There is a certain State Owned Company (SOE) that has been sending me information and enquiries related to their outstanding and ongoing accounts with a private business in Gqeberha.
Luckily for this business I am acquainted with the owner and have kindly forward these e-mails on to him for the last 10 years.
As an aside: Bru, I am so tempted to write about just how much this company owes you just from 2024 – I am sure that they are in breach of some part of the Public Finance Management Act* which stipulates a 30 day payment on presentation of invoice.
We have both tried for TEN YEARS now to get this SOE to correct their records by removing my e-mail address from my mate’s supplier account and placing his e-mail address back.
The excuse is that they cannot do so because of the way that their SAP Software programme is set up. Cue in negative marketing for SAP as well then – no wonder the wags who have been exposed to SAP’s rigid rules refer to the programme as Stop All Production. For more on how devastating an SAP implementation can be read this: SPAR: From R149.87 to R41.42 – Is the Ship Sinking?
Anyway I got to thinking that this SOE is not only engaging in very negative marketing (the pen is SUPPOSED to be mightier than the sword) but also that by continuing to send me sensitive information they may be in breach of the POPIA act. And therein lies the reason why I demur from naming this SOE, my friend or his business.
Imagine if I forwarded these messages to a competitor of my friend and got paid for doing so – the kak would hit the fan in no time.
Online opinion agrees with me that Yes, this SOE is very likely in breach of the Protection of Personal Information Act (POPIA).
How this SOE is Violating POPIA
Data Quality (Section 16): Responsible parties are legally required to take reasonably practicable steps to ensure that personal data is complete, accurate, not misleading, and updated. Failing to correct an email address after multiple notifications over 10 years directly violates this principle.
Information Security & Confidentiality (Section 19): The SOE in question must implement appropriate and reasonable technical and organizational measures to prevent the unauthorized disclosure or access to personal information. Sending sensitive financial records (invoices, statements, outstanding balances) to an unintended recipient constitutes a ongoing security breach.
Failure to Safeguard Account Data (Section 105/106): Invoices and statements often contain banking details or account numbers. Under POPIA, handling or sending account numbers to unauthorized third parties carries strict liability and potential administrative penalties.
My Choices to Stop This Violation:
Submit a Formal Section 24 Request: Download Form 2 under the POPIA regulations (Request for Correction or Deletion of Personal Information). Complete it demanding that the SOE delete/update my email address associated with my friend’s records, and send it directly to the SOE’s designated Information Officer or legal department (not general billing).
Issue an Ultimatum: State in writing that if the issue is not rectified within 14 days, you will lodge a formal complaint with the Information Regulator of South Africa.
Notify My Friend: Inform my friend in writing that you I no longer act as an informal intermediary or forward these emails, as doing so could potentially expose you to third-party privacy complications. Ask my friend to formally issue a legal demand to the SOE regarding the privacy breach of their business records.
Lodge a Complaint: If the SOE sends another statement after your formal notice, complete Form 5 (Complaint Regarding Interference with the Protection of Personal Information) on the Information Regulator’s website (inforegulator.org.za).
The Information Regulator can issue enforcement notices and administrative fines (up to R10 million) against non-compliant entities, particularly where negligence persists after written warnings.
* Governing Act: The Public Finance Management Act (PFMA)
This act is applicabile to Schedule 2 (Major Public Entities) and Schedule 3 (National and Provincial Public Entities) SOEs fall under the ambit of the PFMA.
Under Section 38(1)(f) of the PFMA, accounting officers (such as Chief Executives or Managing Directors of SOEs) have a direct, personal statutory duty to settle all contractual obligations and pay all monies owing within the prescribed or agreed period.
Pursuant to Treasury Regulation 8.2.3 (which operationalizes the PFMA framework), all payments due to creditors must be settled within 30 days of receipt of an invoice (unless otherwise specified in a formal contract or agreement).
The 30-day payment period begins when the SOE receives a valid, compliant tax invoice coupled with proper documentation (such as matching purchase order numbers and verified proof of delivery or service completion).
SOEs are required to verify supplier details against the national Central Supplier Database. Mismatches in banking details, tax clearance status, or registered company names will result in invoice rejection, which resets the 30-day payment cycle.
To combat cash-flow strangulation of small and medium enterprises (SMMEs), National Treasury has routinely issued instruction notes (such as Treasury Instruction No. 34) compelling public entities to report on their 30-day compliance metrics to oversight structures. Failure to comply constitutes financial misconduct under the PFMA.

Leave a Reply
You must be logged in to post a comment.