Data Breach Response Plan
This plan outlines the steps SilverStream Digital will take in the event of a security compromise involving personal information, as required by POPIA Section 22.
Step 1 — Identify and contain the breach
Upon becoming aware of a potential security compromise, the following steps must be taken immediately:
- Immediately notify Vernon Ready — the designated Information Officer
- Isolate affected systems to prevent further unauthorised access
- Preserve all evidence — do not delete or alter any logs or files
- Document the date, time and nature of the breach
- Identify what personal information was involved and how many data subjects are affected
Step 2 — Assess the risk
- Determine the nature and extent of the personal information compromised
- Assess the likelihood of harm to affected data subjects
- Identify whether the breach involves special personal information (health, biometric, financial data)
- Determine whether the breach is likely to result in significant harm to data subjects
Step 3 — Notify the Information Regulator
As required by POPIA Section 22 and the Information Regulator’s 2025 eServices Portal requirement, notify the Information Regulator as soon as reasonably possible via:
Information Regulator eServices Portal
Website: www.justice.gov.za/inforeg
Email: inforeg@justice.gov.za
Your notification must include: nature of the breach, personal information involved, number of data subjects affected, and steps taken to address the breach.
Step 4 — Notify affected data subjects
Notify all affected data subjects as soon as reasonably possible. The notification must include:
- A description of the possible consequences of the security compromise
- A description of the measures being taken to address the breach
- Recommendations for steps data subjects can take to protect themselves
- Contact details of the Information Officer: support@silverstreamdigital.co.za
Step 5 — Remediate and review
- Fix the vulnerability that caused the breach
- Document all actions taken and decisions made throughout the incident
- Review and update security measures to prevent future breaches
- Conduct a post-incident review and update this Response Plan if necessary
- Retain all breach-related documentation for audit purposes