Ross Saunders — Author, Speaker, Passionate Data Privacy And Security Advocate
With Ross Saunders — Data Privacy and the big WhatsApp conspiracy
In short
Ross Saunders had his identity stolen from a single leaked payslip — a green ID book with someone else's photograph, an address in a field outside Witbank, two years to repair his credit rating. He explains what POPI and GDPR ask of South African businesses, why most of compliance is governance rather than IT, and how the Professional Speakers Association helped his own speaking career.
How did Ross Saunders end up working in data privacy?
Through a long IT career that gradually turned into information security. He ran a small IT company servicing Benoni businesses after leaving Willowmore High, then worked the call desk, networking and software development, which he loved studying and disliked in practice. Managing development and IT teams put him in charge of company information, a dual role for roughly seven years.
What actually happened when his identity was stolen?
He woke on a Saturday morning in December to SMS notifications about transactions at a bank where he had no account. When he eventually logged in, his account was empty and cell phone contracts, tablets, computers and laptops had been bought in his name, with debit orders running against him.
How much detail did the fraudsters have?
Enough to pass a full credit application. Because the purchases were debit orders rather than card fraud, the bank needed proof of residence, payslips and identity documents — all of which the syndicate had. His address was a field outside Witbank, backed by a fraudulent Multichoice statement, and there was a real green ID book carrying a different photograph.
How long did it take to recover, and how did it start?
About two years to restore his credit rating and many months to stop the debit orders, with repercussions still felt at the time of recording. South African Fraud Prevention Services helped stop it. The likely origin was a payslip that escaped years earlier, carrying his banking details and ID number — the single document a whole false identity was built from.
Does GDPR apply to a small South African business?
It can. Ross says if a website so much as prices in euro, the business is seen as targeting the European market and European law applies. The local regulator has confirmed a company can be fined under both European and South African legislation, and fines run into the millions rather than a slap on the wrist.
Where should a business start with compliance?
With good governance rather than technology. Of the eight principles, only about an eighth is the IT side. Map out policies, know where data is stored, centralise storage instead of scattering folders across Google Drive and iCloud, and document everything — "he with the most paperwork wins" when a regulator asks questions.
What can an individual do about passwords?
Stop reusing one password and switch on two-factor authentication. Ross explains that a phishing email plus a reused password lets an attacker into your email and from there reset everything else. He recommends Authy for two-factor codes, and password managers like LastPass or 1Password — he holds over 600 passwords and knows none of them.
Is a stolen laptop a data breach?
Yes, and Ross says people wrongly treat it as an insurance claim. Cars get remote-jammed and laptops taken from the boot, and the data on the machine goes with it. Encrypting the hard drive, available in most enterprise operating systems or via separate tools, makes the drive useless without the password.
What does the Professional Speakers Association offer, and can anyone join?
It focuses on the business of speaking, not on teaching public speaking, with events on business models, online training and marketing. Membership splits into professional members earning the majority of their income from speaking and associate members still aspiring or in corporate. Meetings in KZN, Johannesburg, Pretoria and Cape Town, plus a virtual chapter, are open to guests for a small fee.
In their words
My address ended up being some field just outside Whitbank that they'd fraudulently done a multi choice statement for.
if you so much as put pricing in euro, you're seen as targeting the European market. Therefore, the European law applies to you.
It's a case of he with the most paperwork wins.
what you see on stage is about 10% of what actually happens behind the scenes
if you've seen someone up on stage for 45 minutes, they have practiced that for 45 hours before they've got up on that stage
Key takeaways
- A single leaked payslip carrying banking details and an ID number was enough for a syndicate to build a complete false identity, including a green ID book with a stranger's photograph.
- Debit order fraud is far harder to unwind than card fraud, because the bank has been shown proof of residence, payslips and identity documents.
- Compliance with POPI and GDPR is mostly governance and documentation; only about an eighth of the principles concern IT.
- Pricing a website in euro can be read as targeting the European market, exposing a South African business to European fines as well as local ones.
- Paper is data: torn-up proposals in a bin, post-it notes and piles shoved into office cupboards all create breach risk.
- What audiences see on stage is roughly ten per cent of the work, and feedback from peers shortens the learning curve considerably.
Show notes
On this episode I chat with Ross Saunders and we bring two very different aspects of his life together. Firstly we talk data protection and privacy, Ross shares the harrowing story of having his identity stolen. We then weave in his role as the president of the Professional Speakers Association Of Southern Africa.
Frequently asked questions
Is online shopping in South Africa safe?
Ross says reputable stores are generally safe because other legislation already binds them, and he is more afraid of credit card skimming in a shop than of an online transaction. Obscure websites with strings of numbers in the domain warrant scepticism.[
What counts as special personal information?
Medical information, race, trade union membership, political party membership and sexuality — anything that could be used to discriminate against someone. Ross says this category has to be locked down more tightly than ordinary personal information.
Does compliance require expensive legal work?
Not entirely. Ross has assembled a "privacy in a box" offering of baseline policies, templates and some consulting so smaller businesses need not pay large legal fees. Some matters still need an attorney, but much can be put in place immediately.
Should a beginner start with Toastmasters or the PSA?
Both, in parallel. Toastmasters has structured programmes and room feedback that build how you speak, from baseline to distinguished level; the PSA covers turning that into a business. Ross considers the two complementary.
Is there anything for complete newcomers at the PSA?
Yes, a knockout competition closed to anyone already earning a professional living from speaking. Entrants give five-minute presentations, and the winner receives coaching and a slot on the main stage at the convention.
Transcript
So it is Monday night as we do each and every Monday at this time. Time for what's involved. My special guest in studio tonight, Ross Saunders. Hello, Ross. Hello. Good to have you with us. Let me tell you a little bit about Ross. Ross is the owner of Ross Saunders Consulting, also the president of the Professional Speakers Association of South Africa. But his passion, what he lives for is data protection and data privacy. That's the one. So we're going to try and marry those two together during the course of tonight's discussion. Because I must say I'm fascinated. We're telling a bit of air. I'm fascinated about both aspects of what you do. And the first question that would spring to my mind is how do you manage it all? How do I manage which part of it? All of it. I mean, it's not like you've chosen, you know, something that's quiet and doesn't take up a lot of your time. I mean, you're busy. No, that's for sure. That's for sure. It takes up a lot of time. And it's not showing any signs of abating. Because I think if we look at the landscape of these attacks that we're seeing out there on hacking, but also the legislation that's out there that's come into play now in Europe and in South Africa, well, what's coming into play in South Africa, things are going to get a lot more crazy. And people need to comply with these these laws and try and protect people's information. It's the Wild West. Certainly is a hectic kind of thing. But let's start off right at the very beginning.
Tell me a little bit about Russ. I mean, Joburg born and bred, where are you from? Where'd you grow up? Did you study? What did you study? So Benoni born and bred? You're a Benoni boy as well. Damn, yes. Represent us Benoni people got to stick together. Yeah, Willamore High. Did you? Were you a Willamore High guy? I was, yeah. Okay. A mate of mine was actually a teacher at Willamore High. Timothy Keys. He now owns the Sales Institute, but he used to teach there. Oh, so yeah, Willamore. We used to get along because I was a Wordsworth High. So Willamore and us, we got along. But the rest of the schools in the Benoni, we didn't like them so much. I think you were there a little bit after my time. I think I'm, I'm just a little more. I don't like saying old these days, I'm gonna, I'm gonna refer to computer game technology. I think I've leveled up a bit more than you have. So, so Willamore High, then? Yeah, so then I went straight into work. When I left school, I ran my own little IT company servicing the businesses around Benoni. And then eventually went into the working world. I dove straight in with both feet, looking at the IT space for throughout high school and all of that, I was playing games and fixing computers and helping people out. So it became sort of a natural career progression. Okay. And then I went through all the different sides of the IT field. I think I started on the call desk and then I ended up in networking and then from networking decided to study software and loved it in college and absolutely despised programming in the real world. Really? Yeah, no, it was great doing my own projects. It was terrible having to maintain other people's projects. Okay. Yeah, so that all eventually went into a management career. So it moved into managing development teams and IT teams and things like that, which being in that sort of position kind of puts you square in the information security space where you've got to look after people's information because now suddenly you realize how much information an organization has and you have to start looking after it. So over the last seven years or so, I've had that as a dual role looking after info in these different software companies and things like that, which has kind of shaped where I am now. And also living through a couple of data breaches and also having my identity stolen, it sits close to home. That is the bit that fascinated me when we got talking is that because you hear about it, you hear about identity theft, you hear about this, that and the next thing, but seldom. I mean, I've certainly never met anybody that's gone, listen, they literally stole my ID. And I mean, I've read horror stories about what happens. So let's just sort of draw the picture for people that are listening this evening. When you talk data privacy and data protection, if we think about it as your average Joe Soap, we think, okay, I need to make sure that I've got an antivirus and I don't get hacked and stay off dodgy websites. Are you listening? Stay off dodgy websites. And it's but it's far greater than that. And I don't think the South African public in general is as aware of it as they should be because we just happily send out information all over the place and trust that it's all going to be okay. Yeah, that that's that's the crazy case about it is we hand over information really willingly to companies and companies also really willingly take information. And you know, overseas, there's been this whole drive with these new laws that are out that that's stopping companies from doing that and they need to start handling data responsibly. But over here, I think because we haven't had the I mean, we've got our laws, they drafted, they just aren't signed in yet. But we don't have enough awareness as the public or as business. Because there is that I've seen now, like on several websites now that the European Union, you have to now comply to X, Y and Z and Yeah, the GDPR. GDPR. There we go. My favorite four letter word.
Might become mine. We're gonna have to see how the rest of tonight goes. But, you know, as I said, we sort of we share our data quite now. Let's let's talk a little bit about your experience. What happened? I mean, it sounds horrifying if you say somebody stole your identity. Yeah, well, it was the strangest thing realizing it. It was a Saturday morning in December, and I rolled over with an SMS on my phone. And there was a transaction on my bank account for something or somewhere that I don't actually have an account. And I kind of blew it off as you know, maybe this was a false SMS or something like that. And then the SMS has kept coming. And eventually decided, let me log into internet banking and see what's going on. And my account was bone dry. And there were cell phone accounts and tablets and computers and laptops and all sorts of stuff that had just randomly been purchased. And these are all the debit orders coming off now. But now then the first thing that somebody's gonna say is, well, then obviously, you know, did you check the credit card and somebody not steal your credit card? Well, that was it. I did the responsible thing and phone the number at the bottom of the SMS to contact the bank. And they actually said as well, you know, if it was a credit card fraud, it would be easy to reverse and someone could have skimmed the card. But this was debit order. So they needed proof of residence, they needed pay slips, IDs, all that usual fun stuff that you have when you take out a contract somewhere. Yeah. So all of these were out there. My address ended up being some field just outside Whitbank that they'd fraudulently done a multi choice statement for. The scary thing, though, was the ID book, because there was an actual green ID book with a different photograph in it. And you are kidding me. No, that's what they did. And I've never lost an ID. I've never lost my ID. I've never misplaced it for any amount of time. So it was quite crazy. Seeing this level of detail, somebody stole your life. Yeah, well, they tried. Yeah. Thankfully, there's a number of places where you can go in South Africa that they stopped that South African fraud prevention services being one of them. But it was a it was a harrowing experience and took about two years to get my credit rating back and many months to stop the debit orders going off and still have some repercussions from it today. That is and I mean, did they ever catch those responsible? No, no, no. But I do have the photo from the ID book. So if I do see someone that looks similar, I will ask a question. Yeah.
But yeah, no, no one was caught. And it looks like what potentially caused it was a number of years earlier. One of my pay slips got out there. And I don't know if that was from a company being irresponsible and throwing away the pay slips without shredding them, or how this got out there. But the pay slip was the sort of common denominator, which had all the information on it, like my banking details and ID number and things like that. So that was that core little piece of information that a whole profile for me and my identity could be built off. It's it's I'm sitting here and I'm literally it must be a scary shot because I'm sitting here with my mouth open. I mean, wow. And it's not an isolated case. It wasn't just, you know, pour us wrong time, wrong place. This happens a lot. This happens a lot. And in South Africa, particularly, we're way up there on the scales of of most prevalent prevalent things to happen. So it happens all the time. And there are syndicates out there. There are scary things like dumpster diving, where people will go look for paperwork, because they'll get paid a lot more handsomely than the recycling plate, the devices will pay. This is scary stuff. We are chatting to Ross Saunders and we're talking about data protection, data privacy. It's something very close to his heart, as you've just heard.
But Ross does a lot more about that. And we're going to get into that. And we're going to find out what you can do. And maybe, maybe you're going to be sitting there. And if you're a business owner, you're gonna think, whoops, I need to have a chat to Ross at some stage. It is what's involved this Monday night. We'll be back in just a bit. My special guest in studio tonight, we are chatting to Ross Saunders. And we're talking data privacy, data protection. I'm still kind of getting over the fact that they got your identity right down to the little green book. I mean, and now we've got the new ones, the cards. I mean, I don't know what that's going to entail. Hopefully, they're safer. I would imagine those cards are a lot safer. I'm quite a fan of the way technology is advancing. And if it's an actual encrypted card, I'm a lot happier because your ID card is, there is electronics in it and RFID capabilities. Okay, now we're talking data protection. Of course, it just, it suddenly struck me. You know, I've got, literally, we're a tiny, tiny little company. We do have a website, we have mailing lists. There's a couple of products that people are able to purchase online. That now means in terms of these new acts and legislations and everything, I have a responsibility then, do I not, to make sure that I don't just sort of add people willy nilly and explain how this whole thing is going to work.
Yeah, so within the legislations and most of the legislation is fairly similar across each other. So they all, they all stem from the same sort of privacy recommendations that came around after the last world war. And the principles that we look at today are generally based off those. So the South African principles in Poppy are around that GDPR, they've advanced them a little bit for the more digital age now. And there's six conditions under GDPR. But in general, the same principles are used. And it's principles of sort of good governance and saying, no, I'm not going to use too much information, I'm not going to take too much. But these principles apply to anyone who has a business now. So if they're, they're got a mailing list, got a marketing list or anything, it applies to them. And failure to comply to that does also come with a hefty price tag, you might get as small as a slap on the wrist, but the fines go into the millions as well. So South African businesses, where do you focus? You focus mainly corporate? Mainly corporate, but your sort of smaller enterprise up to about 200 people in the company. Generally, your bigger companies have departments for this, the banks have been doing this for ages, the insurance companies have been doing this for ages. But smaller businesses don't generally know that they have to comply with these things. And the crazy thing is, if you, as you say, have your website, and you've got a few products on it, if you so much as put pricing in euro, you're seen as targeting the European market. Therefore, the European law applies to you.
And our local regulator has already confirmed absolutely, that you can get fined by the European legislation, as well as the South African legislation, if it is seen that the European one applies to you. So if you've got anything online at the moment, you should be turning your radio around about now, because this is this is scary. So what do we do as a, you know, I mean, from from from the small businessmen like myself, up to the bigger guys, where would we start? What do we need to look at? So one of the dangerous things that that seems to come across a lot, and perhaps it's a lot of marketing on these computer hardware providers and firewall providers and things like that, is that a lot of people see it almost as an IT department's problem. And that it should sort it out. But the laws are a lot broader than that. So those principles that I was talking about those eight principles, it fits into one of those eighth, about an eighth of it is your IT side. But what you can do as a business is a lot of these things are actually just good business governance. So if you have your policies mapped out, if you know where you store data, if you centralize all your storage, so you don't have folders lying all over the show, one in Google Drive, and one in Apple iCloud, and all of that, and you actually keep things centralized, you're already a good way along there. But you want you want to really document what you're doing. It's a case of he with the most paperwork wins. So if something goes wrong, the regulator can come to you and say, well, why did this data disappear from your office? And you can say, well, it should never have here's all our policies, here's our procedures, here's how we manage data, this is how we comply with those principles. But now this this, I'm trying to wrap my head around this, because this is a big thing. I mean, show. Let's let's give it an example of a company who would who would have my dots. I mean, okay, banks and insurance companies, they would have my data. Yes. But who else would potentially have data that I would as a consumer would go, are you guys looking after this?
Yeah, so I mean, your your banks and them are pretty good at looking after it. Yeah. But you have market research companies, you have state agencies, you have brokers, you, I mean, if you just think of if you're applying for medical aid, yes, the medical aids have great controls in place. But generally, you'll be going through a broker. Does your broker have controls in place? Do they have everything they need to be looking after your data? There's there's a whole bunch of sort of middlemen in these data chains, which you don't really realize are are are gathering your data. Yeah. And part of these laws refer to those that they refer to three different levels where it is the person who the data belongs to, the company who is saying what to do with the data and the company that is actually processing the data because often those are separate. And we may not realize that as the end consumer. But I think as well, we've we've become so sort of conditioned to this digital age. We don't think of data outside of digitally, but it is because using the broker in the medical aid thing, I mean, you fill out a form, then generally it gets scanned or mailed or something. But often I've done it before I've had a broker, I've set and filled everything out in front of him and he takes my little folder and off they go. You don't think of that as data, because it's not the way we fight. But that is yeah, it's not the end point. But it is definitely there by virtue of writing something down on a post-it note, you've generated data. And I mean, we've seen it with brokers before where we've had to have words with them in a mug and bean, because we've watched someone take all this information, provide a proposal, someone didn't take it, they just tore it in half and threw it in the bin. Anyone can come across that paperwork in the bin and reassemble it. And then start the process of stealing somebody's identity. Yeah.
And I mean, I know you sort of, you spoke about it earlier, but you almost glossed over it because I can only imagine what sort of trauma and just the hassle factor you must have gone through. Oh, it gives you a new definition of patience. Because now you've got all these new accounts that have taken out, people have bought furniture in your name and all that. Now you've got to go through to every single one of these providers and get them to reverse the transaction. And go, this me is not me. Yeah. So now you've got that balancing act where you've got to prove who you are now that you're not you. And then following on from that, because of all these debit orders and things like that, you've got to repair your credit rating. And that's six weeks per credit bureau per account that goes out. And then also, I mean, there could be all sorts of stuff that doesn't happen. The next thing you found out, you've got a judgment against you. Oh, there's so many crazy accidental things that happen. Well, it's funny now, it wasn't funny at the time. But what happens is the companies where these accounts get taken out, they need to then contact the service providers and all the South African fraud prevention services and say who was the victim and who was the perpetrator.
When they get that mixed up, it makes for a very, very interesting conversation in the bank. So I was kudos to the bank detained in the bank for a couple of hours while we were waiting for this to be sorted out, because one of the places accidentally put me as a perpetrator. Yowza. Now, okay, so let's talk now in terms of what we need to do as a business. You've spoken about how you document everything. And as you were going, you know, Google Drive and iCloud and everything. I'm like, Oh, I'm one of those people have stuff on Google Drive and on iCloud. What else? What do we what do we need to say? You can have stuff in Google Drive and iCloud and all of that. They are thank you. They are good services. But have your front gate secured. Yeah, have a good password. One of the biggest sort of hacks and breaches that happens in companies now, and it seems to be absolutely on the upswing. I was speaking to a colleague in the UK the other day, he's dealing with four of these a week, where these phishing emails, God, we've all heard about phishing, don't enter your credentials and all of that. Yes, yes, we have. They there's some coming through now that actually have good spelling and look legitimate and and are very, very likely to fool you. Now, if you have a weak password, and you've used the same password for all your services, the first thing that that perpetrator is going to do is go and try that password on your email account. And if he gets into your email account, he can go and reset your password for all your other services like Amazon or take a lot or things like that. And then take over your accounts from that point. So having good passwords is probably your hygiene 101. And we have it's prevalent in almost every service now something called two factor authentication, which will give you a SMS with six digits that you have to put in after your password has been put in. And that sits on your phone. Yes, so it has to be you signing in. And that that's a fantastic defense that everyone overlooks. And it's very easy to implement from almost any of these services. And there's a great app called Authy, where it just sets it up for you beautifully every time. Authy. Yeah. A-U-T-H-Y.
A-U-T-H-Y. Actually, go check that out. I guess you know, okay, I'm not my passwords are okay. In terms of paperwork around the office, though, that also obviously has to get looked after digitized. Is it I mean, wow, suddenly you're making me nervous. Now I'm going Oh, you know, don't just shred all of your papers and throw them in the dustbin. Is it can it get that bad? Yes. Well, so part of the laws is that you have to dispose of paperwork that's not needed or any data that's not needed anymore. So if you're retaining paperwork and things like that for clients that aren't your clients anymore, the information that's not required by another act like the Income Tax Act or conditions of employment or Companies Act or anything like that, you actually have to get rid of that information. Now, when you're getting rid of it, you have to also do that securely. So part of the principles of these laws, if you look at puppy, it's got limitation of what you take. So only taking the information you need. And then you've got to have security safeguards. So that would be if in the case of paperwork, even something like a locking credenza, where you can put that paperwork into and actually lock it, that becomes a security safeguard. So a lot of these things are actually fairly simple to implement. If you've got information that's desperately sensitive, like medical information and what we call special personal information, so race and trade union membership, political party membership, sexuality, that's got to be really locked down. Anything that could have really been used to discriminate against someone is generally seen as special information and that should be secured even more so. Okay, so as a consumer, password on my computer, change the passwords. I started doing that and changing my passwords and changing them up. Because I did, I always used just one password. And then very similar, found out that people that I knew that knew my password were just quietly logging on to various of my software services, which I was dutifully paying for every month. And they were just quietly using it. Then the problem was, I kind of had so many different passwords, I couldn't remember it. So now I've got an app that remembers the passwords. And all I have to do is remember the one password.
Yes, that was the next thing I was going to suggest. These apps that look after your password, like LastPass or OnePassword are fantastic. It's a different way of doing things. And it takes you probably about a week or two to get into the groove of using this new way of entering passwords. Once you're into it, it's great. I mean, I work in this space, so I have a lot of passwords, I've got probably over 600 passwords. But I don't know any of them, really, they are 24 digits long with all sorts of characters and letters. But I let OnePassword manage it. And if anything gets breached, only that service is breached. I've got nothing to worry about on my other services. And also, by the way, I'm sure you do know this, and I'm just saying something that's common sense. But don't use simple passwords. If your little pet's name is Fluffy, let's not make Fluffy your password. We're chatting to our saunas, we're back finding out more about what you as a company need to do. And maybe what steps we should take maybe I need to, you know, for my business, for example, your business, maybe maybe you need to get hold of somebody like Ross and go, please come in, let's consult and help me. We'll be back in just a bit. I'm starting to be wishing that lots of things are well right there. If you if you hear sort of crazy rentings and matterings and everything online, it's like two o'clock tomorrow morning, it'll be me trying to furiously make sure my data is all protected. It's scary. But we got to talk about it. Because I got to talk about I have a responsibility to my customer. Yeah. But the places where I'm a customer have a responsibility to me. Absolutely. So we sort of said what do we do as a private individual and it's to become more aware your passwords, etc, etc. But from a company perspective, what should companies be doing? Because I can see that this is going to be you're gonna have to clone yourself. Because I can see this is going to be something where people are going to be looking at people like yourselves and going, Okay, we're up the creek. We don't have a pedal help. What should we should we start? Is there an audit or something? It's really broad.
Audit wise, you know, most of these laws allow for a certification method mechanism. But it's so new that there aren't really any in at the moment. And there's new standards coming out. So ISO is releasing standards for privacy, but we're still yet to see what are going to be fully approved and ratified by the different regulators. But that being said, there's a lot of things you can do already. That'll be quick wins or get you on track with these legislations. Okay, so you have these principles that you have it have to adhere to three of the main ones being you need to state what you're doing with people's data and not take more data than you should be. And they're not using that data for something that you haven't said you're going to use it for. And those three tie very much into a privacy policy. So you would have seen on a lot of websites and things, particularly European websites last year, May, you would have got this flood in your inbox of we've updated our privacy policy. And this, that was one of those big things that had to be in place. And that is really a declaration as a company that this is what we're going to do with data. This is why we do it, how we do it. And it needs to be detailed enough that people can make a an informed decision. Okay. That's, that's very much on the policy side and the public facing side. But inside your company, there's a whole bunch of things that you can do as well. And on the tech side, one of the biggest risks you face, and I mean, we see this all the time, where people get their cars remote jammed, and the laptop goes missing out the boot. That is seen as a data breach, because there was data on that laptop can that can then be taken off. And people don't see that as more than an insurance claim, but it's actually a data breach. Yeah, literally. Yes. I'll just tell you, oh, my soul. Okay. So to prevent that, most enterprise operating systems, or there are tools available if you don't have an enterprise operating system, but you can encrypt your hard drive on your laptop.
And that makes it so that if someone removes your laptop or something like that, and they don't have your password, that hard drive becomes useless. Yeah. Again, if your password is fluffy, please don't have your password as fluffy. That's not going to help your encryption any, or tape your password to the underside of your laptop. I've seen that. I've seen that many times. Yeah. Post-it notes all over the office. Whiteboards with the password written on it. But you want to encrypt your laptops, because that way, if they get stolen, it's not seen as a material thing. But you need to look at the data in your office. I mean, if you want to scare yourself, go and stand in the middle of your open plan office, and just look around and do a 360 degrees as to what information is lying where, what's in which cupboards, what kind of information is on them. And I guarantee you, you'll be terrified because people have a tendency to clean up a desk and shove everything into one big pile in a cupboard or in a drawer. And that could have medical aid applications from HR, or it could be your supplier's financial information. It could be banking details for someone. It's amazing how we shove paper around without taking into consideration what's there. Which is, you know, why in the old days, we always used to talk about the paper trail and make sure. And then we kind of went digital and that stuff, and we kind of forgot about the paper trail because, you know, everything's fun. So we're looking at this. And smaller to mid-sized companies like myself, is it then worthwhile to sort of set aside and go and do some research, maybe talk to somebody like you, and then put it into your company policies and procedures? Absolutely. And get it to become like part of the culture. Yeah. So there's no time like the present. Poppy, as it's now known, is coming. We don't know exactly when and what day it's going to come, but it is coming and then they give you a grace period. But it is so broad that it's difficult to make that grace period even if it's a year. Now, with that coming and with GDPR already being in play and you may need to comply there already, it's actually vital that you educate yourself on it. These laws are here to stay and people need to know what to do. So there are training courses out there. I host a branch that I take people through for a morning what all the laws and legislations are about. Fantastic. There's so many things you can do to learn more.
We need to talk more about that. And we're going to in a bit. But how do you then find the time with all of this? Because let's talk about the Professional Speakers Association. Because in and of itself, that's a full-time job in my head. And what you do in terms of the data privacy, that's another full-time job. I have an incredibly strong team around me in the PSA, which makes for a real helping hand there. But also, I think if things are really important to you, you make time for them. I'm not one to sit in front of the TV or anything like that. So by day, I'm doing data and by night helping with the PSA. But it's fantastic association for professional speakers.
I look at you now. You've got all of this experience. You talk data privacy and protection privacy. So you have this depth and breadth of knowledge. And I think just explain to me what a professional speaker would then do. Are you somebody who would go out to a company and you would give a presentation based on your field of expertise? Yes. So that's one aspect of it. I think we can take it a lot broader. And you can define a professional speaker as anyone who speaks as a profession or is aspiring to speak as a profession. Yeah. So you're a cell phone radio, where we have voiceover artists, we have keynoters, we have motivational speakers, inspirational speakers, business speakers, subject matter experts, all these ranges of people all fall under that umbrella of professional speaker. Okay. And within the association, we have two differentiations between members of associate members and professional members, where your professional members are drawing the majority of their income from speaking, or speaking related things like training or keynotes. And then the associate membership is for people who are perhaps aspiring to get there to that professional level, or are still incorporate, but love speaking and that side of things. Because I think it's great. And let me just allay any sort of misconceptions you may have. It sounds very romantic. I am a speaker, I am a professional speaker.
It does sound romantic. And then you hear people throwing around, they talk for an hour or half an hour, 45 minutes, whatever the case may be, and get paid stupid money and then they wander off into the sunset. It's not always like that. And you need to put in a lot of hard work. I take my hat off to anybody who makes a full time living speaking, because you know, the idea of old Tim Ferris's, you know, couple of days work week doesn't happen if you're a speaker, I think, I think it's it contributes to some serious health issues, because you stress so much. Why would somebody then join an association? Because at the moment, I don't know, you know, you're closer to this than me. But I mean, it seems like every second person you come across is a speaker these days. So there's a couple of things to take out of that. And you're very right. So what you see on stage is about 10% of what actually happens behind the scenes. There's so much training that goes into it. And I think with an association, it's, you know, you're the some of the people you keep company with. And what better place to keep company than with folks that are speaking professionally, the everyone has different styles, everyone has different ways of doing things. And as an association, we focus on the business of speaking. So we are not there to introduce you to public speaking kind of thing. We're there to say, you know, you want to make a living out of this, let's start looking at this. So we'll have events where we talk about business models for speakers, or online training, how you get into that space. And it gets a lot more netty gritty. But it's also the folks you surround yourself with. I mean, you had Billy Selikani on a few weeks ago, Billy for president, by the way. Absolutely. I'm the first one behind that.
What an amazing man. Yeah, so he's one of our past presidents, he's got multiple awards from the association. And those are the kind of people you interact with these meetings. And I remember one of the speakers Paul de Troy, I've got books of his and my mom gave me his book when I was leaving school and learn to present and things like that. And then to suddenly be sitting at a dinner table with Paul was terrifying, but awesome. And you realize that all these people are there to help each other. I've never had it in the association where someone has been snooty or anything like that. It's like people are there by virtue to help each other. Does it lend a certain sense of credibility if you're a member of the association in terms of you getting to get speaking? Because you're not, and let's be very clear, you're not a speaker bureau, you don't. No, we are not. We don't book speakers, book speakers. I was going to use other words. Okay, so you don't book speakers at all. You're not a bureau, but it must have some some credibility. Surely one of the things you have to do in order to be one of our members is sign a code of ethics. And that code of ethics details how you handle your business dealings. It's how you operate on stage, the quality of presentation that you're going to give. It brings in all of these aspects, which really I think does add to your credibility. Because as you say, there are speakers everywhere.
Someone who has MC Delta wedding is a speaker. And that's not to say they can't be. But there is a certain level in an industry that you need to have that professionalism. And we're there to promote that and we're there to help people get that as well. I was laughing just now because I often get told that because I love doing what I do so much, I would MC the opening of a fridge door if I could.
It's true. I do like it. I do like it a lot. But it's a difficult game. Let's say somebody's now listening and they go, okay, well, Ross, you got it made. I mean, you're doing data privacy protection, right time, right place, you know, the president, so it's easy for you. I'm a business person, maybe, I don't know, let's pick something with finance. I'm an FD or something. And I believe I've got something to share. Where would I start? Is this something where, I mean, you've been this route, so you would know. Would you start with something like Toastmasters? Is it advisable? Yeah, well, so Toastmasters and PSAIC operating in sort of parallel with each other. Toastmasters has fantastic programs and courses that you can do on public speaking. So you can get graded and you get a lot of feedback from the room and it really built how you speak. And then there's on our space, which is how you want to make a business out of it and how you want to get into that side. So I think the two are very complimentary to each other. Because I mean, and I'll be honest with you, I've seen some people who are now being touted as professional speakers and they may have done something interesting in the past. But they get on stage and yes, they may have achieved amazing things or been an exports person, but they get on stage and they got the personality of a wet dish towel. Yes. And cannot like to string more than three to one word to get, you know, it's horrible. And I look at this and I've been at functions where I know what the client has paid and I'm like, oh my goodness. You know, so, you know, you need to be taught how to speak and how to present yourself. Yes, you need to be taught. You also need to have that authenticity about yourself. This is me. I mean, I can't copy Eddie Ezzard style and try and come across as him. It's not going to work with me. No, because there's only one person who can do death star canteen and that's Eddie Ezzard done in the story. But you develop your style and you develop your style with practice. And if you do practice and you take feedback on board from peers who have been there, who've gone through this rodeo, you learn that much quicker. My career has skyrocketed since joining the association. That's why I'm so passionate about it. I want to give back to the association because my, the first talk I gave, I was a nervous wreck and I was torn to pieces is a hard word because it was done with love, but I had a whole bunch of feedback as to what to change.
And because I could take that feedback on board, the next time I presented, it was better. And the next time it was better and with practice and learning the tricks. And I mean, again, that 90% behind the scenes, if you've seen someone up on stage for 45 minutes, they have practiced that for 45 hours before they've got up on that stage. Yeah. At the very least. I mean, yeah, particularly if they are professional. Yeah. Yes. So you learn all of these techniques and methods and you learn it from the people around you. Fantastic. We are speaking to my special guest tonight. Ross Saunders, president of the professional speakers association of South Africa, also a owner of Ross G Saunders consulting. And they talk all about data protection, data privacy. We'll be back in just a bit and wrap up with Ross. Appropriate song. Because as we were talking earlier about the data protection and data privacy with Ross, you heard the story of him having his identity stolen, which is why it's so close to his heart. Everybody is involved. So a couple of people, what about lawyers and the online shopping facility? Somebody's mentioned quite a lot of the big online shopping facilities now. I'm not going to mention them on air. Everybody is going to have to apply or comply with this ruling and regulation.
Yeah. So I mean, the interesting thing about it, and I mean, I'm part of the association of privacy professionals as well. And it's not a case of we're going to comply and we're done. Yeah. John Giles, who's quite a legend in the space of privacy in South Africa, he likens it to gym, where, I mean, when you're first getting fit, it's going to be taking a lot of effort. And then you've got to maintain it when you're there. You don't just get your six pack and decide to even hope to keep it. Well, then it turns into a keg, like in my case. But with these questions, because there's a lot of people that are now concerned about their privacy in online shopping. And I know in South Africa, it's been, it's taken us a while to kind of adopt this online shopping thing, because initially we were very skeptical. But now we seem to have jumped in boots and all. I mean, I've seen some figures that people, sales figures, that people with online businesses have made over this last weekend and today, from Black Friday to Happy Monday. There's silly amounts of money that is being transacted. All of those people have to comply as well. Yes. So I think when it comes to your online shopping, you have to shop from reputable places. If you see some of these ads for a website, 954-something-something.com. Yeah, a bit skeptical there. But if it's a reputable store, generally, because of other legislation out there as well, they would have to be complying with that too. So generally, a lot of the online stores are really safe.
I'm more afraid of credit card skimming in a shop than I am in an online transaction with a reputable place. Yeah. Because that's another thing that could happen there as well, is how they would skim your credit card or get your details. I'm fortunate. That's never happened to me. But I mean, if it ever did happen to me, I pity the poor soul because they would be sorely disappointed. I am after all the radio present. Anyway, so we were chatting about this. Somebody else has just asked now, tell me more about the Speakers Association. We're going to find out about joining. Yes, we will. Somebody else says, I've always wanted to do this. Can anybody be a speaker? Can anybody? Yeah. So I think that's one of the big things. With practice and with a willingness to learn, you can cultivate those skills. Yeah. And we are open to anyone coming and attending our meetings. We've got meetings in KZN, Joburg, Pretoria, Cape Town, and we have a virtual chapter as well for folks that might not be able to get to a physical meeting. So Pretoria meets on the last Thursday of the month, Joburg, the third Thursday of the month, and between Santon and Linwood. And those meetings are open to anyone to attend. There's a small guest fee. You get dinner as well. And you can take a look at our websites to get details of the next meetings. Or Facebook, we have a page and we've got quite a bustling community that's open to the public on our Facebook groups. Okay. So just to clarify, if I want to come to one of the meetings, get hold of you, however the case may be. There we go. There is a fee, but I get dinner.
Yes. I'm a fan of dinner. And then at the meetings, what do you guys talk about? The format changes depending on the evening and the theme changes, but the idea is that it is some sort of topic that comes up that speakers can benefit from. And in most cases, we will have two speakers on an evening where we will have two talks for 45 minutes of some sort of topic that can benefit speakers, be it business models, or training models, or how to do your social media, or how to market. And it's really, really broad. And it'll often be the members that are actually presenting this as well. But we may have panel discussions with professional members and outside people who are really good in a field coming in to talk. Okay. But just to get back to something like a Toastmasters, I mean, you say they ran parallel, but I mean, if I've just got an idea of wanting to be a speaker in my head, an absolutely zero experience. Yes. Coming and having a look at what you guys do is brilliant. Maybe joining is good, but to learn the actual process of speaking is something like a Toastmasters step number one. Yes, I would say so. Toastmasters has fantastic programs from the absolute baseline right the way up to their distinguished Toastmasters that when you hear them speak, no.
Because I'm going to be honest with you, I mean, you might have a brilliant idea, but if you've done the yearly sort of sales retreat function as the sales manager, and you've done like two and a half hour presentations that are death by PowerPoint, it does not make you a speaker. No, but you can still learn from the association. Yes, but that's what I'm saying. Learn, because there's nothing worse than, and I've seen it a couple of times. Somebody's like, "Oh wait, I can do that. I slapped together a quick couple of slides. There I go." And I'm going to talk, what are you going to talk about? Anything that comes up. We actually have a competition specifically for guys that are starting out. Yeah. The competition's actually, it's not open to anyone who's earning a professional living from speaking, where people can come in, they give five minute presentations, and it's a knockout competition, but the winner at the end of the day gets coaching, gets to speak on the main stage at our convention. It's quite an achievement, and there's so much learning and so much willingness to help in the association that even for folks that are really new and have only done death by PowerPoint, there are people that will help you.
See, I like that. I like that, because that's a kind of challenging thing. It's like your elevator pitch. This is who I am. This is what I do. This is my song and dance. Fantastic. Okay, so we are technically over time, but it's okay. Ross, let's start off with getting hold of you personally in terms of data privacy, data protection, because we had a couple of people going, "Oh, we need to speak to Ross. Where do we find you?" Two best places would be my website and on LinkedIn. Okay. So website is www.rosgsanders.com. So Ross, R-O-S-S-G, Saunders, S-A-U-N-D-E-R-S.com.
When you do send him a message, just tell him, "Hey, heard you on the show. Thanks." Something like that. So he can also track and see what we're doing there. People get very shy about that. And then in terms of the PSA, I'm sure you guys must be winding up for the year. I think we're going to be looking at sort of next year for meetings and things like that. Yeah, so the meetings will resume again from January. We've just had a lot of the last meetings now. But to find out more about that, if you go on Facebook and look at the Professional Speakers Association of Southern Africa, you'll be able to find us there as well as our group. And then our website is PSASouthernAfrica.co.za. Yes, Southern Africa. Not like I always go PSA SA because it's Southern Africa, not South Africa. I made that mistake and actually did when I was looking at the website before I got to the right one. Ross, thank you so much. If people need to talk to you about the data privacy and stuff like that, people in businesses that are my size a little bit bigger. I know you said you generally concentrate on the sort of mid to large kind of companies, but you know, there's a lot of people and this show a lot of people listen to because they are entrepreneurs with sort of small or medium businesses. Can they at least contact you?
Absolutely. Because this is scary. I mean, it's scary stuff that's coming. I mean, I'm a small business myself. And one of the things is I have to comply with this too. So part of what I've been doing in this space as well is I've got a product slash solution that I've put together, which is a privacy in a box, which is some baseline policies that you need, templates that you need, and a little bit of consulting on top of that, but so that it's affordable and you're not paying a legal fee of 350,000 rand or whatever. Because I've seen people asking silly amounts and then they start mentioning puppy and GDPR and everything and you automatically go into a panic and you'll fork over your cash when you don't necessarily have to pay that much. Yes. There's a lot of really practical things that you can do. There might be some things that you will need an attorney for and there's so much that you can do that you can just put in place straight off the bat. Fantastic stuff. Ross, thank you so much. I've really enjoyed our chat. You've scared the life out of me. I'm going home to go and start going through all sorts of things. But you know what, I think from a privacy perspective, it makes sense. And I'd like to know where my daughter is and how it's being used. And I'd like to know that it is in safe hands. Thank you very much.
Thank you very much. My special guest, Ross Sorna. So check it out, the Professional Speakers Association of Southern Africa. If you'd like to get into the speaking business or just learn a bit more and meet some really cool people. I've met some really cool speakers and genuine, genuine people. So just in and of itself, that's great. Otherwise, if you want to find out more, get hold of Ross directly. We did have a second guest for tonight. Unfortunately, they canceled at the last moment. So I didn't have time, you know, this time of the year. By the way, next week, next week, Monday, the last show for the year doesn't mean I won't be on air. I am standing in for Tony Blurt during December while he's away. So that's going to be a whole bunch of fun. But last official show of what's involved taking place next Monday. And then we'll be back with the business show as usual every Monday from January up until next week. Have yourselves a fantastic time. And one more thing before I go. Thanks for listening.
Keep listening
Ross Saunders — Data Privacy and the big WhatsApp conspiracy
On this episode I chat with Ross about data privacy and the storm in a teacup that is WhatsApp. We also look at Telegram and Signal and discuss the implications of WhatsApp for business. Ross specialises in data prote…
Cannabis Expo — What is the expo all about and why should you be interested
On this episode I chat to two of the exhibitors from the Cannabis Expo Andrew Kyriacou from Kiricann and Wesley Young from Bioleaf Technologies. We chat about the Expo, why the hype around Cannabis and why you should…
Charlotte Kemp — Futurist, Speaker, Author
On this episode I chat with the effervescent Charlotte Kemp about her latest book Futures Alchemist. The book is a combination of educational guide and adventure story. Definitely on my must read list. http://charlott…
Jamal Sahib — Author, Business Coach, Business Owner
On this episode, I chat with the powerhouse that is Jamal Sahib his love of family, community and helping entrepreneurs is what shines through. https://jamalsahib.com/