Unlawful acts by responsible party in connection with account number
(1) A responsible party who contravenes the provisions of section 8 insofar as those provisions relate to the processing of an account number of a data subject is, subject to subsections (2) and (3), guilty of an offence.
(2) The contravention referred to in subsection (1) must— (a) be of a serious or persistent nature; and (b) likely cause substantial damage or distress to the data subject.
(3) The responsible party must— (a) have known or ought to have known that— (i) there was a risk that the contravention would occur; or (ii) such contravention would likely cause substantial damage or distress to the data subject; and (b) have failed to take reasonable steps to prevent the contravention.
(4) Whenever a responsible party is charged with an offence under subsection (1), it is a valid defence to such a charge to contend that he or she has taken all reasonable steps to comply with the provisions of section 8.
(5) ‘‘Account number’’, for purposes of this section and section 106, means any unique identifier that has been assigned— (a) to one data subject only; or (b) jointly to more than one data subject, by a financial or other institution which enables the data subject, referred to in paragraph (a), to access his, her or its own funds or to access credit facilities or which enables a data subject, referred to in paragraph (b), to access joint funds or to access joint credit facilities.
What this means for your estate
- This is squarely relevant to levy and payment administration, “account number” (subsection (5)) covers bank account and credit facility identifiers, meaning mishandled levy payment details or a PayFast/bank integration gone wrong can trigger this section, not just card fraud in the abstract.
- Subsection (4)'s defence is the practical takeaway: having taken “all reasonable steps to comply with” s.8 (Accountability) is a valid legal defence here, which is one more reason documented accountability isn't just a governance nicety.
PopiGuard's Task Manager documents the “reasonable steps” subsection (4) asks for, building the defence before you'd ever need it.