Handbook
Your supplier was breached. What is yours to answer for?
Outsourcing the processing does not outsource the responsibility. The question a customer asks you is not what your supplier did, it is what you can produce.
Checked 2026-09-09
Operator and responsible party#
POPIA distinguishes the responsible party, who determines why and how personal information is processed, from the operator, who processes it on the responsible party's behalf.
Your vehicle tracking provider, your payroll bureau, your CRM host and your backup vendor are typically operators. You are typically the responsible party. When the operator is breached, the obligations that attach to a responsible party remain yours.
What you must be able to produce#
This is the entire practical content of the position, and it is three documents rather than a legal opinion:
- What they hold, specifically
- Not the vendor's name and the word 'data'. Which categories of personal information, about whom, for how long. A tracking provider holds location history for named drivers, which is a different conversation from a mailing list.
- The contract clause that governs it
- The written agreement requiring the operator to secure the information and to notify you of a compromise. If it does not exist, or exists only as the vendor's standard terms nobody read, that is the finding.
- The notification route, with a named person
- How they tell you, how fast, and who receives it. A breach discovered through a news article is a breach where this route did not work.
The register nobody keeps#
Every business of any size has more operators than it can name from memory. They accumulate: a tool adopted by one department, an integration set up once, a bureau inherited from a previous arrangement.
The artefact that answers all of this is an integration and supplier register with, for each entry, an owner, what personal information it touches, the contract reference, and a last-reviewed date. It is unglamorous and it is the only thing that turns a breach at a supplier from an emergency into a lookup.
The one thing to do about it#
List every system that holds personal information you are responsible for and that you do not run yourself. Do it from your bank statement rather than from memory, because the point of the exercise is the ones you would not have thought of.
Sources
Written as systems guidance, not legal advice. The statutory detail lives behind these links, because the regulator's own page is the one that stays right. How we check what we publish.