SA websites not legally compliant

Hi all,

I would like to comment on the posting made on behalf of Lance Michalson:

1. The "observer" who called the 2004 South African Website Compliance Survey a "useless survey... that [is] a waste of time" is Peter Hill. It comes as no surprise that Peter Hill is a close buddy of Lance and works for one of Lance's so-called "strategic partners". Hardly an independent observer...?

2. Buys Inc. submitted a response to Peter Hill's comments which ITWeb refuses to publish. View the response at: http://www.itweb.co.za/sections/feedback/u.asp?I=146554&C=3653

3. Legal services, like insurance, is a grudge purchase. Also, like insurance, legal services are marketed with reference to the possible risks and liabilities. A typical website owner cannot care less about narrow compliance, wide compliance, best practice and risk management... he or she wants to know i) what they should to and ii) what will happen if they don't. Maybe Lance's clients are much more sophisticated than most, but our experience is that clients care little about the academic issues and is more concerned with the practical legal stuff.

4. The 2004 Website Compliance Survey followed the methodology of similar recent surveys in the US and Australia (these surveys had very much the same results as the SA survey). Lance neither requested nor was the rough data / methodology given to him for an informed opinion.

5. The 2004 SA Website Compliance Survey took over two months and involved the hard work and commitment of many people who did not charge for their services. These people considered the survey a service to the SA online community. Subject to a few nasty remarks, the SA media and IT sector welcomed the survey. Maybe next time Lance Michalson or Steven Ferguson would sponsor and finance such a survey...

6. Lance has a history of bitter and aggressive comments regarding Buys Inc. See, for example, the indirect reference in the Brainstorm article "At best ignorant... at worst charlatans" (http://brainstorm.itweb.co.za/online/ReadStory.asp?StoryID=140196). The official Buys Inc. response is fun to read and available in our June 2004 (III) newsletter (http://www.buys.co.za/gbNewsletters.asp?RID=46).

All these unsubstantiated allegations that Buys Inc. misleads, confuses and scares the public shows very little understanding of the public's intelligence. The "public" is not a group of stupid individuals that believe anything they read. Some e-law firms might find the "public" much more informed than they would like to believe.

Cheers, [:p]


Reinhardt Buys
 
Donn

you are spot on - just over 2 years ago there was no major legislation of specific application to electronic communications or transactions...suddenly it seems as if there is a world full

as a result there are precious few precedents - of these very few are actually reported so as to become common knowledge. i know of a few succesful prosecutions under the cybercrime provisions of the ECT Act for things like unauthorised access. the new interception act has not yet come into force (expected reasonably soon)so nothing there. i know also that charges have been laid under the spam provision but believe that these did not lead to convictions

bear in mind that a lot of the impact of the ECT Act (which holds that electronic data has the same legal force and effect as traditional printed data) is felt in business relations and civil court cases - for example where, say, one party sues another there will usually be a process called discovery (scuse me if you know all this). discovery involves both parties providing a list to the other of the documents which they have which are relevant to that particular matter and which are not priveleged. it is now common for discovery notices to include references to e-mail and other electronic data.

as to policing this is normal law enforcement agencies + the cyberinspectors created and empowered by the ECT Act..i am not too sure what is happening with the cyberinspectors (perhaps someone else could enlighten me)

privacy - fact is there is not much specifically about data privacy in force. the new interception act contains a prohibition on any unlawful interception of indirect communications (would include electronic communications) - lawful interceptions are spelt out in the act (e.g. by ISPs under a court-authorised interception direction, in the workplace under certain conditions); the south african law commission is working on a privacy slash data protection act - personally i think this is incredibly difficult and should not be expected for at least another 2 years; the cybercrime provisions of the ECT Act and the Promotion of Access to Information Act may be helpful

- the kalahari big hole - the success of a court action would depend on a number of variables...was monetary damage sustained by anyone? (this would make life easier); what does the contract between kalahari and those affected say? if the problem related to payments security then they might be required to compensate anyone who suffered loss as a result under the consumer provisions of the ECT Act

the above is really just a toe in the water - there are a number of excellent legal web sites which would give more detail on the above

where there is precedent aplenty in SA is in the CCMA and labour courts and tribunals - there have been lots of cases of employees having disciplinary action taken against them for e-mail and internet abuse in the workplace (and lots of employers forced to take them back because they do not have a proper electronic communications policy in place etc etc)

dominic
_____________________________________________________________________

there are no experts - we are all flying by the seats of our pants
 
oh well - i debase myself further...sackclothe and ashes it will be
______________________________________________________________________

Reinhardt -

i do not have a history of bitter and aggressive comments against your firm, although if you keep telling me to shut up i may have to become just a little grumpy. No matter. I understand the approach you have adopted in establishing Buys Inc as an obviously successful law firm and the reasons therefore & i have seen many good things from and met satisfied clients of the firm.

i feel that you are wrong in your assessment of the impact of the survey and would like to tender the following excerpt from an e-mail sent to me from a former client of yours in response to a demand for payment. (all names and identifiable references deleted)(text edited to remove unflattering references).

Dear ,
I am inreceipt of both your mail, letter to XXXX and his answer.
Unfortunately you have misquoted me to Mr. XXXX. I was NOT referring to any NEW legislation, but to the fact that due to the article published by XXXXXXX, I became aware of the fact that our, as well it seems most other, web-sites do not conform to EXISTING legislation. Legislation which was in effect at the time our web-site was ordered from a "professional developing company", or at lest one that claimed it was professional.

We are NOT asking for any amendmends free of charge due to subsequent legislation which may have come into force after our site was ordered or implemented.

In this respect all three attorneys involved in this case, XXXXXXX, XXXXXX and XXXX have failed in their duty to point out the fact that [my company]was exposed to legal repercussions due to the fact that the web-site developed by was not conforming to basic South African legal standards.

It was this point that prompted us to stop payment and not any new or subsequent legislation. It can be assumed that a company ordereing a product from a "professional" house could at least expect to be delivered a product, however poor it may be, to at at least conform to the law of the land!!! Or is such a basic assumption also too much to ask in South Africa????

Yours Sincerely

Managing Member

This mass of confusion is a result of a small business person reading about the survey and not understanding it. Sure they did not take the time to properly consider your checklist but i would guess that a lot of folk did not. Also i am aware that, as Donn points out, that the survey was a little blown up by the media and it did receive extremely wide exposure.

For me - and please, this is not intended as an attack on you, Buys Inc, the survey or anyone or anything else - the problem is not with the results or methodology, but with the presentation thereof. The effect of the survey would probably have been far greater if the results had been more soberly framed. The public you refer to has, IMHO, enough to be getting on with.

dominic
______________________________________________________________________there are no experts - we are all flying by the seats of our pants
 
Folks, this has been a most interesting debate, and I thank you all.

I think we should all realise that some of the more biting statements that have been made are "all in a day's work" in a profession where accusation and counter-accusation (usually of wrongdoing) are the order of the day (by definition; I am not saying it shouldn't be so).

I have a great deal of admiration for all of you who are attempting to protect my data. And its going to get worse, not better. The risks of data loss/compromise are huge, and most of us IT types are still traditionalistsin the sense that we don't respond quickly to new threats.

For example, it is now possible with a USB flash Memory (The one we got when we all buscribed to Brainstorm) to copy the entire SQL database of the company I am programming for, and walk out the building with it round my neck. Alternatively, I could buy a new iPod and make a backup of all the data on the file server without anyone knowing. The only noticeable activity would be me copying the data to my workstation. Yet the network is considered "secure".

So while the threats change by the month, the legislation changes by the decade. Without sharp minds keeping track of developments, we would still be arguing about the admissability of fax records in court. <b>So keep up the good work, ALL of you</b>. And a little healthy rivalry is better than buddy-buddy complacency.

<hr noshade size="1">
Donn Edwards <font size="2"><div align="right">MyWireless: Diva-style reliability, dial-up performance (or worse)</div id="right"></font id="size2">
<font size="1">“If our government ever goes bad, as sometimes happens in a democracy... As we extrapolate our [surveillance] technologies into the future, if the incumbency has that political advantage over their opposition, then if a bad government ever comes to power, <b>it may be the last government we ever elect</b>.” See http://privacy.4mg.com </font id="size1">
 
Could someone please tell me
What is the definition of a south african website ?

I am thinking about domains, hosting location, owner location, citizens (SA and non-SA) seems to me laws cannot be applied
or if so can easily be obviated.
 
OK, so now that the dust from the fray appears to have settled, it is not inappropriate nor improper to consider some <u>practical</u> mechanisms concerning the legality of websites. To this end, methinks some contributions from the lawyers would be opportune, particularly concerning the questions raised by posters like nOhIwAy - whilst the question may appear simplistic and even naïve, with the answer potentially the converse, this does not reduce the importance or relevancy of its impact on the legally unschooled and the broader public out there. Here's a challenge to the lawyer types - show your backbone and some commitment by attempting to answer nOhIwAy's question, as well as by providing some comment on my earlier suggestion about representations to the Law Commission... [V]
 
Hi all,

A South African website is a website i) hosted in SA or ii) directed at SA citizens.

One cannot simply move the website server to a non-SA location to escape SA legal compliance.

Cheers,

Reinhardt Buys
 
Hi - a "web site" is defined under the ECT Act as

"any location on the Internet containing a home page or web page"
"home page" means the primary entry point web page of a web site;
"web page" means a data message on the World Wide Web;

see http://www.internet.org.za/ect_act.html#Definitions

What is the context of your question?

Lance
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by lance</i>
<br />Hi - a "web site" is defined under the ECT Act as

What is the context of your question?

Lance

<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

Hi Lance,

thank you for the ref and exact answer :).

The context is really quite simple :

How effective can ECT be ??

South African law can have no jurisdiction in other countries.

So as a test case if I wanted to have a website registered in US, I don't have to care two hoots about ECT - true ??

If true - what's the point of ECT ?

ps. please don't misunderstand the question - I don't want to break the law, but I just want to know how effective this law can become and also how it could be applied.

For example: I buy some goods from a seller in zombaland and I get ripped off, I establish that the website I bought from does not comply with ECT Act - what are my choices and what recourse does ECT give me ??
btw. www.zombaland.whatever is not registered in South Africa.
 
It doesn't need to have jurisdiction in other countries, if you are the owner of a website (domain) and reside in SA it doesn't matter where the website is physically hosted, you are subject to SA law. Now if you were to hand over control of the domain to someone residing in another country it would be a different ball game. At least that's how I interpret what Mr Buys is saying.
 
The act talks about "electronic transactions in the Republic" (section 2(1)(c)) so I think that any site that targets its transactions at consumers using the internet in the Republic falls under the jurisdiction of the act. Just how the state would enforce it on Amazon.com is not clear, but I guess an aggrieved consumer could approach his South African bank to nullify the transaction.

Consumers are protected under the act:
47. The protection provided to consumers in this Chapter, applies irrespective of the legal system applicable to the agreement in question.

Chapter VII is the section that deals with consumer protection, and a lot of the "heat" around the debate has been centred around section 43:
43. (1) A supplier offering goods or services for sale, for hire or for exchange by way of an electronic transaction must make the following information available to consumers on the web site where such goods or services are offered ...

So unless there is some other section, it seems to me that unless you are offering goods or services for sale by means of <b>electronic transactions</b>, the act does not apply.

As a non-lawyer, I think this means that if your web site advertises your business, provides contact numbers, product descriptions and so on, or just says "visit my shop" but doesn't provide any way that you could purchase goods by means of a credit card transaction, shopping cart, etc, then exisiting legislation concerning conventional forms of business transaction apply. The ECT act extends this to cyberspace.

That's why there is a clause:
43 (2) The supplier must provide a consumer with an opportunity—­
(a) to review the entire electronic transaction;
(b) to correct any mistakes; and
(c) to withdraw from the transaction, before finally placing any order.

I guess this would also apply to orders placed by email, using PGP to protect sensitive details like credit card numbers. I recently purchased an antivirus package from http://www.nod32.co.za and elected to pay by means of a direct deposit into their bank account. By virtue of the practicality of confirming the exact amount I should pay, I was able to do all of the steps in 43(2) even though there wasn't any evidence of full compliance with every last detail of section 43(1).

Had the deal gone sour and I wanted to demand my money back, I'm sure that had I pointed out the requirements of the Act they would have elected to reverse the deal rather than face prosecution as well as a civil claim.

So I think the Act has its uses to protect the consumer. It certainly means that web sites that just try to take your money by selling you dubious products like "herbal viagra" can no longer hide behind the anonymity that the web provides. OTOH, anyone stupid enough to part with their cash and not know who they are paying deserves to be ripped off.

<hr noshade size="1">
Donn Edwards <font size="2"><div align="right">MyWireless: Diva-style reliability, dial-up performance (or worse)</div id="right"></font id="size2">
<font size="1">“If our government ever goes bad, as sometimes happens in a democracy... As we extrapolate our [surveillance] technologies into the future, if the incumbency has that political advantage over their opposition, then if a bad government ever comes to power, <b>it may be the last government we ever elect</b>.” See http://privacy.4mg.com </font id="size1">
 
Hi all,

These issues are fully covered in Chapter 6 of Cyberlaw@SA - The Law of the Internet in South Africa (Second Edition).

The chapter may be downloaded from: http://www.legalsentry.co.za/downloads/cyberlaw/cyberlaw-2-chapter-6.pdf

Cheers,

Reinhardt Buys
 
I have downloaded the full survey results and its ironic that only the Telkom web site achieved 100% compliance. Ouch!

Question: If I notice that a company has not implemented Chapter VII strictly, and is doing online transactions, can I report them to the police? How do they get prosecuted?

Also, if I feel that my privacy is being violated by a company such as TransUnionITC flouting or ignoring Section 51 of the ECT Act, what redress do I have? Can they be punished?

<hr noshade size="1">
Donn Edwards <font size="2"><div align="right">MyWireless: Diva-style reliability, dial-up performance (or worse)</div id="right"></font id="size2">
<font size="1">“If our government ever goes bad, as sometimes happens in a democracy... As we extrapolate our [surveillance] technologies into the future, if the incumbency has that political advantage over their opposition, then if a bad government ever comes to power, <b>it may be the last government we ever elect</b>.” See http://privacy.4mg.com </font id="size1">
 
donn

this whole compliance thing is a little confusing [:)]

no one can prosecuted for not following chapter 7 - there is no crime or criminal penalties for non-compliance with the chapter; rather the remedies are given to consumers (natural persons) who can get an extended cooling-off period within which they may return goods or stop the supply of services (there are lots of exceptions for different goods and services) + they are given a right to proceed against the web site for any loss they may suffer as a result of the site failing to offer security in line with industry standards

ask yourself how much of a big deal this actually is?

the exception to the above is criminal charges may be pressed where spam is sent that does not comply with the requirements set out in section 45 (opt-out link + revelation of source where requested)

pretty much the same can be said for the privacy - the principles listed in chapter 8 of the act are voluntary...they will only become binding where they are contained in a contract or privacy policy which is properly entered into between you as a user and a web site

check out ITC's privacy policy - [V]just checked...link is not working....your best bet is probably the Credit Bureau Association tel: +27 (11) 886-8519, fax: +27 (11) 789-6080. Visit the website at www.cba.co.za - never tried them myself but pretty sure that they get lots of calls



there are no experts - we are all flying by the seats of our pants
 
The CBA and TransUnionITC are completely useless - they have totally stonewalled all my enquiries. That's why I was hoping to take action against them some other way.

I will be writing an article about them on my Privacy site soon. They care only about their privacy, not their customers', in spite of their public statements to the contrary. And they are quite happy to let their subscribers access your or my contact details without even asking any questions. If you do a "trace" or an "address update" they don't even record the fact. It sucks!

<hr noshade size="1">
Donn Edwards <font size="2"><div align="right">MyWireless: Diva-style reliability, dial-up performance (or worse)</div id="right"></font id="size2">
<font size="1">“If our government ever goes bad, as sometimes happens in a democracy... As we extrapolate our [surveillance] technologies into the future, if the incumbency has that political advantage over their opposition, then if a bad government ever comes to power, <b>it may be the last government we ever elect</b>.” See http://privacy.4mg.com </font id="size1">
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by donn</i>
<br />The CBA and TransUnionITC are completely useless - they have totally stonewalled all my enquiries. That's why I was hoping to take action against them some other way.<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

Hi Donn,

I would like to share my views on these guys.
I have a serious case with them where they recorded some info about me in reverse - Mortgagee vs Mortgagor.
Cost me big, big time.
They admitted their error and had the cheek to say:
"Thanks for pointing out our mistake"

"We do not enter into discussions iro claims against us"
On pushing the point they:
Sent me a letter denying everything I have in writing.

I have started a new topic -

http://www.myadsl.co.za/forum/topic.asp?TOPIC_ID=5337
 
Top
Sign up to the MyBroadband newsletter
X