NIA issues new guidelines to protect personal data held by government agencies

The National Identification Authority (NIA) has issued binding guidelines governing how organisations that access data from the National Identity Register (NIR) must store, secure, and eventually dispose of that personal information, effective Thursday, March 19, 2026. The guidelines, issued under the authority of the National Identity Register Act, 2008 (Act 750) as amended by Act 950 of 2017, are directed at so-called "user agencies", the banks, telecoms companies, government institutions, and other bodies that routinely pull personal data from the NIR for administrative and verification purposes.