Shocking Service and Privacy Breach
I recently became a new fibre client of RSAWeb after 8 months of struggling with back and forth between FrogFoot and RSAWeb.
After 4 days of struggling and fixing human errors, I followed up on a support ticket that I logged about my account on the MyRSAWeb portal not allowing me access to any of my information.
On Tuesday, 4 December, in effort to resolve this issue, an RSAWeb support consultant provided with login details for another customer who coincidentally has the same name and lives in the same area. He asked me to "try these details"... Our email addresses were nothing alike and upon logging in, I was presented with all the user's personal information (name, surname, ID number, home address, contact details etc.).
I took the liberty of reaching out to this individual who then informed me that he was in fact never even a customer of RSAWeb, but rather app**** for fibre and cancelled his application due to slow response and delivery from RSAWeb. He was completely shocked that RSAWeb had created a profile for him on their system, was storing all his personal details and then shared it with a 3rd party. This individual said that he would reach out to RSAWeb personally to have his information removed.
I immediately reported this back to the support team, the Project Lead who was working on my implementation and Information Regulator (SA) and requested that the matter is escalated and my account terminated. At that point the Project Lead roped in the Support Manager.
After following up twice on Wednesday 6 December, I received a call from the Support Manager. He explained that the support consultant assumed that the account details he shared with me was mine, as I didn't correct him last week during when he mentioned the area that I lived in. Therefore the consultant simply searched for my name on their system and took the first one that was listed in the area he assumed I lived in (even though he had my email address and cell number).
The Support Manager also tried to convince me that all client information are in fact stored securely and mentioned various methods that they use to ensure this. He also mentioned that they do retain applicant information for marketing and future client purposes and that the individual's account has now been "deactivated" (as it apparently should have been). According to him, something mysteriously went wrong with both our accounts which resulted in this. Apparently their team is working hard on getting their system compliant with GDPR (General Data Protection Regulation, a standard set by the EU, for the EU... which I doubt covers their client base).
Based on this conduct and the efforts to get my service live, I do not feel that my personal information is in any way safe with RSAWeb and I have requested that my account is terminated with proof that all my personal details are removed.
I am now waiting yet another day for feedback on this matter as this now needs to be escalated to the Business Unit Manager to assess the options available.
