| Authority: | Eswatini Communications Commission (Eswatini Data Protection Authority (EDPA)) |
|---|---|
| Jurisdiction: | Eswatini |
| Relevant law: | Section 17(1)(a) of the Data Protection Act, 2022 |
| Type: | Self Reported |
| Outcome: | Violation |
| Started: | 27 February 2024 |
| Decided: | June 2024 |
| Published: | Yes |
| Fine: | NA |
| Parties: | MTN Eswatini |
| Case No.: | EDPA-NOTICE 3/2024 |
| Appeal: | N/A |
| Original Source: | Eswatini Communications Commission |
| Original contributor: | MZIZI Africa |
The EDPA issued a warning to MTN Eswatini after MTN Eswatini disclosed a customer’s personal data (Mobile Money statement) to a third party without consent, violating the act.The breach occurred when a Call Centre Agent shared a customer’s Mobile Money statement with a third party (a creditor of the customer), which was later used at a police station to pursue a debt claim.
MTN Eswatini reported a data breach to the EDPA in February 2024. MTN Eswatini became aware of the breach after a customer (referred to as X) filed a complaint through their Call Centre.
The customer reported that her Mobile Money statement had been shared with a third party without her consent.
This complaint was made after the customer was summoned to a police station, where she learned that her creditor (referred to as Y) was in possession of her six-month Mobile Money statement, which had been used to support a claim against her.
MTN conducted an internal investigation following the complaint, confirming that the breach occurred when a Call Centre Agent shared the statement via the company's WhatsApp line after being requested by the third party.
The Call Centre Agent involved in the breach was not directly employed by MTN Eswatini. The Call Centre services were outsourced to NDZ Corporate, a third-party service provider. The agent worked under NDZ Corporate's management.
After the incident, the Call Centre Agent resigned before disciplinary proceedings could begin.
MTN Eswatini reported several compliance measures that were in place to prevent such breaches, including: