Following a call for public comments gazetted by the Minister of Home Affairs, Dr Leon Schreiber, in May 2026, this submission addresses several fundamental concerns regarding the democratic legitimacy of the draft amendments to the 1998 Identification Regulations.
The amendments are intended to outline the issuance of digital ID credentials, an additional form of identity document, established via biometric verification, which would eventually serve as an alternative to ID cards and assist in addressing identity fraud, as well as the digital delivery of government services.
However, drawing on DPI research examining the rollout of national digital ID systems in Africa, as well as policy research on data access, this submission identifies significant compliance failures, cybersecurity risks, and general misalignment between the proposed deployment of digital IDs and the nation’s broader digital transformation priorities and ambitions.
Focusing on the draft amendment’s compliance with the Protection of Personal Information Act (POPIA), it calls on the Department of Home Affairs to address several regulatory gaps before the draft amendment can be legally finalised. These include, but are not limited to:
- Failure to fulfil obligations under the Protection of Personal Information Act prior to issuing the draft Regulations;
- Concerns surrounding the practice of ‘dumping’ data onto other government systems without a clear articulation of how to digitally administer such data in alignment with necessary privacy impact assessments, cybersecurity audits and other technical assurances;
- Lack of transparent communication regarding the necessity of a Digital ID in addition to the existing Smart ID;
- The absence of a comprehensive Digital ID Policy, subject to meaningful public consultation, which is required to address essential questions regarding the effective implementation of these regulations, particularly for unconnected citizens.
- Lack of meaningful involvement of the Information Regulator, who should play a deeper role in directing, informing and overseeing the governance architecture supporting the Regulations, assessing whether the system’s architecture meets POPIA’s requirements, and auditing the Department of Home Affairs’ compliance as the responsible party for the population register, the most sensitive personal information database in the country.
This submission ultimately argues that South Africa’s draft Digital ID Regulations are moving ahead of the policy and legislation processes that should anchor them, and calls for their suspension until the Digital Identity Policy is finalised, the National Identification and Registration Bill is properly enacted as the primary governing law, and real governance and technical safeguards are in place to protect personal data. Until then, it is unclear who the system is intended to serve, how it aligns with South Africa’s broader digital public infrastructure strategy, and what citizen-informed limitations are needed to govern its expansion with legitimacy.