South Africa is getting a digital ID. Here is what the draft says.

By Ubuntu Guard Cyber | 22 May 2026

South Africa loses billions every year to identity fraud, mostly because our existing system hands fraudsters too many windows. The irony is that the fix, a proper digital identity credential, creates a new window if the design is wrong. Home Affairs published draft regulations in Government Gazette No. 54610 on 4 May 2026, and the comment window closes on 6 June. Before you share the panicked WhatsApp forward, here is what the document says.

What is being proposed

The Department of Home Affairs, under Minister Leon Schreiber, wants to create a smartphone-based digital identity credential called the MyMzansi Digital ID. It carries the same legal weight as your Smart ID card. You present it via near-field communication, Bluetooth, or QR code. It is valid for five years, renewable through a facial scan in the app, and entirely optional: your physical Smart ID remains valid regardless of whether you enrol. The draft is explicit on this. Regulation 49(3) states that no person is compelled to obtain a digital identity credential in order to continue using a valid physical identity card.

The system is built on elliptic-curve cryptography, which is a well-regarded standard used by financial institutions globally. Biometric templates are stored in encrypted form in the population register. Law enforcement access requires a warrant or court order, and regulation 32(4) states this plainly with no loophole language. The draft also prohibits trusted entities (banks, telcos, and similar accredited organisations) from using your identity data for profiling, open-ended intelligence gathering, or data commercialisation. That language is in regulation 44(i) and it is unusually direct for a government document.

Much of the viral commentary misread the "verified relationship" mechanism in regulation 38A. The idea is that if your bank already holds verified particulars about you, and you update your address through Home Affairs, the bank can receive that update automatically so its records stay accurate. It is a data-hygiene function for institutions that already have a lawful, current relationship with you. Trusted entities cannot receive updates about people they have no existing lawful relationship with, and they cannot use those updates for any purpose beyond what is specified in their data sharing agreement.

Why the good parts are not the whole story

The draft is better than the social media posts suggested. Cleaner, tighter, more rights-conscious. But reading it carefully turns up two gaps that matter in a South African context, and they are worth raising before 6 June.

The first is device recovery. Your digital ID is cryptographically bound to a specific smartphone. This is a sound security design: it limits impersonation risk because the credential cannot simply transfer to another device. The problem is that the regulations are largely silent on what happens when that phone is stolen, which in South Africa happens to a lot of people. SIM swap fraud cost the telecoms sector over R5.3 billion in 2025 alone, according to the Communications Risk Information Centre (COMRiC), and SIM swaps account for roughly 60% of mobile banking fraud in the country. Device theft is an everyday reality, not an edge case. Regulation 21 allows the Director-General to suspend a credential where contact information "has changed and is pending re-verification," which suggests a recovery path exists, but the specific mechanics of how someone restores access after losing their phone are left to future instructions. That is a gap worth naming in a submission, because the draft's silence on it leaves the recovery design entirely to executive discretion, with no minimum standards published for comment now.

The second gap is on the verifier side. The draft describes how Home Affairs issues credentials, and how you as a citizen hold them. It says almost nothing about how banks, retailers, and security companies build the apps to read and trust those credentials, which technical standards they must meet, and whether a single government-issued wallet (MyMzansi) is the only path or whether open, certified third-party wallets will be permitted. Industry specialists flagged this in TechCentral reporting from May 2026, noting that South Africa should anchor the system in international standards such as OpenID Connect for verifiable credentials. A closed single-wallet architecture creates dependency on one government app, which concentrates risk. If MyMzansi has a vulnerability, there is no alternative channel. This is worth asking about, directly, in a submission.

What the security picture looks like on our end

The broader context for all of this: South Africa faces roughly 3,312 cyberattacks per week targeting government systems, per COMRiC's 2025 Sector Report. The Information Regulator recorded 1,607 breach notifications between April and September 2025 alone, a 60% increase from 2024, according to Werksmans Attorneys' cybersecurity analysis from February 2026. Digital banking crime surged 86% in 2024, jumping from approximately 52,000 to 98,000 reported cases, per Technext research published in March 2026.

Layering a national digital identity system onto that environment is a serious undertaking. The draft's cryptographic protections are genuine, but fraud does not wait for policy to catch up. As Facephi's 2026 South Africa cybersecurity report noted, moving to digital ID will likely shift fraud away from forged documents toward account takeover, SIM swap, and device compromise. The architecture of MyMzansi, specifically whether it can withstand that pressure in a country with endemic phone theft and sophisticated SIM swap operations, is the question the regulations do not fully answer yet.

What you can do before 6 June 2026

The comment window is open until 6 June 2026, and your submission is a formal legal record, not a petition. You do not need to write a legal opinion. You need to raise a clear, specific concern. Submissions go to Adv Moses Malakate at [email protected], or by post to the Chief Director: Legal Services, Department of Home Affairs, Private Bag X114, Pretoria, 0001. The Dear South Africa portal at dearsouthafrica.co.za/digital-id/ also routes formal submissions.

  1. Raise the device recovery gap. Ask the Department to publish minimum standards for credential restoration after device theft, as part of these regulations, before they are finalised. The recovery path should not be left entirely to future executive instruction with no public comment opportunity.

  2. Ask about verifier standards. Request that the Department clarify whether MyMzansi will be the sole wallet or whether open, standards-based alternatives will be permitted, and what minimum security standards third-party verifiers must meet to read and trust the credential.

  3. Ask for a POPIA impact assessment. The regulations note that POPIA prevails in any conflict with the data sharing provisions, which is good. A published impact assessment, showing how the verified relationship mechanism and near-real-time update notifications interact with POPIA's data minimisation and purpose limitation principles, would give the public something concrete to scrutinise.

  4. Keep your physical ID maintained. Whatever happens with MyMzansi, your Smart ID card remains your legal fallback. If yours is expired or damaged, renew it now, before the digital system is live and Home Affairs offices are managing two queues simultaneously.

  5. Audit your digital exposure. If you run a business that will eventually become an accredited trusted entity, or that will need to integrate with the MyMzansi verification ecosystem, your security posture and POPIA controls need to be ready before that integration happens, not after.

Where Ubuntu Guard fits

If you run a business and you want to understand what the MyMzansi rollout means for your POPIA obligations, your device security posture, or your exposure as a potential trusted entity in the ecosystem, our cybersecurity assessment covers exactly that ground. We give you a plain-language report and a clear list of what needs attention before the system goes live. You can read how the assessment works at our cybersecurity assessment page.

Not sure if your current setup is secure? Our assessment tells you exactly where the gaps are. WhatsApp us to book yours.

Cybersecurity Made Simple



© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa ubuntuguard.co.za

Sources


© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Worried about scams hitting your team?

Ubuntu Guard Cyber's cybersecurity assessment audits your real exposure across email, accounts, devices, and POPIA controls. Get in contact now

Book a Cybersecurity Assessment

Questions? Reach us at [email protected]