0% found this document useful (0 votes)
7 views4 pages

Data Security in South African Smart Vehicles

The document is an interview with Darron Harris, a dealership principal, discussing data security measures in smart vehicles in South Africa. Key topics include the impact of data privacy policies, technical measures for securing personal information, the role of an information officer, and the right to deletion of personal information under the POPI Act. Darron emphasizes the importance of personal relationships with clients and the need for stringent data protection practices within the dealership.

Uploaded by

fadeel1973
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views4 pages

Data Security in South African Smart Vehicles

The document is an interview with Darron Harris, a dealership principal, discussing data security measures in smart vehicles in South Africa. Key topics include the impact of data privacy policies, technical measures for securing personal information, the role of an information officer, and the right to deletion of personal information under the POPI Act. Darron emphasizes the importance of personal relationships with clients and the need for stringent data protection practices within the dealership.

Uploaded by

fadeel1973
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

For the sake of authenticity, the grammatical structure of the sentences has not been changed.

Title of study: ENHANCING THE SECURITY OF DATA IN MODERN DAY VEHICLES. A CASE STUDY OF SMART VEHICLES
FROM DEALERSHIPS IN SOUTH AFRICA
Interview Transcription
Respondent Darron Harris
Respondent Designation Dealership Principle
Interviewer Moegamat Fadeel Kamalie
Date of Interview 25 August 2024
The respondent had a brief introduction outlining the interview.

Fadeel: Ok so, interview with Darron Harris Dealership Principle at Smart car dealerships. The interview will be conducted as
part of the study Hi Darron.
Darron: Good morning.
Fadeel: Darron, I've got basically just five interview questions, and these questions are based off of themes that I've extracted
from my literature review and basically all of the other acts that I've explored, ok?
Darron: Ok.
Fadeel: So, it's five questions and the first question will deal with the topic of policies, the second one will deal with consent, the
third one with technical measures, the fourth one will be the information officer and then the last one will be the request of
deletion of personal information.
Darron: Ok. Good.
Fadeel: Just to give you some background then on the first question, that's based on policies, the GDPR, which is the data
protection regulation in the European Union, they leave no room for misinterpretation when it comes to the importance of the
adoption of policies, ok? PIPEDA, it is another data protection act that they've got in Canada and they also do not leave any
room for misinterpretation. POPI however, only states that you have to take reasonable organisational measures, and by
measures it can mean policies, it can even mean the technical measures. So my question basically to you is, I would like to
know what are your thoughts on, if you had to implement or to consider the implementation of data privacy policies, what do
you think the impact it could have on the business, or just generally what your opinion would be. Darron: Generally, in terms of
the industry or the country or the way we operate.
Fadeel: The way we operate.
Darron: Ok, it wouldn't have a huge big impact on the way we operate if we had to make things any more stringent because
we're not using data to sell to anybody, we're not giving data away. We even very seldom contact our existing client base to up
sell them onto other products. So, in the past we used to, but we do not do it anymore, we may now if we've got people on
Heritage for example, we may get the agents who are already signed up to work directly with them to phone them to say we
now have another product, would you be interested in that, can I come and see you about it. We never ever going to just take
our database as it stands, give it to our call centre and say right, fire away and phone everybody and see if they're interested in
any other products. We don't do that as it stands. So it's very much a personal relationship between the client and the agent,
and the agent would phone back and say, "Look, I've got something else, would you be interested in talking to me about it. So
it's not on this mass production basis where we're just saying here's a list, go out there and call them. Has that answered your
question?
Fadeel: Well, it has actually answered a bit of question 2, but that's fine, it was more like just to implement policies, if you would
implement like some kind of a privacy policy within the business like for example, users be sure that whenever you do a
customer call to be sure that you do not or ensure that it is the correct person that you are speaking to, maybe even when
sending an email out to an client they need to confirm that email address is correct.
Darron: You see, that is quite difficult. I think our call verification that we do is probably the most fundamental aspect of our
policy process because the agent will meet personally with the client, complete the form, bring the form to us. We then have a
form which gets captured on to system. before we actually put it live, we will make a verification call. And in that call we verify
everything, right down to this is your name, we double check your ID number, your bank details, you did fill in the form, you did
meet with that person, you know what the policy is about, you know what you are going to be paying, you know how often you
are going to be paying, you know what cover you've got, what it includes, what it excludes, all those types of things. And in
doing so I would think, because that's a call recording, you would be saying to the person, "This is you, this is your ID number,
this is your phone number, this is your email address.". I'm hoping that that's enough to then say that in future whenever we
have any form of communication with that person, we've had the call recording, So, to say that this is your information, so if I'm
now emailing you now on that email address that you've confirmed is true and correct, I have to go on the premise that it is in
fact you that's reading it. Whether there's someone else sitting on the other end and reading it, Idon't know how any company
would ever stop that problem from ever happening, you can't. the best we can do is say that you have verified this is your
information and we're sending things to you in good faith.
Fadeel: Ok. That's a very interesting answer. It seems like there might be even a bigger issue within the entire industry when it
comes to authenticating a user.
Darron: One hundred percent.
Fadeel: Thank you for that Darron.
Darron: Pleasure.
Fadeel: The next question has to do with direct marketing but as you've answered in question one you've already mentioned
that Medway itself does not sell any information to anybody else and we don't make outbound calls to attract clients so that's
fine.
Darron: Ok.
Fadeel: Question three, POPI requires that reasonable technical measures be put in place to secure personal information and
what are your thoughts on that? Or things that you think we could implement, things that are implemented?
Darron: So, since the implementation of POPI, POPIA, we have been a lot more sort of rigid in our IT processes. So before,
you would be aware of this because you helped us institute it, the password login wasn't quite as strictly managed as it is now.
It was, you put a password in at the outset and you didn't have to renew your password any given time. Now we've obviously
changed that. So first of all there has to be a password for access and secondly those passwords have got to be updated on a
regular basis. So, for me that already is protecting each workstation. So from a technical perspective we've got that. We've
obviously then got protection on our database, we've got firewalls in place, so we shouldn't have people coming in and being
able to steal the data. In essence, and we're very careful about, we haven't even gone the route of putting information on a web
portal so that, let's say for example, an agent can log in and go and fetch the information. We haven't even gone as far as to do
that yet because we are little bit concerned about security of information. So, the files, you know, sit on our main server, with a
firewall, protected access and password control. And for me that's, that seems to be enough at this stage. We would obviously
watch to see if any changes are coming through but for now we believe that we got enough cover there. We've had IT people
come and do an audit just to see are, do we have enough of a level of protection and our insurers have had to come in and
check on that as well because as our insurers, we have a cell within them they have to make sure that we are a hundred
percent complaint with all the acts and that was one the things that they did look at. So they're comfortable at this stage and
they are also comfortable that we have a backup of data. So that's from a technical perspective. Will you be asking me from a
paper perspective? From hard copies? Fadeel: You are more than welcome to.
Darron: So hard copies pose more of a threat, in my mind. So, we have agents that work all over the country. They go out, they
meet with the client. They then get that piece of paper, scanned in to us but they still sit with the original copy. And that for us
was a risk. Because agents work for themselves they throw things into the boots of their cars, they drive around, they
sometimes driving into areas that are probably a little less safe than we'd like them to be and we've had one or two incidents
where the cars had been broken into. The likelihood of people stealing pieces of paper is not that great, but the fact is it can still
get out there and those pages contain people’s personal identity information. We don't at this point ask for peoples copies of
ID's because of the backwards and forwards in over the last couple of years, about "Should you, shouldn't you, do you need it,
don't you need it" and we will talk about that a little bit later as well because it is still one of those questions that we're still
asking and it comes down to reasonable form of identification. So the "Know your client" aspect but we'll talk about that just
now. But those pieces of paper sitting in agents’ cars or in their brief cases or on the desk at their house, those are the ones
that for me pose a big risk. So we've got a system whereby every month we know which agents have submitted which
applications and they have a certain amount of time in which to get those originals to us. Once we get the original in here we
check on system that we've got a perfectly legible copy, we would've done it anyway but we do a double check, and if we're
satisfied that we've got a good legible copy as a soft copy, we destroy the hard copy. It gets shredded so that we don't have any
pieces of paper that are lying around in anybody's booths or on their desks or anything else, obviously within a reasonable
amount of time. If the agents just been to seen a client and they're on their way back and they get hijacked, unfortunately
there's not much we can do about that. But we do have other sort of options in place where we're saying let's get that
information back from you as quickly as possible. Fadeel: Ok. Alright, and if that type of information is emailed to you, do you
guys then discard the emails as well? That would have that as an attachment?
Darron: Well, yes. We've got a system which cleans up our emails. Nobody is actually keeping all those emails, there is a
delete process for that.
Fadeel: Fantastic.
Darron: Ok.
Fadeel: Thank you, thanks Darron. The fourth question is around the designation of an information officer. Now, just to give you
some background on this, the appointment of data officers is only required by GDPR and POPI. Now, what a data officer’s role
is, that an individual within an organisation or a company that is going to, they are going to deal with all issues that relate to
privacy violations and informing or up skilling the organisation where they are at regarding the different acts. GDPR in the
European Union they actually have got independent bodies that can act as data officers but in South Africa it is recommended
that whenever you employ or designate an information officer it must be someone that is in the close vicinity of where the
business operates and there was one other article that I read it was recommended that when you employ an information officer,
that person should also be aware of other acts that also impact the business and in that way he will be able to then resolve
queries at a much higher rate than what you would if the person had no idea of the other acts that also fall within the ambit of
the business, so in short basically, an information officer is just to assist the business with matters of the POPI Act, so I would
just like to know what are your thoughts on that.
Darron: So, we, effectively, Craig as the operations director, has always sort of taken on that role. He is the custodian of the
data that we have and also being a director of the company and working with, we meet once a month to talk about all the
regulatory requirements, any changes in the industry, so if any new act comes into play we would talk about it, we would meet
on it, and then we would every month when we meet we would say right, three months ago we implemented the POPIA
process into the company, what progress have we made, where are we at with that and we would do that with every other act
as well that we're looking at, so it's a forum where we're actually talking about all new legislation's and changes or updated
requirements etc. So, the directors of the company are talking about that once a month and in doing so, obviously, Craig's
knowledge is quite wide spread, he knows exactly what’s happening. We also have to look at our risk management policies
where we have to take every act that affects us as a business in the financial services environment and we have to mark it
down and at least once a year we have to go back and re-look at that and go, "Right, now lets go through all the acts again and
how do those acts impact our business. What is the risk rating.". And we would do that in respect of POPIA as well. So, Craig is
very very aware of the information and how it needs to be protected and he is looking at it all the time in respect of all the other
acts because he is so well versed on them and he is the custodian at the moment who would be, if anybody, even if an agent
came to us and said, "Please can I a list of all my business for the past five years?", it needs to be an authorised process
before he is just given that information. So the agent is obviously welcome to keep copies of or names and addresses and
phone numbers of his own client base because they are his clients but when they come to us say," Please can I have a list of
them, my client base?", it tells us first of all that they're not so diligent in doing that, they do rely on us for that information but
they need to motivate why they want the list and what they're going to do with it. And ninety percent of the time, unless off
course they can give us a proper motivation as to why they would need it, the contact details are removed from those lists. So,
even with us having the data, people like our own agents don't even have immediate access to it. Its very very stringent and
Craig is monitoring it all the time to see how it fits in with other acts and are we in keeping with the overall regulatory
requirements in the country.
Fadeel: Ok, alright.
Darron: Also, I need to just add to that, obviously your knowledge on this and your involvement and the fact that you're now with
us, we would obviously have you as the second pinnacle person, who could become our official designated information officer.
Fadeel: Ok, alright. Because there's apparently a process involved that information officers have to be registered with the
information regulator.
Darron: Like a compliance officer.
Fadeel: And I've contacted the information regulator numerous times and I'm not getting feedback from them, I tried calling
them but they've moved offices from Pretoria to Joburg. And I've sent an email to the privacy commissioner in Canada and they
responded to me in, I think it was two weeks. And I had a question about their right to deletion, which is the next question, and
they weren't too explicit about granting the right for deletion. But then i asked them, look according to it you kind of hint at it and
then they responded, they replied to me and said yes, that it is actually the case, that it is covered when you withdraw consent
then that is the right to deletion, so.
Darron: Ok, interesting ways. So that's obviously something in the wheel, they had to come back to us and say, "Now you need
to have on official appointed information officer like you do a compliance officer and this is the process.", we would follow the
process. So when it comes into being that would be something that would be tabled at the regulatory meeting, it would be put
on there until such time as we can actually sign it off to say that that it has been fully implemented, and then we would watch it
to see how it's actually working there after.
Fadeel: Awesome, awesome. Ok, the last question
Darron. This would be the request for deletion of personal information. Now POPI does grant individuals that right to request
that their information be removed from system or hard copy.
Darron: Ok, so is that, are we talking about a client saying ,"I am going to give you this application form, put it onto your system,
implement my policy, but then I want my...", because you can't, it's not reasonable to ask that the company then remove your
information because you can't administer a policy and talk about, you can't sit and advocate that you know your client if your
clients information's been removed. So, at best I would think that what you could do for that client whilst they still have an active
policy would be to have their information somehow encrypted so you would keep information up front which would be, give you
the bare minimum enough to identify the person but all the actual information such as their full ID number and address details
etc would be encrypted.
Fadeel: Okay.
Darron: We're not at that level yet, but if the act came out and said that this what you need to start doing, we would certainly
comply.
Fadeel: Well look, there was no specific technical requirements from POPI, for them reasonable, I mean, that is one of the
biggest problems with POPI is that it does not give you, for example, the technical requirements, right? It does not even
mention encryption at all, whereas GDPR mentions encryption and pseudonymisation, they mention it to say look, you can take
these routes, but POPI does not, they say reasonable technical measures which then means I can have a person at a desk
with a username and password that can be considered reasonable, for a web portal it can be, it can also just have a username
and password, maybe two-factor authentication, that can also be considered reasonable. So, you know the POPI act is not very
clear.
Darron: It is, it's still quite wide open, So now, POPIA comes along and says, actually you can't do that with the data, and we
going well, do we don't we? Or do we hang on to it five years post termination or do we get rid of it. And now, so that's where
we're at as it stands we still abide by FAIS which says you only terminate a person’s information five years after the termination
of their policy. And that's what we do. So on system, we're busy refining that, but that's ultimately it's gonna work at the click of
a button. At the moment it takes a lot more manual intervention to do that. But we are managing it on the basis that everything
that's terminated every month, everything that's been terminated for five years gets terminated off system, deleted off system.
Fadeel: Or the masking, it’s also a technique that gets used. At the company we use a relational
database and in order to maintain the relation integrity and all of the transactions that you need to store as a FAIS requirement,
it wouldn't be feasible to delete that information, the best we can do is mask that data and have a masked identifier which we
can later refer to
Darron: Hundred percent. So my mind, deleting or masking it’s probably the same thing. The average person in the office isn't
gonna go and be able to access that person’s information after that set amount of time.
Fadeel: Look, also,
Darron, the other thing with POPI is that, look, they give the right for a client to request the deletion of information but it will, you
are only obliged to delete the information if you no longer require that information to perform a function that you need to in the
best interest of the client, for example, having an active policy. You cannot send us a request, look delete my information but
you've got an active policy. That's not gonna happen. They must either then terminate or whatever the case my be, but. One
thing I have also found in my research is that Google actually had a few legal battles that they lost. They had a person request
deletion of information because when he would search for himself on google it would pick up information about him from five
years ago. Now, he's a business man he had his own business, and it picked up that he was under sequestration, now that
information can damage his current reputation. he had to fight Google to have it removed but then he won the case. There was
however one instance where Google won the case. It was a lady that starred in a short movie and it was posted on YouTube. It
had to with Islamic rights and woman abuse. And after the video was posted the poor lady got death threats, and then she
contacted Google to have it removed because it's an infringement of her rights but the courts found in favour of google because
they did not transgress in anyway.
Darron: And she had agreed to appear in the movie in the first place. So, I suppose its the same as this where you agree to
speak out about something then you know that its for a particular purpose to be viewed by the public fully. So interesting, I
could add here that for me, one of the big challenges on the whole POPIA act if I may just give it to you at this stage has been
the hard copies of documents. We now since we were made aware of the fact that POPIA was coming into being we started
taking steps so we no longer send every single hard copy to metrofile, for example, we don't do that anymore, we destroy the
hard copy once we've confirmed we have a soft copy because the FAIS act states that we only need to have a soft copy, we
don't need both. our problem lies with the apps that we have had in storage for a number of years and I'm talking pre-two
thousand, so those applications are sitting in metrofile in a particular order which depending on the times of the year some of
them we're able to identify right down to the box, others not really, it’s more about a period that we could track it down to but
what we don't have at this stage is a system whereby we can say to metrofile, "Fadeel, their policy has been deleted for 5 years
now, please go to this box to this file and remove
Fadeel Theys's file and destroy it". That process we don't know how to do that. We've
met with a number of service providers, we've met with metrofile themselves, we've met with other insurers to ask them if they
have a system whereby they can do this and nobody can actually tell us how to do this. But I'm sure that you will agree, that it's
too expensive for a company, because metrofile is going to ask a fortune, because you're sending them on a wild goose chase
into a file, into a warehouse with millions of documents and they must go locate one box, one file and take out one piece of
paper and then destroy it, and then send us confirmation to say that that document has
been successfully destroyed. Can you imagine the infrastructure and the logistics around trying to
manage that process so as much as we are wanting to comply one hundred percent, that is the one area where we have got a
little bit more of a struggle so what we're hoping is that the information is sitting in metrofile and metrofile we have spoken to
about it they saying to us that there documents are really safe there and no one can get access to those documents. So on that
basis we're just hoping that the information could never fall into the wrong hands, there's just too much of it and no one's going
to break into a warehouse and look for a particular piece of paper, they not gonna find it, so our hope would be that it would
never fall into the wrong hands, at worst it could be a fire, but
we're not too concerned with that because we've got soft copies of it anyway, so if you can, in your research come up with a
solution to that problem it would help us immensely.
Fadeel: Alright Darron, i think that is it.
Darron: Pleasure.
Fadeel: I just have one last question. Do you perhaps think that you've maybe learnt anything form the interview?
Darron: I have yes, thank you. It's good to know that where we sit in relation to this kind of act and rest of the world. It's good to
know that we're following suite of some of the big powers and I would be very interested to hear you come to me one day to
say, "Remember we were talking about how vague POPIA is? We can now confirm just how specific the act is in Canada and
the states, sorry I forget the names, but that we're at that same level, that there's no concern about how they're open to
interpretation, that they're actually so fastidious in the policy wording that there's no leave to apply it as you want to.
Fadeel: And if you think about it, one of the reasons, I think it is like that is because the application of POPI is very subjective
because companies will have different methods and different ways and like you said, this company is also bound by the FAIS
act. So, I think that's why, but also its true what you say that it should become a lot more clear.
Darron: Completely, so we're all trying to comply and do the best we can but we know that there's some loopholes. And even
this particular questioni posed to you about managing hard copies. Nobody can give me an answer, nobody. So I don't know if
while people were sitting here talking about this what they've thought about in terms of historical information. So pre the FAIS
act, pre all the other acts, people have got files sitting in warehouses somewhere, and what do you do to fix that.
Fadeel: Because we can't erase history.
Darron: That's exactly it. So we can take on the new acts by all means and we can say that as of today we will not here and
now we will definitely not have a file sitting in metrofile that we can’t get rid of, but we can't say that for that happened pre 2000
or even early 2000's .
Fadeel: I think they will probably make a provision for that.
Darron: Yes.
The interview closed with me thanking Darron for his time.

You might also like