The new Act - which is not available to the public despite becoming law at the end of December - makes provision for stiff penalties for "decryption key holders" who fail to comply with a decryption order. These include 10-year jail sentences and R2 million fines for individuals, and fines of up to R5 million for companies.
A decryption order can be issued to anyone thought to be able to assist in decrypting a message, such as an e-mail, intercepted under the Act. Thanks to a broad definition of a decryption key, which includes any algorithm, code or password that can put a message in intelligible form, such an order could also be issued to the companies that make or distribute crypto software.