out of the scope of the powers of the South African Information Regulator. Section 4
considers data protection in specific context such as electronic/automated
processing, electronic communications sector, and digital forensics. In Sect. 5, the
international dimension of data protection is examined before the chapter concludes
with some reflections on the state of data protection on the internet in South Africa.
2 The General Data Protection Framework in South Africa
2.1 Background to the Applicable Rules: The POPI Act
In South Africa, the protection of personal data (information) is realized through a host
of legislation. These legislation either have general of sectoral application. Recently,
South Africa enacted its omnibus/general data protection legislation which is the
Protection of Personal Information Act (hereinafter, ‘POPI Act’ or ‘the Act’) No 4 of
2013.
2 This followed extensive deliberations which started since 2000 by the
South African Law Reforms Commission (SALRC) when it included ‘privacy and
data protection’ among its research topics.
3 This long process only yielded fruits in
2013 when the Act was adopted by parliament after much expectation and anticipation.
Although, the law has been signed by the President of South Africa, it is imperative to
state that it is yet to fully come into force. Section 115 of the Act inter alia provides that
the Act only comes into force “on a date determined by the President by proclamation in
the Gazette”.
4 The President has, as yet, not so determined. Nevertheless, the Act
provides that “Different dates of commencement may be determined in respect of
different provisions of this Act or in respect of different class or classes of information
and bodies”.
5 It is in the light of this section that the President has determined that
certain provisions should take effect—for example, the provision which establishes the
supervisory authority.
6 Annelise Roos contends that “It is assumed that the Act will
enter into force fully once the office of the Regulator has been established and
regulations have been issued”.
7
Apart from the POPI Act which is the general legislation on data protection in
South Africa, there is quite a number of legislation of sectoral application. These
legislation have certain provision that have the implication of protecting individuals’
with regard to the processing of their personal information. Notable among the
legislation are The Promotion of Access to Information Act,
8 the Electronic
2 Ibidem.
3 See SALRC (2009).
4 Section 115 of the POPI Act.
5 Ibidem.
6 See https://www.saica.co.za/Portals/0/Technical/LegalAndGovernance/37544_pro25.pdf.
7 Roos (2016b), p. 203.
8 Act No 2 of 2000.
350
L. A. Abdulrauf
considers data protection in specific context such as electronic/automated
processing, electronic communications sector, and digital forensics. In Sect. 5, the
international dimension of data protection is examined before the chapter concludes
with some reflections on the state of data protection on the internet in South Africa.
2 The General Data Protection Framework in South Africa
2.1 Background to the Applicable Rules: The POPI Act
In South Africa, the protection of personal data (information) is realized through a host
of legislation. These legislation either have general of sectoral application. Recently,
South Africa enacted its omnibus/general data protection legislation which is the
Protection of Personal Information Act (hereinafter, ‘POPI Act’ or ‘the Act’) No 4 of
2013.
2 This followed extensive deliberations which started since 2000 by the
South African Law Reforms Commission (SALRC) when it included ‘privacy and
data protection’ among its research topics.
3 This long process only yielded fruits in
2013 when the Act was adopted by parliament after much expectation and anticipation.
Although, the law has been signed by the President of South Africa, it is imperative to
state that it is yet to fully come into force. Section 115 of the Act inter alia provides that
the Act only comes into force “on a date determined by the President by proclamation in
the Gazette”.
4 The President has, as yet, not so determined. Nevertheless, the Act
provides that “Different dates of commencement may be determined in respect of
different provisions of this Act or in respect of different class or classes of information
and bodies”.
5 It is in the light of this section that the President has determined that
certain provisions should take effect—for example, the provision which establishes the
supervisory authority.
6 Annelise Roos contends that “It is assumed that the Act will
enter into force fully once the office of the Regulator has been established and
regulations have been issued”.
7
Apart from the POPI Act which is the general legislation on data protection in
South Africa, there is quite a number of legislation of sectoral application. These
legislation have certain provision that have the implication of protecting individuals’
with regard to the processing of their personal information. Notable among the
legislation are The Promotion of Access to Information Act,
8 the Electronic
2 Ibidem.
3 See SALRC (2009).
4 Section 115 of the POPI Act.
5 Ibidem.
6 See https://www.saica.co.za/Portals/0/Technical/LegalAndGovernance/37544_pro25.pdf.
7 Roos (2016b), p. 203.
8 Act No 2 of 2000.
350
L. A. Abdulrauf
