Truecaller Faces Complaint Over Alleged POPIA Violations in South Africa

Truecaller
Truecaller

The Information Regulator of South Africa has confirmed receiving a formal complaint alleging that caller ID and spam-blocking app Truecaller is violating multiple sections of the Protection of Personal Information Act (POPIA).

The complaint, following an anonymous tip-off, is currently under review. The regulator has stated that the matter is within the timeframe for processing and will soon be assigned to an investigator.

“We are still within the timeframe to process the complaint and allocate it to an investigator, who will then engage further with the complainant and the responsible party against whom the complaint was lodged,” said Nomzamo Zondi, spokesperson for the Information Regulator. “Therefore, we are unable to respond to the other questions at this time.”

The identity of the complainant has not been disclosed.

How Truecaller Operates

Truecaller, a widely used app, leverages user-provided data to identify unknown callers and block spam calls or messages. Upon registration, users provide their names and phone numbers, which are then made available to other Truecaller users for caller identification—a process that aligns with data privacy laws, as users explicitly consent to the use of their data.

The potential breach arises from Truecaller’s practice of accessing users’ address books. When users permit the app to upload their phone contacts, the names and numbers of individuals not registered on Truecaller can be added to its database without their explicit consent. Under POPIA, Truecaller may be obligated to notify each third party whose data has been uploaded in this manner.

Background and Past Criticism

The complaint adds to mounting scrutiny surrounding Truecaller’s practices. A 2022 report by Viceroy Research accused the Sweden-based company of operating as adware and spyware, citing its decision to relocate data servers from Europe to India prior to the implementation of the General Data Protection Regulation (GDPR).

“GDPR threatened Truecaller’s spyware features, which feed the spam detection service. In response, Truecaller moved all its data servers and substantially all of its operations to India where management appear to believe it is safe from legislation designed to protect the privacy of its customers,” the Viceroy report stated.

The report argued that such measures would ultimately make the app obsolete as global data privacy regulations strengthen.

Balancing Privacy and Spam Prevention

This case presents a unique challenge for the Information Regulator: safeguarding individuals’ data privacy under POPIA while recognizing the value Truecaller provides in combating spam calls and messages.

Truecaller remains one of the most effective tools in helping users fight the growing issue of robo-calls and spam communication. The outcome of this investigation could set a significant precedent for balancing data privacy rights and the need for technological solutions against spam.

Truecaller has been approached for comment regarding the allegations but has not responded at the time of publication.