LD
Leri D

1 reviews | Active since Jun 2020

20 May 2026, 08:05

POPI breach

I wanted to raise a serious concern regarding how SAMSUNG is protecting my information, which was brought to light in the Samsung promotions process

While your promotions department was requesting proof of purchase documentation from me, I was mistakenly sent an Excel spreadsheet containing other customers’ personal information, by Thozoma including names, surnames, email addresses, cellphone numbers, place of purchase, and IMEI numbers.

The document was also not password protected, which increases the seriousness of the incident.

My concern is not only that I received another customer’s data, but that this suggests there may be insufficient controls around how customer information is stored, shared, and protected internally.

If this information could be sent to me accidentally, I’m concerned about how my own personal information is being handled and whether adequate POPIA safeguards are actually in place. What concerns me most is that the spreadsheet was not password protected and appears to have been freely accessible for emailing without additional security controls. I also want to raise a concern regarding how the matter was handled after I requested escalation.

When I asked to speak to a supervisor regarding the privacy concern, I was advised that a supervisor would call me back. However, instead of an independent escalation, I then received a call from the same consultant involved in the incident apologising to me after she was contacted internally by the consultant whom i raised the concern with.

From my perspective, this did not provide confidence that the matter was being handled with the level of independence and seriousness expected for a potential POPIA-related issue.

For matters involving customer data exposure, I would expect direct engagement from a supervisor, compliance representative, or data privacy representative rather than the matter being redirected back to the individual involved in the incident. I would like this matter formally logged as a privacy and POPIA concern, escalated to the relevant compliance or information security team, and I would like feedback on what corrective actions Samsung is implementing to prevent a recurrence.

I also want confirmation regarding how my own personal information is protected within your systems given what has occurred.

Given the seriousness of the information disclosed, I expect this matter to be treated as more than a standard customer complaint

0
Replies (1)
Samsung South Africa
Samsung South Africa's reply20 May 2026, 08:06
Official
Good day Leri

Thank you for bringing your query to our attention, we apologize for any inconvenience that this may have caused. 
  
We have noted your concerns, and we are currently investigating the matter further. 
  
Your complaint has been assigned to our escalations department and we will be in contact with you. 
  
 Kind Regards, 
 Samsung ZA
^NM