Overview: The Companies and Intellectual Property Commission (CIPC) enforces strict security protocols to reserve access for verified South African citizens and approved foreign nationals. The CIPC Terms and Conditions of Use and Notice 18 of 2024 explicitly define the legal nature of access credentials, establishing that a Customer Code is not merely a login tool, but a binding legal signature.
Key Legal Constraints
1) The Customer Code is a Legal Signature. CIPC equates a Customer Code login to a formal signature. Under the definitions in the Terms and Conditions (read with the Companies Act, 71 of 2008), “Signature” includes:
“(a) Biometrics, e.g. fingerprint verification; (b) One-time pins; or (c) Customer code login”
Implication: Using a code is legally synonymous with signing a document. Sharing the code is equivalent to handing someone a blank cheque signed in your name.
2) Strict Confidentiality & Liability. The Terms and Conditions (Section 12(3)) impose a non-delegable duty on the account holder:
- Non-Disclosure: “A customer is responsible for securing his/her customer login password and such customer login password may not be disclosed to unauthorised persons.”
- Sole Responsibility: “Such customer will be held responsible for all transactions performed with his/her login and password.”
3) Duty to Declare Breaches. There is a mandatory reporting obligation under Section 12(4)
“A customer must immediately notify CIPC in writing of any unauthorised use of his/her password or of any other breach of security.”
4) Criminal Liability for Misrepresentation: Software or third parties logging in using a person-specific username may violate Section 7(4) of the Terms and Conditions:
“It is a criminal offence in terms of the Companies Act, 71 of 2008 to submit any information that is misleading.”
Implication: Presenting a login as the actions of the account holder when it is in fact an unverified third party or a software bot may constitute “misleading information” regarding the submitter’s identity.
Summary and recommendation of CIPC customer code confidentiality
A final reminder on CIPC Customer code confidentiality. It is potentially unlawful (in the context of misrepresentation) and a potential material breach of contract to share CIPC credentials:
For Colleagues: If a colleague requires access, they should register their own free Customer Code. You can then appoint them as an intermediary, or they can file documents using their own code while listing you as the director/member.
For Directors: Never share your personal director login. Your company secretary or accountant must use their own practice number or customer code to file on your behalf to ensure the audit trail remains accurate.
