Skip to main content
NOSWEAT.CO.ZA
NOSWEAT.CO.ZA

Data Breach & Security Compromise Response Plan

No Sweat Work Media CC
Trading as NoSweat
Registration Number: 2009/090625/23
Website: www.nosweat.co.za
Effective Date: 10 August 2026


1. Our Commitment

NoSweat is committed to protecting the confidentiality, integrity and availability of personal information entrusted to us by candidates, freelancers, clients, suppliers and other users of our services.

We maintain procedures designed to identify, contain, investigate, respond to and recover from security incidents involving personal information.

This Data Breach & Security Compromise Response Plan (“Response Plan”) describes the steps NoSweat will take where personal information may have been lost, unlawfully accessed, acquired, disclosed, altered, destroyed or otherwise compromised.

Our approach is guided primarily by the Protection of Personal Information Act 4 of 2013 (“POPIA”), particularly sections 19 to 22, and current guidance issued by the South African Information Regulator. Section 19 requires responsible parties to implement reasonable technical and organisational safeguards and to identify risks, establish safeguards, regularly verify them and update them where necessary.



2. What Is a Data Breach or Security Compromise?

POPIA uses the term security compromise rather than “data breach”.

The Information Regulator describes a security compromise as an event affecting the security, confidentiality, integrity or availability of personal information that results in accidental or unlawful loss, destruction, alteration, disclosure, processing or access.

Examples may include:

  • an email containing personal information being sent to the wrong person;
  • a CV or candidate record being disclosed to an unauthorised recipient;
  • loss or theft of a laptop, phone or storage device containing personal information;
  • compromised passwords or user accounts;
  • phishing attacks;
  • malware or ransomware;
  • unauthorised access to NoSweat systems;
  • unauthorised downloads or copying of information;
  • employee or contractor misuse of personal information;
  • information accidentally made publicly accessible;
  • loss of paper records;
  • unauthorised alteration or deletion of personal information;
  • compromise of a cloud, CRM, email or other technology provider processing NoSweat information; or
  • other circumstances in which an unauthorised person may have accessed or acquired personal information.

The Information Regulator specifically identifies human error, theft or loss, fraud, misrepresentation and cyberattacks such as phishing and ransomware as examples of security compromises.



3. Personal Information That May Be Affected

Because NoSweat operates a talent and work platform, a security compromise could potentially involve information relating to:

Candidates and Freelancers

This may include:

  • names;
  • contact details;
  • CVs and résumés;
  • portfolios;
  • employment history;
  • skills;
  • qualifications;
  • rates or salary expectations;
  • job applications;
  • availability;
  • identity or verification information;
  • banking information;
  • tax-related information; and
  • correspondence.

Clients

This may include:

  • names and contact details;
  • company information;
  • account information;
  • hiring requirements;
  • candidate selections;
  • contracts;
  • invoices;
  • payment information; and
  • communications.

Other Individuals

A security compromise may also affect employees, contractors, suppliers, referees, website users and other persons whose personal information is processed by NoSweat.



4. Reporting a Suspected Breach to NoSweat

Anyone who believes that NoSweat information has been lost, exposed or improperly accessed should report the matter as soon as possible.

Please contact:

NoSweat Information Officer
Sebastian van ’t Hoff
Email: sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053

Please use the subject line:

URGENT: POSSIBLE DATA BREACH

Where possible, please provide:

  • what happened;
  • when it happened or was discovered;
  • what information may be involved;
  • whose information may be affected;
  • how you became aware of the issue; and
  • any immediate action already taken.

Please do not send copies of additional sensitive information unnecessarily when reporting an incident.



5. Immediate Response

When NoSweat becomes aware of a suspected security compromise, our initial priorities are to:

  1. identify the incident;
  2. contain it where possible;
  3. protect affected systems and information;
  4. preserve relevant evidence;
  5. determine what personal information may be involved;
  6. establish who may be affected;
  7. assess how the compromise occurred;
  8. mitigate potential harm; and
  9. meet applicable notification obligations.

The Information Regulator recommends that organisations identify the compromise, notify the Information Officer, take necessary mitigation measures, notify affected individuals and the Regulator, and review safeguards to address identified weaknesses.



6. Containment

Depending on the circumstances, containment measures may include:

  • disabling compromised accounts;
  • resetting passwords or access credentials;
  • terminating unauthorised sessions;
  • revoking access permissions;
  • isolating affected systems or devices;
  • securing exposed files;
  • removing unintended public access;
  • requesting deletion of information sent to an unintended recipient;
  • contacting a technology or cloud provider;
  • suspending affected integrations;
  • blocking malicious access;
  • preserving system logs; and
  • taking other reasonable steps to stop further unauthorised processing.

The appropriate action will depend on the nature of the incident.

NoSweat will endeavour to contain an incident without unnecessarily destroying information that may be required for investigation.



7. Investigation

Once an incident has been identified and initial containment is underway, NoSweat will investigate the nature and scope of the compromise.

The investigation may consider:

  • when the compromise started;
  • when it was detected;
  • how it occurred;
  • whether the compromise is ongoing;
  • the systems or service providers involved;
  • the categories of personal information affected;
  • the approximate number of affected people;
  • whether the information was encrypted or otherwise protected;
  • whether the information was actually accessed or acquired;
  • who may have received or accessed it;
  • whether information has been deleted or recovered;
  • the potential consequences for affected individuals; and
  • the corrective action required.

The Information Regulator states that responsible parties should investigate the nature and scope of a compromise, determine its potential impact and take steps to mitigate adverse consequences.



8. Assessment of Potential Harm

Although NoSweat will assess the seriousness of an incident to determine the appropriate response and mitigation measures, risk assessment does not replace our statutory notification obligations.

The Information Regulator’s current position is that POPIA does not establish a risk threshold below which a security compromise can simply be treated as non-reportable. The Regulator states that security compromises must be reported irrespective of the organisation's assessment of their level of risk.

The potential impact will nevertheless be considered carefully when determining how urgently affected people should act and what protective guidance they should receive.

Potential consequences may include:

  • identity fraud;
  • financial fraud;
  • account compromise;
  • phishing;
  • impersonation;
  • loss of confidentiality;
  • reputational harm;
  • discrimination;
  • misuse of employment information; or
  • other harm arising from the circumstances of the incident.


9. Notification to the Information Regulator

Where a security compromise triggers section 22 of POPIA, NoSweat will notify the Information Regulator as soon as reasonably possible after discovery.

Since 1 April 2025, the Information Regulator requires section 22 security-compromise notifications to be submitted through its eServices Portal.

NoSweat’s Information Officer or an appropriately authorised Deputy Information Officer will coordinate the notification.

If all facts are not yet known, the Regulator advises organisations to notify based on the information currently available and update the notification as further information emerges.

NoSweat will therefore not unnecessarily delay an initial notification simply because an investigation has not yet been completed.



10. Notification to Affected Individuals

Where required by POPIA, NoSweat will also notify affected data subjects as soon as reasonably possible.

Notification may be made, as appropriate, through:

  • email;
  • postal communication;
  • a prominent notice on the NoSweat website;
  • news media where appropriate; or
  • another method permitted or directed by the Information Regulator.

These are methods specifically recognised by the Information Regulator for security-compromise notifications.

Where we have reliable direct contact information, we will generally seek to communicate directly with affected persons where reasonably practicable.



11. What Our Breach Notification May Tell You

Depending on what is known at the time, a notification may explain:

  • what happened;
  • when the incident occurred or was discovered;
  • what personal information may have been affected;
  • what NoSweat has done to contain or address the incident;
  • possible consequences;
  • steps NoSweat recommends you take;
  • how to obtain further information;
  • who to contact at NoSweat;
  • whether further updates are expected; and
  • where known and appropriate, information concerning the unauthorised person who accessed or acquired the information.

The Information Regulator states that notifications should provide enough information to enable affected people to take protective action and should address what occurred, mitigation steps, advice for the data subject and, where known, the person who accessed the information.



12. Advice to Affected Individuals

Depending on the type of information compromised, NoSweat may recommend actions such as:

  • changing your NoSweat password;
  • changing passwords on other accounts where the same password was reused;
  • enabling multi-factor authentication;
  • monitoring email accounts for suspicious activity;
  • being alert for phishing emails, SMS messages or WhatsApp messages;
  • not providing passwords or verification codes to unsolicited callers;
  • monitoring financial accounts;
  • contacting a bank where banking information may be at risk;
  • watching for attempted impersonation; or
  • taking other measures appropriate to the incident.

The exact advice will depend on the nature of the information affected.



13. Website Breach Notices

In circumstances where a website notification is appropriate, NoSweat may publish a prominent security-compromise notice on www.nosweat.co.za.

The Information Regulator’s 2025 fact sheet notes that the appropriate period for leaving such a notice online depends on how likely affected persons are to see it and gives 30 to 90 days as a general rule of thumb, rather than a fixed statutory period.

NoSweat will determine the appropriate publication period based on the circumstances of the particular incident.



14. Breaches Involving NoSweat Service Providers

NoSweat uses third-party service providers and technology platforms in operating its business.

Under POPIA, where an operator processing information for a responsible party experiences a security compromise affecting that information, the operator must notify the responsible party. The responsible party remains responsible for the section 22 notification to the Regulator and affected data subjects.

NoSweat therefore expects suppliers and operators handling our personal information to:

  • notify us promptly of an actual or suspected compromise;
  • provide sufficient information to allow us to investigate;
  • assist with containment;
  • preserve relevant records;
  • cooperate with our notification obligations;
  • take corrective action; and
  • provide reasonable updates during the incident.

Relevant contractual agreements may impose additional requirements.



15. Where NoSweat Acts as an Operator

In some circumstances, NoSweat may process information on behalf of another responsible party.

If NoSweat identifies a security compromise involving information for which another organisation is the responsible party, we will notify that responsible party promptly and cooperate with its response obligations.

The responsible party generally retains responsibility for notifying the Information Regulator and affected data subjects in relation to information it controls.



16. Communication During an Incident

Security incidents can develop quickly and initial information may later change.

NoSweat therefore aims to:

  • communicate verified information;
  • distinguish confirmed facts from matters still under investigation;
  • avoid unnecessary speculation;
  • provide updates where materially relevant;
  • protect the confidentiality of the investigation;
  • avoid compromising security controls; and
  • provide practical advice to affected people.

NoSweat may update previous communications as further information becomes available.



17. Preservation of Evidence

Where appropriate, NoSweat may preserve evidence including:

  • system logs;
  • email records;
  • access records;
  • screenshots;
  • affected files;
  • security alerts;
  • correspondence;
  • audit trails;
  • service-provider reports; and
  • other relevant records.

Records may be required to investigate what occurred, respond to the Information Regulator, address contractual matters or support potential legal or criminal proceedings.

Access to incident records will be restricted where appropriate.



18. Law Enforcement and Other Authorities

Where a security compromise involves suspected:

  • fraud;
  • theft;
  • extortion;
  • ransomware;
  • hacking;
  • identity theft;
  • deliberate unauthorised access; or
  • other potentially criminal conduct,

NoSweat may report or cooperate with appropriate law-enforcement authorities.

Such involvement does not remove NoSweat's obligations under POPIA, subject to any lawful instruction or restriction affecting the timing or content of notification.



19. Recovery

Once the immediate incident has been contained, NoSweat will take reasonable steps to safely restore affected services and information.

Recovery may include:

  • restoring data from appropriate backups;
  • re-establishing secure account access;
  • correcting compromised records;
  • updating software;
  • replacing compromised credentials;
  • modifying permissions;
  • monitoring systems for continuing suspicious activity; and
  • validating that remediation measures have been effective.

Systems will be restored in a manner appropriate to the nature and severity of the incident.



20. Post-Incident Review

After responding to a material security compromise, NoSweat will review the incident and consider what improvements should be made.

The review may consider:

  • the root cause;
  • whether safeguards failed;
  • whether the incident could have been detected earlier;
  • whether procedures were followed;
  • whether supplier arrangements were adequate;
  • the effectiveness of containment;
  • the effectiveness of communications;
  • whether additional training is required;
  • whether access privileges should change;
  • whether policies need updating; and
  • whether additional technical or organisational safeguards are appropriate.

The Information Regulator expects responsible parties to continually review and update security safeguards and specifically identifies security-compromise response planning as an appropriate organisational measure.



21. Incident Records

NoSweat may maintain an internal security-incident register recording matters such as:

  • date reported;
  • nature of incident;
  • information affected;
  • systems affected;
  • individuals affected;
  • cause;
  • containment measures;
  • investigation results;
  • notification to the Regulator;
  • notifications to data subjects;
  • remediation;
  • closure date; and
  • lessons learned.

These records assist NoSweat with accountability, compliance and improving its safeguards.

Repeated or high-risk security compromises may attract regulatory scrutiny; the Information Regulator states that the number and risk rating of reported compromises can be factors considered when deciding whether to conduct a POPIA compliance assessment.



22. Prevention and Security Safeguards

Preventing security compromises is preferable to responding after one occurs.

NoSweat takes reasonable technical and organisational measures appropriate to its operations and the nature of the information processed.

The Information Regulator identifies examples of appropriate measures including:

  • access controls;
  • encryption;
  • endpoint security;
  • firewalls;
  • multi-factor authentication;
  • security monitoring;
  • policies and procedures;
  • cybersecurity awareness; and
  • incident-response planning.

For security reasons, NoSweat does not publicly disclose detailed information about the configuration of its internal security systems or controls.



23. Roles and Responsibilities

Information Officer

The Information Officer has overall responsibility for coordinating NoSweat’s POPIA response and regulatory obligations.

For NoSweat:

Information Officer:
Sebastian van ’t Hoff

Responsibilities may include:

  • receiving incident reports;
  • coordinating investigations;
  • determining notification requirements;
  • notifying the Information Regulator;
  • coordinating notification to affected individuals;
  • maintaining appropriate records;
  • engaging service providers and advisers;
  • overseeing corrective actions; and
  • reviewing the effectiveness of this Response Plan.

The Information Regulator confirms that Information Officers have responsibility for encouraging POPIA compliance, dealing with POPIA-related requests and cooperating with regulatory investigations.

Employees, Contractors and Suppliers

Anyone handling NoSweat personal information is expected to report an actual or suspected compromise promptly rather than attempting to conceal or independently resolve a serious incident without escalation.



24. False Alarms and Good-Faith Reporting

NoSweat encourages the prompt reporting of suspected incidents.

A person should not delay reporting merely because they are uncertain whether an event constitutes a data breach.

An incident that turns out not to involve a security compromise can be closed following assessment.

NoSweat does not support retaliation against a person who raises a genuine security or privacy concern in good faith.



25. Complaints

If you believe NoSweat has failed to appropriately protect or respond to a compromise of your personal information, please contact:

Sebastian van ’t Hoff
Information Officer
Email: sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053

You also have the right to lodge a privacy complaint with the Information Regulator (South Africa). The Regulator provides facilities for POPIA complaints and security-compromise reporting through its eServices environment.



26. Related NoSweat Policies

This Response Plan should be read together with NoSweat’s:

Privacy Policy
POPIA & Data Protection
Cookie Policy
PAIA Manual
Information Officer Registration & Contact Details
Direct Marketing Policy
Supplier Code of Conduct
Anti-Slavery & Human Trafficking Policy



27. Review of This Plan

NoSweat will review this Response Plan periodically and following a material security compromise where appropriate.

Updates may be made in response to:

  • changes in POPIA or applicable regulations;
  • Information Regulator guidance;
  • changes in NoSweat’s systems or services;
  • changes in service providers;
  • new security risks;
  • lessons learned from incidents; or
  • changes in recognised security practices.

The most recent public version will be available on www.nosweat.co.za.



28. Contact NoSweat

For privacy, security or data-protection matters:

No Sweat Work Media CC
Trading as NoSweat
Registration Number: 2009/090625/23

Information Officer: Sebastian van ’t Hoff
Email: sebastian@nosweat.co.za
Telephone / WhatsApp: +27 81 818 2053
Website:www.nosweat.co.za
South Africa

For a suspected personal-information compromise, please mark your communication:

URGENT: POSSIBLE DATA BREACH

http://www.nosweat.co.za/direct-marketing-policy