Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      South Africa's broadband future is being decided in orbit, not in Pretoria

      South Africa’s broadband future is being decided in orbit, not in Pretoria

      30 June 2026
      Takealot bets local scale can hold Amazon at bay - Frederik Zietsman

      Takealot Group bets local scale can hold Amazon at bay

      30 June 2026
      Tony Leon rejects 'state capture' label in Starlink lobbying row

      Tony Leon rejects ‘state capture’ label in Starlink lobbying row

      30 June 2026
      Vodacom takes the reins at Safaricom

      Vodacom takes the reins at Safaricom in R35-billion deal

      30 June 2026
      South Africa's fibre underdogs are beating the giants

      South Africa’s fibre underdogs are beating the giants

      30 June 2026
    • World

      SK Hynix ends Samsung’s 26-year reign at the top

      22 June 2026
      Google on the hook for what its AI tells users, court rules

      Google on the hook for what its AI tells users, court rules

      15 June 2026
      How Russians juggle VPNs to outwit the Kremlin

      How Russians juggle VPNs to outwit the Kremlin

      15 June 2026
      Amazon CEO flagged Anthropic AI risks to Washington - Andy Jassy

      Amazon CEO flagged Anthropic AI risks to Washington

      14 June 2026
      Trouble at Xbox

      Trouble at Xbox

      11 June 2026
    • In-depth
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
      What Wi-Fi 8 will mean for wireless networks

      What Wi-Fi 8 will mean for wireless networks

      1 June 2026
      Alfa's electric rebel - Alfa Romeo Junior Elettrica Veloce

      Alfa’s electric rebel

      29 April 2026
      Africa switches on as Europe dims the lights

      Africa switches on as Europe dims the lights

      9 April 2026
    • TCS
      TCS+ | IBM Bob: an AI-powered 'development partner' for the enterprise - David Spurway

      TCS+ | IBM Bob: an AI-powered development partner for the enterprise

      30 June 2026
      Watts & Wheels S1E6: 'A flawless Alfa and a bakkie that divides'

      Watts & Wheels S1E6: ‘A flawless Alfa and a bakkie that divides’

      17 June 2026
      Watts & Wheels S1E6: 'A flawless Alfa and a bakkie that divides'

      Watts & Wheels S1E5: ‘A Bentley of the bush and a car that swims’

      8 June 2026
      TCS | Charge's R1.8-billion bet on an off-grid EV future - Charge chairman Joubert Roux

      TCS | Charge’s R1.8-billion bet on an off-grid EV future

      18 May 2026
      TCS+ | The Up&Up Group on the hidden cost of AI - Jason Harrison

      TCS+ | The Up&Up Group on the hidden cost of AI

      13 May 2026
    • Opinion
      The pivot South Africa's MVNOs cannot afford to miss

      The pivot South Africa’s MVNOs cannot afford to miss

      23 June 2026
      Brazil's online gambling crackdown is a lesson for South Africa

      Brazil’s online gambling crackdown is a lesson for South Africa

      22 June 2026
      Finish the job Mandela started - Farzam Ehsani

      Finish the job Mandela started

      18 June 2026
      The author, Fanie van Rooyen

      The US just showed it can switch off our AI

      17 June 2026
      The pivot South Africa's MVNOs cannot afford to miss

      The clock is ticking on South African banks’ biggest advantage

      9 June 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM Telecom
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Information Regulator pursues Dis-Chem over data breach

    Information Regulator pursues Dis-Chem over data breach

    The Information Regulator has issued Dis-Chem with an enforcement notice for various contraventions of Popia.
    By Staff Reporter1 September 2023
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    The Information Regulator has issued pharmacy chain Dis-Chem Pharmacies with an enforcement notice for various contraventions of the Protection of Personal Information Act (Popia).

    “Around April and May 2022, Dis-Chem’s third-party service provider, Grapevine, suffered a brute-force attack by an unauthorised party. Some 3.7 million data subjects’ records were accessed from Dis-Chem’s e-statement service database which was managed by Grapevine,” the regulator said in a statement on Friday.

    “The affected records in this database were limited to names and surnames, e-mail addresses, and cellphone numbers of the data subjects,” it said.

    Dis-Chem must now conduct a personal information impact study to ensure that its systems are Popia compliant

    In its assessment of the data breach, the Information Regulator found that Dis-Chem failed to identify the risk of using weak passwords and to put measures in place to detect unlawful access to their system or, at the very least, secure an agreement with Grapevine to have adequate security measures in place along with reporting protocols in the event of a breach.

    According to the enforcement notice, Dis-Chem must now conduct a personal information impact study to ensure that its systems are Popia compliant.

    This must be supplemented by an incident response plan to better deal with future breaches. The pharmacy chain must also update all its contracts with operators that process personal information on Dis-Chem’s behalf, like Grapevine, to compel them to become Popia compliant.

    Dis-Chem must implement these and other stipulations in the enforcement notice and provide a report to the regulator within 31 days. Should Dis-Chem not abide by these guidelines, it will find itself liable to a fine of up to R10-million, similar to the R5-million fine the regulator issued to the department of justice in July.

    Dis-Chem responds

    TechCentral first reported about a data “incident” at Dis-Chem last year involving a “third-party service provider or operator” that had led to the compromise of millions of client records containing personal information. Dis-Chem did not name the third party at the time, but did say no sensitive medical, financial or banking information was contained in the database.

    In a statement released on Friday, Dis-Chem disputed the accuracy of the Information Regulator’s allegations.

    The pharmacy chain agreed with the assertion that the data breach was restricted to customer data relating only to mailing information, confirming that no “medical, financial or banking information” had been breached because “the [service] provider, Grapevine, can never have access to this type of information”.

    However, Midrand-based Dis-Chem refuted the regulator’s claim that it was inadequate in its efforts to fulfil its reporting duties once the breach had occurred.

    “Dis-Chem strongly disputes the regulator’s claim that it failed to notify data subjects as it followed all required Popia guidelines to ensure that customers were immediately made aware of the breach. A formal notice was published on the Dis-Chem website and a media statement was released nationally.”

    Dis-Chem also dismissed the regulator’s stipulations regarding the failure to implement an incident response plan as per the Payment Card Industry Data Security Standards (PCI DSS), saying that the PCI DSS response plan “has no bearing at all and is irrelevant to the enforcement notice” because Grapevine, the compromised service provider, played no role in card payments and therefore did not hold any customer card data in its possession.

    Read: 3.7 million client records compromised in Dis-Chem data ‘incident’

    “Following the data breach, Dis-Chem implemented all necessary steps and protocols to control access to the database and isolate the threat. The company has responded to the regulator via written communication on all concerns raised. It has, and will, continue to work with the regulator to ensure full compliance on any relevant and accurate areas of concern,” the retailer said.  – © 2023 NewsCentral Media

    Get the latest tech news in your inbox at 5am daily

    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Dis-Chem Grapevine Information Regulator
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleJoJo tanks are going hi-tech
    Next Article Top 5 in-demand IT courses to boost your CV

    Related Posts

    Amazon

    Amazon’s long game in South Africa

    3 June 2026
    Security by design is the channel's strongest pitch - Othelo Vieira

    Security by design is the channel’s strongest pitch

    23 April 2026
    Sita, Sars rubbish reports they were hacked

    Standard Bank data breach fallout deepens

    16 April 2026
    Company News
    A smarter switch for networks that can't afford to fail

    A smarter switch for networks that can’t afford to fail

    30 June 2026
    Johann Combrink

    How a garage start-up became one of South Africa’s trusted software houses

    30 June 2026
    Why more data is not the answer - better operational signals are - Sigfox South Africa

    Why more data is not the answer – better operational signals are

    30 June 2026
    Opinion
    The pivot South Africa's MVNOs cannot afford to miss

    The pivot South Africa’s MVNOs cannot afford to miss

    23 June 2026
    Brazil's online gambling crackdown is a lesson for South Africa

    Brazil’s online gambling crackdown is a lesson for South Africa

    22 June 2026
    Finish the job Mandela started - Farzam Ehsani

    Finish the job Mandela started

    18 June 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    South Africa's broadband future is being decided in orbit, not in Pretoria

    South Africa’s broadband future is being decided in orbit, not in Pretoria

    30 June 2026
    Takealot bets local scale can hold Amazon at bay - Frederik Zietsman

    Takealot Group bets local scale can hold Amazon at bay

    30 June 2026
    Tony Leon rejects 'state capture' label in Starlink lobbying row

    Tony Leon rejects ‘state capture’ label in Starlink lobbying row

    30 June 2026
    Vodacom takes the reins at Safaricom

    Vodacom takes the reins at Safaricom in R35-billion deal

    30 June 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}