{"id":183673,"date":"2017-07-05T09:07:33","date_gmt":"2017-07-05T07:07:33","guid":{"rendered":"https:\/\/businesstech.co.za\/news\/?p=183673"},"modified":"2017-07-05T09:07:33","modified_gmt":"2017-07-05T07:07:33","slug":"sa-businesses-arent-obligated-to-tell-you-if-your-data-has-been-ransomed","status":"publish","type":"post","link":"https:\/\/businesstech.co.za\/news\/it-services\/183673\/sa-businesses-arent-obligated-to-tell-you-if-your-data-has-been-ransomed\/","title":{"rendered":"SA businesses aren&#8217;t obligated to tell you if your data has been ransomed"},"content":{"rendered":"<p>With the recent WannaCry and NotPetya attacks, South African businesses are feeling the effects of cyber attacks first-hand, but they may now also have a duty to their customers, according to Norton Rose Fulbright&#8217;s\u00a0Kerri Crawford and Rakhee Bhikha.<\/p>\n<p>&#8220;Barely recovering from the WannaCry ransomware attack, many across the globe now have to deal with the latest ransomware attack, NotPetya,&#8221; the legal experts said.<\/p>\n<p>Originally thought of to be the Petya ransomware, security analysts quickly realised that the current cyber-attack was not designed to make money. It appears that NotPetya has actually just been designed to cause maximum damage, while disguising itself as ransomware.<\/p>\n<p>&#8220;You know you\u2019ve been affected by NotPetya if you receive a message that your files have been encrypted with a demand to pay $300 in Bitcoin.&#8221;<\/p>\n<p>&#8220;Unlike with WannaCry there is no \u2018kill-switch\u2019 with NotPetya. A \u2018kill-switch\u2019 enables tech-wizards to infiltrate the malware and stop it from encrypting data or causing damage&#8221;.<\/p>\n<p>The result is that the\u00a0NotPetya ransomware has affected large organisations all over Europe and the US.<\/p>\n<h3 class=\"my-4\"><strong>Local<\/strong><\/h3>\n<p>In South Africa, there is currently no legal obligation on companies to notify anyone, either a local authority or customers of the company, the experts noted.<\/p>\n<p>Barring any confidentiality or similar contractual obligation that companies may have to customers, companies do not have to publicise their breach.<\/p>\n<p>&#8220;However, once the Protection of Personal Information Act 2013 (POPI) commences there will be an obligation on organisations to report data breaches to the information regulator and customers; and once the Cybercrimes and Cybersecurity Bill is enacted there will be new offences created that will make cyber attacks and breaches illegal in South Africa.&#8221;<\/p>\n<p>The pair noted, however, that\u00a0South African companies with affiliates or headquarters in other jurisdictions may currently have notification obligations in terms of those foreign laws.<\/p>\n<p>&#8220;Companies may also notify people potentially affected by a data breach as a policy decision or good practice, although proper legal and public relations advice should be taken before doing so.&#8221;<\/p>\n<hr \/>\n<p><strong>Read:\u00a0<a href=\"https:\/\/businesstech.co.za\/news\/technology\/183647\/parliament-opens-controversial-cyber-crime-bill-to-public-comment\/\" target=\"_blank\" rel=\"noopener\">Parliament opens controversial cyber crime Bill to public comment<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the recent WannaCry and NotPetya attacks, South African businesses are feeling the effects of cyber-attacks first-hand but they now may also have a duty to their customers, according to Norton Rose Fulbright&#8217;s\u00a0Kerri Crawford and Rakhee Bhikha.<\/p>\n","protected":false},"author":10,"featured_media":120895,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9872,31],"tags":[25],"class_list":["post-183673","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-it-services","tag-active"],"_links":{"self":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/183673","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/comments?post=183673"}],"version-history":[{"count":9,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/183673\/revisions"}],"predecessor-version":[{"id":183695,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/posts\/183673\/revisions\/183695"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media\/120895"}],"wp:attachment":[{"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/media?parent=183673"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/categories?post=183673"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/businesstech.co.za\/news\/wp-json\/wp\/v2\/tags?post=183673"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}