The critical role played by Internet Service Providers (ISPs) in the modern digital ecosystem
necessitates a clear and balanced legal framework that governs their rights and responsibilities. As
intermediaries that facilitate the flow of vast amounts of information, ISPs are uniquely positioned to
be exposed to potential liability for unlawful activities conducted by third parties using their services,
including copyright infringement, defamation, and other unlawful acts.¹ Recognizing this, the South
African legislature, through the Electronic Communications and Transactions Act 25 of 2002
(ECTA), established a specific legal regime to regulate the liability of service providers.² This
regime seeks to foster a predictable environment for the growth of electronic commerce by providing
a measure of protection, or a 'safe harbour', for ISPs, while also providing mechanisms for rights
holders to address unlawful content. This advice aims to provide 'Genius Gurus', a new entrant to the
South African ISP market, with a comprehensive legal clarification of this regime.
2.1 Identify and discuss the provisions under the Electronic Communications and Transactions
Act 25 of 2002 (ECTA) that give rise to the ISP regime in South Africa. (How a ‘service
provider’ is defined and regulated in terms of the ECTA).
The legal framework that gives rise to the ISP regime in South Africa is primarily encapsulated in
Chapter XI of the ECTA, which is expressly titled "Limitation of Liability of Service Providers".
This chapter creates a statutory framework designed to protect qualifying service providers from
certain liabilities that might arise from the actions of third parties or the automated, technical
functions they perform. The regime is largely based on a self-regulatory model, a key feature that
distinguishes it from a purely prescriptive legislative framework.³
The foundational element of this regime is the definition of a service provider. Section 70 of the
ECTA defines a "service provider" in broad terms as "any person providing information system
services".⁴ This definition is intentionally wide to encompass a diverse range of entities that facilitate
online activities. Further clarification is provided by scholarly analysis, which interprets "information
system services" to include the provision of connections, the operation of facilities for information
systems, the provision of access to information systems, the transmission or routing of data messages
between or among points specified by a user, and the processing and storage of data at the individual
request of the recipient of the service.⁵ This definition is broad enough to cover not only traditional
access providers but also entities providing services such as web hosting, caching, and information
location tools like hyperlinks.⁶
The eligibility for protection under the ISP regime is, however, contingent upon specific criteria.
Section 72 of the ECTA establishes two threshold requirements that a service provider must meet to
qualify for the limitations on liability provided by the chapter.
¹ See generally the discussion on the role of ISPs as intermediaries in the digital ecosystem in the study guide for LML411Q, particularly the sections on
service-provider liability for copyright infringement and the limitations introduced by the ECT Act.
² The Electronic Communications and Transactions Act 25 of 2002, Chapter XI, "Limitation of Liability of Service Providers".
³ Frans E Marx and Neil O'Brien, 'To Regulate or to Overregulate? Internet Service Provider Liability: The Industry Representative Body in Terms of the
ECT Act and Regulations' (2011) 32(3) Obiter 633, discussing the legislature's emphasis on self-regulation.
⁴ Electronic Communications and Transactions Act 25 of 2002, s 70.
⁵ 'Limitation of liability for ISP activities', Ellipsis, 3 January 2017, http://www.ellipsis.co.za/isp-issues/limitation-of-liability-for-isp-activites/.
⁶ Stanford CIS, 'WILMAP: South Africa', 15 February 2014, https://cyberlaw.stanford.edu/wilmap-south-africa/.