Sun.Star Cagayan de Oro

Privacy Commission orders suspension of Jollibee online delivery

-

MANILA – The National Privacy Commission (NPC) has ordered the suspension of local fast-food giant Jollibee’s online delivery platform after it was found to be vulnerable to unauthoriz­ed access.

Aside from the online delivery platform, NPC also ordered the Jollibee Foods Corp. (JFC) to suspend the operation of its entire data processing platform to the public through the internet and also to restrict external access to their networks.

The Commission’s order is a result of its investigat­ion in relation to a “data breach notificati­on” submitted by JFC in December 2017.

“Persons unknown to the JFC Group appeared to have been able to gain access to the customer database of the delivery website for Jollibee,” the NPC said.

In subsequent meetings with the NPC, the dominant local fast-food company made assurances that it will institute corrective measures regarding the supposed data leak.

However, the NPC’s Complaints and Investigat­ion Division (CID) found out that JFC’s delivery service website remains vulnerable to unauthoriz­ed access.

“Such vulnerabil­ities may allow malefactor­s with little to moderate technical knowledge and skill to access personal informatio­n of Jollibee patrons through its website,” the NPC noted.

It noted that about 18 million individual­s on JFC’s database have “high risk” to exposure of personal data.

The suspension will remain effective for an “indefinite time”, according to NPC, until the website’s vulnerabil­ities are satisfacto­rily addressed. (PNA)

Newspapers in English

Newspapers from Philippines