Unique Identifiers and Secondary Purposes: A Growing Compliance Risk

A growing compliance risk when unique identifiers are used for secondary purposes

One of the four triggers for prior authorisation under the Protection of Personal Information Act (POPIA) concerns the processing of unique identifiers. A responsible party must obtain authorisation from the Information Regulator before processing any unique identifier of a data subject for a purpose other than the one for which it was specifically collected, where the aim is to link that information with information processed by other responsible parties.

This requirement is increasingly relevant. Digital systems routinely collect identifiers for one purpose and later reuse them for another. When that reuse involves linking data across organisations or systems, the prior authorisation obligation is likely to apply.

What counts as a unique identifier

A data subject is considered identified when they can be distinguished from others within a group. Unique identifiers are the data elements that make this possible. They include:

The list is illustrative rather than exhaustive. Any data element or combination of elements that enables a person to be singled out can function as a unique identifier.

Secondary purposes and linking

The obligation is triggered when two conditions are met. First, the identifier is processed for a purpose different from the one for which it was originally collected. Second, the processing aims to link the information with data processed by other responsible parties.

Common examples include:

Many of these activities are now routine in digital and AI-supported environments. The fact that they are common does not remove the legal requirement. Where the conditions in Section 57 are met, prior authorisation is required before the processing may begin.

Safeguards and accountability

Where authorisation is granted, the unique identifier may only be processed under appropriate safeguards. This reinforces the need for a proper Personal Information Impact Assessment before the application is submitted. The assessment should examine the original purpose of collection, the new purpose, the nature of the linking involved, the risks to data subjects, and the measures that will be put in place to protect the information.

From a governance perspective, this category of processing carries particular weight under King V. Boards are expected to oversee the use of data and technology with clear accountability. Systems that reuse identifiers for secondary purposes and link them across sources often involve higher privacy risk. Evidence that these activities have been identified, assessed and, where required, submitted for prior authorisation supports the demonstration of responsible oversight.

Practical implications

Organisations that rely on digital platforms, AI systems, biometric tools or cross-organisational data sharing need to examine their processing activities carefully against this requirement. The question is not only whether an identifier is being used, but whether it is being used for a new purpose and with the intention of linking it to other information.

Failure to obtain prior authorisation where it is required constitutes an offence. Continuing to process after notification but before the Regulator has completed its investigation is also an offence. Both carry the possibility of fines, imprisonment or administrative penalties.

The reuse of unique identifiers is a defining feature of modern data processing. POPIA treats certain forms of that reuse as sufficiently significant to require advance scrutiny by the Regulator. Organisations that recognise this early, and that support their applications with thorough impact assessments, are better placed to meet the requirement and to manage the associated risks.