Litigation may require parties to disclose documents, but that does not give them carte blanche to collect, process and share personal information. South Africa’s discovery rules and the Protection of Personal Information Act (“POPIA”) must operate alongside one another and getting that balance wrong can create regulatory risk even while complying with court procedures.
In any civil litigation process, parties are expected to lay their cards on the table by producing relevant documents and allowing the court to adjudicate on the full evidentiary record. However, since POPIA became fully operational, litigants have had to confront a question their European counterparts have grappled with for over a decade: how does one reconcile the breadth of discovery obligations with the discipline of data protection?
The answer is not that one regime displaces the other: POPIA does not create a blanket bar to civil discovery; nor do the Rules of Court displace data protection. Rather, data privacy law constrains how discovery is conducted, requiring proportionality in every step of personal data processing.
Discovery and POPIA in a nutshell: the balance between disclosure and data protection
Discovery is a process in the High Court and Magistrates’ Court requiring parties to disclose relevant documents by sworn affidavit. Parties may request the production of specific documents and access to discovered documents. Non-compliance can result in the court mandating compliance, adverse costs, or exclusion of undisclosed documents at trial.
POPIA regulates how organisations process personal information. Although courts are exempt in respect of their judicial functions, litigants are not. Discovery invariably involves processing personal information and POPIA’s conditions for lawful processing therefore apply.
Common pitfalls and how to prevent them
There are a number of common data-related errors we see in practice. The first of these is failing to identify and record the lawful basis relied on for discovery-related processing of personal information. If later challenged, the responsible party may be unable to demonstrate lawful processing.
For purposes of discovery, the most appropriate legal basis - as recognised by the High Court - is compliance with a legal obligation. For special personal information - such as health, biometric or criminal data - POPIA permits processing where it is necessary for the establishment, exercise or defence of a right or obligation in law. In De Jager v Netcare Limited, the court confirmed that surveillance evidence constituting special personal information was lawfully obtained under this provision.
Legitimate interests may serve as an alternative basis but cannot be used for processing special personal information. Consent is generally ill-suited to discovery, given its strict validity requirements and the risk of withdrawal.
Overbroad discovery requests and a failure to define the purpose of litigation are the second common pitfall. POPIA requires that personal information may only be processed for a specific, explicitly defined and lawful purpose; and that processing is adequate, relevant and not excessive given its purpose. Accordingly, without a defined litigation purpose, a discovery request cannot satisfy this minimality threshold.
A common mistake is requesting "all documents" without adequate limitation. Where a request cannot be linked to a defined purpose, it is vulnerable to objections of excessiveness. Requests should be framed with reference to the essential facts; and the litigation purpose articulated with sufficient precision to satisfy the aforementioned POPIA requirements.
Where personal information originally collected for other purposes is sought for discovery, further processing must be addressed.
POPIA restricts collection from third-party sources except where collection is necessary for the conduct of proceedings in any court or tribunal that has commenced or is reasonably contemplated. A common error is assuming that litigation automatically authorises collection from any source. Litigants should document the basis on which the exception applies and limit collection to what is necessary for the proceedings.
POPIA also requires that data subjects be notified of processing. A common mistake is failing to account for litigation-related processing in existing or additional privacy notices. This is especially problematic for high-risk processing related to discovery. Although notification exemptions exist in POPIA, these must be interpreted narrowly.
Parties often fail to implement proportionate safeguards regarding discovery information. POPIA requires responsible parties to safeguard the integrity and confidentiality of personal information. To avoid falling foul of these, POPIA's security requirements should be applied, including anonymisation and pseudonymisation where possible.
Where discovery may involve the transfer of personal information outside South Africa (for example, where e-discovery platforms are located abroad), litigants should assess this at the outset and ensure they have a lawful basis to transfer the personal information in terms of section 72 of POPIA.
Finally, POPIA requires that personal information not be retained longer than necessary. It is a mistake to indefinitely retain discovery material after proceedings conclude. Litigants should therefore establish retention and deletion policies and processes.
Proportionality as an overarching discipline
The lesson from the EU is that proportionality should guide the entire discovery process. Disclosure must satisfy procedural obligations whilst safeguards minimise unnecessary intrusion into privacy. POPIA’s Preamble acknowledges the "fine balance" between privacy and the free flow of information. Practitioners should treat proportionality as an overarching discipline informing every decision in the course of discovery.
POPIA compliance during discovery requires measured judgement, documented policies, proportionate safeguards, and a careful balancing of legal obligations with privacy rights.
As POPIA matures and the Information Regulator becomes more active, the consequences of non-compliance will become increasingly significant. Litigants who develop robust frameworks for discovery will be better positioned to process personal information lawfully, comply with the court of law, and avoid regulatory enforcement.
Written by Ahmore Burger-Smidt, a Director and Head of Regulatory, and Armand Swart, a Director at Werksmans Attorneys
EMAIL THIS ARTICLE SAVE THIS ARTICLE ARTICLE ENQUIRY FEEDBACK
To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here









