Singapore says Grab’s fourth privacy breach is concerning

    The breach, which included the profile pictures, names, wallet balance of users and vehicle plate numbers, was related to GrabHitch, a service that allows carpooling.
    By BLOOMBERG
    | Updated on Sep 13 2020, 01:23 PM IST
    GrabCar posted revenue of S$67.5 million and a loss of S$119.7 million in 2018, according to its most recent filings with Singapore regulators.
    GrabCar posted revenue of S$67.5 million and a loss of S$119.7 million in 2018, according to its most recent filings with Singapore regulators. (REUTERS)
    GrabCar posted revenue of S$67.5 million and a loss of S$119.7 million in 2018, according to its most recent filings with Singapore regulators.
    GrabCar posted revenue of S$67.5 million and a loss of S$119.7 million in 2018, according to its most recent filings with Singapore regulators. (REUTERS)

    Singapore’s privacy regulator imposed a S$10,000 ($7,311) penalty on ride-hailing company GrabCar Pte for a personal-data breach incident last year and raised the alarm on repeated violations by the unit of Grab Holdings Inc.

    In August 2019, an update of Grab’s mobile application exposed the personal data of more than 21,500 users to the risk of unauthorised access, according to the Personal Data Protection Commission. 

    Also read: Looking for a smartphone? To check mobile finder click here.

    The glitch was fixed in less than an hour, according to the report. Still, the company should have had “properly scoped pre-launch tests” of the update before deployment, the commission said, adding that it was Grab’s fourth personal data violation since 2018.

    ALSO READ: TikTok owner ByteDance to invest billions in Singapore over three years

    “Given that the organisation’s business involves processing large volumes of personal data on a daily basis, this is a significant cause for concern,” Yeong Zee Kin, deputy commissioner for the Personal Data Protection Commission, said in the announcement dated Sept. 10.

    Singapore is among a handful of Asian countries with comprehensive data protection rules. Multinationals that do business in Singapore must follow its Personal Data Protection Act, which requires companies to get user consent before collecting or using personal data.

    GrabCar posted revenue of S$67.5 million and a loss of S$119.7 million in 2018, according to its most recent filings with Singapore regulators.

    Grab, which has operations in 351 cities across eight countries in Southeast Asia, has diversified into digital offerings such as food delivery and financial technology services. The mobile application had more than 187 million downloads, according to a statement on the company’s website.

    ALSO READ: Singapore says blockchain payments project ready for commercial rollout

    Grab’s cooperation with the investigation and prompt, forthcoming responses to queries was a “mitigating factor” when arriving at the penalty amount, the regulator said. For Grab’s mobile applications, the regulator ordered a so-called data protection by design policy -- where developers consider data and privacy issues at the design phase -- within 120 days.

    By Ameya Karve and Yoolim Lee

    Follow HT Tech for the latest tech news and reviews , also keep up with us on Twitter, Facebook, and Instagram. For our latest videos, subscribe to our YouTube channel.

    First Published Date: 13 Sep, 01:23 PM IST
    NEXT ARTICLE BEGINS
    keep up with tech