South Africa South Africa biometric surveillance ICASA

SAPS's New Bodycam Tender Makes Facial Recognition Mandatory Without a Law to Govern It

Tender RFB 3286-2026 requires facial-matching in police cameras, but South Africa has no statute on activation, access, retention, or matching rules.

Cameras Mandated, Safeguards Absent People of Internet Research · South Africa 29 Sep 2026 Bid closing date SITA's deadline for RFB 3286-2026,… 3 years Contract duration Length of the SITA supply, deliver… ~2 weeks AI policy lifespan before withdrawal South Africa's Draft National AI P… ~10% Fabricated references in draft AI policy Share of academic citations in the… peopleofinternet.com
Cameras Mandated, Safeguards Absent People of Internet Research · South Africa 29 Sep 2026 Bid closing date 3 years Contract duration ~2 weeks AI policy lifespan before … ~10% Fabricated references in dr… peopleofinternet.com

Key Takeaways

A mandatory feature, an empty rulebook

On 7 September 2026, the State Information Technology Agency (SITA) published tender RFB 3286/2026 on behalf of the South African Police Service: a three-year contract to supply, deliver, support and maintain body-worn and vehicle dashboard cameras, closing 29 September. Facial recognition is not an optional add-on. Bidders must confirm the system's "ability to conduct facial recognition and integrate with various security platforms," and a bid that fails this mandatory requirement is excluded from evaluation entirely (ProTenders listing; TechCentral).

The specification sheet is detailed on hardware and thin on everything else. Dashboard cameras need embedded AI for number-plate recognition and event detection; body cameras must auto-activate when an officer's firearm leaves its holster; a video-management platform must run motion, face and plate recognition centrally. What the 2026 tender does not specify: how many cameras will be bought, what facial recognition is actually for, who may query a match, how long footage is kept, or under what circumstances a camera may be switched off. There is no companion regulation, code of conduct, or statute governing any of it.

The regulator already found SAPS can't be trusted with the data it has

This isn't a hypothetical risk. In 2023, South Africa's Information Regulator issued a formal enforcement notice against SAPS under section 95 of the Protection of Personal Information Act (POPIA) after the personal details of Krugersdorp rape survivors — names, addresses, occupations — circulated on WhatsApp and then Facebook. The Regulator found SAPS had breached the lawful-processing conditions of POPIA and failed to notify it of the security breach, and ordered a public apology, disciplinary investigations, organisation-wide POPIA training and a new privacy policy (Information Regulator enforcement notices; Werksmans).

That finding matters directly here because POPIA's exemption for police processing is conditional, not automatic. Section 6(1)(c) excuses public bodies processing personal information for crime prevention, detection, investigation and prosecution — but only "to the extent that adequate safeguards have been established in legislation for the protection of such personal information" (POPIA s6 text). No such legislation exists for facial recognition in South Africa. The 2023 notice already established that SAPS, absent codified safeguards, doesn't qualify for the carve-out — which means a fleet of facial-matching cameras procured under RFB 3286-2026 would process biometric data with the same absence of legal footing the Regulator already penalised the service for.

No law is coming soon, either

South Africa did attempt to build that legislative safeguard. A Draft National AI Policy, gazetted 10 April 2026, proposed a risk-based framework modelled on the EU AI Act with stricter rules for "high-risk" uses including law enforcement. It lasted two weeks: Cabinet withdrew it on 26 April 2026 after roughly 10% of its academic citations turned out to be fabricated — evidence the policy document had itself been drafted with unchecked AI assistance (DLA Piper). No replacement has been published. The one national instrument that might have supplied POPIA's missing "adequate safeguards" collapsed under the same discipline problem — unverified output presented as authoritative — that critics worry about in the surveillance systems themselves.

Steelmanning the mandate

The case for facial-recognition-capable cameras isn't frivolous. South African policing operates under severe strain — SAPS has for years cited understaffing and a murder rate among the world's highest — and body cameras are one of the few tools with real evidence of reducing both officer misconduct and false complaints. Facial matching against a limited, court-authorised watchlist (missing persons, wanted suspects at flagged scenes) is a materially different tool from always-on biometric scanning of every civilian a camera passes, and treating the two as identical understates what disciplined deployment could achieve. Waiting for perfect legislation before adopting any camera technology also has a cost: officers and victims go unrecorded in the interim, and evidentiary gaps in prosecutions persist.

But a mandatory-but-unconstrained capability clause is the wrong way to capture that benefit. The tender doesn't limit facial matching to a defined watchlist, require a match to be logged and auditable, or bar continuous scanning of bystanders — it simply requires the capability exist. That is the difference between procuring a tool and procuring a policy vacuum with a camera attached.

What proportionate regulation looks like

A workable path exists, and it's the one POPIA already points to: legislate the safeguards section 6(1)(c) demands before, or alongside, procurement — not after deployment. That means a statute or binding regulation fixing activation triggers, a closed and auditable purpose for facial matching, defined retention limits, and an access log reviewable by the Information Regulator. None of this blocks bodycams from reaching officers this year; SITA's own procurement timeline could run in parallel with a fast-tracked amendment to SAPS's governing regulations, distinct from the failed AI policy process. What proportionate regulation cannot mean is buying the surveillance capability first and hoping the rules catch up — precisely the sequence POPIA's own text was written to prevent, and the one South Africa's Information Regulator has already penalised SAPS for once.

Sources & Citations

  1. ProTenders — RFB 3286/2026 tender listing
  2. Information Regulator South Africa — Enforcement Notices
  3. POPIA — Section 6 Exclusions text
  4. TechCentral — SAPS bodycam facial recognition tender
  5. Werksmans — Information Regulator enforcement notice against SAPS
  6. SAnews — Minister announces withdrawal of draft AI Policy