Data Breach Response Policy
This is a placeholder Data Breach Response Policy. Replace this text from the admin Legal Content page with a policy reviewed against POPIA section 22 (notification of security compromises) before launch. At minimum it should define what counts as a security compromise (any unauthorised access to or acquisition of personal information), require immediate containment and an internal incident log the moment one is suspected, require notification to the Information Regulator and to every reasonably identifiable affected data subject "as soon as reasonably possible" after discovery (POPIA sets no fixed number of days — reasonableness is assessed case by case, so a short internal SLA target, e.g. 72 hours to Regulator notification, is strongly recommended practice), and specify what the notification itself must contain: a description of the possible consequences, the measures LaProfy has taken or intends to take, and a recommendation of what affected individuals can do to mitigate harm.
Until a reviewed policy replaces this placeholder, incident response is undocumented — this should be treated as a priority item, not a formality.
