Image created by AI

SAPS and IEC Under Scrutiny for Alleged Breaches of South Africa's Data Protection Laws

Published March 28, 2024
2 years ago


The Information Regulator of South Africa has raised concerns about the lack of compliance with the Protection of Personal Information Act (Popia) within the public sector, signaling a problematic trend with serious implications for personal data security. Recent incidents involving the South African Police Service (SAPS) and the Electoral Commission of South Africa (IEC) have highlighted this issue.


During a recent briefing, it was revealed that the SAPS faced an enforcement notice following the unauthorized distribution of personal information of sexual assault victims. Despite having complied with this notice, the SAPS once again fell afoul of the legislation for circulating sensitive information related to ongoing investigations on WhatsApp. The details included crime scene reports, car registration numbers, and home addresses of individuals connected to high-profile cases. These actions triggered another inquiry by the Information Regulator, emphasizing the need for stricter adherence to Popia.


Moreover, concerns have now extended to the IEC, following an admission that candidate lists for the forthcoming national and provincial elections were inadvertently leaked. The Information Regulator has since commenced a full-scale investigation into the data breach, with the aim of finalizing the matter before election day.


This scrutiny comes against the backdrop of an increasing number of complaints, rising to 982 in the 2023/24 financial year, indicating a surge in public awareness and concern over data protection rights. Out of these, 682 were resolved, and 10 comprehensive assessments were conducted, awaiting enforcement notices which hold the weight of a court order. These notices, when disregarded, can result in hefty fines up to R10 million or imprisonment, underscoring the seriousness of Popia compliance.


This spate of non-compliance has led advocate Pansy Tlakula, chairperson of the Information Regulator, to offer training to organizations in understanding and implementing Popia and the Promotion of Access to Information Act (Paia) requirements. Despite these initiatives, the private sector appears more inclined to follow the stringent data protection laws than their public counterparts, casting doubt on the public sector's commitment to data privacy.


The Information Regulator has emphasized its role in investigating complaints, either lodged by individuals or initiated by itself, and is considering implementing further measures against the SAPS to prevent future breaches.


Overall, the efficient enforcement of Popia is critical to safeguarding personal information and upholding citizens' privacy rights in South Africa amidst an era of digital vulnerability.



Leave a Comment

Rate this article:

Please enter email address.
Looks good!
Please enter your name.
Looks good!
Please enter a message.
Looks good!
Please check re-captcha.
Looks good!
Leave the first review