Afrihost client data leaked: company apologises and explains

Gian, dude....wtf??

The Protection of Personal Information Bill was signed last week. Have you guys not been paying attention in this space?

I don't care how sincerely you apologise. You didn't get permission to use the information in the manner in which it was used from the data subject. Data Privacy 101.

Doesn't Afrihost get 12 months of leeway to comply with POPI?
 
Doesn't Afrihost get 12 months of leeway to comply with POPI?

Sure they do. But the act has been well publicized since it was a bill. The principles and expectations are clear.

Why deliberately go against the principles of the act (or blatantly ignore it) when you know it was going to be signed soon?

Should companies have "made the most" of giving customers crappy service before the consumer protection act became applicable?

Should banks have "made the most" of reckless lending before the national credit act was applicable?
 
I actually haven't seen anybody raving on about POPI set out how this would fall within the scope of conduct within the POPI framework as there was no sale of the information and measures to protect personal information were taken - their insufficiency is a separate question. Section references would help
 
Sure they do. But the act has been well publicized since it was a bill. The principles and expectations are clear.

Why deliberately go against the principles of the act (or blatantly ignore it) when you know it was going to be signed soon?

Should companies have "made the most" of giving customers crappy service before the consumer protection act became applicable?

Should banks have "made the most" of reckless lending before the national credit act was applicable?

Your questions are all rhetorical, as is my reply.
 
gian-visser-12.jpg
 
I actually haven't seen anybody raving on about POPI set out how this would fall within the scope of conduct within the POPI framework as there was no sale of the information and measures to protect personal information were taken - their insufficiency is a separate question. Section references would help

I really don't have time for section references at the moment but suffice to say the act is not only about the sale of info. But here are some clear points of failure:
1- did the obtain permission from the data subject to use the info in the way it was used - No
2- did they make efforts to de-sensitize personal info before it was used like this - No
3- did they take reasonable measures to protect the data - No (you can argue this but considering this info was accessible via google puts it in the public domain)

Lastly, considering that you had a breach, did you disclose this individually to those affected, the details of the situation, what data exactly was lost, any steps being taken to remedy, etc - Hell No - haven't heard of anyone receiving any personal emails on this.
 
I really don't have time for section references at the moment but suffice to say the act is not only about the sale of info. But here are some clear points of failure:
1- did the obtain permission from the data subject to use the info in the way it was used - No
2- did they make efforts to de-sensitize personal info before it was used like this - No
3- did they take reasonable measures to protect the data - No (you can argue this but considering this info was accessible via google puts it in the public domain)

Lastly, considering that you had a breach, did you disclose this individually to those affected, the details of the situation, what data exactly was lost, any steps being taken to remedy, etc - Hell No - haven't heard of anyone receiving any personal emails on this.

The act don't apply here at all.

Not only do companies still have another year to comply to the act, but the incident actually happened way before the act was signed into power.

So, either which way, you can drop the POPI act and move along now.
 
The act don't apply here at all.

Not only do companies still have another year to comply to the act, but the incident actually happened way before the act was signed into power.

So, either which way, you can drop the POPI act and move along now.

Perhaps you should read previous posts, I am fully aware that the act is not yet applicable.

That doesn't mean you should happily ignore it until it is applicable.
 
What bothers me more than the leak itself is that I found out about it via MyBroadband and not from Afrihost themselves... They should've sent out an email the moment they found out about the leak.
Anyone have a copy so I can check if my details were on there?
 
What bothers me more than the leak itself is that I found out about it via MyBroadband and not from Afrihost themselves... They should've sent out an email the moment they found out about the leak.
Anyone have a copy so I can check if my details were on there?

I believe if any other personal info was on the leaked data they would have sent a mail immediately, but the fact that it was only names and addresses, they did damage control before making a decision on the way forward.

If your line was managed by afrihost, you are most likely on the list.
 
I thought that they would have sent out an email - after all they knew who the customers are. Agree with other sentiments, that the right thing to do was to actually mail people (irrespective of the type or sensitivity of data)
 
I thought that they would have sent out an email - after all they knew who the customers are. Agree with other sentiments, that the right thing to do was to actually mail people (irrespective of the type or sensitivity of data)

Damage control. They know they cant avoid the tech minded people of MyBB. So they have to be super nice here. However, they also know that their mybb users are a small but vocal minority. The only damage control they really have to do is here. They can get away with not telling everyone else. But I may be wrong an they may send an email to everyone :D

:D
 
I thought that they would have sent out an email - after all they knew who the customers are. Agree with other sentiments, that the right thing to do was to actually mail people (irrespective of the type or sensitivity of data)
+1, this should be standard procedure
 
Top
Sign up to the MyBroadband newsletter
X