Legal
Rapid Sports (Pty) Ltd Data Breach Notification Protocol
Effective date: September 2026
This Data Breach Notification Protocol outlines the procedures to be followed in the event of a data breach involving personal data collected and processed by Rapid Sports (Pty) Ltd. This protocol ensures compliance with applicable data protection laws.
1. Purpose
The purpose of this protocol is to provide a clear and structured approach for identifying, responding to, and notifying relevant parties about data breaches to mitigate risks and protect the rights of data subjects.
2. Definitions
2.1. Data Breach: A security incident that results in unauthorised access, disclosure, alteration, or destruction of personal data.
2.2. Data Subject: An identified or identifiable natural person to whom personal data relates.
2.3. Notification: The process of informing data subjects, regulatory authorities, and other relevant parties about a data breach.
3. Identification of a data breach
3.1. Reporting mechanism
Employees, contractors, and third parties must report any suspected or confirmed data breaches immediately to the designated Data Protection Officer.
3.2. Initial assessment
Upon receiving a report, the Data Protection Officer will conduct an initial assessment to determine whether a data breach has occurred, evaluating the nature, scope, and potential impact of the breach.
4. Response to a data breach
4.1. Containment
4.1.1. Implement immediate measures to contain the breach and prevent further unauthorised access or disclosure.
4.1.2. Secure affected systems and data to limit potential damage.
4.2. Investigation
4.2.1. Conduct a thorough investigation to understand the cause of the breach and the data affected.
4.2.2. Document all findings, actions taken, and decisions made during the investigation.
5. Notification requirements
5.1. Data subject notification
If the breach is likely to result in a high risk to the rights of data subjects, the Data Protection Officer will notify affected individuals without undue delay, providing the following information—
- 5.1.1. Description of the nature of the breach;
- 5.1.2. Categories and approximate number of data subjects affected;
- 5.1.3. Categories and approximate number of personal data records affected;
- 5.1.4. Consequences of the breach;
- 5.1.5. Proposed measures to mitigate the breach;
- 5.1.6. Contact information for the Data Protection Officer.
5.2. Regulatory authority notification
If required by law, the Data Protection Officer will notify the relevant supervisory authority of the breach within 24 hours of becoming aware of it. The Data Protection Officer will provide his/her superior with the following—
- 5.2.1. Description of the breach;
- 5.2.2. Categories and approximate number of data subjects and data records affected;
- 5.2.3. Likely consequences of the breach;
- 5.2.4. Proposed measures to address the breach.
6. Post-incident review
6.1. Review and improvement
Following a data breach, the Data Protection Officer will conduct a post-incident review to evaluate the effectiveness of the response and identify areas for improvement in data protection practices.
6.2. Reporting
Prepare a detailed report summarising the breach, response actions, and recommendations for future prevention. This report will be shared with senior management and relevant stakeholders.
7. Training and awareness
All employees and contractors will receive training on data breach awareness and response procedures as part of their onboarding process and ongoing training initiatives.
8. Documentation
Rapid Sports (Pty) Ltd is required to maintain comprehensive records of all data breaches, including—
- 8.1. Description of the breach;
- 8.2. Dates of detection and reporting;
- 8.3. Actions taken in response;
- 8.4. Notifications made to data subjects and regulatory authorities.
9. Contact information
For any questions or concerns regarding this Data Breach Notification Protocol, please contact us at support@rapidsportss.com.
