The Wedding Studio · a division of Regi Health Pty Ltd · Last updated 19 July 2026
1. INTRODUCTION
1.1 The Wedding Studio ("we", "us", "our") is committed to protecting the personal information of our Clients, Guests, and website visitors.
1.2 This Data Breach Response Plan ("Plan") outlines the procedures we will follow in the event of a data breach involving personal information.
1.3 This Plan ensures that we:
- Respond quickly and effectively to a breach
- Comply with the South African Protection of Personal Information Act (POPIA)
- Protect the rights and interests of affected individuals
- Minimise harm and prevent future breaches
1.4 This Plan should be read together with our:
- Terms and Conditions
- Privacy Policy
- POPIA Compliance Statement
- Cookies Policy
2. WHAT IS A DATA BREACH?
2.1 A data breach is any incident where personal information is:
- Lost
- Stolen
- Destroyed
- Damaged
- Altered
- Unlawfully accessed
- Unlawfully disclosed
- Made available to unauthorised persons
2.2 Examples of data breaches include:
- Hacking or cyberattack
- Unauthorised access to our systems
- Accidental loss of data (e.g., lost device)
- Insider threat (employee or contractor)
- Phishing or social engineering attacks
- Human error (e.g., misdirected email)
- Physical theft (e.g., stolen laptop or server)
2.3 Under POPIA Section 22, we are legally required to notify the South African Information Regulator and affected individuals if a breach is likely to result in harm.
3. OBJECTIVES OF THIS PLAN
3.1 The objectives of this Plan are to:
- Detect a breach as quickly as possible
- Contain the breach to prevent further damage
- Assess the impact and risk to affected individuals
- Notify affected individuals and the Information Regulator
- Mitigate harm to affected individuals
- Investigate the cause of the breach
- Prevent future breaches through corrective action
- Document all steps taken for compliance and learning
4. RESPONSE TEAM
4.1 The following individuals are responsible for managing a data breach:
| Role | Name | Responsibility |
|---|
| Information Officer | Vince Willett | Overall responsibility for breach response, notification to Regulator, and communication |
| Deputy Information Officer | Gideon van der Merwe | Assists the Information Officer and acts in their absence |
4.2 The Information Officer is the primary point of contact for all breach-related matters.
4.3 If the Information Officer is unavailable, the Deputy Information Officer will assume responsibility.
5. BREACH RESPONSE PROCEDURE
The following steps must be followed in the event of a data breach:
- Step 1: Detection and Reporting
- Who: Any employee, contractor, or third-party provider who becomes aware of a potential breach.
Action:
Immediately notify the Information Officer at:
- Email: info@theweddingstudio.co
- Phone: 079 471 9268
- Do not attempt to investigate or fix the breach independently unless instructed.
- Preserve all evidence (e.g., logs, screenshots, emails) for investigation.
- Timeline: Immediate – within 1 hour of detection.
- Step 2: Containment
- Who: Information Officer and Deputy Information Officer.
Action:
- Identify the source and scope of the breach.
- Take immediate steps to stop further unauthorised access or data loss.
- Isolate affected systems (e.g., disconnect from network, disable compromised accounts).
- Secure physical areas if applicable.
- Change passwords, revoke access, or implement emergency patches.
- Timeline: Within 2–4 hours of detection.
- Step 3: Assessment and Investigation
- Who: Information Officer and Deputy Information Officer.
Action:
- Determine what personal information was compromised.
- Determine how many individuals are affected.
- Determine the cause of the breach.
- Assess the risk of harm to affected individuals.
- Assess whether the breach is likely to result in harm (POPIA Section 22).
Key Questions to Answer:
- What type of personal information was compromised?
- Who was affected?
- How did the breach occur?
- Was the breach deliberate or accidental?
- Is the data encrypted or otherwise protected?
- Has the data been accessed or used by unauthorised persons?
- What is the potential harm to affected individuals?
- Timeline: Within 12–24 hours of detection.
- Step 4: Notification to Affected Individuals
- Who: Information Officer.
Action:
If the breach is likely to result in harm, notify affected individuals as soon as reasonably possible.
Notification must include:
- Description of the breach
- Type of personal information affected
- Measures taken to mitigate harm
- Advice on steps individuals can take to protect themselves
- Contact details of the Information Officer
Notification Methods:
- Direct communication (email, WhatsApp, SMS)
- Public notice (if direct communication is not possible)
- Timeline: As soon as reasonably possible, but no later than 72 hours from becoming aware of the breach.
- Step 5: Notification to the Information Regulator
- Who: Information Officer.
Action:
If the breach is likely to result in harm, notify the South African Information Regulator.
Provide details of:
- The breach
- The personal information affected
- The number of individuals affected
- Measures taken to mitigate harm
- Contact details of the Information Officer
Regulator Contact Details:
- Website: https://www.justice.gov.za/inforeg/
- Email: inforeg@justice.gov.za
- Phone: 012 406 4818
- Timeline: As soon as reasonably possible, but no later than 72 hours from becoming aware of the breach.
- Step 6: Mitigation and Remediation
- Who: Information Officer and Deputy Information Officer.
Action:
- Take all reasonable steps to reduce the risk of harm to affected individuals.
- Offer support to affected individuals (e.g., advice on monitoring accounts).
- Restore affected systems securely.
- Implement additional security measures to prevent recurrence.
Examples of Mitigation:
- If passwords were compromised, advise individuals to change passwords.
- If financial data was compromised, advise individuals to monitor bank accounts.
- If identity theft is possible, advise individuals to register for credit monitoring.
- Timeline: Ongoing – as soon as possible.
- Step 7: Investigation and Root Cause Analysis
- Who: Information Officer and Deputy Information Officer.
Action:
- Conduct a detailed investigation to determine the root cause of the breach.
- Identify vulnerabilities that allowed the breach to occur.
- Assess whether internal policies or procedures contributed to the breach.
- Timeline: Within 7–14 days of the breach.
- Step 8: Corrective Action and Prevention
- Who: Information Officer and Deputy Information Officer.
Action:
- Implement corrective actions to address vulnerabilities and prevent future breaches.
- Update security measures, policies, and procedures as needed.
- Provide training to staff on data protection and breach prevention.
Examples of Corrective Action:
- Patch software vulnerabilities
- Strengthen access controls
- Implement multi-factor authentication (MFA)
- Update privacy and security policies
- Conduct regular security audits
- Timeline: Within 30 days of the breach.
- Step 9: Documentation and Record-Keeping
- Who: Information Officer.
Action:
Maintain a detailed record of the breach, including:
- Date and time of detection
- Description of the breach
- Type of personal information affected
- Number of individuals affected
- Root cause analysis
- Steps taken to contain, notify, and remediate
- Corrective actions implemented
- Retain records for at least 3 years as required by POPIA.
- Timeline: Ongoing – as steps are completed.
6. COMMUNICATION GUIDELINES
6.1 Internal Communication:
- Only authorised personnel (Response Team) should discuss the breach.
- Do not speculate or share unconfirmed information.
- Use secure communication channels.
6.2 External Communication:
- Only the Information Officer or designated spokesperson should communicate externally.
- Do not disclose information to the media without legal advice.
- Ensure all communications are factual, accurate, and consistent.
6.3 Communication to Affected Individuals:
- Be transparent and honest.
- Explain what happened, what data was affected, and what steps are being taken.
- Provide practical advice on how they can protect themselves.
- Provide contact details for further questions.
7. BREACH ASSESSMENT CRITERIA
7.1 When assessing whether a breach is likely to result in harm, consider:
- Type of personal information: Is it sensitive information (e.g., photos, financial data)?
- Number of individuals affected: How many people are involved?
- Nature of the breach: Was data accessed, stolen, or merely exposed?
- Risk of misuse: Could the data be used for identity theft, fraud, or other harm?
- Existing protections: Is the data encrypted or otherwise protected?
7.2 If the breach is not likely to result in harm, notification is not required (POPIA Section 22). However, the breach should still be documented and remediated.
7.3 If in doubt, the Information Officer should err on the side of caution and notify.
8. CONTACT DETAILS
8.1 Internal Contacts:
| Role | Name | Contact |
|---|
| Information Officer | Vince Willett | info@theweddingstudio.co / 079 471 9268 |
| Deputy Information Officer | Gideon van der Merwe | info@theweddingstudio.co |
8.2 External Contacts:
| Contact | Details |
|---|
| South African Information Regulator | https://www.justice.gov.za/inforeg/ |
| Regulator Email | inforeg@justice.gov.za |
| Regulator Phone | 012 406 4818 |
9. TESTING AND REVIEW
9.1 This Plan will be:
- Tested annually through simulated breach scenarios
- Reviewed and updated at least once a year
- Updated immediately following any actual breach
9.2 The Information Officer is responsible for ensuring this Plan remains current and effective.
10. TRAINING
10.1 All employees and contractors will receive training on:
- How to detect a potential data breach
- How to report a breach to the Information Officer
- Their responsibilities under this Plan
10.2 Training will be provided:
- Upon commencement of employment
- Annually as part of refresher training
- Following any material changes to this Plan
11. UPDATES TO THIS PLAN
11.1 This Plan may be updated to reflect changes in:
- Legal requirements (e.g., POPIA updates)
- Technology or systems
- Business practices
- Lessons learned from incidents
11.2 The latest version will be maintained by the Information Officer and made available to all staff.
12. CONTACT US
- If you have any questions about this Data Breach Response Plan, or if you wish to report a potential breach, please contact our Information Officer:
- The Wedding Studio
- A division of Regi Health Pty Ltd
- Information Officer: Vince Willett
- Email: info@theweddingstudio.co
- Phone: 079 471 9268
- Address: 236 Vaandrager, Dorandia, Pretoria, 0182, South Africa
- Last Updated: 19 July 2026