DA to report e-Panic button data breach to Information Regulator of South Africa

Issued by Michael Waters MPL – DA Gauteng Spokesperson for e-Government
28 Sep 2026 in Press Statements

Note to the editors: Please find attached English soundbite by Michael Waters MPL.

The Democratic Alliance (DA) will report the data breach of the e-Panic Button app to the Information Regulator of South Africa. We seek an investigation into a possible violation of the Protection of Personal Information Act (POPIA), the circumstances of the exposure of crime victims’ sensitive information, the e-Government Department’s response, and its notification to affected residents.

The exposure of highly sensitive personal information belonging to Gauteng residents who used the provincial government’s e-Panic Button app represents a serious failure by the Gauteng Department of e-Government to protect people who turned to the state for help. Even more concerning is that the department has never informed the Gauteng Legislature’s Portfolio Committee responsible for overseeing e-Government about this serious security failure. This is the second data breach in which highly sensitive information submitted to the Gauteng Provincial Government (GPG) is exposed.

It is disturbing that this data breach was exposed in a report by GroundUp and not by the department first. The report alleges that system exposed the names and personal details of people who reported crimes, the contents of their reports, photographs, GPS locations, and location histories. Reports relating to domestic violence and assault were among the information that could be accessed. The system also reportedly exposed one-time PINs used to log into the application.

The DA demands that the department urgently appear before the Portfolio Committee on e-Government. The department needs to provide answers on how long the personal information of residents who use the e-Panic button has been exposed, and whether the information was accessed by unauthorised persons. Have the access logs been independently examined? These are but a few of the questions that the department needs to answer.

Given the department’s limited budget, it raises the question of whether the department should invest in e-Panic Buttons instead of focusing on improving its cybersecurity systems.

According to GroundUp, these were not sophisticated vulnerabilities requiring advanced hacking skills. A tech-savvy computer user could access the information, while some of the exposed data dated back to the launch of the app in 2024. This is unacceptable.

Residents who report domestic violence, assault and other serious crimes must be able to trust that the information they provide to the government will be protected. Instead, a person reporting an alleged abuser could potentially have had their identity, location, movements, and crime report exposed.

This revelation comes at an especially disturbing time for Gauteng. The province, and Ekurhuleni in particular, is reeling from the recent deaths of 11 women, while South Africa continues to confront an enormous gender-based violence and femicide crisis.

Government has repeatedly encouraged victims of violence to speak out and report crimes. Government systems cannot expect vulnerable residents to come forward and trust them while failing to adequately protect the sensitive information they provide.

A government that cannot protect the personal information submitted electronically is putting the digital economy and job creation at risk.

Gauteng residents need to have confidence that there is a government in place that is committed to protecting personal information by having the proper cybersecurity systems in place that will attract investors in the digital economy, which in turn would create more job opportunities.

The Gauteng Provincial Government (GPG) now owes every affected resident a full explanation of what happened, whether their information was accessed, what steps have been taken to protect them, and who will be held accountable. A DA-led Gauteng provincial government would protect sensitive information to ensure that victims are not exposed or made to suffer a double crisis.