Breach Response

What to do after a data breach in South Africa

A breach alert does not always mean identity theft has happened, but it is a signal to act quickly and calmly.

Key takeaways
  • Change reused passwords and add multi-factor authentication where available.
  • Watch for calls or messages that ask for codes or account details.
  • Use privacy requests where you need clarity, correction, objection, or deletion where legally available.

First, understand what was exposed

A breach may expose an email address, phone number, password, physical address, identity number, account history, or other personal details. The risk depends on what was exposed and whether the same details are reused elsewhere.

Immediate steps

POPIA and breach notifications

POPIA requires responsible parties to take security safeguards seriously and to notify affected people and the Information Regulator in certain breach situations. The notice should help you understand what happened, what information was affected, and what steps are recommended.

Privacy requests after a breach

Depending on the context, you may ask an organisation what information it holds, request correction of inaccurate information, object to certain processing, or request deletion where legally available. You can also ask for clarity on the source of your information if marketing or broker records appear after a breach.

How DataRights helps

DataRights helps users monitor breach exposure, understand likely data categories, submit requests to covered data holders, and track responses. It does not guarantee removal from every system, but it gives customers a structured way to reduce unnecessary exposure and record evidence.

Related guides

Check your exposure signals

Run a free scan to see likely exposure categories, or view pricing for ongoing monitoring and request tracking.

Run Free Scan View Pricing