Data Breach Response for Small Businesses: The POPIA 24-Hour Plan

⚡ Quick answer
Under POPIA, a data breach — personal information accessed or acquired by an unauthorised person — must be reported to the Information Regulator and to the affected data subjects as soon as reasonably possible. For a small business the response is: contain the breach in the first hours (recover the device, kill the access, recall the email if possible), assess what information and whose, notify the Regulator and the affected people with the details and your remediation, document everything, and fix the root cause. Notification can be delayed only where law enforcement needs it — embarrassment is not a lawful reason.

The words ‘data breach‘ summon images of hackers — but the small-business reality is a stolen laptop with the payroll spreadsheet, the salary schedule emailed to the whole staff list, or the ex-bookkeeper whose cloud access nobody revoked. POPIA does not grade breaches by sophistication: if personal information reached unauthorised hands, the notification duties apply. This guide gives you the response plan, hour by hour.

Data breach response — POPIA notification duties and 24-hour response plan for small businesses
Data Breach Response for Small Businesses: The POPIA 24-Hour Plan
📌 Key takeaways
  • Breaches must be reported to the Information Regulator AND affected people — as soon as reasonably possible.
  • The first hours are for containment: recover, revoke, recall, reset.
  • Assess scope honestly: what data, whose, how sensitive, how many people.
  • Document the breach and your response — the record is part of compliance.
  • Most SME breaches are mundane: lost laptops, wrong recipients, ex-employee access.

What counts as a data breach under POPIA

A breach is any compromise of personal information you hold: unauthorised access, acquisition, use, disclosure, loss or destruction. The hacked server qualifies — but so does the misdirected email, the stolen phone with the staff WhatsApp groups, the CV file left at the printer, the payroll bureau (your operator) leaking your data, and the ex-employee who still logs into shared drives. The question is never ‘was it our fault?’ — it is ‘was personal information compromised?’

ℹ️ Your operator's breach is your notification
If your payroll or HR provider is breached, POPIA still looks to you as the responsible party for notification. Operator agreements (privacy and operators) should oblige providers to inform you immediately — so you can inform the Regulator.

The first 24 hours: contain, assess, document

1
Contain
Stop the bleeding: remote-wipe or recover the device, revoke the access, recall or retract the email where possible, change the passwords, suspend the compromised account. Speed here shrinks the breach.
2
Assess
What information was involved, whose, how many people, how sensitive (ID numbers and banking details rate high; special personal information rates highest), and is misuse likely? This assessment drives every later decision.
3
Document
Timeline, what happened, what was compromised, what you did and when. The breach register entry starts now — the Regulator expects it, and your memory will not survive the month.
4
Decide notification
If personal information was compromised, notification duties apply. Assemble the facts for the Regulator and the affected individuals.

Notifying the Regulator and the people affected

POPIA requires notification as soon as reasonably possible to two audiences. The Information Regulator gets the formal notification: what happened, the categories and approximate number of data subjects, the likely consequences, and your measures. The affected data subjects get a clear, direct notification — unless their identity cannot be established, in which case public communication — telling them what happened, what information was involved, what you have done, and what they should do (watch bank statements, change passwords, guard against phishing using the leaked details).

Two narrow delays are lawful: where notification would impede a criminal investigation (law enforcement may ask you to hold), and where you need reasonable time to establish the scope. Embarrassment, reputation and busy season are not lawful delays. The notification itself is not an admission of liability — it is the statutory duty, and silence converts a bad week into an enforcement matter.

After the storm: root cause and prevention

  • Root cause identified and fixed — not just the symptom
  • Access reviews: leavers removed, shared logins eliminated, permissions least-privilege
  • Devices encrypted and passwords managed
  • Staff briefed — most SME breaches are human, and training is the patch
  • Operator agreements checked — did the provider meet its duties?
  • Breach register updated and the response plan revised
  • Retention schedule enforced — you cannot breach what you destroyed on time (retention guide)

The best breach response is the one written before the breach: a one-page plan naming who contains, who assesses, who notifies, and how. Keep it with your POPIA file next to the information officer registration — because the information officer is the person this plan belongs to. The full framework is in the POPIA pillar guide.

📚 Official sources & references

Always confirm current requirements with the official source — rules and deadlines change.

Free tool by Admin Boss
🧭 Business Compliance Dashboard
Check which registrations and submissions your business still needs — free, instant, online.
Try the free tool →
Done-for-you by Admin Boss
Rather hand this over?
  • Admin Boss handles registrations, filings and payroll admin
  • Registered tax practitioner · 20+ years experience
  • Fully remote — all 9 provinces
Send us your question →Visit Admin Boss ↗📞 074 918 7130 (Mon–Fri 08:00–16:00)

Frequently asked questions

What counts as a data breach under POPIA?

Any unauthorised access, acquisition, use, disclosure, loss or destruction of personal information — from hacked systems to misdirected emails, lost devices, and ex-employees retaining access. Sophistication is irrelevant; compromise is the test.

Who must be notified of a data breach?

The Information Regulator and the affected data subjects, as soon as reasonably possible. Delay is only lawful where law enforcement requires it or reasonable time is needed to establish scope.

Do small breaches need to be reported?

If personal information was compromised, the duty applies — there is no minimum-size exemption in POPIA. The scope and sensitivity shape the response, but the notification duty stands. A breach register entry documents even small incidents.

What if my payroll provider is breached?

As the responsible party you still carry the notification duty to the Regulator and your employees. Your operator agreement should oblige the provider to inform you immediately and cooperate — check it now, not after an incident.

AB
Written and reviewed by Andre van Niekerk — registered tax practitioner and founder of Admin Boss, with 20+ years helping South African businesses with SARS, CIPC and labour-department compliance.
Last reviewed: July 2026 · How we research our guides

EmployerGuide.online provides general information about South African employer obligations — not legal, tax or professional advice for your specific situation. Laws, rates and deadlines change; confirm current requirements with the official sources linked above, or ask Admin Boss. See our disclaimer.