Be aware of privacy and cybercrimes issues

Issue 5 2022 Security Services & Risk Management, Information Security, Retail (Industry)

The acceleration of the fourth industrial revolution due to the COVID-19 pandemic has contributed to our general understanding of artificial intelligence (AI). AI is no longer viewed as a creation of science fiction. Instead, it is now understood in relation to its capabilities that allow machines to perform tasks that require human intelligence.


Wendy Tembedza.

Specifically, AI functions by using complex algorithms to assess large amounts of data and gain insights from the data. The continuous ingestion of data teaches the AI tool to identify patterns and provide insights that can be predictive in nature. Increasingly, retailers are seeing the benefits of using these AI capabilities to better service consumers.

Personalised retail achieved through AI is redefining customer shopping trends. AI can help deliver enhanced customer experiences by making better product suggestions, enabling faster checkouts, and facilitating more convenient in-person shopping.

An example of AI in retail can be seen in the use of facial and voice recognition. The SPD Group, a London-based e-commerce solutions company, has developed a system for product suggestions based on tracking a customer’s location and actions in-store. The system analyses video footage from cameras, identifies customers in frames and tracks the customer’s location in the store.

Walmart Tesco, and many other established retail brands, use Google or Amazon AI technology to provide customers with simple and quick voice searches. For example, the introduction of Walmart Voice Over by Walmart and Google allows customers to simply say “Hey Google, talk to Walmart and add milk to my cart” to their Google Assistant. The specific milk the customer regularly buys is then added automatically to the customer’s online cart.

Retailers are also using AI in virtual fitting rooms which are a great way for customers find the perfect outfit while saving time. A virtual fitting kiosk from Me-Ality can scan a customer in 20 seconds and measure 200 000 points of their body in this period. Companies like Levi’s and Gap have installed these scanners in selected stores and have seen a notable increase in sales as a result.

Locally, Superbalist.com recently launched Fit Finder – the first South African retailer to do so. Consumers know all too well that certain brands do not always run true to size. Fit Finder, developed by Fit Analytics GmbH, is an intuitive tool that assists consumers shopping online to make accurate sizing choices by answering a series of size- and brand-related questions. Fit Finder then uses the responses, along with sale and return records to suggest the correct size.

The viability of AI-driven consumerism depends on retailers’ ability to show they can process personal data responsibly. While the use of AI creates opportunities for retailers, the deployment of any AI tool in the South African retail context must be carefully scrutinised for compliance with data protection laws. AI tools should be configured and operate in such a way that they help the retailer to meet its obligations under the Protection of Personal Information Act, 4 of 2013 (PoPIA). For example, the use of facial recognition AI meets the definitional requirements of personal information regulated by PoPIA. Retailers will therefore need to be comfortable that their chosen tool includes appropriate controls to reduce the risk of unauthorised access to the relevant data.

Retailers must also be aware of the implications of the Cybercrimes Act, 19 of 2020 (Cybercrimes Act) on their operations. The Cybercrimes Act creates offences in relation to cybercrime. AI requires access to vast volumes of data, which results in an increased risk of cybercrimes. Cybersecurity is essential as a prerequisite and enabler of AI processing. It is best practice for retailers to put measures in place to reduce the risk of the occurrence of an offence contemplated in the Cybercrimes Act, for example, measures to prevent the unlawful access to, or interception of data. Certainly, retailers should be alive to the reputational consequences of a failure to put measures in place to guard against the identified cybercrimes and should understand that their AI tools should be configured in such a way as to assist in this protection.

AI can have a significant positive impact on how retailers deliver personalised customer experiences. It has been shown that these experiences can result in retailers not only retaining their existing customer base, but also gaining new customers. However, when implementing AI retailers must be cognisant of their obligations under PoPIA and the Cybercrimes Act.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
The post-Q1 security checklist
Asset Management Security Services & Risk Management
By this time of year, employees have changed jobs or roles, suppliers may have changed, and devices have moved between offices, homes, and sites. This is the right time for businesses to run a practical post-Q1 security check.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Surge in AI-enabled cybercrime and a 389% increase in ransomware
News & Events Information Security
Cybercrime no longer functions as a series of isolated campaigns; it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...
Excellerate Services sets a new standard
News & Events Security Services & Risk Management
Excellerate Services relies on specialist expertise and the sophistication of its operations deployment and management. Central to this is an investment in smarter, data-driven operations through the Velocity and Performance Centre platforms.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.