IRSA launches investigation into SARS over Zuma’s tax records as well CIPC.

By Lehlohonolo Lehana.

The Information Regulator South Africa (IRSA) has confirmed that it has received a complaint against SA receiver of Revenue (SARS) for disclosing the tax records of former president Jacob Zuma. 

The regulator says assessments are under way following the complaint.

IRSA’s executive for the Promotion of Access to Information Act Ntsumbedzeni Nemasisi says this is the second complaint against SARS but the first to be investigated.

Nemasisi said, “We anticipate that the matter will be finalised by May but in terms of the question as to whether the regulator has received a complaint before against SARS, yes, we have received a complaint against SARS before.”

Zuma has been credibly accused of failing to file annual tax returns while he was president.

For an individual occupying such high office, failure to do so represents a serious contravention of the law and it is the public’s right to know whether this is the case.

The tax authority previously did not describe which test it applied in determining its decision for non-disclosure, which meant the public had no idea whether the former president has ever filed annual tax returns for the years he was in office.

AmaBhungane and the Financial Mail first submitted a Promotion of Access to Information Act (Paia) request to Sars in February 2019. 

Following protracted litigation between the tax authority and these media organisations, the Constitutional Court handed down a landmark judgement in May 2023. 

The court ruled that certain provisions within the Tax Administration Act and Paia were unconstitutional in that they provided blanket protections, guaranteeing taxpayer secrecy. 

The court said there should be a “public interest override” that allows for some information to be released through mechanisms like Paia. The court also gave Parliament two years to fix the flaws in the law.

Meanwhile the regulator says it has launched an own-initiative investigation into the Companies and Intellectual Property Commission (CIPC) following a widely publicised security breach of its systems.

CIPC – an agency inside the Department of Trade, Industry, and Competition where companies, co-operatives, and intellectual property are registered – issued a notice on 29 February that its systems were compromised and the personal information of its clients and employees was exposed.

Reports received by the Regulator indicate that the threat actors that breached the CIPC systems are still in the CIPC IT environment, and the CIPC systems remain compromised,” it said.

“Another point of inquiry regarding the CIPC’s organisational and technical measures for protecting personal information will be whether the CIPC’s business model facilitates the selling and buying of personal information in its possession.”

The regulator further issued an enforcement notice to credit bureau TransUnion, giving the group until 26 May 2024 to implement remedial measures to address various failings found in a major 2022 data breach.

In March 2022, TransUnion, a registered credit bureau and a repository of credit information on consumers and businesses, submitted a section 22 notification indicating that it had suffered a security compromise.

A host of details were stolen, including names, ID numbers, contact details, vehicle finance data and other personal information.

At the time, TranUnion indicated that the breach did not take place through a systems hack or a ransomware attack. Instead, the systems were breached by the hacker group obtaining access to the TransUnion South Africa server through “misuse of an authorised client’s credentials”.

While TransUnion initially issued a statement confirming the breach had taken place, this was deemed an ‘inadequate response’ by the information regulator.

Following an investigation into the breach, the regulator found that TransUnion violated the conditions for the lawful processing of information.

TransUnion has until 26 May 2024 to submit proof to the regulator that all the remedial measures in the Enforcement Notice have been implemented, it said.

Scroll to Top