Singapore says Grab’s 4th privacy breach is concerning

SINGAPORE • Singapore’s privacy regulator imposed a S$10,000 (RM30,351) penalty on ride-hailing company GrabCar Pte Ltd for a personal-data breach incident last year and raised the alarm on repeated violations by the unit of Grab Holdings Inc.

In August 2019, an update of Grab’s mobile application exposed the personal data of more than 21,500 users to the risk of unauthorised access, according to the Personal Data Protection Commission (PDPC). The breach, which included the profile pictures, names, wallet balance of users and vehicle plate numbers, was related to GrabHitch, a service that allows carpooling.

The glitch was fixed in less than an hour, according to the report. Still, the company should have had “properly scoped pre-launch tests” of the update before deployment, the commission said, adding that it was Grab’s fourth personal data violation since 2018.

“Given that the organisation’s business involves processing large volumes of personal data on a daily basis, this is a significant cause for concern,” Yeong Zee Kin, deputy commissioner for the PDPC, said in the announcement dated Sept 10.

Singapore is among a handful of Asian countries with comprehensive data protection rules. Multinationals that do business in Singapore must follow its Personal Data Protection Act, which requires companies to get user consent before collecting or using personal data.

GrabCar posted revenue of S$67.5 million and a loss of S$119.7 million in 2018, according to its most recent filings to Singapore regulators. Grab, which has operations in 351 cities across eight countries in South-East Asia, has diversified into digital offerings such as food delivery and financial technology (fintech) services.

The mobile app had more than 187 million downloads, according to a statement on the company’s website.

Grab’s cooperation with the investigation and prompt, forthcoming responses to queries were “mitigating factors” when arriving at the penalty amount, the regulator said.

For Grab’s mobile apps, the regulator ordered a so-called data protection by design policy — where developers consider data and privacy issues at the design phase — within 120 days. — Bloomberg