PREVIOUS ARTICLENEXT ARTICLE
NEWS
By 20 July 2026 | Categories: news

0

By Gerhard Oosthuizen, Chief Technology Officer, Entersekt 

South Africa is on the cusp of a major shift in how we prove who we are in the digital world. If the deluge of posts on community message groups is anything to go by, the proposed new digital identity (ID) regulations have captured public attention, and for good reason. Done right, digital IDs could make everyday life significantly easier, from eliminating the need to print proof of identity or address to reducing our reliance on carrying physical documents.

What matters is that digital identity is introduced in a safe and responsible manner. 

We’re halfway there

South Africans are already comfortable storing sensitive information on our cellphones. Beyond chats, emails and calendars, most of us have our bank cards loaded into apps and wallets, and are happy to store events and airline tickets on these too. 

However, we still need to have our driving licence on hand when driving, present an ID when boarding planes, verify our identity when entering some estates and buildings, and prove we are old enough to buy a drink. 

The missing link in this mobile-first utopia is being able to easily and securely identify ourselves. 

Lesson learned on securing our identity

The security challenges in any national digital ID solution are many and nuanced. 

We know that AI-powered image editing tools are making it increasingly easy to manipulate credentials. We also know that to ensure trust and integrity, digital IDs must be issued by the same bodies responsible for physical documents, like government departments or driver licensing authorities. 

Robust security measures are essential to prevent tampering, fraud, and unauthorised access. Digital IDs should incorporate lifecycle controls, including expiry and revocation mechanisms, mirroring the safeguards we already use for physical ID cards. 

Fortunately, the industry has had years to wrap its head around the technical challenges and Apple and Google have offered robust wallet support for some time, with Samsung recently also throwing its hat in the ring.

Both the regulatory-driven world, like Europe, and market-driven economies, embodied by the U.S., are racing towards a digital ID future. 

The USA’s Transportation Security Authority (TSA) already accepts digital driving licences from 21 states. In Europe the EIDAS-2 regulation (adopted in November 2024) ensures each EU state must offer a European Digital Identity by December 2026, and financial institutions must allow citizens to open bank accounts and make payments using these credentials.

While local law makers can learn a lot from their international counterparts, the current draft regulations still contain some obvious shortcomings. 

How much personal information is enough? 


One of the main concerns for many South Africans is who will have access to their personal information - and how much of it needs to be shared.

Encouragingly, the proposed regulations recognise the principle of data minimisation. Organisations should only request the information they genuinely need to deliver a service. That means a retailer, for example, should not automatically ask for your email address or phone number for marketing purposes if it is not required for the transaction. In many cases, people should be able to remain effectively anonymous - sharing only what is necessary, like confirming they are over 18 rather than revealing a full birthdate.

This concept, often referred to as selective disclosure, is central to making digital ID both practical and privacy-preserving.

While there is an expectation that data will be used for a stated purpose and handled securely, the current digital ID framework is still vague on three critical points: how a requesting party proves its identity to the user; how clearly and specifically the purpose of the data request is communicated; and how the system enforces that only the minimum necessary information is shared.

Greater clarity on these elements is not only about privacy but also about a critical defence against fraud. In a digital environment where criminals can convincingly impersonate trusted institutions, users need simple, reliable ways to verify that a request genuinely comes from their bank, a government department, or another legitimate party.

Equally important is ensuring that the purpose of the request is explicit and verifiable. For instance, a request to approve a payment should be clearly distinguishable from one attempting to open a new account or change personal details. When these elements are well defined and enforced, users are far less likely to be misled into sharing credentials under false pretences. 

Hold the right institutions responsible 

To tackle the risk of abuse of personal information, the system must change at both the rules level and the technology level. 

The law needs to stop treating “you clicked share” as the end of the story. It should require that any organisation asking for your data proves who they are, states what they are going to use that data for, and only collects the minimum information needed for that job. 

Every request and approval should be recorded so that, if or when something goes wrong, we can see who asked for what and hold the right party, like the bank, the wallet provider, or the state, legally responsible, instead of blaming the citizen.

Fixing this isn’t just about telling people to be careful with their information. It’s about designing the system so that abuse is hard, transparency is automatic, and powerful institutions carry the appropriate amount of risk if they get it wrong. 

USER COMMENTS

Read
Magazine Online
TechSmart.co.za is South Africa's leading magazine for tech product reviews, tech news, videos, tech specs and gadgets.
Start reading now >
Download latest issue

Have Your Say


What new tech or developments are you most anticipating this year?
New smartphone announcements (46 votes)
Technological breakthroughs (29 votes)
Launch of new consoles, or notebooks (14 votes)
Innovative Artificial Intelligence solutions (29 votes)
Biotechnology or medical advancements (24 votes)
Better business applications (160 votes)