The Gauteng Provincial Legislature’s Portfolio Committee on e-Government has launched a hard-hitting inquiry following a massive security failure that left the personal data of thousands of residents exposed via the province’s e-Panic Button App.

The breach, which threatens to undermine public trust in digital safety initiatives, has raised urgent questions regarding state oversight, legal compliance under the Protection of Personal Information Act (POPIA), and the security of victims of gender-based violence (GBV).
A Catastrophic Oversight
The security flaw—which reportedly left a database unsecured and accessible—was discovered by Joel Cedras, a Stellenbosch University student. According to reports, the compromised data included sensitive information dating back to the application’s launch in 2024, such as identities and locations of crime-reporting citizens, case contents, images, contact details, vehicle registration numbers, ID numbers, and medical aid information.
The timing of this digital exposure could not be more critical. Gauteng continues to grapple with staggering rates of gender-based violence and femicide, compounded by a recent string of murdered women in Ekurhuleni.
The exposed database contained records of domestic violence and assault complaints, potentially exposing the identities of women who reported their abusers along with their precise home and workplace GPS coordinates.
“A woman who presses a panic button is asking the State to protect her. Instead, the State may have handed her details to anyone who looked,” the Committee noted, warning that the breach could deter victims from seeking vital help in the future.
Legislature Demands Accountability
Despite the Department of e-Government’s assertions that no personal information was compromised, the Portfolio Committee—led by Chairperson Honourable Mbali Hlophe—has refused to accept unverified assurances. The Committee is demanding independent examinations of access logs and a comprehensive accounting of how a flaw of this magnitude went undetected despite previous briefings.
Lawmakers are strictly testing adherence to POPIA mandates, specifically Sections 19, 21, and 22, which govern data security, third-party service provider compliance, and mandatory reporting of security compromises to the Information Regulator and affected citizens.
A 13-Point Ultimatum
The Committee has issued a stringent 13-point ultimatum to the Department, requiring a detailed written report within seven days. Key demands include:
- Timeline and Impact: A complete incident timeline detailing when the vulnerability existed, when it was discovered, when leadership was notified, and whether data was actively misused.
- Legal and Regulatory Compliance: Proof of notification sent to the Information Regulator and affected residents, alongside an explanation of the Information Officer’s response.
- Victim Protection: Immediate collaborative efforts with the South African Police Service (SAPS) and support services to safeguard residents who reported GBV through the app.
- Consequence Management: The naming of responsible officials, initiation of disciplinary processes, and potential legal or contractual penalties against the service provider tied to the R269 million platform contract.
As political pressure mounts, the Department faces a severe test of credibility. With hundreds of millions of public rands invested in digital infrastructure, the Committee has made it clear that systemic negligence will not go unchecked, warning that officials and contractors alike must face strict consequences.

