Last materially reviewed: September 3, 2026
Direct Answer
When a personal data breach occurs, the organization should contain the incident, preserve evidence, assess the affected data and risk, decide whether mandatory notification is triggered, notify the NPC and affected data subjects when required, and document corrective action.
Immediate Response Checklist
- Activate the security incident response team.
- Contain affected accounts, systems and access paths.
- Preserve logs, timestamps, messages and forensic evidence.
- Identify what personal data was affected.
- Estimate the number and type of data subjects affected.
- Determine whether an unauthorized person likely acquired the data.
- Assess the risk of serious harm.
- Document the time the organization first knew or reasonably believed a breach occurred.
Notification Checklist
NPC guidance states that mandatory notification applies when all required elements are present, including sensitive or identity-fraud-enabling information, likely unauthorized acquisition, and a real risk of serious harm. Where mandatory notification applies, the current DBNMS process uses a 72-hour window.
- Prepare the Personal Data Breach Notification in DBNMS.
- Notify affected data subjects where required.
- Explain the breach, likely consequences and mitigation steps.
- Provide contact details for further information.
- Keep records supporting the notification decision.
After Containment
- reset credentials and revoke compromised sessions;
- patch the vulnerability or close the process gap;
- review vendor involvement;
- update controls and policies;
- conduct lessons-learned review;
- include non-mandatory incidents in required security-incident reporting where applicable.
For a fuller explanation, see What Should a Company Do After a Personal Data Breach?.
