A juristic or legal person is a non-human entity, such as a corporation, that the law recognises as having many (if not all) of the legal rights and duties of a human being. Data protection is the area of law that controls how organisations, businesses and the government use the personal information of data subjects and safeguard it against loss or compromise. The data protection laws of most jurisdictions do not extend privacy rights to juristic persons as data subjects. However, certain countries have done so in some circumstances — for example, both Austria and Switzerland have done so on a case-by-case basis. However, South African lawmakers have done so explicitly at a legislative level for all juristic persons in the Protection of Personal Information Act. What does this extension mean for South Africans? What could we see coming out of this aspect of South African data protection law in the future? Let’s discuss possible answers to these questions.
Juristic persons are more protected in South Africa
Juristic persons can take advantage of additional protections in terms of South African data protection law. For example, they theoretically have access to the same right to make data subject access requests as human beings do. This means that your suppliers or contractors who are juristic persons could potentially contact your organisation and ask you to give them access to any personal information that you have about them. They would then have the right to ask for that information to be erased or restricted if you no longer have a purpose to process it, such as for example if your supplier or contractor relationship with them has come to an end, and you may be obliged to do so — in certain circumstances where you cannot otherwise justify the need to retain the data. They will certainly have the right to ask you to update that personal information to the extent that it is out-of-date or otherwise inaccurate. This means that you may need to develop processes or systems, such as contact centres with relevant scripts or supplier or contractor portals, for these juristic persons to exercise their data subject access rights.
Juristic persons may have too much protection in terms of South African data protection law
In our law, we typically see a distinction between the rights and remedies available to juristic persons and human beings. For example, South Africa’s consumer protection legislation classifies a ‘consumer’ as someone with an annual turnover or asset value below a certain relatively low threshold. Most ‘consumers’ are therefore human beings and not juristic persons (although some smaller juristic persons are classified as ‘consumers’). This is justifiable on the basis that ‘consumers’ as the legislation defines them are a vulnerable class of person, subject to abuse by the suppliers of goods or services if the law does not afford them this special status and additional protections. In contrast, South African consumer protection law effectively deems larger juristic persons big enough to look after themselves in terms of their own contractual negotiations without the need for the law to help them.
This trend goes against what we see in the South African realm of data protection where juristic persons are seemingly afforded the same protections as human beings. Looking at comparative case studies from other jurisdictions makes it clear that juristic persons cannot have exactly the same rights of human beings (for example, they do not have physical bodies from which personal information relating to health and sex life originates), however, South African data protection law certainly gives them access to a whole suite of tools not usually available to them. Juristic persons in other jurisdictions typically have to rely on other areas of law, notably intellectual property and competition law. The one fear is that the South African legislature may have gone too far in extending privacy rights to juristic persons under POPIA and inadvertently equipped corporations to weaponise their privacy rights against each other in a way that they wouldn’t be able to under other data protection laws.
The application of data protection law to juristic persons in South Africa may help develop robot and AI law
Some believe that we are living through, or at least on the cusp, of the next industrial revolution which will culminate in the emergence of increasingly sophisticated robotics and true artificial intelligence (AI). If and when this happens, it will likely be challenging for our existing laws to handle the business and organisational paradigms that will emerge. For example, would it be possible or advisable for an AI to have personal information necessary of protection in the same way as a human being? Should it be necessary to comply with data protection laws when engaging in the surveillance of a robotic workforce in the same way as with a group of human workers? The answers to these or similar questions will no doubt emerge in time, but the application of South African data protection law to juristic persons may set the foundation for robot and AI law in South Africa. Both juristic persons and robots or AIs are effectively non-human persons and it may be useful to draw some parallels between the two.
Unintended benefits
While it is clear that juristic persons are more protected in terms of South African data protection law, time will tell whether they have too much protection. There will hopefully be regulatory guidance on this issue from the relevant supervisory authorities and case law on the topic in the future, but until then — robot and AI law in South Africa may benefit from the decision by South African lawmakers to extend privacy rights to juristic persons. We’ll see whether this quirk of South African data protection law may bear fruit down the line.