
Every major corporate data breach, from Yahoo to LinkedIn to the many that have followed since, teaches the same lesson: customer trust, once broken by a data breach, doesn’t quietly come back once the apology statement goes out.
Why breaches keep happening at scale
The companies most likely to suffer major breaches are, ironically, technology companies whose entire business is built on managing data securely. Breaches routinely expose far more than names and emails, phone numbers, identity numbers, encrypted passwords and security questions have all been compromised in major incidents, giving attackers what they need for follow-on fraud long after the initial breach.
What customers actually remember
A corporate breach apology that avoids the word “sorry” while emphasising legal and technical framing tends to compound customer anger rather than resolve it. Customers who feel betrayed don’t just quietly churn, they actively discourage others, delay payments, and become disproportionately difficult in every future interaction with the brand, real reputational costs that outlast the initial headline.
Why this still matters under South African law
South Africa’s Protection of Personal Information Act (POPIA) now requires businesses to notify both the Information Regulator and affected individuals as soon as reasonably possible after a data breach, with no minimum severity threshold. A business’s data-handling reputation is no longer just a customer-trust issue, it’s a direct compliance obligation, POPIA complaints and enforcement ultimately sit within the same justice system the Department of Justice and Constitutional Development administers, with real regulatory consequences for getting it wrong.
Frequently asked questions
Why do data breaches damage customer trust so severely?
Because breaches often expose far more than basic contact details, identity numbers, passwords and security answers, fuelling further fraud risk.
Does a corporate apology after a breach repair customer trust?
Rarely on its own; apologies that avoid direct accountability tend to deepen customer anger rather than resolve it.
What does South African law require after a data breach?
Under POPIA, businesses must notify the Information Regulator and affected individuals as soon as reasonably possible, with no minimum severity threshold.
How do customers typically respond to a betrayal of trust?
Beyond leaving, many actively discourage others, delay payments, and become harder to satisfy in every future interaction with the brand.
Is data security only an IT company’s responsibility?
No, any business handling customer data, banks, retailers, insurers included, carries the same trust and compliance obligations.
Further reading
Originally published in October 2016. Updated September 2026 to add current figures on what a breach actually costs a South African business now that POPIA enforcement carries real regulatory consequences.
