Legal updates and opinions
News / News
Cybercrimes Act: South Africa Finally Joins The Big Boy Table
1. President Cyril Ramaphosa has just signed the Cybercrimes Bill, which seeks to bring South Africa’s cybersecurity laws in line with the rest of the world, into law. This Bill which is now an Act of Parliament creates offences for and criminalises, amongst others, the disclosure of data messages which are harmful. Examples of such data messages include:
1.1 those which incite violence or damage to property;
1.2 those which threaten persons with violence or damage to property; and
1.3 those which contain an intimate image.
Not every crime is a cybercrime – The dichotomy of cyber-enabled crimes and cybercrimes.
2. Other offences include cyber fraud, forgery, extortion and theft of incorporeal property. The unlawful and intentional access of a computer system or computer data storage medium is also considered an offence along with the unlawful interception of, or interference with data.
3. This creates a broad ambit for the application of the Cybercrimes Act which defines “data” as electronic representations of information in any form. It is interesting to note that the Act does not define “cybercrime” but rather creates a number of offences such as those canvassed above.
4. There is no doubt that the Cybercrimes Act will be of particular importance to electronic communications service providers and financial institutes as it imposes obligations upon them to assist in the investigation of cybercrimes, for example by furnishing a court with certain particulars which may involve the handing over of data or even hardware on application. There is also a reporting duty on electronic communications service providers and financial institutions to report, without undue delay and where feasible, cyber offences within 72 hours of becoming aware of them. A failure to do so may lead to the imposition of a fine not exceeding R50 000.
5. A person who is convicted of an offence under the Cybercrimes Act is liable to a fine or to imprisonment for a period of up to fifteen years or to both a fine and such imprisonment as may be ordered in terms of the offence.
6. It is further interesting to note the impact this Act will have on businesses, especially considering its overlap with the Protection of Personal Information Act 4 of 2013 (POPIA), amongst other regulatory codes and pieces of legislation. POPIA, which deals with personal information, aims to give effect to the right to privacy by protecting persons against the unlawful processing of personal information. One of the conditions for lawful processing in terms of POPIA is security safeguards which prescribes that the integrity and confidentiality of personal information must be secured by a person in control of that information. This is prescribed by POPIA in order to prevent loss, damage or unauthorised access to or destruction of personal information. POPIA also creates a reporting duty on persons responsible for processing personal information whereby they must report any unlawful access to personal information (data breach) to the Information Regulator within a reasonable period of time.
7. In light of the above, companies should be cognisant of their practices especially in dealing with data or information. The value of data as an asset, the oil of the new economy, cannot be understated. To quote the CEO of Apple, Tim Cook:
“We shouldn’t ask our customers to make a trade-off between privacy and security. We need to offer them the best of both. Ultimately, protecting someone else’s data protects all of us.”
Read more on the major cyber security risks to your business here.
by Ahmore Burger-Smidt, Director and Head of Data Privacy Practice and member of Competition Law Practice; and Nyiko Mathebula, Candidate Attorney.
Latest News
Copyright and Artificial Intelligence in South Africa: Rethinking Authorship and Originality in the Digital Age
by Janine Hollesen, Director & Head of Intellectual Property, Preeta Bhagattjee, Director & Head of Technology & Innovation, and Malique Ukena, Candidate [...]
No! It is NOT all about consent!
by Ahmore Burger-Smidt, Director & Head of Regulatory “I believe that a guarantee of public access to government information is [...]
The Consequences of Lessons not Learnt – A Cautionary POPIA Tale
by Dakalo Singo, Director & Head of Pro Bono and Ahmore Burger-Smidt, Director & Head of Regulatory “All men make [...]
To Dismiss or Not to Dismiss – That is the Operational Question
by Bradley Workman-Davies, Director The recent Labour Court judgment in Inxuba Yethemba Municipality v Msweli & others underscores two important principles for [...]
The Clock is Ticking on Unfair Labour Practice Referrals – Labour Court Confirms They Are One-Time Events
by Bradley Workman-Davies, Director In the recent case of NEHAWU obo Makhubele & others v Ramalatso NO & others , the Labour [...]
When a Withdrawal Doesn’t Really Withdraw: Provisional Liquidation is not Set Aside by Withdrawal
by Walid Brown, Director and Nombulelo Bashe, Associate Introduction We were recently reprimanded by an opponent for having the temerity [...]