POPIA Data Breach Response Checklist for understanding popia data breach checklist, preparing consultation questions, and comparing related lawyers or law firms.
Prepared byLexuno legal resource team
Time to prepare1-4 hours
Last updatedJune 2026
First response
0/3 completed
Need help with this checklist?
Get support from a lawyer who works with consumer protection matters.
Your business, firm, school, body corporate, NPO, or organisation suspects personal information was lost, accessed, disclosed, encrypted, or sent to the wrong person.
You need to prepare facts before speaking to a privacy lawyer, IT provider, insurer, or Information Regulator contact.
Not For
Replacing incident-response advice, cyber-forensics, notification decisions, insurance advice, or legal advice about a specific breach.
Documents
Incident timeline
System logs
Screenshots
Data-type list
Affected-person estimate
POPIA policy
Operator agreements
Vendor notices
Insurance policy
Notification drafts
Question list
Timeline
Immediately: contain the incident and preserve evidence.
Before consultation: identify data types, affected people, vendors, and decision-makers.
During consultation: confirm notification and remediation route.
Afterwards: maintain an incident log and save notices.
Tips
Keep a decision log from the first day.
Separate confirmed facts from assumptions.
Do not delete logs or tickets casually.
Coordinate legal, IT, insurer, and communications steps.
Warning Signs
ID numbers, financial data, health data, children data, employee files, legal files, passwords, or large datasets may be involved.
A vendor or attacker is involved.
The incident is public or customers are asking questions.
There is no information officer or incident owner identified.
This checklist is for general information only and does not constitute legal advice.