South Africa's Department of Home Affairs (DHA) wants to put biometric identity verification in the hands of street-level immigration officers. Tender DHA10-2026, published July 7 and closed July 24, 2026, seeks a service provider to build and maintain a Biometric Case Management System (BCMS) and supply 600 handheld devices with built-in fingerprint and camera readers to the department's inspectorate directorate, on a 36-month contract with an option to extend two more years (ITWeb). Officers conducting raids will capture ten fingerprints and a photo in the field, check the result against DHA records in real time, and — per the tender text — move a flagged person from arrest to deportation within 48 hours.
The Case for the Tender
The strongest argument for BCMS is administrative, not ideological. Home Affairs has spent years fighting document fraud — forged permits, cloned IDs, officials taking bribes to backdate paperwork. A biometric check that compares a live fingerprint against a central register is much harder to fake than a laminated card, and it removes a point of discretion (and corruption) from an individual officer's judgment call. Minister Leon Schreiber has directly credited biometric tools, alongside operations like the department's "Operation New Broom" enforcement campaign, with lifting deportations by 46% — from 39,672 in 2023/24 to a cumulative 109,344 over the two most recent financial years (SAnews). For a department that has publicly struggled with backlogs and under-resourcing, a tool that speeds up correct identification, and reduces reliance on paper records that are easy to forge and slow to check, is a legitimate modernisation goal. Faster, more accurate identification also cuts both ways: it can clear a legal resident faster than a manual records check would, not just catch someone undocumented.
Where the Law Already Answers the Critics — On Paper
South Africa is not regulating this in a vacuum. The Protection of Personal Information Act (POPIA) explicitly classifies biometric information as "special personal information," alongside race, health and political affiliation, and Section 26 prohibits its processing outright unless one of the narrow authorisations in Sections 27–33 applies (POPIA s.26). Breaching the Act's core processing conditions is not merely a compliance footnote — Section 107 sets a maximum penalty of ten years' imprisonment for the most serious offences (POPIA s.107). That is a meaningfully strict regime on paper, comparable to the EU's GDPR treatment of biometric data as a special category. The question the tender raises is not whether South Africa has a law for this — it does — but whether a 36-month field-deployment contract has been built to satisfy it, or bolted on afterward.
The Real Risk Is Operational, Not Just Legal
The Public Servants Association, the union representing DHA staff, has already flagged the practical version of this concern: it says the department must have "robust data-protection measures" in place before rollout, and separately warned that Operation New Broom's success depends on funding and staffing levels the department does not currently have (Biometric Update). That combination — a legally sensitive dataset, a chronically under-resourced inspectorate, and a 48-hour clock from arrest to removal — is where wrongful-detention risk actually lives. A fingerprint match against a stale or incomplete database doesn't announce its own uncertainty; it returns a result an officer in the field is trained to act on quickly. Immigration lawyers' warnings about function creep are not paranoia: a device built to check status during a raid is, by design, also a device that can be repurposed for identity checks in contexts well outside enforcement, and nothing in the public tender documents describes a sunset clause, an independent audit mechanism, or a published retention limit for the biometric data 600 devices will generate.
What Should Actually Happen Next
This publication's editorial position is not that Home Affairs should abandon biometric tools — a modern immigration system needs faster, harder-to-forge identity verification, and the status quo of paper documents and manual checks serves neither legitimate migrants nor the department's own staff well. The position is that a rollout of this scale, touching a legally protected data category for potentially hundreds of thousands of people a year, should not proceed on a standard IT procurement timeline. Before the 600 devices reach the field, DHA should publish the data protection impact assessment POPIA's own guidance calls for, define a hard retention and deletion window for biometric captures of people later found to be lawfully present, and give the Information Regulator — POPIA's dedicated enforcement body — a public role in reviewing the BCMS design rather than a reactive one after complaints arrive. None of that requires killing the tender. It requires treating the compliance obligations Parliament already wrote into POPIA as a design constraint on the system, not paperwork to be completed after the scanners ship.