There are no specific legislation with regard to data protection in employment
relations in South Africa. Similarly, the South African courts have made little or no
significant contribution in this regard.
101
4.1.7 Security Obligations and Data Breach Notifications in the Context
of Electronic Processing
A responsible party, under the POPI Act, has a strict duty of security safeguard of
personal information in his possession by ensuring that he takes “appropriate,
reasonable technical and organisation measure to prevent information for loss,
damage or unlawful access”.
102 Where there is a security compromise or there are
reasonable grounds to believe so, there is an obligation to notify the Regulator and
the data subject (in as much as the identity of the data subject can be ascertained).
103
4.2 Data Protection in the Electronic Communication Sector
The Primary law regulating the electronic communications sector in South Africa is
Electronic Communications Act 2005.
104 It does not make any serious provision on
personal data protection. It merely provides that the Independent Communications
Authority of South Africa may prescribe or impose through licence conditions in
respect of directories and directory enquiry services, regarding, inter alia, the
protection of personal data and the protection of privacy.
105
It is therefore arguable that both POPI Act and the ECT Act are applicable in the
context of processing of personal information in the electronic communication
sector. In any case, the POPI Act has already provided that in the context of data
protection, its provisions supersedes where it has more extensive provisions on the
conditions for lawful processing.
106 With regard to the POPI Act specifically, there
is a provision for protection of a data subject who is a subscriber to electronic
directory of subscribers.
107 A subscriber within the context of the provision is
defined as “any person who is party to a contract with the provider of publicly
available electronic communication services for the supply of such services”.
108
101 See generally Gondwe (2011).
102 Section 19 of the POPI Act.
103 Section 22 of the POPI Act.
104 Act 36 of 2005. Also available at http://www.wipo.int/edocs/lexdocs/laws/en/za/za082en.pdf.
105 Section 75 of the Electronic Communications Act.
106 Section 3(2)(b) of the POPI Act.
107 Section 70 of the POPI Act.
108 Section 70(5) of the POPI Act.
362
L. A. Abdulrauf
relations in South Africa. Similarly, the South African courts have made little or no
significant contribution in this regard.
101
4.1.7 Security Obligations and Data Breach Notifications in the Context
of Electronic Processing
A responsible party, under the POPI Act, has a strict duty of security safeguard of
personal information in his possession by ensuring that he takes “appropriate,
reasonable technical and organisation measure to prevent information for loss,
damage or unlawful access”.
102 Where there is a security compromise or there are
reasonable grounds to believe so, there is an obligation to notify the Regulator and
the data subject (in as much as the identity of the data subject can be ascertained).
103
4.2 Data Protection in the Electronic Communication Sector
The Primary law regulating the electronic communications sector in South Africa is
Electronic Communications Act 2005.
104 It does not make any serious provision on
personal data protection. It merely provides that the Independent Communications
Authority of South Africa may prescribe or impose through licence conditions in
respect of directories and directory enquiry services, regarding, inter alia, the
protection of personal data and the protection of privacy.
105
It is therefore arguable that both POPI Act and the ECT Act are applicable in the
context of processing of personal information in the electronic communication
sector. In any case, the POPI Act has already provided that in the context of data
protection, its provisions supersedes where it has more extensive provisions on the
conditions for lawful processing.
106 With regard to the POPI Act specifically, there
is a provision for protection of a data subject who is a subscriber to electronic
directory of subscribers.
107 A subscriber within the context of the provision is
defined as “any person who is party to a contract with the provider of publicly
available electronic communication services for the supply of such services”.
108
101 See generally Gondwe (2011).
102 Section 19 of the POPI Act.
103 Section 22 of the POPI Act.
104 Act 36 of 2005. Also available at http://www.wipo.int/edocs/lexdocs/laws/en/za/za082en.pdf.
105 Section 75 of the Electronic Communications Act.
106 Section 3(2)(b) of the POPI Act.
107 Section 70 of the POPI Act.
108 Section 70(5) of the POPI Act.
362
L. A. Abdulrauf
