The Cybercrimes Act 19 of 2020 is South Africa’s primary legislation for combating cybercrime. The Act was signed into law in June 2021 and most of it commenced on 1 December 2021. It replaces outdated provisions in the Electronic Communications and Transactions Act (ECTA) and provides a modern, comprehensive framework for addressing cyber-related offences.

One point is worth making at the outset: the Act was brought into force in stages, and several parts of it have still not been proclaimed. Knowing which provisions are actually operative matters as much as knowing what the Act says.

Offences Under the Cybercrimes Act

Part I of Chapter 2 creates the core cybercrimes:

  • Unlawful access to a computer system or data, commonly referred to as hacking (section 2);
  • Unlawful interception of data (section 3);
  • Unlawful acts in respect of software or hardware tools, which covers the distribution of malware and hacking tools (section 4);
  • Unlawful interference with data or a computer program (section 5), and with a computer data storage medium or computer system (section 6);
  • Unlawful acquisition, possession, provision, receipt or use of a password, access code or similar device (section 7);
  • Cyber fraud — unlawful and intentional misrepresentation through a computer system to obtain a benefit (section 8);
  • Cyber forgery and uttering (section 9);
  • Cyber extortion (section 10);
  • Theft of incorporeal property, for example data or digital assets (section 12).

Section 11 provides for aggravated offences, which apply where the conduct is directed at restricted computer systems or critical infrastructure and which attract heavier sentences.

Malicious communications

Part II of Chapter 2 deals separately with harmful data messages. It is an offence to send a data message inciting damage to property or violence (section 14), to send a data message threatening a person with damage to property or violence (section 15), and to disclose a data message containing an intimate image of a person without their consent (section 16), the offence often described as “revenge porn”. All three of these offences are in force.

There is, however, an important gap. Part VI of Chapter 2 — sections 20 to 23 — creates the machinery of protection orders for victims of malicious communications. It provides for a court to make an order protecting a complainant while criminal proceedings are pending, to compel an electronic communications service provider to disclose the identifying details of the sender, and to make orders on the conclusion of proceedings. Part VI has not yet been proclaimed into force. In practice this means a victim can lay a criminal charge under section 16, but cannot yet rely on the Act’s own statutory order to compel removal of the material or identification of the sender, and must instead pursue the ordinary remedies available in the High Court or under the Protection from Harassment Act 17 of 2011.

Investigation and Prosecution

Chapter 4 of the Act is headed “Powers to investigate, search, access or seize”. It empowers the South African Police Service (SAPS) to investigate cybercrimes, including provisions for the search and seizure of electronic evidence and the issuing of preservation-of-evidence directions. Designated SAPS members receive specialised training to handle these cases, and courts may issue orders compelling electronic communications service providers to assist with investigations.

Parts of Chapter 4 remain unproclaimed, including sections 41 to 44 and portions of sections 38 and 40. Chapter 5, which deals with mutual assistance between South Africa and foreign states, and Chapter 6, which establishes the designated 24/7 point of contact for international cybercrime cooperation, have not commenced at all. Cross-border cooperation therefore still runs through the existing mutual legal assistance framework rather than through the Act.

Penalties

Penalties under the Cybercrimes Act vary depending on the severity of the offence and can include substantial fines, imprisonment, or both. For the more serious offences, such as cyber extortion or the aggravated offences involving critical infrastructure, the penalties are correspondingly heavier.

Reporting Obligations

The reporting duty is created by section 54, which sits in Chapter 8 of the Act (“Reporting obligations and capacity building”). Section 54 requires an electronic communications service provider or financial institution that becomes aware that its service or network is involved in the commission of a prescribed category of offence to:

  • report the offence to the SAPS in the prescribed form and manner, without undue delay and, where feasible, not later than 72 hours after becoming aware of it; and
  • preserve any information that may assist the SAPS in investigating the offence.

Failure to comply is itself an offence, carrying a fine of up to R50 000. Section 54 does not impose a general surveillance duty: a provider is not required to monitor the data it transmits or stores, or to actively seek out facts indicating unlawful activity. Financial sector regulators and the South African Reserve Bank are excluded from the duty.

Section 54 has still not been proclaimed into force. Its commencement date remains one to be fixed by the President, and it was expressly excluded from the December 2021 commencement. Until that proclamation is issued, the 72-hour reporting duty and the R50 000 penalty are not yet operative. Businesses in the affected sectors would nonetheless be well advised to build the reporting capability now, since commencement can follow a proclamation at short notice, and separate breach-notification duties already apply under POPIA.

The Cybercrimes Act and Data Protection

The Cybercrimes Act works alongside the Protection of Personal Information Act (POPIA) to protect South Africans in the digital space. While POPIA regulates how organisations collect, process, and store personal information, the Cybercrimes Act criminalises the unlawful access to or interference with that information.

The two statutes can be triggered by a single incident. A ransomware attack that exfiltrates customer records may constitute offences under sections 2, 5 and 10 of the Cybercrimes Act while simultaneously obliging the responsible party to notify the Information Regulator and the affected data subjects under section 22 of POPIA. That POPIA notification duty is in force now and is independent of whether section 54 has been proclaimed. For businesses, understanding both laws is essential — read more in our article on data protection law in South Africa and our guide to the application of POPIA in the workplace.

In conclusion, the Cybercrimes Act 19 of 2020 gives South Africa a modern legal framework for addressing cybercrime, and the substantive offences it creates are fully enforceable today. What remains outstanding is largely procedural and institutional: the private-sector reporting duty, the protection-order machinery for victims of malicious communications, and the international cooperation architecture. As those provisions are proclaimed, the practical reach of the Act will expand considerably.


Reviewed 18 August 2026 — Corrected the location of the reporting duty, which is created by section 54 in Chapter 8 and not by Chapter 4, and set out its terms: a 72-hour reporting window to the SAPS, a duty to preserve information, a maximum R50 000 fine, no general monitoring obligation, and an exclusion for financial sector regulators and the Reserve Bank. Confirmed section 54 remains unproclaimed, added the statutory section numbers for each offence, and added that the section 20 to 23 protection orders for victims of malicious communications, parts of Chapter 4, and Chapters 5 and 6 are likewise not yet in force.