Cybercrimes Act 19 of 2020
za-cyber-2020 · Act
The Cybercrimes Act 19 of 2020 is South Africa's dedicated cybercrime statute, consolidating and modernising offences previously found in the Electronic Communications and Transactions Act, 2002. It was assented to on 26 May 2021 and the majority of its provisions were brought into force on 1 December 2021 by Presidential proclamation; certain provisions (notably those dealing with structures for mutual assistance, aspects of SAPS capacity, and related amendments to the Criminal Law (Sexual Offences) Amendment Act) were commenced on different dates or remain to be proclaimed. The Act creates a comprehensive set of cyber-offences: unlawful access (hacking), unlawful interception of data, unlawful acts in respect of software or hardware tools, unlawful interference with data, computer programs, computer data storage mediums or computer systems, and the unlawful acquisition, possession, receipt or use of passwords and access codes. It introduces cyber-specific property offences, cyber fraud, cyber forgery and uttering, and cyber extortion, and aggravated offences where restricted computer systems (including critical information infrastructure) are targeted. A distinct chapter criminalises malicious communications, including data messages that incite damage to property or violence, that threaten persons, and the unlawful disclosure of intimate images, which carry the Act's principal digital-rights dimension. On procedure, the Act confers extensive investigative powers on the South African Police Service (SAPS): search, access and seizure of articles and data under warrant (and limited warrantless powers in urgent circumstances), expedited preservation and disclosure directions, and orders to obtain and preserve evidence. It imposes obligations on electronic communications service providers and financial institutions to report cyber-offences within 72 hours and to preserve information that may assist investigations, and it provides a framework for international cooperation, mutual legal assistance and a designated 24/7 point of contact, consistent with the Budapest Convention. Institutionally, enforcement is led by SAPS (supported by a designated point of contact and capacity-building obligations), while prosecution falls to the National Prosecuting Authority. The Act's unlawful-access and data-interference offences create a clear interface with the Protection of Personal Information Act 4 of 2013, and its requirements dovetail with sector measures such as the South African Reserve Bank's cybersecurity and cyber-resilience directive for the national payment system.
- Criminalises unlawful access (hacking), unlawful interception, and unlawful interference with data, programs and computer systems, with aggravated penalties where critical information infrastructure or restricted systems are targeted.
- Introduces cyber-specific offences of cyber fraud, cyber forgery and uttering, and cyber extortion.
- Creates malicious-communications offences, including data messages inciting violence/damage, threats, and the unlawful disclosure of intimate images.
- Confers SAPS powers of search, access and seizure under warrant, plus expedited preservation and disclosure directions.
- Imposes 72-hour reporting and data-preservation duties on electronic communications service providers and financial institutions.
- Provides for international cooperation, mutual legal assistance and a 24/7 designated point of contact.