Singapore Watchdog Fines Ride-Hailing App Grabcar $10000 For Data Privacy Violation

In this article (4)
Singapore’s privacy watchdog fined ride-hailing app Grabcar S$10,000 ($7,310), saying a 2019 update put the data of some users at risk of unauthorized access in what the watchdog said was the fourth breach of data privacy regulations and “a significant cause for concern”. In a filing published on Sept. 10, the Personal Data Protection Commission (PDPC) said the update risked the personal data of 21,541 drivers and passengers, including profile pictures, names and vehicle plate numbers, related to carpooling service GrabHitch.
Grabcar, a unit of Southeast Asia’s largest startup Grab Holdings, rolled back the app to the previous version within about 40 minutes and took other remedial action, the PDPC said.
“Given that the organization’s business involves processing large volumes of personal data on a daily basis, this is a significant cause for concern,” the PDPC said.
The regulator also directed Grab to put in place data protection by design policy, where data protection measures are considered and built into tech systems as they are being developed.
In a statement, Grab said: “To prevent a recurrence, we have since introduced more robust processes, especially pertaining to our IT environment testing, along with updated governance procedures and an architecture review of our legacy application and source codes.”
Questions & Answers
Q.What kind of personal data was put at risk by the Grabcar update?
What kind of personal data was put at risk by the Grabcar update?
The update risked personal data including profile pictures, names, and vehicle plate numbers. This information belonged to 21,541 drivers and passengers involved with the GrabHitch carpooling service.
Q.What measures has Grab stated they are taking to prevent future data breaches?
What measures has Grab stated they are taking to prevent future data breaches?
Grab has introduced more robust processes for IT environment testing, updated governance procedures, and undertaken an architecture review of their legacy applications and source codes to prevent recurrence.
Q.How quickly did Grabcar address the problematic app update once the issue was discovered?
How quickly did Grabcar address the problematic app update once the issue was discovered?
Grabcar responded promptly, rolling back the app to its previous version within approximately 40 minutes of the issue arising. They also took other unspecified remedial actions.
Reader pulse
Will Grab's new measures prevent future breaches?
19,403 votes so far