Reading an Employee's Email Can Be a Criminal Offence
POPIA is the regulatory question. RICA is the criminal one, and it comes first. Clearing RICA does not clear POPIA, and most policies address neither.
Read this before you rely on anything below. This is general information about South African law, written by a business owner rather than a lawyer, and it has not been reviewed by one. It is not legal advice, it is not a substitute for advice on your own facts, and reading it creates no attorney-client relationship. RICA creates criminal offences and its penalties can fall on individuals personally, so the stakes here are higher than on most compliance questions. Before you monitor anything, or act on something monitoring has turned up, check the current wording of the Act itself and get advice. If any of this turns out to be wrong or out of date, act on the Act and not on this page.
The criminal statute comes first
Most employers approach workplace monitoring as a POPIA question. It is, but POPIA is the second question.
Intercepting a communication engages RICA, the Regulation of Interception of Communications and Provision of Communication-related Information Act. RICA is criminal legislation. Its penalties run to a fine of up to R2 million or imprisonment of up to ten years, and they attach to individuals, not only to the company.
That reordering matters, because the two laws answer different questions and clearing one does not clear the other:
- RICA asks whether intercepting the communication was a crime.
- POPIA asks whether processing the resulting personal information was lawful.
An employer can satisfy RICA perfectly and still be processing employee information without a ground, a defined purpose or any notice. RICA gets you past the criminal law. It does nothing else.
This page goes deeper than the monitoring section of our employee data guide, which sets out the POPIA side more generally.
The three doors through RICA
RICA starts from a general prohibition on intercepting communications. There are three exceptions an employer might realistically stand in.
Section 4: you are a party to the communication. Any person may intercept a communication they are themselves party to, unless the interception is for the purpose of committing an offence. If a manager is in the meeting or on the call, recording it is not an interception offence.
Worth knowing that this runs both ways, and employers are regularly surprised by it. An employee who records a disciplinary hearing, a grievance meeting or a conversation with their manager is a party to that communication, and section 4 covers them just as it covers you. Recordings made by employees turn up in CCMA proceedings constantly, and the answer is not that they were unlawfully obtained.
Section 5: prior written consent. Interception is permitted where one of the parties has consented in writing, in advance, and again not where the purpose is to commit an offence. First prize in theory. In practice employers rarely obtain genuinely free written consent from every employee, and consent extracted as a condition of employment is on shaky ground under POPIA's definition of voluntary consent in any event.
Section 6: interception in connection with carrying on business. This is the provision that actually does the work, and it is the one worth knowing properly.
Section 6, condition by condition
Section 6 permits a system controller to intercept indirect communications in the course of carrying on a business. It is not a general licence, and each element does work:
- It must be your system. The communication has to be sent, received or stored using the employer's own infrastructure. Your server, your domain, your tenancy, your laptop. An employee's personal Gmail account, opened on a work laptop, is not your system.
- It must relate to the business. The communication must relate to the business, or otherwise take place in the course of carrying it on.
- It must be authorised by the system controller, expressly or impliedly. This is a defined term and it is narrower than people assume: for a company it is the chief executive officer or equivalent officer, or a person duly authorised by that officer. It is not automatically your IT manager, and it is certainly not the line manager who wants to know what a subordinate is saying about them. If your IT lead is going to authorise interception, the CEO has to have authorised them to do it.
- It must serve a permitted purpose, which covers things like establishing facts relevant to the business, detecting unauthorised use, and securing or checking the effective operation of the system.
- You must have made all reasonable efforts to inform users in advance that communications may be intercepted — or that user must have consented. Notice is the limb an employer can actually build a system on; consent from every employee is the one you will not reliably get.
That last one is where most employers fail, and it is the cheapest to fix. "All reasonable efforts" and "in advance" are doing real work. A clause buried in a contract signed four years ago is a weak answer. A written monitoring policy that people are taken through, reissued when it changes, and reinforced by a login banner is a strong one.
One honest uncertainty. There is genuine debate about whether opening a message already sitting in a mailbox is "interception" at all, as opposed to accessing stored data. We would not build a monitoring programme on winning that argument. Assume RICA applies, satisfy section 6, and the question becomes academic.
Then POPIA, as a separate exercise
Having cleared the criminal law, you still have to justify the processing. Employees are data subjects, and the eight conditions apply to them in full.
- A ground under section 11. Usually legitimate interests, occasionally a legal obligation. Note that consent is a poor fit here for the same reason as in RICA: an employee is not well placed to refuse.
- A specific purpose under section 13. Written down before you start, not reverse-engineered from what you found.
- Minimality under section 10. Not excessive relative to the purpose. Continuous keystroke logging to address a suspicion about one person's timekeeping fails this.
- Notification under section 18. People must know. Covert monitoring is not simply a stronger version of open monitoring; it is a different act requiring a much better justification, and normally a specific, documented suspicion.
- Security under section 19. Monitoring output is itself sensitive personal information. Recordings and logs need to be access-controlled and deleted on a schedule, or you have created a new liability while investigating an old one.
Where this goes wrong in practice
The purpose switch. A camera installed for stock loss, later used to time a tea break. A phone system that records for quality assurance, later mined for a disciplinary. Section 13 does not permit the quiet change of purpose, and it is the single most common failure in this area. It is also what makes an employee feel deceived, which is what turns a manageable process into a dispute.
Personal communications on work systems. Section 6 covers communications relating to the business. It does not turn every personal message on a work laptop into your property. If your monitoring sweeps up an employee's medical appointments or union correspondence, you are processing special personal information you have no basis for.
Union activity. Monitoring that captures organising activity is not just a POPIA problem. It reaches into the Labour Relations Act quickly.
Places nobody may monitor. Bathrooms and change rooms, without exception. Rest areas are close behind.
Personal devices. If staff use their own phones for work, be precise about what any management software can see. Software that can read a personal handset's photographs or messages is not proportionate to checking that the mail client is patched. This is also where the CCTV and audio question sits: see CCTV and POPIA.
The policy that makes this workable
Almost everything above is fixed by one document that people have actually read. A monitoring policy should say:
- What is monitored, specifically. Email on the company domain, internet traffic on the company network, calls on the company system, access logs, vehicle tracking. Not "electronic communications" as a category.
- Why, tied to the section 6 purposes and to a section 13 purpose.
- Who may authorise it, and who may see the output. Naming the system controller matters.
- What is not monitored, which is as important for trust as anything else on the list.
- How long output is kept, and who deletes it.
- What happens with what is found, including the right to be heard before it is used against someone.
Issue it as a policy rather than a contract clause, take people through it, and reissue it when it changes. A contract clause is signed once and forgotten; a policy is a thing you can show you communicated, which is the language section 6 speaks.
Using what you find
Two things employers underestimate.
First, evidence obtained through monitoring can be challenged at the CCMA on the basis of how it was obtained, and an unlawful interception is a poor foundation for a dismissal you want to survive review. The fairness of the process is a separate question from whether the misconduct happened.
Second, an employee can ask for it. Section 23 gives every data subject a right of access, and an employee under investigation is a data subject. POPIA itself sets no fixed period for answering, only a reasonable time; the 30 days usually quoted is PAIA's, and it is a deadline for deciding rather than delivering. See how to respond to an access request. It is worth assuming, when you collect it, that the person will eventually read it.
A short checklist
- Is there a written monitoring policy, or only a clause in the contract?
- Were people told in advance, and can you show it?
- Who is your system controller, and did they authorise this?
- Is the monitoring on your infrastructure, or reaching onto personal accounts and devices?
- Is the purpose written down, and is it still the purpose you are using it for?
- Could you achieve the same result with less?
- Who can see the output, and when does it get deleted?
- Would you be comfortable if the employee read the whole file, given they can ask for it?
POPIA Ready generates a privacy policy, a PAIA manual and five other documents customised to your business, free to preview. The free checklist will show you what else is missing.
To repeat the warning at the top, because it matters more here than on most pages: this is general information as at September 2026, written by a non-lawyer and not reviewed by one. It is not legal advice and creates no attorney-client relationship. Monitoring sits across RICA, POPIA and the Labour Relations Act; RICA carries criminal liability for individuals; and covert monitoring, or any dismissal based on intercepted communications, needs a professional opinion before you act rather than after. No liability is accepted for any action taken on the basis of this page.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview