The Labour Court in Cape Town has found that a CCMA commissioner misdirected himself when he ruled that the dismissal of a National Student Financial Aid Scheme (NSFAS) employee was substantively unfair after she repeatedly forwarded confidential work emails to her personal Gmail account.
In the matter of National Student Financial Aid Scheme v Commission for Conciliation, Mediation and Arbitration and Others, Acting Judge Coen De Kock considered an application by NSFAS to review and set aside a CCMA arbitration award that had ordered the reinstatement of former employee Zenobia Abrahams.
Abrahams, who worked as an Accountant: Budgeting and Expenditure and served as a Public Servants Association shop steward, was dismissed in September 2023 after a disciplinary hearing found that she had, between March and October 2022, forwarded or blind-copied nine work emails containing NSFAS information to her personal email account.
The CCMA commissioner, C M Bennett, later ruled that while the dismissal was procedurally fair, it was substantively unfair. The commissioner ordered Abrahams’ retrospective reinstatement with full benefits and awarded her backpay totaling R1.045 million, equivalent to 20 months of remuneration.
However, NSFAS challenged the ruling, arguing that the commissioner misunderstood the nature of the misconduct and applied the wrong legal test.
Central question before the court
The case centred on whether Abrahams’ actions constituted the negligent or intentional disclosure of confidential information, an offence that NSFAS’s disciplinary code identifies as warranting dismissal for a first offence, or whether her conduct amounted merely to a failure to comply with internal policies, which ordinarily attracts a final written warning.
ALSO READ: NSFAS: From beacon of hope to symbol of state failure
It was common cause that Abrahams had forwarded confidential work emails to a personal account outside NSFAS’s network. The dispute concerned how that conduct should be characterised.
The commissioner found that no “disclosure” had occurred because Abrahams was already familiar with the information and could not be regarded as an external party. He also reasoned that the risk of the information reaching unauthorised individuals was merely possible rather than probable.
Court finds commissioner asked wrong question
The Labour Court found that the commissioner focused on whether confidential information had been shared with an outside third party rather than examining the misconduct that was actually charged.
According to the judgement, the disciplinary charge was based on the unauthorised transfer of sensitive information to a personal email account outside the employer’s controlled environment. NSFAS relied on provisions in its Information Security Policy that specifically prohibit employees from forwarding work-related emails to personal accounts.
Judge De Kock noted that the commissioner relied on considerations relevant to a different type of misconduct, namely disclosure to unauthorised outsiders, which was not the charge that Abrahams faced.
ALSO READ: NSFAS board reinstated after court suspends administrator Mathebula’s appointment
The court pointed out that the relevant policy distinguishes between forwarding work emails to personal accounts and disclosing confidential information to unauthorised individuals. While the latter requires an external recipient, the former does not.
“The gravamen of the charge,” the court held, “is therefore the placing of confidential information onto a personal platform outside the employer’s control.”
Misdirection on risk assessment
The court also criticised the commissioner’s conclusion that the risk of harm needed to be probable rather than merely possible before it could justify disciplinary action.
NSFAS argued that, as a public entity responsible for large volumes of student information, it was entitled to impose strict controls on the movement of confidential data outside its secure systems. The court appeared to accept that transferring sensitive information outside an employer-controlled environment creates risks that disciplinary policies are intended to prevent, irrespective of whether actual harm can be shown.
- The Labour Court found that a CCMA commissioner misdirected himself by ruling Zenobia Abrahams' dismissal from NSFAS was substantively unfair after she forwarded confidential work emails to her personal Gmail account.
- Abrahams was dismissed in September 2023 for forwarding or blind-copied nine confidential NSFAS emails between March and October 2022, which violated NSFAS's Information Security Policy.
- The CCMA commissioner had ruled the dismissal procedurally fair but substantively unfair, ordering her reinstatement and backpay of R1.045 million, equivalent to 20 months of remuneration.
- The Labour Court held the commissioner wrongly focused on whether confidential information was shared with an external third party, while the actual charge was unauthorized transfer of confidential information to a personal platform outside NSFAS's control.
- The court rejected the commissioner's view that risk of harm must be probable for disciplinary action, affirming that the mere possibility of harm from transferring sensitive data outside secure systems justifies strict disciplinary measures.
In the matter of National Student Financial Aid Scheme v Commission for Conciliation, Mediation and Arbitration and
Abrahams, who worked as an Accountant:
However, NSFAS challenged the ruling, arguing that the commissioner misunderstood the nature of the misconduct and applied the wrong legal test.
ALSO READ: NSFAS: From beacon of hope to symbol of state failure
It was common cause that Abrahams had forwarded confidential work emails to a personal account outside NSFAS's network.
Judge De Kock noted that the commissioner relied on considerations relevant to a different type of misconduct, namely disclosure to unauthorised outsiders, which was not the charge that Abrahams faced.
ALSO READ: NSFAS board reinstated after court suspends administrator
"
NSFAS argued that, as a public entity responsible for large volumes of student information, it was entitled to impose strict controls on the movement of confidential data outside its secure systems.


