NNewsGPT ← Home
Africa

Minas Gerais Public Prosecutor's Office Investigates Data Leak from Poços de Caldas Parking App

Africa1 d ago

The Public Prosecutor's Office of Minas Gerais (MPMG) has launched an investigation into a data leak affecting users of the EXP Parking app, the company managing Poços de Caldas's paid parking system. The investigation aims to determine the scope of the cyberattack, assess EXP Parking's compliance with data protection laws like the LGPD and the Consumer Defense Code, and identify measures taken to safeguard customer information. In early July, EXP Parking notified customers of a cyberattack on its central servers, which exposed personal data including names, CPF numbers (Brazilian individual taxpayer registry identification), and credit card details. The number of affected individuals has not been disclosed.

The MPMG's inquiry was prompted by local council members, following an investigation already initiated by Procon, which had temporarily suspended the app and mandated individual notifications to affected users. Although the app has since resumed operation, the suspension of parking violation notifications remains in effect until the company proves its system's security is fully restored. The MPMG has given EXP Parking ten days to provide detailed information about the attack, including its cause, extent, categories of compromised data, and the estimated number of affected users, specifically those from Poços de Caldas. The prosecutor's office also seeks confirmation that the vulnerability has been fixed, whether independent audits were conducted, and details of communications with the National Data Protection Authority (ANPD) and users.

Beyond the data leak, the MPMG intends to address broader service issues with EXP Parking, aiming for a conduct adjustment agreement to resolve all customer complaints. The investigation is seen as an opportunity to improve the parking service. EXP Parking has stated it is cooperating with authorities and has notified the ANPD and financial institutions. While no fraudulent use of the exposed data has been reported, the Civil Police are conducting a separate inquiry to identify those responsible for the breach.

AI Analysis

This incident highlights the critical need for robust cybersecurity measures in public service concessions, particularly when handling sensitive personal data. The investigation by the MPMG and Procon underscores the regulatory framework designed to protect consumer data privacy under laws like the LGPD. The situation presents a complex challenge for EXP Parking, balancing operational continuity with the imperative to restore full system security and rebuild user trust. Future considerations for such services may involve enhanced data anonymization techniques, more frequent security audits, and clearer contractual obligations for data breach response and user notification, all within the evolving landscape of digital governance and consumer rights in the AI era.

AI-generated to prompt reflection — not editorial opinion, not advice, not a statement of fact. How this works.

Compiled by NewsGPT from Globo G1 (BR). Read the original for full details.