Liberty SMS - Unauthorized access to IT infrastructure

How is a local company, who doesn't operate in the EU, going to be charged criminally here in SA?

Article 27. It requires companies without operations in the EU to appoint an EU representative, through who remedies may be pursued. If that doesn't happen, you can expect local enforcement actions in 3rd countries through mutual legal assistance treaties (MLAT), and private prosecutions under similar local laws.
 
And again I ask, if the directors reside in SA, how would you criminally prosecute them? And if they have licences in the EU, then they are operating in the EU, which is a point I agreed on.

They would be prevented from entering the EU territory.

Judgments in absentia would be performed against them in the EU and they would be unfit to become directors (read on delinquent directors and all).

For the fines, an exequatur can be requested and hardly challenged (if it was, this would become a major diplomatic incident and denial of law).

I was speaking of Liberty specifically regarding the licenses.

Anyway, go read the GDPR instead of wasting my time challenging everything I say on key points of the GDPR.

A topic on MyBB already explains all this, look for it.
 
Article 27. It requires companies without operations in the EU to appoint an EU representative, through who remedies may be pursued. If that doesn't happen, you can expect local enforcement actions in 3rd countries through mutual legal assistance treaties (MLAT), and private prosecutions under similar local laws.

hey, I haven't looked at this in detail, but I am pretty sure very few organisations in SA have this.

Again, it's foreign law trying to dictate to other governments. It's like us passing a law telling the EU what to do...
 
They would be prevented from entering the EU territory.

Judgments in absentia would be performed against them in the EU and they would be unfit to become directors (read on delinquent directors and all).

For the fines, an exequatur can be requested and hardly challenged (if it was, this would become a major diplomatic incident and denial of law).

I was speaking of Liberty specifically regarding the licenses.

Anyway, go read the GDPR instead of wasting my time challenging everything I say on key points of the GDPR.

A topic on MyBB already explains all this, look for it.

Hey, you claiming to be the expert now, so it's more efficient usage of my time :)

So, you really think it would be a major diplomatic incident? I don't think so.

But, having said that, has Liberty mentioned if it is even contemplating GDPR? Most firms that I know of (and no, I'm not going to tell you which ones) have just been focused on the POPI Act.
 
And again I ask, if the directors reside in SA, how would you criminally prosecute them? And if they have licences in the EU, then they are operating in the EU, which is a point I agreed on.

Well as long as they then never want to go on European holidays, I guess they can shrug at it...
 
hey, I haven't looked at this in detail, but I am pretty sure very few organisations in SA have this.

Again, it's foreign law trying to dictate to other governments. It's like us passing a law telling the EU what to do...

Many large SA companies do comply (all the ones where you have the little banner where you click ok for the cookies since that comes from the GDPR).

Which is exactly what the US does very often...

It’s designed to protect EU citizens so by definition it has to have a worldwide jurisdiction, otherwise every company would base its mailing activities and data centers in Kazakhstan to not comply.

https://asia.nikkei.com/Economy/Trade-tensions/US-Senate-showdown-on-Trump-s-ZTE-deal-set-for-Monday

https://www.reuters.com/article/us-...er-sanctions-violations-idUSKBN0NM41K20150501
 
Many large SA companies do comply (all the ones where you have the little banner where you click ok for the cookies since that comes from the GDPR).

Which is exactly what the US does very often...

It’s designed to protect EU citizens so by definition it has to have a worldwide jurisdiction, otherwise every company would base its mailing activities and data centers in Kazakhstan to not comply.

https://asia.nikkei.com/Economy/Trade-tensions/US-Senate-showdown-on-Trump-s-ZTE-deal-set-for-Monday

https://www.reuters.com/article/us-...er-sanctions-violations-idUSKBN0NM41K20150501

Just having had a quick squiz online it seems that POPI and GDPR are not that different, and that POPI might even be amended slightly towards GDPR. I see also though that a lot of law firms are punting this as a way to get business - i.e. how do you know if you are affected, we can consult for you...typical neh :)

Interesting though.
 
Just having had a quick squiz online it seems that POPI and GDPR are not that different, and that POPI might even be amended slightly towards GDPR. I see also though that a lot of law firms are punting this as a way to get business - i.e. how do you know if you are affected, we can consult for you...typical neh :)

Interesting though.

Yes, GDPR is this generation's Y2K problem.
Everyone is kinda being forced to comply, and there is a Gupta amount of money to be made as a consultant.
 
Just having had a quick squiz online it seems that POPI and GDPR are not that different, and that POPI might even be amended slightly towards GDPR. I see also though that a lot of law firms are punting this as a way to get business - i.e. how do you know if you are affected, we can consult for you...typical neh :)

Interesting though.

If they are the same or will be the same, then it means that European countries(and all other countries) will have to comply with SA law and vice versa.
 
If they are the same or will be the same, then it means that European countries(and all other countries) will have to comply with SA law and vice versa.

I said similar, not same. Don't think POPI has tried to instill obligations outside of SA?
 
I said similar, not same. Don't think POPI has tried to instill obligations outside of SA?

Ofcourse it has.

In circumstances where personal information is transferred outside the borders of South Africa, the responsible party must notify all persons who will be affected, that it intends to transfer their personal information to another country. The responsible party must also inform the persons whose personal information is being transferred abroad of the level of protection that their information will be afforded in such foreign country. These considerations are based on the underlying intention of POPI that personal information should remain protected and secure even after it has been transferred to another country where POPI does not apply.

In addition to the above, POPI also requires that personal information can only be transferred to another country if one of the following primary circumstances is present:

• The country to which the information will be sent affords an adequate and similar level of protection to the personal information as that afforded by POPI, as well as other countries to which the personal information may be subsequently transferred.
• The recipient of the personal information in the foreign country agrees to treat the personal information in accordance with the provisions of POPI.
• The person whose personal information is being transferred abroad consents to the transfer.
• The transfer is necessary for the performance of a contract between the person whose personal information is being transferred and the responsible party.
• The transfer is necessary for the conclusion of a contract between the responsible party and the third party in the other country.
 
Please take the GDPR/popi/crap fighting off this thread and let's keep it relevant to the Liberty breach and info about it? Pleease?
 
Please take the GDPR/popi/crap fighting off this thread and let's keep it relevant to the Liberty breach and info about it? Pleease?

If we say no then what will you do? Hmmm...

In reality though I agree with you.

I'm still interested to find out WHAT was breached and how...
 
I'm still interested to find out WHAT was breached and how...

Me too. What we know is that it appears email related. I suspect it's either unauthorized access to a mail server or packet capture of unencrypted relay traffic. Email is a weak spot. Many firms just blindly trust upstream mail service providers... also, if an ISP has an unencrypted smtp service that's used by entire domains, it's a fairly big risk.
 
Me too. What we know is that it appears email related. I suspect it's either unauthorized access to a mail server or packet capture of unencrypted relay traffic. Email is a weak spot. Many firms just blindly trust upstream mail service providers... also, if an ISP has an unencrypted smtp service that's used by entire domains, it's a fairly big risk.

Yeah, and unfortunately lots of private info is sent unencrypted via emails these days... because people just dont think.
 
Top
Sign up to the MyBroadband newsletter
X