MBABANE – Most reported personal data breaches in Eswatini originate from the financial sector, ESCCOM has revealed.
The main breaches reported involve unauthorised disclosure of customer information, inadequate security controls and improper handling of personal data.
Some of the cases cited included bank statements being sent to the wrong customers because of similar names, invoices being sent to incorrect suppliers and cybersecurity breaches that resulted in sensitive financial records being accessible to external parties.
These risks are not merely theoretical but are real, current and capable of causing significant financial, reputational and emotional harm to individuals.
The disclosure was made as the Eswatini Communications Commission (ESCCOM), through the Eswatini Data Protection Authority, hosted a week-long workshop aimed at strengthening compliance with the Data Protection Act, 2022.
Challenges
The workshop brought together data protection officers and practitioners from the health and financial sectors to validate proposed data protection guidelines and ensure that they address challenges specific to the two sectors.
ESCCOM Acting Chief Executive Officer Fikile Gama said the reported breaches highlighted the need for financial institutions to strengthen the way they handle personal information.
She said the increasing digitisation and interconnection of financial services made the protection of personal information a business priority.
“As financial services become increasingly digital and interconnected, protecting personal information is no longer simply a legal obligation; it is a business imperative,” Gama said.
She said customers placed significant trust in financial institutions, which needed to protect that trust through lawful, transparent and secure processing of personal data.
The workshop was facilitated by Advocate Dirontsho Mohale from Smart Africa, with support from the German Embassy.
It brought together representatives from the Ministry of Health, Ministry of Finance, insurers, private and public health institutions, regulators and consumer protection organisations.
The participants used the workshop to share experiences and challenges encountered in implementing the Data Protection Act, while learning from practices adopted by other institutions.
The exercise was also aimed at assisting organisations in operationalising the proposed guidelines and strengthening measures needed to comply with the Act.
Whistle-blowing
Another key outcome of the workshop was the conclusion of a whistle-blowing mechanism.
The proposed framework seeks to strike a balance between protecting whistleblowers and safeguarding the rights of people implicated in whistle-blowing reports.
It will also provide for the lawful processing of personal information during the whistle-blowing process.
The workshop also incorporated cybersecurity, with participants being introduced to the work of the National Cybersecurity Agency, which is housed within ESCCOM.
Siboniso Sibandze introduced the agency and its work, including issues relating to cybercrime offences affecting organisations.
Participants were also taken through provisions relating to electronic transactions, as well as the obligations of institutions regarding data protection and cybersecurity.
The training further covered the appointment of data protection officers and cybersecurity focal points within organisations.
This placement makes the specific examples of information leaks prominent near the top, which strengthens the lead and gives readers an immediate sense of the problem.
BY NCAMISO XABA
Leave a comment