Namibia does not yet have a legal framework to protect personal details such as full names, date of birth and personal contact details. In fact, many businesses and government departments are not even trained in what is considered personal information. Take for example the website of the Law Society of Namibia (LSN). On its “Find a Firm or Practitioner” page (https://lawsocietynamibia.org/find-a-firm-or-practitioner/), it shows public information in a browser window, namely Name, Surname, Designation and Industry. If, however you investigate the coding of the page, it will also give you the Full Names, Date of Birth, and Personal Cellular Number of all its members.
The ability to save information on a computer and share this electronically necessitates legislation to be promulgated that protects the abuse of this information. These laws are especially necessary in our Information and Communication enabled society where information is stored on electronic retrieval systems. The Namibian Constitution states in Article 13 Privacy: “(1) No persons shall be subject to interference with the privacy of their homes, correspondence or communications save as in accordance with law and as is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the protection of health or morals, for the prevention of disorder or crime or for the protection of the rights or freedoms of others.” The Constitution thus guarantees only “Physical Privacy”. The storage of personal and business information (“Informational Privacy”) must have legislation that will prevent misuse of this information. In addition, the individual in Namibia must be able to access any, and all, information that is stored by the state (public institutions). There are thus things that are needed to guarantee informational privacy: 1. Data Protection Act; 2. Privacy and Electronic Communications Regulations; 3. Freedom of Access to Information Act The Namibia Consumer Protection Group (NCPG) once again calls on the broader society in Namibia to become aware of the need for data privacy and protection and encourages open discussion and what can be done. The NCPG will be preparing Public Facing Information Reports for our largest businesses and vulnerable person to encourage them to manage their data better. As for the members of the Law Society, you should expect correspondence from me regarding the data leaked as well as on any other public facing information you need to manage.Tuesday, 23 April 2024
๐๐ก๐ ๐๐๐ฆ๐ข๐๐ข๐๐ง ๐๐จ๐ฆ๐ฉ๐๐ญ๐ข๐ญ๐ข๐จ๐ง ๐๐จ๐ฆ๐ฆ๐ข๐ฌ๐ฌ๐ข๐จ๐ง ๐ก๐๐ฌ ๐๐จ๐ง๐๐ฅ๐ฎ๐๐๐ ๐ข๐ญs ๐ข๐ง๐ฏ๐๐ฌ๐ญ๐ข๐ ๐๐ญ๐ข๐จ๐ง ๐ข๐ง๐ญ๐จ ๐ข๐ง๐ญ๐๐ซ๐๐๐ง๐ค ๐๐ฑ๐๐ก๐๐ง๐ ๐ ๐๐๐๐ฌ - A Consumer Activist opinion
I have attached below an explanation of the advantages and disadvantages when banks set their own interchange fees. As you can see, if they do it themselves, it benefits the banks. BUT, all the disadvantages are on the side of the merchants and the consumers.
๐๐ข๐ ๐๐๐ฆ๐ข๐๐ข๐๐ฌ๐ ๐๐๐๐๐๐ข๐ง๐ ๐ข๐ง๐ ๐ฌ๐ค๐จ๐ฆ๐ฆ๐ข๐ฌ๐ฌ๐ข๐ ๐ก๐๐ญ ๐ฌ๐ฒ ๐จ๐ง๐๐๐ซ๐ฌ๐จ๐๐ค ๐ง๐ ๐ข๐ง๐ญ๐๐ซ๐๐๐ง๐ค๐๐จ๐จ๐ข๐ ๐๐๐ ๐๐ก๐๐ง๐๐๐ฅ
Ek heg hieronder 'n verduideliking aan oor die voordele en nadele wanneer banke hul eie interbankfooie bepaal. Soos jy kan sien, indien hulle dit self doen, is dit tot voordeel van die banke. MAAR, al die nadele is aan die kant van die handelaars en die verbruikers.
Tuesday, 10 October 2023
Social Security Commission leaks data (2018)
The Namibian reported in the edition of 11 June 2018 (https://www.namibian.com.na/68242/read/SSC-leak-exposes-personal-info-online), about the data leak noticed last week on the website of the Social Security Commission (SSC). The reporters that took up the story were able to alert the appropriate staff and the data leak was closed on Sunday, 10 June 2018.
As the leak has now been closed, the following is an overview of the occurrence and what should have been done to prevent such events in other organisations.
The Director of the Namibia Consumer Protection Group (NCPG), Milton LOUW, is an IT expert and owner of Aardvark Investments, a company that often undertakes tracing for insurance companies wishing to trace people who are due monies but their contact details are no longer current.
On Thursday 7 June 2018, a routine search for “Box 1141, Oshakati” showed the following results on Google.
Clicking on this link opened up the following page.
Once in this directory, there are 1,885 files in this directory which consists of submission to the SSC. Some of these files include very personal information such as ID number, SSC Registration number, and even salaries of certain companies. . PLEASE note that the information is from around 2013- 2018 and it is personal information that should not be in the public domain.
In addition to files submitted to SSC by companies, there was also adirectory of files containing the signed performance Performane Agrrements of top managers for the period 2016/17.
Are my company files compromised?
PLEASE NOTE: All inquiries regarding the information of employees and employers should now be addressed to the Social Security Commission: Chariold.Auchab@ssc.org.na, Tel: +264 61 2807712.
What happened?
The website was created with the default directory www.(company).na/files/downloads. In this directory were placed all the electronic forms that employers can use to submit their employee details.Unfortunately, the webmaster also used this directory to download all the files submitted to the SSC. This directory for ovious reasons needs to be available to the public, search engines, etc. and this did not have a prohibitive .htaccess file.
How to prevent this?
The public face of the company / organisation through its online presence should always be kept seperate from information received from its clients via the internet. This means that any and all correspondence from customers should be automatically routed to a directory that is not part of the public domain.Conclusion
This is the first, and certainly not the last data breach that the media will report on. Namibia has to develop its security and implement the Electronic Transactions, Data Protection, and Access to Information Acts.NOTE: .htaccess is the default name for a file that is used to indicate who can or cannot access the contents of a specific file directory from the Internet or an intranet.
Thursday, 28 September 2023
DEBT REVIEW needed for consumers
One of the biggest problems in starting a family is that most of the things I want, such as furniture, motor vehicle, etc. costs more money than what I earn in a month. The only option for purchasing these high cost items is to either save or to take it on credit. For myself, I have learned the hard way that it is better to save and buy later, rather than purchase on credit and not be able to afford the monthly payments later.