Protecting our data

Our data is one of our most valuable assets as it enables us to personalise customer experiences. Consumers have become more protective of their personal data and PwC's December 2021 Global Consumer Insights survey indicates that data security has a greater impact on consumer trust than any other factor. We keep up to date with best data management practices and meet our regulatory obligations to manage the personal information of our stakeholders securely and responsibly.

POPIA promotes the protection of personal information in line with international standards. It covers individuals and business clients, and limits the rights of businesses to collect, process, store and share personal information. It also makes businesses accountable for protecting the privacy of this information.

Our Promotion of Access to Information Act manuals provide the South African public with the means to request access to our records and the terms and conditions associated with such requests: http://paia.motus.co.za.

The top five types of cybercrime reported are phishing scams, website spoofing, ransomware, malware and hacking. In addition, a new threat has emerged that targets opensource software libraries used in many commercial applications – essentially exposing hundreds of well-known applications and systems that host them to potential compromise. These threats affect all aspects of our information management systems – from the basic documentation processes in dealerships and branches to all the devices used every day throughout the Group as well as our core network and server infrastructure.

  • Maintaining compliance with POPIA, which impacts our systems and personnel across all areas of the business where information is collected.
  • The additional preventative measures and costs, both technical intervention and user awareness, required to prevent security breaches.
  • Increasing levels of crime and burglaries in South Africa increases the risk that personal information is compromised when computers are stolen.

What we are doing

Privacy by design

We have adopted a 'privacy by design' approach, which is to embed good privacy practices into the design specifications of new and existing systems and business processes. This includes privacy impact assessments before a new system or enhancements to an existing system are launched. Privacy impact assessments are updated annually.

Cyber Resilience and Information Protection Programme

Our Group-wide Cyber Resilience and Information Protection Programme aligns with international standards and best practice, including POPIA requirements and the European Union's General Data Protection Regulation rules. It focuses on protecting the data that is most critical to the Group, ensuring that the most relevant security controls are effectively applied to our systems, critical infrastructure and end user devices. It also ensures that we maximise our return on investment and meet regulatory, audit and customer requirements.

Ongoing cyber-threat assessments analyse our cyber-security controls. In the event of a data leak, our systems and data backup and recovery capability ensure business continuity and that further exposure is prevented.

Employee responsibility and training

Our employees are subject to a duty of confidentiality. We ensure that they have the right level of access to the information they need to do their work and meet customer expectations. To drive good data handling behaviour, various internal platforms provide POPIA training, including the Act's requirements, its application and employee accountability when processing personal information. Ongoing cyber resilience and information security awareness and training are also provided, covering our data-related policies, standards and practices, and employee responsibility in terms of protecting the Group's assets.

Cyber Resilience and Information Protection Programme

External relationships

We work with technology and financial partners to develop integrated data security solutions and reduce cyber risk for our customers and businesses. This includes an external review of our IT security measures in relation to best practice. Data privacy and protection clauses and security assessment criteria in our supplier contracts ensure that our data management responsibility is extended to third parties. Controls are in place to manage third-party connections and access.

How we measure our performance

We monitor and report on data breaches as well as the loss of personal computers or devices with access to personal information. In 2022, we introduced a POPIA compliance assessment as part of all internal audits.

We measure the maturity of our cybersecurity capabilities against the National Institute of Standards and Technology (NIST) Cybersecurity Framework1, an internationally recognised and accepted standard for cybersecurity. The framework's five critical capability domains include cyber risk management and oversight, threat intelligence and collaboration, cybersecurity controls, external dependency management, and cyber incident management and resilience. Capabilities in each domain are assessed quarterly and consider prevailing industry and regional conditions and threats. Additional operational security measures include continuous vulnerability assessments, periodic network and application security testing, event monitoring and incident tracking.

Governance of data management.

1 The NIST Cybersecurity Framework is a globally accepted standard for cybersecurity (ISO 27001).

2022 performance and key objectives

Group

  • There were no incidents of non-compliance with data-related regulations and/or voluntary codes.
  • One data breach was reported to the regulator in Australia, where email was compromised.
  • In South Africa, where it was deemed applicable, we reported the theft of personal devices to the Information Regulator.

South Africa

  • The POPIA working group continues to meet to identify any areas that require attention following the extensive work completed to ensure that our systems and those of our suppliers and partners in the financial services industry comply with POPIA. All Motus entities have registered and approved information officers.
  • Additional safety controls are being put in place at our dealerships, including locking away personal computers, adding perimeter security detection and moving to laptops, where possible, to mitigate the risk associated with stolen computers.

Regions

  • Progress was made in both the UK and Australia on enhancing our capabilities in line with the NIST Cybersecurity Framework.
  • In Australia, we published updated privacy policies on our websites, allowing us to engage with customers sooner and assist them with their finance, warranty and insurance needs.

Objectives

  • Group: enhance key policies and develop security standards and procedures to achieve the improvements identified in the NIST benchmarking exercise, supported by training and awareness, improved governance and periodic assessments to ensure that progress is being achieved.
  • South Africa: enhance our POPIA controls and performance based on the learnings from the first hearings adjudicated by the Information Regulator. We will also drive a POPIA awareness campaign, with posters displayed at customer-facing touchpoints, new emailers, new email disclaimers and updated training.
  • South Africa: share threat intelligence across our businesses and with our partners and service providers.
  • South Africa: develop a supplier management tool (over three years) to reduce our reliance on external expertise in terms of business continuity.