All Article Properties:
{
"access_control": false,
"status": "publish",
"objectType": "Article",
"id": "1065039",
"signature": "Article:1065039",
"url": "https://staging.dailymaverick.co.za/article/2021-10-11-beware-data-breaches-that-leak-private-information-or-be-prepared-to-face-costly-popia-class-action-lawsuits/",
"shorturl": "https://staging.dailymaverick.co.za/article/1065039",
"slug": "beware-data-breaches-that-leak-private-information-or-be-prepared-to-face-costly-popia-class-action-lawsuits",
"contentType": {
"id": "1",
"name": "Article",
"slug": "article"
},
"views": 0,
"comments": 0,
"preview_limit": null,
"excludedFromGoogleSearchEngine": 0,
"title": "Beware data breaches that leak private information — or be prepared to face costly Popia class action lawsuits",
"firstPublished": "2021-10-11 19:17:15",
"lastUpdate": "2021-10-11 19:17:15",
"categories": [
{
"id": "29",
"name": "South Africa",
"signature": "Category:29",
"slug": "south-africa",
"typeId": {
"typeId": "1",
"name": "Daily Maverick",
"slug": "",
"includeInIssue": "0",
"shortened_domain": "",
"stylesheetClass": "",
"domain": "staging.dailymaverick.co.za",
"articleUrlPrefix": "",
"access_groups": "[]",
"locale": "",
"preview_limit": null
},
"parentId": null,
"parent": [],
"image": "",
"cover": "",
"logo": "",
"paid": "0",
"objectType": "Category",
"url": "https://staging.dailymaverick.co.za/category/south-africa/",
"cssCode": "",
"template": "default",
"tagline": "",
"link_param": null,
"description": "Daily Maverick is an independent online news publication and weekly print newspaper in South Africa.\r\n\r\nIt is known for breaking some of the defining stories of South Africa in the past decade, including the Marikana Massacre, in which the South African Police Service killed 34 miners in August 2012.\r\n\r\nIt also investigated the Gupta Leaks, which won the 2019 Global Shining Light Award.\r\n\r\nThat investigation was credited with exposing the Indian-born Gupta family and former President Jacob Zuma for their role in the systemic political corruption referred to as state capture.\r\n\r\nIn 2018, co-founder and editor-in-chief Branislav ‘Branko’ Brkic was awarded the country’s prestigious Nat Nakasa Award, recognised for initiating the investigative collaboration after receiving the hard drive that included the email tranche.\r\n\r\nIn 2021, co-founder and CEO Styli Charalambous also received the award.\r\n\r\nDaily Maverick covers the latest political and news developments in South Africa with breaking news updates, analysis, opinions and more.",
"metaDescription": "",
"order": "0",
"pageId": null,
"articlesCount": null,
"allowComments": "1",
"accessType": "freecount",
"status": "1",
"children": [],
"cached": true
}
],
"content_length": 6559,
"contents": "<span style=\"font-weight: 400;\">Globally, class actions are starting to gather pace in the wake of breaches of data privacy laws. Following the introduction of Popia in July this year, South Africa is likely to follow suit, especially since the groundwork on class actions has been laid in the mining and retail sectors in the past few years.</span>\r\n\r\n<span style=\"font-weight: 400;\">In the US, Google recently faced a $5-billion class-action lawsuit for tracking the browsing history of users who chose the “incognito” mode. In the UK, a class action is under way, relating to the hacking of the Marriott Hotel chain’s global database in September 2018. This action is being brought on behalf of hotel residents from England and Wales.</span>\r\n\r\n<span style=\"font-weight: 400;\">In South Africa, there are two potential areas of litigation for a data breach under Popia. The first is that the party liable for the data breach may have to argue its case before the Information Regulator. The second is that the responsible party may face a civil action.</span>\r\n\r\n<span style=\"font-weight: 400;\">Section 99 (1) of Popia states that: “A data subject or, at the request of the data subject, the Regulator, may institute a civil action for damages in a court having jurisdiction against a responsible party for breach of any provision of this Act… whether or not there is intent or negligence on the part of the responsible party.”</span>\r\n\r\n<span style=\"font-weight: 400;\">This means strict liability applies, and the potential defences are limited. These are: extraneous events beyond the control of the responsible party; consent of the plaintiff; fault on the part of the plaintiff; if compliance was not reasonably practicable in this context; or if the regulator granted an exemption under Section 37 (for example, where the public interest in the processing outweighs, to a substantial degree, any interference with the privacy of the data subject that could result from such processing).</span>\r\n\r\n<span style=\"font-weight: 400;\">Under Section 99 (3), the courts can award any amount that is “just and equitable”, including damages as compensation for patrimonial and non-patrimonial loss; aggravated damages; interest; and costs of suit.</span>\r\n\r\n<span style=\"font-weight: 400;\">This is a big deal. It means that the Information Regulator can extract damages from the responsible party even if it is not negligent (eg where a data breach occurs).</span>\r\n\r\n<span style=\"font-weight: 400;\">We think it is only a matter of time before we see the first class action brought under Popia for a data breach. In South Africa, there have already been some high-profile cases involving the release of personal information of millions of data subjects. Class actions have also been gathering pace after the successful silicosis action brought against a group of gold mining companies on behalf of workers who contracted the occupational disease, and the listeriosis action brought against Tiger Brands.</span>\r\n\r\n<span style=\"font-weight: 400;\">In the leading class action case, involving Pioneer Foods (Pty) Ltd, the Supreme Court of Appeal set out the factors that should be weighed in deciding whether to certify a class action. Certification essentially involves bringing an application before a court for a decision on whether a class action is a suitable avenue for addressing the issues at hand. In the absence of certification, a class action will not be able to proceed to the trial stage.</span>\r\n\r\n<span style=\"font-weight: 400;\">Some of the factors that the court will consider include the existence of a class identifiable by reference to objective criteria; whether the proposed class representative is suitable to conduct the action and represent the class; a cause of action raising a triable issue; issues of fact or law common to all members of the class; and that a class action is the most appropriate means by which the claims of the class may be determined. </span>\r\n\r\n<span style=\"font-weight: 400;\">The Constitutional Court has, however, left open the question of whether prior certification for a class action is even necessary in a case involving a fundamental right, such as the right to privacy.</span>\r\n\r\n<span style=\"font-weight: 400;\">Any potential class action within the context of Popia could be expected to follow a procedure requiring potential plaintiffs to contact legal representatives to “opt in”. This would be in response to the inevitable challenges which would arise in the gathering of evidence. The vast spectrum of affected data subjects would make an “opt-in” process the most practical choice. The alternative would be an “opt-out” process, whereby potential plaintiffs are automatically bound by the outcome of the judgment if they fail to indicate their objection by a set date.</span>\r\n\r\n<span style=\"font-weight: 400;\">Class actions scare companies, as the US experience shows. In the Google breach, app developers had obtained access to the profile information of users through what was described as a series of “software glitches”. This information included names, birth dates, home towns, addresses, locations, email addresses, photos and videos. Following notice being given to the data subjects, the class action lawsuit elicited a tender of settlement from Google. Subsequent to approval from the California district court, a settlement of about $7.5-million was paid over to the plaintiffs.</span>\r\n\r\n<span style=\"font-weight: 400;\">In the Marriott class action, the personal information of almost half a billion guests was compromised between 2014 and 2018. This information included passport and credit card numbers that had been hacked from the reservation systems of a number of hotels. The result was the launch of 11 different class-action lawsuits against Marriott, which were eventually consolidated into a single claim. This matter is still ongoing, but the sheer size of the affected class signals the possibility of a large eventual settlement.</span>\r\n\r\n<span style=\"font-weight: 400;\">One issue that could inhibit class actions for data breaches in South Africa is the history of modest claims being awarded by courts for non-patrimonial loss. For example, in the case of the naming of three HIV-positive women in a biography of politician Patricia de Lille by Charlene Smith, published by New Africa Books, the Constitutional Court awarded R35,000 in damages to each of the plaintiffs in 2007. Fifteen years later, that award would be about R75,000 — still a paltry sum when someone has had their HIV status revealed without their consent.</span>\r\n\r\n<span style=\"font-weight: 400;\">But if a similar award — and on top of it aggravated damages — were to be made in a case involving a few million plaintiffs brought together in a class action for a data breach (eg where bank account details are unlawfully accessed), it could be very costly for the responsible party.</span>\r\n\r\n<span style=\"font-weight: 400;\">One way or the other, this is certainly an area of the law that will see rapid development in the near future. Fasten your seatbelts. </span><b>DM</b>\r\n\r\n<i><span style=\"font-weight: 400;\">Dario Milo, Pooja Dela, Kenan Petersen and Daniella Ghillino are with law firm Webber Wentzel.</span></i>",
"teaser": "Beware data breaches that leak private information — or be prepared to face costly Popia class action lawsuits",
"externalUrl": "",
"sponsor": null,
"authors": [
{
"id": "244153",
"name": "Dario Milo, Pooja Dela, Kenan Petersen and Daniella Ghillino",
"image": "",
"url": "https://staging.dailymaverick.co.za/author/dario-milo-et-al/",
"editorialName": "dario-milo-et-al",
"department": "",
"name_latin": ""
}
],
"description": "",
"keywords": [
{
"type": "Keyword",
"data": {
"keywordId": "7349",
"name": "Listeriosis",
"url": "https://staging.dailymaverick.co.za/keyword/listeriosis/",
"slug": "listeriosis",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Listeriosis",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "7924",
"name": "Tiger Brands",
"url": "https://staging.dailymaverick.co.za/keyword/tiger-brands/",
"slug": "tiger-brands",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Tiger Brands",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "8757",
"name": "Google",
"url": "https://staging.dailymaverick.co.za/keyword/google/",
"slug": "google",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Google",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "23175",
"name": "Constitutional Court",
"url": "https://staging.dailymaverick.co.za/keyword/constitutional-court/",
"slug": "constitutional-court",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Constitutional Court",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "74082",
"name": "Pioneer Foods",
"url": "https://staging.dailymaverick.co.za/keyword/pioneer-foods/",
"slug": "pioneer-foods",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Pioneer Foods",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "193224",
"name": "Popia",
"url": "https://staging.dailymaverick.co.za/keyword/popia/",
"slug": "popia",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Popia",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "360182",
"name": "class action lawsuits",
"url": "https://staging.dailymaverick.co.za/keyword/class-action-lawsuits/",
"slug": "class-action-lawsuits",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "class action lawsuits",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "360183",
"name": "Marriot",
"url": "https://staging.dailymaverick.co.za/keyword/marriot/",
"slug": "marriot",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "Marriot",
"translations": null
}
},
{
"type": "Keyword",
"data": {
"keywordId": "360184",
"name": "data breaches",
"url": "https://staging.dailymaverick.co.za/keyword/data-breaches/",
"slug": "data-breaches",
"description": "",
"articlesCount": 0,
"replacedWith": null,
"display_name": "data breaches",
"translations": null
}
}
],
"short_summary": null,
"source": null,
"related": [],
"options": [],
"attachments": [
{
"id": "97798",
"name": "",
"description": "",
"focal": "50% 50%",
"width": 0,
"height": 0,
"url": "https://dmcdn.whitebeard.net/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg",
"transforms": [
{
"x": "200",
"y": "100",
"url": "https://dmcdn.whitebeard.net/i/Y4TsCdJ-pse2fufbHnSfb_K-Veg=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg"
},
{
"x": "450",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/k9J_0ZYPkqN-9gi8zI6ASXVbFfA=/450x0/smart/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg"
},
{
"x": "800",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/shijY0ZPXxr-cgkLhdSgsAJv56s=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg"
},
{
"x": "1200",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/NZsNTnapls2akxGibYhXHIvVZJI=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg"
},
{
"x": "1600",
"y": "0",
"url": "https://dmcdn.whitebeard.net/i/CvR-sbTUHd88x-3GXTmCt_mWVDI=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg"
}
],
"url_thumbnail": "https://dmcdn.whitebeard.net/i/Y4TsCdJ-pse2fufbHnSfb_K-Veg=/200x100/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg",
"url_medium": "https://dmcdn.whitebeard.net/i/k9J_0ZYPkqN-9gi8zI6ASXVbFfA=/450x0/smart/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg",
"url_large": "https://dmcdn.whitebeard.net/i/shijY0ZPXxr-cgkLhdSgsAJv56s=/800x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg",
"url_xl": "https://dmcdn.whitebeard.net/i/NZsNTnapls2akxGibYhXHIvVZJI=/1200x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg",
"url_xxl": "https://dmcdn.whitebeard.net/i/CvR-sbTUHd88x-3GXTmCt_mWVDI=/1600x0/smart/filters:strip_exif()/file/dailymaverick/wp-content/uploads/2021/10/Oped-Milo-PopiaTW.jpeg",
"type": "image"
}
],
"summary": "Class actions caused by breaches of the Protection of Personal Information Act (Popia) are likely to emerge in South Africa in the next few years, and they could be costly for companies.",
"template_type": null,
"dm_custom_section_label": null,
"elements": [],
"seo": {
"search_title": "Beware data breaches that leak private information — or be prepared to face costly Popia class action lawsuits",
"search_description": "<span style=\"font-weight: 400;\">Globally, class actions are starting to gather pace in the wake of breaches of data privacy laws. Following the introduction of Popia in July this year, South Africa is",
"social_title": "Beware data breaches that leak private information — or be prepared to face costly Popia class action lawsuits",
"social_description": "<span style=\"font-weight: 400;\">Globally, class actions are starting to gather pace in the wake of breaches of data privacy laws. Following the introduction of Popia in July this year, South Africa is",
"social_image": ""
},
"cached": false,
"access_allowed": true
}