Data Breach At Pam Golding Puts Spotlight On Protection Laws In South Africa
Written by: BizCommunity Editor Save to Instapaper
The security incident took place on 7 March, when an unauthorised third party gained access to Pam Golding’s customer relationship management system.
Pam Golding’s notification says that it took immediate action to secure its systems, remove unauthorised access, and notify affected persons in accordance with South Africa’s Protection of Personal Information Act (PoPIA).
Although the notification indicates that no banking details, financial information or other documents were compromised, the notice does state that a customer relationship management system hosted on servers in South Africa had been compromised, which may have resulted in unauthorised access to personal information.
POPIA imposes a legal obligation on responsible parties to notify the South African Information Regulator, and the data subject, where “there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by any unauthorised person”.
Under the data protection law, “personal information” is information relating to a natural person and, in some cases, companies, including but not limited to identity numbers, email addresses, physical addresses, telephone numbers, and names.
The notification must be made as soon as reasonably possible after the discovery of the security compromise. A notification to the data subject can only be delayed if the notification might impede a criminal investigation.
The purpose of the notification is to provide the data subject with sufficient information to allow the data subject to take protective measures against the potential consequences of the compromise.
In the email communication Pam Golding sent out to affected individuals, it emphasised its commitment to data protection and its obligations under PoPIA, and set out seven steps it intends to take to contain the incident and prevent any further recurrence.
While the company is still investigating the incident, it has informed the affected data subjects of the potential risks, such as potential identity fraud by cybercriminals, and provided advice on how to protect themselves against these potential frauds.
Regulatory expert Andrew Attieh of Pinsent Masons said: “Simply because you receive a notification, it is not necessarily a cause for alarm. The fact that you have received a notification means that the notifying party is doing so in compliance with their legal obligations in terms of POPIA, and is a responsible action to take”
However, with cybercrime becoming a growing threat throughout the world, Attieh said, affected clients need to take proactive steps to protect themselves against identity theft and fraud and stay alert against any suspicious calls, texts or emails that could be a scam.
For example, if an individual receives any suspicious messages or calls, it is important not to hand over any sensitive information such as bank account details or user login passwords.
It is also prudent to check that links look correct before clicking on them, while looking out for signs of a phishing scam, such as emails containing spelling mistakes. Installing the latest security updates is another important step to protect against potential cybercrimes.
We submit and automate press releases distribution for a range of clients. Our platform brings in automation to 5 social media platforms with engaging hashtags. Our new platform The Pulse, allows premium PR Agencies to have access to our newsletter subscribers.
Latest from
- Seven Reasons Smart Consumers Prefer Brands That Educate Rather Than Push Products or Hard-Sell
- Youth in Oil and Gas Summit Sparks Call for Pragmatic Leadership to Drive Skills and Opportunity in Namibia
- African Energy Chamber Advocates for Youth Inclusion as Pillar of Namibia’s Oil and Gas Strategy
- Shark Exhibition Showcases Innovative Solutions to Protect Both Marine Life and Human Safety in SA Waters
- Domain Parking Demystified A Strategic Tool for Brand Protection and Future Online Growth
- Toyota South Africa and Kaizer Chiefs Turn Sponsorship Into Impact With Outreach to Ethelbert Centre
- Woolworths Becomes First SA Retailer to Offer Tailored Health Cover to Thousands of Employees
- Celebrating PR With Purpose A Tribute to Storytellers Who Place Humanity at the Heart of Influence
- Tired of the Grind? Why So Many South Africans Are Unhappy at Work and Looking for Something Better
- Megapro Appoints Marc Jury as CEO as Sports Marketing Veteran Prepares to Become Majority Shareholder
- Glencore-Merafe Resources Commits to Sustainable Impact With Handover of 11 Community Projects
- The Business Show Africa 2025 Promises Game-Changing Opportunities for Entrepreneurs and Startups
- Flow Launches Shoppable Audience Marketplace Giving Advertisers Instant Access to Premium First-Party Data
- CILTSA ESG Conference Unites Transport and Logistics Leaders to Accelerate Sustainable Industry Change
- South Africa Continues TO Engage The United States (US) Government ON The Reciprocal Tariffs
The Pulse Latest Articles
- Xlink: An Avant-garde, Purpose-driven Fintelco Driving Digital And Payments Interoperability On The African Continent (August 1, 2025)
- Success Is Just The Beginning For This South African Brand (July 31, 2025)
- Embassies Business Fair And Conference 2025 To Fast-track Africa’s Global Economic Integration (July 31, 2025)
- There Is A Small Business Funding Readiness Crisis In South Africa (July 30, 2025)
- Young Achievers Shine At The Top Of The Growthpoint Gems Class (July 30, 2025)