
DA Reports Gauteng e-Panic Data Breach to Information Regulator
Summary
- Gauteng's e-Panic Button app database was left unsecured, exposing sensitive personal data and crime reports.
- The exposed information included names, phone numbers, locations, movement histories, and details of domestic violence and assault cases.
- The Democratic Alliance plans to report the incident to the Information Regulator, seeking an investigation into potential POPIA breaches and the department's handling of the exposure.
- This marks the second data breach involving sensitive information submitted to the Gauteng Provincial Government.
- The e-Panic Button platform, with a total contract value of R269-million, has seen slow user uptake and a change in its backend service provider.
What Happened: Gauteng e-Panic Data Breach
The incident highlights a critical vulnerability in government systems, raising concerns about the protection of sensitive information provided by residents and the need for robust data security measures.
The Gauteng e-Panic Button application, designed to assist residents in emergencies, has been at the center of a significant data exposure incident. Its underlying database was discovered to be unsecured, leaving a vast array of sensitive personal information vulnerable. This breach compromised crime reports, including highly sensitive accounts of domestic violence and assault, alongside the personal identifiers of those who filed them.
Exposed data included the names, telephone numbers, geographical locations, and historical movement patterns of individuals utilizing the service. Each crime report contained detailed descriptions, categories, and any accompanying photographs, in addition to the user's account specifics and GPS coordinates. The account information itself comprised names, genders, ages, phone numbers, email addresses, and even vehicle registration numbers. An examination of the initial 100 crime reports revealed 11 instances of domestic violence, 8 of assault, 14 of theft, and 4 related to drug offenses, with 7 of these reports including attached images. Overall, more than 5,000 crime report images were exposed to the internet. This incident marks the second time sensitive information submitted to the Gauteng Provincial Government has been compromised.
DA Calls for POPIA Investigation
In response to the data exposure, the Democratic Alliance (DA) has announced its intention to formally report the Gauteng e-Panic Button data breach to the Information Regulator. Michael Waters, the DA's Gauteng spokesperson on e-Government, stated that the party is seeking a comprehensive investigation into several critical areas. These include a potential breach of the Protection of Personal Information Act (POPIA), the precise mechanisms that led to the data exposure, the Department of e-Government's subsequent actions, and whether affected residents have been appropriately notified of the compromise.
The DA has also highlighted a concerning lack of transparency, noting that the department failed to inform the Gauteng Legislature's portfolio committee on e-Government about the security lapse. The party is demanding that the department appear before this committee to provide answers. Specifically, the DA seeks clarity on the duration of the information's exposure, whether any unauthorized parties accessed the data, and if access logs have undergone independent scrutiny. The incident highlights a critical vulnerability in government systems, raising concerns about the protection of sensitive information provided by residents and the need for robust data security measures.
Context and Concerns: App Performance and Contract Details
The e-Panic Button platform's operational and financial aspects have also come under scrutiny. While an unofficial tender listing initially indicated a R10-million award to systems integrator Evolve Value Added Services, the department later disclosed the total contract value for the platform to be a substantial R269-million. Evolve has received payments totaling R131.3-million over the last three financial years, with the contract scheduled to continue until March 10, 2027. It is important to note that the reported financial figures have not been independently confirmed by the original reporting source.
Despite the significant investment, the department claims 180,000 downloads for the app, though it has not specified the number of active users. The app's uptake has reportedly slowed, with only approximately 15,000 new downloads recorded between October 2025 and August 2026. This decline coincided with the departure of Aura, the emergency response network that initially powered the app's backend, which stated in August that it had not been involved in the program for over a year. The app's code now indicates Trigger Systems as its power source. The department attributes the low uptake to competition from existing private panic-button services, including those still supported by Aura, as well as offerings from other providers. The rationale behind the government's decision to introduce yet another panic-button service, rather than addressing issues with the 10111 emergency line, remains unclear.
Practical Implications
This incident underscores the critical need for robust data security and breach notification protocols under POPIA for any entity, including government, handling sensitive personal information. Lawyers and compliance officers should review their clients' data protection frameworks and incident response plans, as this high-profile case could inform future regulatory enforcement actions by the Information Regulator.
Source
Source: Original reporting via GroundUp.
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in South Africa
Wansom is AI and can make mistakes.
