The limits of consent in South African data protection law

  • 0

Abstract

The Protection of Personal Information Act 4 of 2013 (POPIA) represents South Africa’s primary legislative framework for the protection of personal information and gives effect to the constitutional right to privacy. Although POPIA recognises several lawful grounds for processing personal information, consent has assumed a particularly prominent role in both public discourse and organisational compliance practices. Consent is often portrayed as the central mechanism through which individuals exercise control over their personal information and safeguard their privacy interests. This article questions that assumption. It argues that while consent occupies an important place within POPIA’s normative framework, its practical ability to protect data subjects is significantly constrained by both cognitive limitations and the socio-technical realities of contemporary South African digital life.

The article begins by examining the historical and conceptual foundations of POPIA’s consent framework. It traces the origins of the legislation to the South African Law Reform Commission (SALRC) Project 124 on Privacy and Data Protection and demonstrates how the Commission drew heavily on constitutional jurisprudence that linked privacy to autonomy, dignity, and self-determination. Consent emerged within this framework as a mechanism through which informational self-determination could be exercised. At the same time, the SALRC recognised that privacy is not absolute and must be balanced against competing public and private interests.

The article demonstrates that POPIA’s approach to consent was strongly influenced by international data protection instruments, particularly the 1981 Organisation for Economic Cooperation and Development’s Guidelines Governing the Protection of Privacy and Transborder Data Flows of Personal Data, the Council of Europe 1980 Convention for the Protection of Individuals with regard to the Automatic Processing of Personal Data, and the European Union Data Protection Directive 95/46/EC. As a result, POPIA inherited many of the assumptions underlying earlier European data protection models, including the belief that individuals are capable of exercising meaningful control over personal information through informed decision-making. While these assumptions were already being questioned internationally by the time POPIA was enacted, they remain embedded within South Africa’s legislative framework.

This study then undertakes a doctrinal analysis of POPIA’s consent provisions. Section 11 identifies consent as one of several lawful grounds for processing personal information, alongside contractual necessity, legal obligations, legitimate interests, and public law duties. POPIA defines consent as a “voluntary, specific and informed expression of will” through which permission is granted for processing. Although the definition appears conceptually robust, each of its constituent requirements rest on assumptions that become increasingly difficult to sustain in modern digital environments.

A voluntary act requires that individuals have genuine freedom to refuse consent without suffering detriment. Specificity requires consent to relate to clearly defined processing purposes. Informed consent presupposes that individuals understand what they are agreeing to, while the requirement of an expression of will demands some affirmative indication of agreement. The article demonstrates that these requirements mirror international standards and reflect a strong commitment to informational autonomy. However, it argues that the practical conditions necessary to achieve these ideals are frequently absent.

The first major challenge identified by the article arises from cognitive and behavioural limitations. Drawing on behavioural decision-making literature, the article argues that POPIA’s consent model assumes an idealised version of human decision-making that does not reflect how individuals actually interact with digital technologies. Individuals operate under conditions of bounded rationality, characterised by limited time, attention, and cognitive capacity. Modern data processing practices are highly complex, often involving secondary uses of data, algorithmic decision-making, cross-border transfers, and opaque processing ecosystems that are difficult even for sophisticated users to understand.

Faced with these complexities, individuals rely on heuristics and cognitive shortcuts rather than careful deliberation. Decisions about privacy are frequently influenced by factors such as brand familiarity, institutional trust, or perceived convenience rather than detailed assessments of data processing practices. The article argues that these behavioural realities undermine the assumption that consent reliably reflects informed and autonomous choice.

These problems are compounded by consent fatigue. Individuals encounter countless consent requests across digital platforms and services. Repeated exposure to consent notices encourages habituation and disengagement, leading users to accept requests automatically rather than evaluate them critically. In such circumstances, consent becomes a routine procedural act rather than a meaningful exercise of self-determination.

The article further highlights the role of behavioural influences such as default settings and choice architecture. Digital interfaces are frequently designed in ways that steer users toward acceptance through prominent “accept” options, complex refusal processes, and strategically structured interfaces. Although users technically retain the ability to refuse consent, the architecture of decision-making environments strongly encourages acceptance. Consequently, formal legal choice often masks substantial behavioural manipulation.

The second major challenge explored by the article concerns the structural realities of the South African digital environment. The effectiveness of consent depends on individuals possessing meaningful alternatives and genuine bargaining power. However, South Africa’s socio-economic conditions often undermine these prerequisites.

Persistent digital inequality remains a defining feature of South African society. While internet penetration has increased significantly, substantial disparities remain in access, affordability, digital literacy, and quality of connectivity. Many individuals rely exclusively on mobile internet access and operate within resource-constrained environments where engaging with lengthy privacy disclosures is impractical. Digital literacy deficits further weaken the ability of individuals to understand and evaluate data processing practices.

The article also examines growing platform dependency. Access to communication, employment opportunities, education, commerce, and social participation increasingly depends on a small number of dominant digital platforms. For many users, participation in digital life requires accepting extensive data collection practices. In these circumstances, refusal is often not a realistic option. Consent becomes formally available but substantively meaningless because declining processing may effectively exclude individuals from essential social and economic activities.

State datafication presents an additional challenge. The article highlights the increasing use of biometric systems, digital identity verification, and data-driven public administration within South Africa. Access to welfare benefits, public services, financial products, and identity verification increasingly requires the surrender of personal information. Here, consent becomes particularly problematic because individuals cannot realistically opt out without forfeiting access to essential services. While POPIA contains alternative lawful grounds that better justify such processing, the continued dominance of consent discourse obscures the reality that many forms of data processing are effectively unavoidable.

Against this backdrop, the article argues that consent should no longer be viewed as the primary safeguard within South African data protection law. Instead, greater emphasis should be placed on institutional accountability, transparency, and structural regulation. POPIA already contains a comprehensive accountability framework, including obligations relating to purpose limitation, information quality, security safeguards, openness, and data subject participation. However, the effectiveness of these mechanisms depends on robust enforcement and institutional oversight.

The article concludes that South Africa’s data protection framework would be strengthened by shifting its regulatory focus away from individualised consent and toward stronger accountability obligations on responsible parties. This includes enhancing the capacity of the Information Regulator, improving transparency mechanisms, and ensuring meaningful enforcement of existing legal duties. Consent should remain available where genuine choice exists, but it should be regarded as a supplementary safeguard rather than the central mechanism through which privacy and informational self-determination are protected. Such an approach would better reflect the realities of contemporary digital life and more effectively advance the constitutional values that underpin South African data protection law.

Keywords: behavioural decision-making; consent; data protection law; digital governance; digital inequality; information privacy; informational self-determination; lawful basis for processing; Protection of Personal Information Act (POPIA)

 

  • This article’s featured image was created by Ron Lach and obtained from Pexels.

 

Lees die volledige artikel in Afrikaans

Die beperkings van toestemming in die Suid-Afrikaanse inligtingsbeskermingsreg

  • 0

Reageer

Jou e-posadres sal nie gepubliseer word nie. Kommentaar is onderhewig aan moderering.


 

Top