Cybercrimes Act

We defend your rights passionately and expertly.

2023

[6 October 2023]

The government has established clear procedures for cybercrime investigations. The Minister of Police recently approved these final Standard Operating Procedures (SOPs) which outline how law enforcement will handle evidence collection and other aspects of cybercrime cases under the Cybercrimes Act.

Cybercrimes Act Standard Operating Procedures 6 October 2023

2022

[25 July 2022]

South African Police Service (SAPS) is seeking public feedback on their draft Standard Operating Procedures (SOPs) for handling cybercrime investigations. Submit your comments by August 15th, 2022, to Captain Marlize Jooste at joosteme@saps.gov.za.

Draft SAPS Standard Operating Procedures under section 26 of the Cybercrimes Act

Invitation to comment

2021

[30 November 2021]

Cybercrimes Act Commencement of certain sections 19 November 2021

[9 June 2021]

The Cybercrimes Act of 2020 is now official! While it’s not active just yet, the President has signed it into law. There’s no specific start date yet, but the wait will be used to prepare everything needed to make the law work smoothly. This means creating clear instructions (called “standing operating procedures”) for how things will be done under the Act.

Cybercrimes Act, 19 of 2020

This law defines new criminal acts related to computer crime in South Africa. These include:

  • Breaking into computer systems or storage devices without permission.
  • Spying on someone’s data or using information you get this way illegally.
  • Having or using tools designed to harm computers or data.
  • Tampering with data or computer programs.
  • Damaging computer systems or storage devices.
  • Stealing passwords or access codes.
  • Cyber fraud: Tricking someone online to steal their money or cause them harm.
  • Creating fake data or programs to defraud someone.
  • Cyber extortion: Threatening someone online to get money or something else.
  • Stealing intellectual property like digital creations.
  • Sending harmful messages: This includes threats of violence, inciting property damage, or sharing intimate images without permission.

This law also changes how police interact with internet service providers (ISPs). It gives them new ways to get evidence stored by ISPs.

Reporting Requirements for ISPs Coming Soon

A future section of the law will require ISPs to report certain information once details are finalized.

Obligations of electronic communications service providers and financial institutions

54(1) An electronic communications service provider or financial institution that is aware or becomes aware that its electronic communications service or electronic communications network is involved in the commission of any category or class of offences provided for in Part I of Chapter 2 and which is determined in terms of subsection (2), must—

(a) without undue delay and, where feasible, not later than 72 hours after having become aware of the offence, report the offence in the prescribed form and manner to the South African Police Service; and

(b) reserve any information which may be of assistance to the South African Police Service in investigating the offence.

(2) The Cabinet member responsible for policing, in consultation with the Cabinet member responsible for the administration of justice, must by notice in the Gazette, prescribe—

(a) the category or class of offences which must be reported to the South African Police Service in terms of subsection (1); and

(b) the form and manner in which an electronic communications service provider or financial institution must report offences to the South African Police Service

(3) An electronic communications service provider or financial institution that fails to comply with subsection (1), is guilty of an offence and is liable on conviction to a fine not exceeding R50 000.

(4) Subject to any other law or obligation, the provisions of subsection (1) must not be interpreted as to impose obligations on an electronic service provider or financial institution to—

(a) monitor the data which the electronic communications service provider or financial institution transmits or stores; or

(b) actively seek facts or circumstances indicating any unlawful activity.

2020

[23 June 2020]

The path to becoming law became much clearer for the Cybercrimes Bill after a committee greenlit amendments and a report on June 11th, 2020. The next hurdle is a vote by the full National Council of Provinces.

Committee statement on adoption of Cybercrimes Bill 11 June 2020

Cybercrimes Bill Committee Report 11 June 2020

NCOP proposed amendments to Cybercrimes Bill

[19 February 2020]

South Africa’s proposed Cybercrimes Act is still under review by the National Council of Provinces’ security and justice committee. They’re currently considering feedback from the public. Key concerns involve how much power law enforcement will have to search computers without warrants, and whether the police force is equipped to handle the finalized Act.

Presentation by the Directorate for Priority Crime Investigation

2019

[6 February 2019]

The South African Parliament is asking for your input on the Cybercrimes Bill! The National Council of Provinces (NCOP) committee overseeing security and justice matters wants to hear from the public.

You can submit your comments in writing by email to Mr. G Dixon (gdixon@parliament.gov.za). The deadline for submissions is March 8th, 2019.

2018

[24 November 2018]

After being approved by the Portfolio Committee for Justice and Correctional Services on November 7th, 2018, the Cybercrimes Bill heads to the National Assembly for debate scheduled for November 27th, 2018.

[30 October 2018]

Cybercrimes Bill 23 October 2018 (clean version)

Cybercrimes Bill 23 October 2018 (showing changes from previous draft)

The Department of Justice introduced a significantly revised version of the cybercrime legislation on October 23rd, 2018, to the parliamentary committee. The most notable change is the separation of cybersecurity measures from the bill. This split necessitated a name change, with the bill now titled the “Cybercrimes Bill” instead of the “Cybercrimes and Cybersecurity Bill.”

Here’s a breakdown of the key revisions:

  • Cybersecurity Focuses Elsewhere: The revised bill no longer includes provisions on cybersecurity. These will be addressed in a separate piece of legislation.
  • Sharper Definition of “Unlawful”: The definition of “unlawful” online activity has been tightened to better align with the Protection of Personal Information Act.
  • Narrowed Malicious Communications: This section now specifically targets the non-consensual sharing of intimate images coupled with threats of violence.
  • Critical Infrastructure Crimes Omitted: Offenses related to cyberattacks on critical infrastructure have been removed from the bill.

[24 March 2018]

The Portfolio Committee is still reviewing the Bill.

Cybercrimes and Cybersecurity Bill [28 Feb 2018] showing proposed amendments

2017

[18 November 2017]

The Department of Justice (DOJ) has been explaining its reply to comments on the Cybercrimes Bill to the Portfolio Committee. These explanations include a written document summarizing all the responses.

Responses to submissions: Chapters 1-9

Responses to submissions: Chapters 10-13

[11 September 2017]

Submissions:

[9 September 2017]

The public will have a chance to voice their opinions on the Bill at hearings set for September 13th and 14th, 2017. The hearings will be held in room M514 of the Marks Building, starting at 9:30 am each day.

Programme for Hearings 13 14 September

[26 July 2017]

The deadline to submit comments on the Bill has been extended until August 10th, 2017.

[4 July 2017]

The Portfolio Committee on Justice and Correctional Services is inviting you to submit your comments on the Cybercrimes and Cybersecurity Bill 2017 (B6-2017) in writing.

Deadline: July 28th, 2017

Want to speak up in person? Indicate your interest in giving a verbal presentation at future public hearings when submitting your comments.

How to Submit:

  • Email: vramaano@parliament.gov.za
  • Mail: Mr V Ramaano, Portfolio Committee on Justice and Correctional Services, 3rd Floor, 90 Plein Street, Cape Town, 8000
  • Note: Include enquiries in your submission.

[30 May 2017]

The Justice Department just explained the Cybersecurity and Cybercrime Bill 2016 to the parliamentary committee overseeing justice issues. This is the start of the committee’s official review. We expect the bill to be made public for comments soon, followed by public hearings.

Cyber Bill Parliament Presentation – May 30 2017

[22 February 2017]

Here are the Cybercrimes and Cybersecurity Bill, along with the official notice from Parliament when it was introduced.

Cybercrimes and Cybersecurity Bill [B6-2017]

Parliamentary notice

[19 January 2017]

The Bill and its accompanying summary, which are scheduled to be introduced in Parliament later this month, can be found below.

Cybercrimes and Cybersecurity Bill 2017

Summary of Cybercrimes and Cybersecurity Bill 2017

Announcement from Deputy Minister Jeffery: A new bill to address cyber threats.

2016

[9 December 2016]

The Minister of Justice and Correctional Services has signaled the upcoming introduction of the Cybercrimes and Cybersecurity Bill, 2017, in the National Assembly. This notice appeared in a recent Government Gazette.

Publication of the Explanatory Summary of the Cybercrimes and Cybersecurity Bill 2017

The explanatory summary of the Bill published in the Notice reads as follows:

The Bill intends to –

(a) create offences which has a bearing on cybercrime and to prescribe penalties;

(b) criminalise the distribution of data messages which is harmful and to provide for interim protection orders;

(c) further regulate jurisdiction in respect of cybercrimes;

(d) further regulate the powers to investigate cybercrimes;

(e) further regulate aspects relating to mutual assistance in respect of the investigation of cybercrime;

(f) provide for the establishment of a 24/7 Point of Contact;

(g) further provide for the proof of certain facts by affidavit;

(h) impose obligations on electronic communications service providers and financial institutions to assist in the investigation of cybercrimes and to report cybercrimes;

(i) provide for the establishment of structures to promote cybersecurity and capacity building;

(j) regulate the identification and declaration of critical information infrastructures and measures to protect critical information infrastructures;

(k) provide that the Executive may enter into agreements with foreign States to promote cybersecurity;

(l) delete and amend provisions of certain laws; and (m) provide for matters connected therewith.

[7 September 2016]

The Department of Telecommunications and Postal Services has launched their new virtual cybersecurity hub website to bridge the gap until a new bill is introduced into Parliament early next year. (This bill is expected to be presented to Cabinet in September.)

[9 March 2016]

In response to public input, the Department of Justice has established a panel of experts to review the heavily amended Bill. This review is expected to be completed by mid-2016, after which a new iteration of the Bill will be released.

2015

[5 December 2015]

The release of the edited National Cybersecurity Framework Policy (NCPF) on December 4th, 2015, came after the comment period for the Draft Cybercrimes and Cybersecurity Bill 2015 had closed. This timing is regrettable.

National Cybersecurity Policy Framework 2012 (Public Edit)

[4 December 2015]

Submissions:

[21 November 2015]

The deadline to submit comments on the Cybercrimes and Cybersecurity Bill 2015 is approaching! Submit yours by Monday, November 30th.

[5 November 2015]

The South African government launched the Cybersecurity Hub in October 2015 to improve online safety for everyone in the country. You can find more information on their website at www.cybersecurityhub.gov.za If you experience a cyber security incident, you can report it to incident@cybersecurityhub.co.za

In short the functions of the hub will be among others to:

  • Receiving incident reports from stakeholders and establishing clear incident management processes.
  • Disseminating information to stakeholders about threats and attacks as a pre-emptive measure as well as mitigating procedures against emerging attacks
  • Creating an archive of lessons learnt to ensure ease of access in dealing with future threats and vulnerabilities
  • In the case of cyberbullying involving Cybersecurity Hub legal entities and assisting with escalating attacks to the relevant authorities
  • And chairing of scheduled meetings with reporting and trending attacks and incidents for the specific period.

The hub will become a point of reference for citizens in as far as cybersecurity issues are concerned providing a repository of information regarding the do’s and don’t s of Internet for children, best practice guide for parenting on the Internet and how the average South African can protect against malicious attacks, identity theft and online financial security. The hub will create platforms to allow parents to share information on how to manage their children online and also provide links to Internet resources to assist both children and parents.

For the very first time in South Africa, the hub will ensure collaboration between businesses and create a platform for partnership between government and the private sector on cybersecurity. It will also facilitate the leveraging of high end cybersecurity capacity which is scarce as we build confidence and trust among stakeholders and place our nation in a better position to respond to cybersecurity in a much more coordinated matter. The shared information also provides an opportunity for cost savings as the hub’s expertise will allow for quicker incident recovery, which can translate to less money spent on incident response.

[11 September 2015]

This resource is a 45-minute presentation about cybercrime and its legal implications for Internet Service Providers (ISPs) in South Africa. The presentation was given at the iWeek Conference hosted by the Internet Service Providers’ Association (ISPA).

iWeek 2015 – Cybercrime and the Law

[28 August 2015]

Cybercrimes and Cybersecurity Bill 2015

Discussion Document 2015

Invitation to comment

The Department of Justice & Constitutional Development is seeking public comment on a new bill: The Cybercrimes and Cybersecurity Bill. This bill aims to improve cybersecurity and fight cybercrime in South Africa.

What the Bill Covers:

  • Creating new cybercrime offenses and their punishments
  • Giving authorities clearer rules for investigating cybercrime
  • Establishing a 24/7 point of contact for cybercrime issues
  • Setting up structures to handle cybersecurity threats
  • Protecting critical national infrastructure from cyberattacks
  • Outlining how electronic communication companies can help with cybersecurity
  • Allowing the government to make international agreements on cybersecurity

You have until November 30th, 2015 to submit your comments.

You can comment by:

If you’d like to discuss the bill in person, contact the Department of Justice & Constitutional Development to schedule a meeting. Meetings will typically be held at the department’s offices.

[22 May 2015]

The announcement by the Deputy Minister of Justice and Correctional Services in his Budget Speech for the 2015/2016 financial year means the public will get to weigh in on the Cybercrimes and Related Matters Bill before it goes to Parliament. The Bill will be open for public comment soon.

The Cybercrimes and Related Matters Bill is aimed at strengthening the criminal justice system as envisaged in the National Development Plan, by introducing measures which are aimed at combatting cybercrime. It will be released for public comment by the Department in the near future before being introduced into Parliament.

The Minister mentioned in his Budget Speech that a conviction rate of 95% has been reached in cybercrime prosecutions.

[6 May 2015]

On May 5, 2015, the Minister of State Security delivered his Budget Vote Speech for the 2015/2016 fiscal year, which included a section on cybersecurity and cybercrime.

Although the content of the speech relies primarily on a prior address (see previous post), the following merits particular attention:

Working with universities and other research institutes like the CSIR to build the cybersecurity pipeline through competitive scholarship, fellowship, and internship programs must be our preoccupation to attract top talent and develop systems that have command and control in our hands, national sovereignty.
This financial year, 2015/16 we plan to move with speed to:
a) Enhance the institutional cybersecurity capacity
b) Finalize the national cybersecurity policy and legislation
c) Working with the security cluster to present the Cyber Security Bill before Cabinet this year
d) Build on our first symposium work held this year to promote partnership and public cybersecurity awareness campaign designed to increase public understanding of cyber threats and promote simple steps the public can take to increase their safety and security online.
e) Strengthen our cooperation in this space with our SADC, AU and BRICS partners through existing mechanism.
f) Prioritize the establishment of the Cybersecurity Centre and the repositioning of the current Electronic Communications Security Computer Security Incident Response Team (ECS-CSIRT) to become a Government CSIRT

[12 March 2015]

At a Johannesburg Cybersecurity Symposium on March 1, 2015, the Minister of State Security addressed South Africa’s cybersecurity landscape.

Remarks by Minister of State Security on Cybersecurity Symposium 1 March 2015

The speech aimed to introduce the upcoming public discussion on the Cybercrimes and Related Matters Bill. This bill is currently being discussed privately but is expected to be made public in the Government Gazette next month. It also made clear that cybersecurity is the responsibility of the security cluster.

The Government’s approach in dealing with this matter is premised on the policy principle that National security, which includes the security of the Information and Communications Technologies in the country, is a responsibility of the structures responsible for security in the Republic.”).

While the Department of Telecommunications and Postal Services and the Department of Communications have expressed interest in cybersecurity, finding information about the National Cybersecurity Policy Framework (NCPF) from 2012 remains difficult. Therefore, the following details are particularly valuable:

In March 2012, Cabinet approved a National Cybersecurity Policy Framework (NCPF) which seeks to, amongst others, deal with the following:
a. Centralize coordination of Cybersecurity activities within SA so as to have a coordinated approach to cybercrime, national security imperatives and enhance the information society and knowledge based economy;
b. Strengthen intelligence collection, investigation, prosecution and judicial processes, in respect of preventing and addressing cybercrime, cyber terrorism and cyber warfare;
c. Anticipate and confront emerging cyber threats, in particular threats to National Critical Information Infrastructure and coordinate responses thereto;
d. Foster cooperation and coordination between Government, the private sector and civil society including ensuring that South Africa becomes a critical contributor to international cooperation on Cybersecurity matters.
e. Develop skills, Research and Development capacity, promote Cybersecurity culture and promote compliance with appropriate technical and operational Cybersecurity standards.

The State Security Agency (SSA) chairs a strategic committee – the Cybersecurity Response Committee (CRC). This committee is responsible for deciding what’s most important and ensuring the National Cybersecurity Policy Framework (NCPF) is implemented.