WEBVTT - Gauteng’s e-Panic Button app breached ‘

0:00:00.210 --> 0:00:02.450
<v Speaker 1>So I don't know if this has affected you, but

0:00:02.509 --> 0:00:06.820
<v Speaker 1>people who turn to Gauteng's e-panic button for help may

0:00:06.890 --> 0:00:10.640
<v Speaker 1>instead have had some of their most sensitive information exposed.

0:00:11.360 --> 0:00:15.660
<v Speaker 1>Ground Up found names, phone numbers, crime reports, photographs, and

0:00:15.700 --> 0:00:21.599
<v Speaker 1>locations were accessible. Some reports involved domestic violence and assault. Now,

0:00:21.620 --> 0:00:24.419
<v Speaker 1>the security problems appear to have been fixed, but affected

0:00:24.520 --> 0:00:27.410
<v Speaker 1>users had still not been told almost a week after

0:00:27.750 --> 0:00:31.950
<v Speaker 1>the breach was first reported. Nomzama Zonde is the information

0:00:32.370 --> 0:00:36.210
<v Speaker 1>regulator spokesperson. A good afternoon to you. This is pretty disturbing,

0:00:36.270 --> 0:00:39.270
<v Speaker 1>isn't it? Tell us what happened and how many people

0:00:39.290 --> 0:00:40.199
<v Speaker 1>do you think have been affected?

0:00:42.420 --> 0:00:45.840
<v Speaker 2>Good day, Jane, to you and your listeners. And thank

0:00:45.860 --> 0:00:49.140
<v Speaker 2>you so much for inviting us. What we can indicate

0:00:49.200 --> 0:00:52.000
<v Speaker 2>right now, Jane, is that we have not received the

0:00:52.040 --> 0:00:57.630
<v Speaker 2>notification yet. from the department as per the obligation and

0:00:57.670 --> 0:01:01.330
<v Speaker 2>requirement by the Protection of Personal Information Act that when

0:01:01.350 --> 0:01:05.000
<v Speaker 2>they believe to have suffered a security compromise, which is

0:01:05.020 --> 0:01:09.100
<v Speaker 2>a data breach, they need to or must notify us

0:01:09.200 --> 0:01:14.020
<v Speaker 2>as the information regulator as well as the affected persons,

0:01:14.060 --> 0:01:17.550
<v Speaker 2>which are data subjects. So at this current point, we

0:01:17.590 --> 0:01:23.070
<v Speaker 2>do not have the facts behind the the breach nor

0:01:23.090 --> 0:01:25.830
<v Speaker 2>do we have the number of people that have been

0:01:25.950 --> 0:01:30.660
<v Speaker 2>impacted except for what we have received through the reports

0:01:30.700 --> 0:01:33.459
<v Speaker 2>that have been coming through. So we're uncertain at this

0:01:33.520 --> 0:01:36.319
<v Speaker 2>point what are the numbers in terms of affected persons.

0:01:36.700 --> 0:01:38.570
<v Speaker 1>So how do you get in touch with people if

0:01:38.590 --> 0:01:41.230
<v Speaker 1>you don't know what the numbers are or if this

0:01:41.330 --> 0:01:43.070
<v Speaker 1>information is actually being downloaded?

0:01:45.720 --> 0:01:51.760
<v Speaker 2>The department itself has a responsibility to actually secure the

0:01:51.800 --> 0:01:55.510
<v Speaker 2>integrity and confidentiality of the information of people who are

0:01:55.610 --> 0:02:00.330
<v Speaker 2>using their application. So they need to ensure that the

0:02:00.370 --> 0:02:04.160
<v Speaker 2>information that is under their control, they've taken reasonable and

0:02:04.190 --> 0:02:08.870
<v Speaker 2>appropriate technical or organizational safeguards or measures to to prevent

0:02:09.030 --> 0:02:13.329
<v Speaker 2>any damage or unauthorized access to that information. So they

0:02:13.590 --> 0:02:17.360
<v Speaker 2>need to know how many people are using that application

0:02:17.800 --> 0:02:20.760
<v Speaker 2>and in regards to this alleged security compromise, how many

0:02:20.780 --> 0:02:23.800
<v Speaker 2>people have been affected so that we are able also

0:02:23.820 --> 0:02:27.780
<v Speaker 2>as the information regulator to conduct the necessary investigation into

0:02:27.820 --> 0:02:31.130
<v Speaker 2>their systems and whether they did indeed put in place

0:02:31.190 --> 0:02:34.809
<v Speaker 2>safeguards that will protect the personal information that they have

0:02:34.850 --> 0:02:38.639
<v Speaker 2>collected through their application. So it is important that they

0:02:38.700 --> 0:02:42.359
<v Speaker 2>know how many data subjects were affected because they must

0:02:42.380 --> 0:02:46.340
<v Speaker 2>notify them if there has been a security compromise or

0:02:46.360 --> 0:02:47.000
<v Speaker 2>a data breach.

0:02:47.400 --> 0:02:50.280
<v Speaker 1>So we know that some reports involve domestic violence. Are

0:02:50.300 --> 0:02:52.940
<v Speaker 1>you concerned that this breach could put people in some

0:02:52.980 --> 0:02:55.500
<v Speaker 1>sort of physical danger? How are you going to go

0:02:55.540 --> 0:02:57.560
<v Speaker 1>about preventing that from potentially happening?

0:02:58.750 --> 0:03:03.290
<v Speaker 2>No, absolutely. We're definitely concerned given the severity of the

0:03:03.350 --> 0:03:07.260
<v Speaker 2>allegations or the reports and the sensitivity. around the matter

0:03:07.360 --> 0:03:12.380
<v Speaker 2>because if you are going to look into getting some

0:03:12.470 --> 0:03:16.570
<v Speaker 2>kind of remedy or protection through a certain application and

0:03:16.630 --> 0:03:20.010
<v Speaker 2>now your information may potentially be exposed, which is going

0:03:20.050 --> 0:03:24.010
<v Speaker 2>to further cause harm, that is a serious problem for

0:03:24.070 --> 0:03:27.430
<v Speaker 2>us as the information regulator, which is why, Jane, as

0:03:27.550 --> 0:03:31.030
<v Speaker 2>much as we have not received an official Section 22 notification,

0:03:31.620 --> 0:03:37.440
<v Speaker 2>from the responsible party being the e-government department, we are

0:03:37.520 --> 0:03:40.839
<v Speaker 2>going to engage and interact with the department to get

0:03:40.940 --> 0:03:45.660
<v Speaker 2>more information about the matter and then thereafter we will

0:03:45.760 --> 0:03:49.340
<v Speaker 2>determine the cause of action and potentially conduct an assessment

0:03:49.410 --> 0:03:50.890
<v Speaker 2>or an investigation on the matter.

0:03:51.070 --> 0:03:53.490
<v Speaker 1>Okay, so what is your message to somebody who's listening

0:03:53.550 --> 0:03:57.050
<v Speaker 1>now who uses this panic button, what they should do

0:03:57.070 --> 0:03:57.750
<v Speaker 1>or what they shouldn't do?

0:03:59.350 --> 0:04:03.000
<v Speaker 2>We definitely always encourage data subjects that if there is

0:04:03.060 --> 0:04:06.740
<v Speaker 2>such a security compromise that they do not obviously respond

0:04:07.140 --> 0:04:12.600
<v Speaker 2>to any weather messages or requests for them to share

0:04:12.650 --> 0:04:17.409
<v Speaker 2>their personal details or verify or authenticate any activities on

0:04:17.470 --> 0:04:22.070
<v Speaker 2>their devices and also report to the department themselves or

0:04:22.089 --> 0:04:26.320
<v Speaker 2>the responsible parties responsible for the information that they've collected.

0:04:27.060 --> 0:04:32.979
<v Speaker 2>But also if you have suffered any further harm as

0:04:33.060 --> 0:04:36.020
<v Speaker 2>a result of such a security compromise, you then can

0:04:36.080 --> 0:04:39.760
<v Speaker 2>obviously lodge a complaint with us as the information regulator.

0:04:40.080 --> 0:04:42.680
<v Speaker 2>But currently, with the current matter and the fact that

0:04:42.720 --> 0:04:45.670
<v Speaker 2>we have not even received a notification, we are unable

0:04:45.730 --> 0:04:47.690
<v Speaker 2>to really go into the merits of the issue. But

0:04:47.770 --> 0:04:50.630
<v Speaker 2>as the regulator, we definitely are going to be following

0:04:50.730 --> 0:04:54.470
<v Speaker 2>through with this matter with the department.

0:04:54.610 --> 0:04:59.450
<v Speaker 1>Concerning, isn't it? From the information regulator's spokesperson, Nom Zama Zondi.

0:04:59.490 --> 0:04:59.789
<v Speaker 1>Thank you.