Authority: Eswatini Communications Commission (Eswatini Data Protection Authority (EDPA))
Jurisdiction: Eswatini
Relevant law: Section 17(1)(a) of the Data Protection Act, 2022
Type: Self Reported
Outcome: Violation
Started: 27 February 2024
Decided: June 2024
Published: Yes
Fine: NA
Parties: MTN Eswatini
Case No.: EDPA-NOTICE 3/2024
Appeal: N/A
Original Source: Eswatini Communications Commission
Original contributor: MZIZI Africa

Contents

  1. Summary
    1. Facts
    2. Holding
  2. Comment
  3. Further resources
  4. The Decision

Summary

The EDPA issued a warning to MTN Eswatini after MTN Eswatini disclosed a customer’s personal data (Mobile Money statement) to a third party without consent, violating the act.The breach occurred when a Call Centre Agent shared a customer’s Mobile Money statement with a third party (a creditor of the customer), which was later used at a police station to pursue a debt claim.

Facts

MTN Eswatini reported a data breach to the EDPA in February 2024. MTN Eswatini became aware of the breach after a customer (referred to as X) filed a complaint through their Call Centre.

The customer reported that her Mobile Money statement had been shared with a third party without her consent.

This complaint was made after the customer was summoned to a police station, where she learned that her creditor (referred to as Y) was in possession of her six-month Mobile Money statement, which had been used to support a claim against her.

MTN conducted an internal investigation following the complaint, confirming that the breach occurred when a Call Centre Agent shared the statement via the company's WhatsApp line after being requested by the third party.

The Call Centre Agent involved in the breach was not directly employed by MTN Eswatini. The Call Centre services were outsourced to NDZ Corporate, a third-party service provider. The agent worked under NDZ Corporate's management.

After the incident, the Call Centre Agent resigned before disciplinary proceedings could begin.

MTN Eswatini reported several compliance measures that were in place to prevent such breaches, including: