Selangkah data remains private, assures creator amid ministry concerns

THE VIBES.COM
BY A.AZIM IDRIS Published on 22 Oct 2020 10:57AM ยท

Selangkah app creator says its website and database have AES 256 encryption, defence and monitoring technology to safeguard sensitive information. โ€“ Pic courtesy of Selangkah, October 22, 2020

KUALA LUMPUR โ€“ The Selangor government’s Selangkah Covid-19 contact tracing app takes the appropriate technical and organisational measures to ensure personal data security, its creator said today.

This came after Health Director-General Tan Sri Dr Noor Hisham Abdullah on Monday expressed concern over the confidential data collected by Selangkah.

Dr Helmi Zakariah, who is on the Selangor Task Force for Covid-19 (STFC) member, said its website and database have AES 256 encryption, defence and monitoring technology to safeguard sensitive information.

โ€œThe platform was initially rolled out as a pioneer QR-based contact tracing, but since then it has undergone multiple development cycles, and now provides many functionalities for the stateโ€™s Covid-19 coordination,โ€ he told The Vibes.

In explaining what is being done to the data collected by the app, Dr Helmi pointed to a thread on Twitter that provided the basic functions of the app.

โ€œEach time you scan a Selangkah QR code, we capture your name and your phone number, and create a timestamp of your visit,โ€ the thread explained.

โ€œThese are the only data that you crowdsource. Eventually, with many more people scanning, it creates a data lake of visitor logs across premises.โ€

The visitor logs, Selangkah said, were merely collected for the purpose of contact tracing, a functionality that is only available for public health personnel.

Dr Helmi said through Selangkah, state officers and local authorities could rely on a centralised dashboard to monitor population movement and overcrowding situations.

โ€œContextual surveys were intermittently posted to the public to remind, educate, and alert the public of the need for SOP compliances.

โ€œPublic reports were used to determine the area of non-compliances, so enforcement and community educators can be mobilised when needed.โ€

Meanwhile, Dr Noor Hishamโ€™s concerns over Selangkahโ€™s data security came after the state government accused the ministry of hampering its efforts to combat the pandemic by denying it granular data.

In response, Dr Helmi said Selangkah was about community empowerment and runs in harmony with the ministryโ€™s prevent and educate, practice, comply and monitor (CAPP) strategy to avoid the 3Cs โ€“ crowded places, confined spaces and close conversation.

He added Selangkah encouraged users to practice the Health Ministryโ€™s 3Ws โ€“ frequent washing of hands, wearing of face masks in public place, and practise caution by avoiding handshakes, staying at home and seeking treatment if you are developing symptoms related to Covid-19.

โ€œAdditionally, through its wide presence previously, the Selangkah platform is used as an additional tool to identify and connect citizens to the state economic stimulus and welfare package.โ€

For businesses and premises, Dr Helmi said the platform has allowed them to monitor the footfall to their respective premises for better human resource management and to avoid overcrowding.

โ€œSome premises can opt for a pre-booking function if they choose to regulate visitor attendance.โ€

Customers, through the Covid-19 map functions found on the receipt, can opt to visualise an updated map of recently affected premises, and their date of sanitisation, to assure them of their visits.

Customers would also be able to cross-check their visit records with a reported incidence through the โ€œCheck Your Exposure Riskโ€ feature in the app.

For enforcement officers, Selangkah has a โ€œVisitor Listโ€ function, so logging practice can be checked while protecting the customersโ€™ phone numbers.

โ€œWe masked the phone numbers and only showed the last 4 digits for enforcement purposes,โ€ Dr Helmi said. โ€“ The Vibes, October 22, 2020