Every organisation that processes personal information in South Africa is a responsible party under POPIA, and every responsible party will, at some point, face a suspected breach. What separates a managed incident from a reportable failure is not whether it happens, but how quickly and defensibly you respond.

Does POPIA require breach notification within 72 hours?

Direct answer

Not literally. POPIA (Section 22) requires notification “as soon as reasonably possible” after a compromise is discovered. It does not fix a 72-hour deadline. The 72-hour figure is borrowed from the EU’s GDPR and has become a practical industry benchmark. Treat it as a target, not the letter of the law.

The Act deliberately avoids a hard clock because circumstances vary. But “as soon as reasonably possible” is not an invitation to delay. The Information Regulator expects you to notify without undue holdup once you have grounds to believe a breach occurred, and only permits a delay where law enforcement needs it to protect an investigation.

Who must you notify after a data breach?

Direct answer

Two parties: the Information Regulator, and each affected data subject whose personal information was compromised. Notification to data subjects must be in writing and detailed enough for them to protect themselves.

Your notification to data subjects must describe the possible consequences of the breach, the measures you intend to take (or have taken) to address it, what the person can do to mitigate harm, and, if known, the identity of whoever accessed the data. Vague, reassuring statements do not meet the standard.

What should a POPIA breach response plan include?

Direct answer

A defensible plan covers six things: detection and triage, severity assessment, containment, pre-drafted notification templates, an evidence and decision log, and a post-incident review. The evidence log is what proves you acted “as soon as reasonably possible”.

  • Detection & triage: how a suspected breach is raised, and who owns the decision within the first hour.
  • Severity assessment: a consistent method to judge scope, sensitivity and likely harm.
  • Containment: pre-agreed actions to stop the bleeding without destroying forensic evidence.
  • Notification templates: drafts for the Regulator and data subjects, so legal review is fast, not from scratch.
  • Evidence & decision log: a timestamped record of what you knew and when you acted.
  • Post-incident review: the lessons that feed back into controls and the next assessment.
“The organisations that come through a breach well are the ones that decided how they’d respond long before it happened.”

How can Resilitech help?

Direct answer

We build and test POPIA-aligned incident readiness, response plans, tabletop exercises and evidence logging, and provide the independent assurance your board and the Regulator will look for. When something does happen, our retained clients have a plan and a partner on call.

Readiness is cheaper than response. A short tabletop exercise usually surfaces the gaps that matter: unclear ownership, missing templates, no evidence trail, all while there’s still time to fix them calmly.