top of page

The SAPS Wants Facial Recognition Bodycams. The Tender Does Not Say What For, How Many, or Under What Law.

8 hours ago
7 min read

Reading the RFB 3286-2026 procurement as the governance failure it actually is, and what a responsible South African deployment would require.



Sign up for my Substack daily AI newsletter here.


See my AI Training course portfolio for corporate Business Leaders here.




The State Information Technology Agency published a tender that will define, for a generation, whether South Africans can walk through their own cities without their faces being matched against a database they cannot see, by a system they cannot question, under a legal framework that does not yet exist. The tender is for body-worn and dashboard cameras for the South African Police Service, procured over three years under reference RFB 3286-2026. The specific requirement that makes it consequential is that the cameras must be able to perform facial recognition. That is not a nice-to-have. It is a mandatory functional requirement. A bid that fails to comply is not evaluated further. What the tender does not say is what the police would use facial recognition for, how many cameras the state intends to buy, which database any face captured will be matched against, or under what law any of this is authorised. Those silences are not procurement oversights. They are the story.


CONTEXT AND BACKGROUND

The tender documents, first reported by TechCentral on 10 September 2026, describe a three-year contract for the “supply, delivery, support and maintenance of body-worn and vehicle dashboard cameras” and related software. The scope of work says the solution must give the SAPS the “ability to conduct facial recognition and integrate with various security platforms.” The video management software tying the fleet together must have analytics including “motion detection, facial recognition and licence plate recognition.” The dashboard cameras must carry embedded artificial intelligence, including automatic number plate recognition. Other requirements together describe a device that can record without anyone around it knowing: a continuous background recording function, buffers capturing 120 seconds either side of the record button, and the ability to turn off sound, alarm and light indicators.


Three of the four basic questions any responsible facial recognition procurement should answer are missing. The tender does not specify quantities. The pricing schedule asks for a unit price and reserves Sita’s right to negotiate quantities before the award and to “vary the scope with number and or capability of equipment to procure based on customer affordability.” That is not a procurement number. It is a signature on a blank cheque. The tender does not specify whether the facial recognition will operate in real time on live video streams as officers walk through public spaces, or retrospectively against captured footage in a controlled setting after a specific incident. Those are two fundamentally different systems with fundamentally different civil liberties implications, and the tender leaves the choice open. The tender also does not specify what reference database any captured face will be matched against. The Criminal Record Centre, the Department of Home Affairs National Population Register, an ad hoc watchlist maintained by SAPS itself, or some combination of all three, are legally distinct and administratively distinct choices. The tender is silent on all of them.


The tender is also silent on the legal basis for facial recognition. Under the Protection of Personal Information Act, biometric data is classified as Special Personal Information, which is subject to the enhanced prohibitions of sections 26 to 33 of the Act and can only be processed under specific exemptions. Section 6(1)(c) of the same Act excludes public-body processing for crime prevention only “to the extent that adequate safeguards have been established in legislation.” South Africa has no legislation setting out when an officer must switch a camera on, who may view the footage, how long it is kept, or whether a face may be matched against anything. The Information Regulator has already ruled on this specific clause with respect to the SAPS.


In an April 2023 enforcement notice concerning the circulation of Krugersdorp rape survivors’ details on WhatsApp, the regulator found the SAPS “did not meet the requirements for exclusion under section 6 (1) (c) (ii)” because it had “failed to demonstrate that it has any safeguards in place, let alone safeguards established in legislation.” The regulator’s reasoning applies directly to facial recognition. Without safeguards in legislation, the processing falls under POPIA and the regulator’s jurisdiction. That is a matter of settled law, not policy preference.


INSIGHT AND ANALYSIS

The temptation is to read this as a debate about whether facial recognition should be used by police at all. That is the wrong debate. Facial recognition, deployed responsibly, is a genuine investigative tool that can help law enforcement identify suspects in serious crimes, locate missing persons, and support prosecutions with evidence. The question is not whether South Africa should use it. The question is which facial recognition system, trained on which data, verified against which accuracy thresholds, matched against which specific database, used under which specific legal authorisations, subject to which oversight, and answerable to which authority when the system is wrong. The SAPS tender asks none of these questions.


The evidence for why they matter is well established. The United States National Institute of Standards and Technology has run the Face Recognition Vendor Test since 2018, and its work on demographic effects continues under what is now called the Face Recognition Technology Evaluation programme. The 2019 demographic-effects study, NISTIR 8280, tested 189 algorithms from 99 developers and found that a majority of them are more likely to misidentify people with darker skin, women and the elderly. The ongoing programme now covers nearly 200 algorithms from nearly 100 developers using 18 million images. The critical finding is not that all facial recognition is equally biased. It is that the most accurate algorithms show demographic differentials that are close to undetectable, while others show significant disparities. The technology can be procured well or badly, and the difference is measurable.


The consequences of procuring it badly are documented. The American Civil Liberties Union maintains a running list of more than a dozen wrongful arrests of individuals in the United States identified by police facial recognition systems, most of them Black Americans. Robert Williams was arrested in front of his wife and two young daughters in January 2020 after Detroit police used a facial recognition system that matched his driver’s licence photo to grainy footage of a shoplifter he was not. Porcha Woodruff, heavily pregnant, was arrested by the same department in February 2023 for a carjacking committed by someone who was not visibly pregnant. The system produced the match. Officers acted on it without corroboration. Innocent people spent hours in cells because a computer said something a human should have questioned.


The wrongful arrest cases are that principle failing in the specific way it fails when governance is absent. The technology is not the problem. The absence of the safeguards that would prevent an officer from acting on a match without corroboration, the absence of independent verification of the algorithms’ demographic accuracy, and the absence of a legal framework requiring both, is the problem. Every one of those safeguards is available to South Africa. None of them is in the SAPS tender.


IMPLICATIONS

The European Union has published the international benchmark for how a democratic society governs law enforcement facial recognition. The EU AI Act, which came into force with respect to prohibited practices on 2 February 2025, treats real-time remote biometric identification in publicly accessible spaces for law enforcement as prohibited by default, permits it only under three narrow exceptions with prior judicial authorisation, and classifies retrospective facial recognition and one-to-one identity verification as high-risk rather than prohibited. This is not a ban on facial recognition. It is a governance framework. It represents the position that democratic peer nations have arrived at after extensive negotiation and public debate. It is available to South Africa to study and adapt.


A responsible South African facial recognition deployment would specify several things the current tender does not. It would require the procured system to meet a specific NIST demographic-accuracy threshold, disaggregated by race, age and sex, verified independently rather than certified by the vendor. It would prohibit real-time identification in public spaces for law enforcement, following the EU model, and limit the technology to retrospective identification of specific individuals under judicial authorisation. It would name the specific offences for which facial recognition may be used. It would name the specific reference database against which faces may be matched, and would prohibit cross-departmental linkage to broader civic databases such as the Home Affairs population register without specific enabling legislation. It would require documented human corroboration and independent evidence before any arrest based on a facial recognition match. It would specify quantities so the public knows the scale of the deployment. It would place the whole framework under Popia section 6(1)(c) with adequate safeguards established in legislation, closing the gap the Information Regulator has already ruled the SAPS cannot ignore. Each of these safeguards is technically feasible. Each is politically achievable. None is in the current SAPS tender.


CLOSING TAKEAWAY

The SAPS is not about to procure a body camera. It is about to procure a surveillance capability. That is a legitimate thing for a state to consider, and there is a defensible case for facial recognition as a tool in specific circumstances, under specific legal constraints, with specific accountability mechanisms. But it is not a defensible thing to procure by tender when the tender does not say what the technology will be used for, how many will be deployed, which database will be searched, or under what law the deployment is authorised. The Information Regulator has already told the SAPS that POPIA section 6(1)(c) requires safeguards established in legislation, and the SAPS has none.


Between now and then, the Portfolio Committee on Police can invoke its powers under Section 56 of the Constitution to summon SITA and SAPS leadership and require them to explain why mandatory biometric capabilities were built into a procurement before Standard Operating Procedures, legislation and public consultation had been completed. The responsible actions available to Parliament, to the Information Regulator, and to the Minister of Police are to withdraw the current tender, publish the specific legal framework that would authorise it, and reissue the procurement with quantities specified, algorithmic accuracy thresholds specified, database restrictions specified, and rules of engagement specified. That is the difference between procuring a technology and building a surveillance capability. South Africa has a chance to make the distinction. The tender as it stands does not.


Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net




 
 
 

Comments


Leveraging AI in Human Resources ​for Organisational Success
CTU Training Solutions webinar

bottom of page