; no blame-storming in writing.
The notification to affected people should be plain and useful: what happened, what data was involved, what you are doing about it, and what they should watch for. The full response structure, including the decision record, is in the data breach response guide.
After the data breach: notification and prevention
Once the dust settles, the Regulator’s follow-up questions are predictable: what security measures existed, who had access, what training happened, what changed since. Your answers should already exist as documents β the privacy notices, the operator agreements, the access list. Then close the loop technically: payroll access restricted to named people, a two-person send-check on anything with salaries, encryption on laptops, and a shared-drive structure that does not put payroll next to the office party photos.
Deleting the sent email from every mailbox before assessing feels like containment but destroys the evidence the Regulator will ask for β and looks like a cover-up. Contain first, but preserve everything.
Breaches are also people events: salaries are emotive, and a leak can damage trust for months. Handle the HR side as deliberately as the legal side. The complete POPIA framework this slots into is in the POPIA pillar guide.
- Information Regulator (South Africa)
- Protection of Personal Information Act
- Department of Employment & Labour
Always confirm current requirements with the official source β rules and deadlines change.
- βAdmin Boss handles registrations, filings and payroll admin
- βRegistered tax practitioner Β· 20+ years experience
- βFully remote β all 9 provinces
Frequently asked questions
Is accidentally emailing salaries to staff a data breach?
Yes. Salaries, ID numbers and bank details are personal information, and unauthorised disclosure β even an accidental internal email β is a security compromise under POPIA with notification duties to the Information Regulator and affected staff.
When must a data breach be reported to the Information Regulator?
As soon as reasonably possible after you have reasonable grounds to believe personal information was compromised. Affected data subjects must also be notified unless their identity cannot be established, with limited exceptions for law-enforcement needs.
What is the first thing to do after a payroll data breach?
Contain it: recall the email or revoke access to stop further spread. Then assess scope β whose data, what fields, how far it travelled β and document everything with timestamps before deciding on notification.
Last reviewed: July 2026 Β· How we research our guides
EmployerGuide.online provides general information about South African employer obligations β not legal, tax or professional advice for your specific situation. Laws, rates and deadlines change; confirm current requirements with the official sources linked above, or ask Admin Boss. See our disclaimer.


