South Africa South Africa POPIA data protection

South African Court Rules Exam Numbers Aren't Personal Information — And That's the Right Test

Gauteng High Court refuses regulator's leave to appeal, holding matric exam numbers don't trigger POPIA absent real identifiability.

The Matric Results POPIA Fight People of Internet Research · South Africa R5 million Fine sought against education dept Infringement Notice penalty the Re… 3 Judges on the full bench Panel that ruled exam numbers alon… Dec 2025 Original ruling date Full bench first held exam-number … Jun 2026 Leave to appeal refused Court found no reasonable prospect… peopleofinternet.com
The Matric Results POPIA Fight People of Internet Research · South Africa R5 million Fine sought against educatio… 3 Judges on the full bench Dec 2025 Original ruling date Jun 2026 Leave to appeal refused peopleofinternet.com

Key Takeaways

South Africa's Information Regulator has lost, for a second time, its bid to stop the Department of Basic Education from publishing matric (school-leaving exam) results using candidates' examination numbers. On June 3, 2026, the Gauteng High Court in Pretoria refused the Regulator's application for leave to appeal a full-bench ruling of December 12, 2025 that held publication by exam number alone does not breach the Protection of Personal Information Act (POPIA). The three-judge panel — led by Judge Omphemetse Mooki — found the appeal "enjoys [no] reasonable prospect of success," closing off, for now, one route to reversing the underlying judgment.

What the Regulator Was Trying to Stop

The dispute dates to November 2024, when the Information Regulator issued an Enforcement Notice ordering the DBE to stop publishing matric results in newspapers, arguing the practice unlawfully disclosed learners' personal information without consent. When the department missed the compliance deadline, the Regulator followed up with an Infringement Notice imposing a R5 million administrative penalty — one of the largest fines it has sought under POPIA since the Act's full commencement. The department challenged both notices, and in December 2025 a full bench set them aside, ruling that publishing results tied only to a candidate's exam number — with no name attached — did not process "personal information" as POPIA defines it.

The Regulator's Case, Fairly Stated

The Regulator's underlying concern is not frivolous. POPIA defines personal information broadly, as "information relating to an identifiable, living, natural person," precisely so that data controllers cannot dodge accountability through superficial de-identification — stripping a name while leaving other identifiers intact. Minors' academic records are a legitimate category for heightened protection, and the European Union's GDPR framework, which the Regulator's argument echoes, treats pseudonymized data as still "personal" wherever any party could plausibly re-identify the subject using auxiliary information, such as a class list or seating chart. On that logic, an exam number published alongside a school and subject list is not meaningfully different from a name, since anyone with access to the class register can complete the link. A regulator whose statutory job is to prevent identifiable disclosure of vulnerable people's data has good reason to test that boundary in court rather than assume good faith compliance.

Why the Court Got the Balance Right

But the Regulator's theory required more than a hypothetical link — it required proof that ordinary members of the public, not just a classmate or teacher with independent knowledge, could identify a specific learner from an exam number alone. Judge Mooki rejected the cross-referencing argument as "fanciful," a "poorly constructed thought experiment" unsupported by empirical evidence, holding that identifiability under POPIA requires more than an "elaborate chain of recall and inference." That is the correct question to ask. A precautionary standard that treats any theoretically reversible code as personal information — regardless of who could realistically reverse it, and at what cost — would sweep in vast categories of routine, low-risk public-interest disclosure: matric results, professional licensing exam outcomes, court case numbers, ticket and reference numbers used across government services. Each of those relies on an identifier that is not designed to be public-facing but also is not, on its own, a meaningful re-identification risk to the ordinary recipient.

The practical stakes are real. Matric results published by exam number let millions of families — many without reliable internet access to a school portal — verify outcomes in a newspaper or on a public noticeboard the same day results are released. An enforcement regime that could shut that down over a hypothetical, effort-intensive re-identification chain would impose a real transparency cost for a speculative privacy gain. The R5 million fine the Regulator sought to impose on the education department, for a practice with no demonstrated victim, illustrates the proportionality problem: POPIA's enforcement tools are calibrated for genuine data breaches and unlawful processing, not for testing novel legal theories against a government department already following a widely used, years-old publication convention.

What Comes Next

This is not the final word. The Regulator can still petition the Supreme Court of Appeal directly for leave to appeal, and reporting indicates it has already done so. If the SCA takes up the case, it will be ruling on a question with consequences well beyond exam results: how South African courts should read "identifiable" under POPIA generally, and whether the country will converge toward the EU's expansive, precautionary approach to coded data or hold to a narrower, effects-based test tied to actual re-identification risk. For a regulator still building POPIA enforcement precedent, and for the many public bodies that rely on coded identifiers to communicate with citizens at scale, that clarity — whichever way it lands — matters more than the fine itself.

Until the SCA rules, the December 2025 judgment stands, and the Gauteng High Court's message is consistent: proportionate data protection enforcement should track real-world identifiability, not the outer edge of what a determined analyst could theoretically reconstruct.

Sources & Citations

  1. Information Regulator — Infringement Notice media statement (R5m fine)
  2. POPIA Section 1 — definition of 'personal information'
  3. Werksmans Attorneys — Leave to Appeal Refused, but Questions Remain
  4. ITWeb — Information Regulator flunks matric results appeal
  5. Moonstone Information Refinery — Regulator's argument dismissed as 'fanciful'