TO: ALL MEDIA

FOR IMMEDIATE RELEASE

DATE: 08 OCTOBER 2026

GPL COMMITTEES DEMAND ACCOUNTABILITY OVER ALLEGED E-PANIC BUTTON SECURITY BREACH

The Gauteng Provincial Legislature’s Portfolio Committee on e-Government and Research & Development and Portfolio Committee on Community Safety have called for urgent accountability following an alleged security breach involving the Gauteng e-Panic Button platform, with serious questions raised about the role and responsibility of the external service provider responsible for developing and hosting the app.

The Committees convened a joint meeting on Monday, 5 October 2026, to allow the Department of e-Government to account for the reported exposure of personal information belonging to users of the e-Panic Button and to outline measures taken to address the alleged security compromise.

The Committees were not satisfied with the Department’s response.
The Gauteng e-Panic Button is an important public safety platform designed to connect residents to emergency services when they are in danger. It carries highly sensitive information, including residents’ names, contact details, locations, movement histories and crime reports.

The Provincial Government procured services of an external service provider to develop and host the application on its behalf. While the Committees will await the outcome of the investigations before making definitive findings, they are clear that any party found to have failed in its responsibilities must be held accountable.

The Department informed the Committees that the service provider had appointed a cybersecurity specialist to conduct what it described as an independent investigation into the vulnerability. The Committees have serious reservations about this arrangement.

A service provider cannot reasonably be expected to investigate a security failure involving its own system and then have the public accept that process as sufficiently independent.

The Committees therefore require that an investigation independent of the service provider be commissioned to establish what happened, how the vulnerability occurred, the extent of the exposure and whether any contractual, regulatory or legal obligations were breached.

The preliminary report from the investigation appointed by the service provider is expected on 20 October 2026. The Committees will consider its findings, but will not regard it as a substitute for an independent investigation.

The Committees convened jointly because this matter is not simply a technology failure. It is a public safety and public trust matter.

The e-Panic Button is intended to protect residents, including victims and potential victims of gender-based violence.

This is particularly concerning amid the recent killings of women in Ekurhuleni and ongoing police investigations into whether some of the incidents may be linked.

A woman who reports an abusive partner or requests emergency assistance through a government-supported platform must be able to trust that her identity, location and movements will remain protected.

A system designed to protect vulnerable residents must never become a source of additional risk.

The Department informed the Committees that it was alerted to the vulnerability on 21 September 2026. Media reports subsequently revealed that the database had allegedly exposed residents’ personal information and crime-related reports, including information relating to domestic violence and assault.

The Department did not inform the Committees of the incident at the time.
The Committees are also concerned that the Department only informed the Information Regulator on the morning of 5 October 2026, approximately two weeks after becoming aware of the vulnerability.

Section 22 of the Protection of Personal Information Act (POPIA) requires security compromises to be reported as soon as reasonably possible. The Department must therefore account fully for the delay.

The Department could not tell the Committees how many residents’ records were exposed, despite indicating that it preserved a copy of the database when the vulnerability was reported.

The Committees require the Department to submit, within seven days:
1. The number of users, records and images exposed, based on the preserved database;
2. Proof of notification to the Information Regulator and the communication sent to affected residents;
3. A plan, developed with SAPS and relevant support services, to protect residents who reported gender-based violence through the application;
4. The contractual provisions dealing with data protection, cybersecurity, incident reporting and liability; and
5. Details of consequence management against officials responsible for contract oversight.

The Committees further require an independent investigation, with the full report submitted to them on the same day it is received by the Department.

The Portfolio Committee on Community Safety will also engage SAPS and the Department of Community Safety on the response required for residents whose safety may have been compromised.

The Committees will not prejudge the outcome of the investigations. However, they will insist that the facts are established and that accountability follows.

If the service provider is found to have failed in its contractual, technical or legal obligations, appropriate action must be taken against the service provider. Where failures of oversight, negligence or misconduct by government officials are established, consequence management must equally follow.

The Committees will continue to exercise oversight until there is clarity on what was exposed, how the breach occurred, whether residents were placed at risk, what remedial measures have been implemented and what consequences will follow.

Residents in immediate danger should continue to use whichever emergency channel brings assistance fastest, including SAPS 10111.

The e-Panic Button was created to protect residents. Those responsible for any failure that compromised that protection must ultimately be held to account.

ISSUED BY THE GPL COMMUNICATIONS SERVICES ON BEHALF OF HON. MBALI HLOPHE, CHAIRPERSON OF THE PORTFOLIO COMMITTEE ON E-GOVERNMENT AND RESEARCH & DEVELOPMENT, AND HON. BANDILE MASUKU CHAIRPERSON OF THE PORTFOLIO COMMITTEE ON COMMUNITY SAFETY.

For Interview requests with the Chairperson of the Portfolio Committee please contact Ms Valerie Langa on Vlanga@gpl.gov.za or 081 011 7449

GAUTENG PROVINCIAL LEGISLATURE