Data Breach Response Plan

Legally Required

Data Breach Response Plan

This plan outlines the steps SilverStream Digital will take in the event of a security compromise involving personal information, as required by POPIA Section 22.

Version date: 21 September 2026
Requirement: POPIA Section 22

Step 1 — Identify and contain the breach

Upon becoming aware of a potential security compromise, the following steps must be taken immediately:

  • Immediately notify Vernon Ready — the designated Information Officer
  • Isolate affected systems to prevent further unauthorised access
  • Preserve all evidence — do not delete or alter any logs or files
  • Document the date, time and nature of the breach
  • Identify what personal information was involved and how many data subjects are affected

Step 2 — Assess the risk

  • Determine the nature and extent of the personal information compromised
  • Assess the likelihood of harm to affected data subjects
  • Identify whether the breach involves special personal information (health, biometric, financial data)
  • Determine whether the breach is likely to result in significant harm to data subjects

Step 3 — Notify the Information Regulator

As required by POPIA Section 22 and the Information Regulator’s 2025 eServices Portal requirement, notify the Information Regulator as soon as reasonably possible via:

Information Regulator eServices Portal

Website: www.justice.gov.za/inforeg

Email: inforeg@justice.gov.za

Your notification must include: nature of the breach, personal information involved, number of data subjects affected, and steps taken to address the breach.

Step 4 — Notify affected data subjects

Notify all affected data subjects as soon as reasonably possible. The notification must include:

  • A description of the possible consequences of the security compromise
  • A description of the measures being taken to address the breach
  • Recommendations for steps data subjects can take to protect themselves
  • Contact details of the Information Officer: support@silverstreamdigital.co.za

Step 5 — Remediate and review

  • Fix the vulnerability that caused the breach
  • Document all actions taken and decisions made throughout the incident
  • Review and update security measures to prevent future breaches
  • Conduct a post-incident review and update this Response Plan if necessary
  • Retain all breach-related documentation for audit purposes