Processing Information on Criminal or Objectionable Conduct

Processing information on criminal or objectionable conduct and when authorisation is required

The second category of processing that requires prior authorisation under the Protection of Personal Information Act (POPIA) concerns information relating to criminal behaviour or to unlawful or objectionable conduct. A responsible party must obtain authorisation from the Information Regulator before processing such information on behalf of third parties.

This includes, but is not limited to, any reference check pertaining to past conduct or disciplinary action taken against a data subject. The requirement reflects the sensitivity of this type of information and the potential impact it can have on individuals’ opportunities, reputations and rights.

Scope of the requirement

The obligation applies when the processing is carried out on behalf of third parties. Typical examples include:

Not every examination of a person’s background will fall within this category. The key elements are that the information relates to criminal behaviour or unlawful or objectionable conduct, and that the processing is performed on behalf of third parties. Where these conditions are met, prior authorisation is required before the processing may begin.

It is also important to note related legal constraints. For example, the South African Police Service Act restricts certain forms of criminal record enquiry that are not conducted for law enforcement purposes. Responsible parties must consider both POPIA and any other applicable legislation when assessing these activities.

Why this category carries heightened risk

Information about criminal behaviour or past misconduct can significantly affect a data subject’s ability to obtain employment, secure contracts, access services or maintain their reputation. Because the consequences of inaccurate, outdated or unfairly processed information can be severe, the law requires the Information Regulator to examine such processing in advance.

This is particularly relevant in sectors that rely on background screening, fraud prevention or risk assessment. As digital systems and artificial intelligence tools are increasingly used to support these functions — for example, through automated screening, pattern detection or cross-referencing of records — the volume and speed of such processing can increase. The underlying legal requirement remains the same: where the processing falls within Section 57, prior authorisation is needed.

The role of the Personal Information Impact Assessment

A thorough Personal Information Impact Assessment is especially important in this context. The Regulator will investigate the lawfulness of the proposed processing. The assessment should therefore examine the purpose of the processing, the necessity of the information being used, the accuracy and relevance of the data, the safeguards in place, and the impact on data subjects. Weak or incomplete assessments increase the risk that an application will be delayed or refused.

Governance considerations

From a governance perspective, this category of processing aligns with the expectations set out in King V. Boards are required to oversee data and technology risks with appropriate accountability. Processing that involves information about criminal or objectionable conduct is, by its nature, sensitive. Evidence that such activities have been properly identified, assessed and submitted for prior authorisation where required contributes to the demonstration of responsible oversight.

Consequences of non-compliance

Proceeding with this type of processing without the required authorisation is an offence. Continuing to process after notification but before the Regulator has completed its investigation is also an offence. Both can attract fines, imprisonment of up to 12 months, or administrative fines of up to R10 million. Non-compliance with a statement issued by the Regulator after investigation carries even more serious potential penalties.

Organisations that conduct reference checks, fraud prevention activities or related screening on behalf of others need to examine these processes carefully against the requirements of Section 57. Where the conditions are met, prior authorisation is not optional. It is a legal prerequisite, and one that should be supported by a clear and well-documented assessment of the privacy risks involved.