When Data Walks Out the Door: What Zulu Nyala v Beukes Means for POPIA
The recent High Court decision in Zulu Nyala Game Ranch (Pty) Limited v Beukes and Another provides important guidance on how the Protection of Personal Information Act, 2013 (POPIA) applies within the employment context.
What happened?
A former employee used a client database (containing personal information such as contact details) obtained during employment to solicit business for a competing entity in his wife’s name.
The Court found that:
- The client database constituted personal information and confidential information and the employee’s use of this information was in contravention of the act and unlawful.
- The employee breached both contractual obligations and section 20 of POPIA, which requires confidentiality when processing personal information on behalf of an employer.
The court granted an interdict and ordered the deletion and return of the data.
Key POPIA Principles Highlighted
Employees can be “operators”
The Court confirmed that employees who process personal information act as operators under POPIA and are directly bound by confidentiality obligations.
Confidentiality extends beyond employment
POPIA obligations do not end when employment ends. Former employees may not retain, use, or disclose personal information obtained during employment.
Employers Rights and Responsibilities
This case reinforces that employers:
- Have the right to protect client data from misuse and unlawful competition
- May seek urgent legal relief (interdicts) where personal information is misused
- Must ensure clear confidentiality clauses, POPIA policies, and access controls are in place.
Key Takeaway
The Zulu Nyala judgment confirms that POPIA is not just a compliance exercise it creates real, enforceable obligations on both employers and employees.
For organisations the message is clear:
Strong governance, employee awareness, and robust data protection controls are essential to mitigate legal and reputational risk. Organisations should ensure that employment contracts are POPIA compliant by including clear confidentiality and data protection clauses within employment contracts that prohibit employees from retaining, copying, or using personal information after termination, and require the return or deletion of all data upon exit. These obligations must extend beyond employment. In line with section 20 of POPIA, organisations must also implement appropriate technical and organisational measures such as access controls, monitoring, data loss prevention, to safeguard personal information and prevent misuse.

