Data Breach Response for Small Businesses: The POPIA 24-Hour Plan
The words ‘data breach‘ summon images of hackers — but the small-business reality is a stolen laptop with the payroll spreadsheet, the salary schedule emailed to the whole staff list, or the ex-bookkeeper whose cloud access nobody revoked. POPIA does not grade breaches by sophistication: if personal information reached unauthorised hands, the notification duties apply. This guide gives you the response plan, hour by hour.

- ✔Breaches must be reported to the Information Regulator AND affected people — as soon as reasonably possible.
- ✔The first hours are for containment: recover, revoke, recall, reset.
- ✔Assess scope honestly: what data, whose, how sensitive, how many people.
- ✔Document the breach and your response — the record is part of compliance.
- ✔Most SME breaches are mundane: lost laptops, wrong recipients, ex-employee access.
What counts as a data breach under POPIA
A breach is any compromise of personal information you hold: unauthorised access, acquisition, use, disclosure, loss or destruction. The hacked server qualifies — but so does the misdirected email, the stolen phone with the staff WhatsApp groups, the CV file left at the printer, the payroll bureau (your operator) leaking your data, and the ex-employee who still logs into shared drives. The question is never ‘was it our fault?’ — it is ‘was personal information compromised?’
If your payroll or HR provider is breached, POPIA still looks to you as the responsible party for notification. Operator agreements (privacy and operators) should oblige providers to inform you immediately — so you can inform the Regulator.
The first 24 hours: contain, assess, document
Notifying the Regulator and the people affected
POPIA requires notification as soon as reasonably possible to two audiences. The Information Regulator gets the formal notification: what happened, the categories and approximate number of data subjects, the likely consequences, and your measures. The affected data subjects get a clear, direct notification — unless their identity cannot be established, in which case public communication — telling them what happened, what information was involved, what you have done, and what they should do (watch bank statements, change passwords, guard against phishing using the leaked details).
Two narrow delays are lawful: where notification would impede a criminal investigation (law enforcement may ask you to hold), and where you need reasonable time to establish the scope. Embarrassment, reputation and busy season are not lawful delays. The notification itself is not an admission of liability — it is the statutory duty, and silence converts a bad week into an enforcement matter.
After the storm: root cause and prevention
- ✓Root cause identified and fixed — not just the symptom
- ✓Access reviews: leavers removed, shared logins eliminated, permissions least-privilege
- ✓Devices encrypted and passwords managed
- ✓Staff briefed — most SME breaches are human, and training is the patch
- ✓Operator agreements checked — did the provider meet its duties?
- ✓Breach register updated and the response plan revised
- ✓Retention schedule enforced — you cannot breach what you destroyed on time (retention guide)
The best breach response is the one written before the breach: a one-page plan naming who contains, who assesses, who notifies, and how. Keep it with your POPIA file next to the information officer registration — because the information officer is the person this plan belongs to. The full framework is in the POPIA pillar guide.
- Information Regulator — breach notification
- POPIA — Act 4 of 2013
- Information Regulator (justice portal)
Always confirm current requirements with the official source — rules and deadlines change.
- ✔Admin Boss handles registrations, filings and payroll admin
- ✔Registered tax practitioner · 20+ years experience
- ✔Fully remote — all 9 provinces
Frequently asked questions
What counts as a data breach under POPIA?
Any unauthorised access, acquisition, use, disclosure, loss or destruction of personal information — from hacked systems to misdirected emails, lost devices, and ex-employees retaining access. Sophistication is irrelevant; compromise is the test.
Who must be notified of a data breach?
The Information Regulator and the affected data subjects, as soon as reasonably possible. Delay is only lawful where law enforcement requires it or reasonable time is needed to establish scope.
Do small breaches need to be reported?
If personal information was compromised, the duty applies — there is no minimum-size exemption in POPIA. The scope and sensitivity shape the response, but the notification duty stands. A breach register entry documents even small incidents.
What if my payroll provider is breached?
As the responsible party you still carry the notification duty to the Regulator and your employees. Your operator agreement should oblige the provider to inform you immediately and cooperate — check it now, not after an incident.
Last reviewed: July 2026 · How we research our guides
EmployerGuide.online provides general information about South African employer obligations — not legal, tax or professional advice for your specific situation. Laws, rates and deadlines change; confirm current requirements with the official sources linked above, or ask Admin Boss. See our disclaimer.