What is an Acceptable Use Policy (AUP)?
Is an Acceptable Use Policy legally binding and enforceable in South Africa?
“An agreement is not without legal force and effect merely because it was concluded partly or in whole by means of data messages. [s 75] A service provider that provides a service that consists of the storage of data provided by a recipient of the service, is not liable for damages arising from data stored at the request of the recipient of the service, as long as the service provider … does not have actual knowledge that the data message or an activity relating to the data message is infringing the rights of a third party … and … upon receipt of a take-down notification referred to in section 77, acts expeditiously to remove or to disable access to the data.”
“Any person who unlawfully and intentionally accesses a computer system or a computer data storage medium, is guilty of an offence. [s 3] Any person who unlawfully and intentionally intercepts data … within or which is transmitted to or from a computer system, is guilty of an offence.”
“A supplier must not … supply … any goods or services … on terms that are unfair, unreasonable or unjust. [s 49] The fact, nature and effect of [a limitation, assumption-of-risk or indemnity] provision … must be drawn to the attention of the consumer … in a conspicuous manner and form that is likely to attract the attention of an ordinarily alert consumer … before … the consumer enters into the transaction.”
When you need a Acceptable Use Policy
- You run a website, online platform, marketplace, forum or SaaS application where users can sign up, post content, upload data or interact with each other — and you need clear, enforceable rules about what they may and may not do, plus the right to suspend or remove on breach.
- You host user-generated content (comments, listings, reviews, files) and want to rely on ECTA’s section 75 host liability shield — which depends on having a take-down mechanism and acting on valid section 77 notifications, both of which an AUP operationalises.
- You provide an internet, hosting, connectivity or telecommunications service (an ISP or network operator) and must define prohibited use — spam, illegal content, network abuse, bandwidth limits — and the conditions for throttling, suspension or disconnection.
- You are an employer giving staff access to company email, internet, devices or systems, and need a workplace AUP (IT / email / internet-use policy) that sets the rules, supports lawful monitoring and grounds disciplinary action for misuse.
- You licence an API, app or developer platform and need to bind users to rate limits, anti-scraping, anti-reverse-engineering, AI-training restrictions and security rules, with suspension as the remedy for abuse.
What a Acceptable Use Policy should contain
Scope and definitions
States exactly what the AUP covers — the website, app, network, account or service — and who is bound (registered users, visitors, the account holder and everyone using its credentials). A clear scope clause prevents arguments that a particular user, sub-user or use was never covered, and ties the AUP to the main Terms of Use or subscription agreement.
Prohibited conduct (the heart of the AUP)
Lists the banned uses in concrete terms: sending spam or unsolicited commercial communications (electronic direct marketing is regulated by POPIA section 69), posting unlawful, defamatory, infringing or harmful content, hacking, scanning or unauthorised access, distributing malware, scraping or harvesting data, circumventing security or rate limits, and harassment. Mapping these to the Cybercrimes Act offences makes clear that breach can be both a contractual and a criminal matter.
User-generated content and intellectual property
Allocates ownership and licence of content users post, requires users to warrant they have the rights to it, and prohibits infringing or unlawful material. This clause underpins your ECTA Chapter XI position: it is the contractual basis for removing content and for the take-down workflow that keeps your section 75 host immunity intact.
Take-down and reporting (ECTA section 77) mechanism
Explains how a complainant can report unlawful or infringing content and how the operator will respond. A take-down notification under section 77 of ECTA must, among other things, identify the complainant, the right infringed, the material and its location, and contain the prescribed statements — so the AUP should signpost the operator’s designated agent (often via its recognised industry body, such as ISPA) and the process for acting expeditiously on a valid notice.
Suspension, termination and other enforcement remedies
Sets out the operator’s right to remove content, suspend or throttle, or terminate accounts for breach — and whether warning is given first. For consumers this right must be fair under CPA section 48 and cannot strip statutory cancellation rights; a clause allowing immediate, no-notice termination for any trivial breach risks being struck down as unreasonable or one-sided.
Monitoring, fair-use and acceptable-use thresholds
Reserves the operator’s right to monitor and investigate suspected breaches (subject to POPIA and, in an employment setting, the Regulation of Interception of Communications Act), and sets fair-use or capacity limits for "unlimited" plans. ECTA section 78 confirms an intermediary has no general duty to monitor, so this is a discretionary right, not an obligation that defeats the host immunity.
Limitation of liability and indemnity
Caps the operator’s exposure for user conduct and requires users to indemnify the operator for claims arising from their breach. Against a consumer these are exactly the clauses CPA section 49 polices: they must be in plain language and conspicuously flagged before acceptance, and section 51 makes any attempt to exclude liability for the operator’s own gross negligence void.
Changes, incorporation and acceptance
Records how the user accepts the AUP (click-wrap "I accept", or notice that continued use means acceptance — valid under ECTA section 22), how the operator may amend it, and how changes are notified. Without a workable acceptance and amendment mechanism, an updated AUP may never bind existing users.
Governing law, jurisdiction and dispute resolution
Chooses South African law and a forum, and may add a notice-and-cure or arbitration step before suspension or litigation. The CPA still cannot be contracted out of for consumers, and a clause forcing a consumer into an unduly inconvenient forum may be challenged as unfair under section 48.
Acceptable Use Policy vs Terms of Use / Terms of Service in South African law
| Feature | Acceptable Use Policy (AUP) | Terms of Use / Terms of Service |
|---|---|---|
| Core purpose | Defines permitted and prohibited conduct and the enforcement remedies (suspension, take-down, termination) | The full contract governing the relationship — accounts, fees, IP, liability, warranties, termination |
| Focus | Behaviour: what users may and may not do with the service | The whole deal: rights, obligations and commercials between operator and user |
| Where it sits | Often a standalone policy referenced by, or a section inside, the Terms of Use | The umbrella agreement the AUP plugs into |
| Statutory anchors | ECTA (take-down, spam), Cybercrimes Act (offences it mirrors), POPIA (monitoring/data) | ECTA (e-contracts), CPA (consumer fairness, ss 48–51), common law of contract |
| Typical remedy for breach | Content removal, account suspension, throttling or termination | Damages, cancellation and the general contractual remedies |
Common South African pitfalls
- Treating the AUP as a notice rather than accepted contract terms. An AUP only binds a user if it was accepted — a signed or click-wrapped "I accept", or reasonable notice before use. ECTA section 22 validates electronic acceptance, but an AUP merely linked in a footer that the user never engaged with may not be incorporated, leaving you unable to enforce suspension or termination.
- Drafting a one-sided or punitive suspension/termination clause against consumers. CPA section 48 prohibits terms that are unfair, unreasonable or unjust, and section 49 requires limitation, risk and indemnity clauses to be conspicuously flagged in plain language. A clause allowing instant, no-notice termination plus forfeiture of pre-paid fees for any breach is a classic candidate to be struck down.
- Relying on ECTA’s host immunity without operating a take-down process. The section 75 liability shield for user content is conditional: it depends on not having actual knowledge of unlawful content and acting expeditiously once a valid section 77 take-down notice is received. An AUP that promises a take-down mechanism the operator does not actually run can forfeit the very protection it was meant to secure.
- Confusing a take-down notice with a court order. A section 77 notification triggers a private removal process; it does not itself make content unlawful. Acting on an abusive or bad-faith notice — or refusing a valid one — carries risk, so the AUP and internal process should require notices to contain the prescribed particulars before content is removed.
- Ignoring POPIA and interception law when you reserve monitoring rights. Logging, scanning or intercepting user or staff communications engages the Protection of Personal Information Act 4 of 2013 and, for live interception, the Regulation of Interception of Communications Act. A blanket "we may monitor everything" line will not displace those statutory duties — monitoring must have a lawful basis and proportionate safeguards.
- Forgetting the spam and direct-marketing rules. Prohibiting users from sending spam is good, but the operator’s own electronic direct marketing must comply with POPIA section 69 (consent / existing-customer rules for direct marketing by unsolicited electronic communication). An AUP that polices users while the operator itself spams undermines both compliance and credibility.
Frequently asked questions
Is an Acceptable Use Policy legally binding in South Africa?
Yes, once the user has accepted it. An AUP binds as part of your contract terms — through a click-wrap "I accept", a signature, or reasonable notice that using the service means accepting the rules. ECTA section 22 confirms an electronically concluded agreement is valid, so a properly presented and accepted AUP lets you enforce suspension, content removal and termination for breach.
What is the difference between an Acceptable Use Policy and Terms of Use?
Terms of Use are the full contract governing the relationship — accounts, fees, intellectual property, liability and termination. An Acceptable Use Policy is narrower: it focuses on user behaviour, listing prohibited conduct and the operator’s enforcement remedies. In practice the AUP is often a standalone policy referenced by, or a section within, the Terms of Use; both should be drafted to work together.
What conduct should an Acceptable Use Policy prohibit?
Typically: spam and unsolicited commercial communications; unlawful, defamatory or infringing content; hacking, scanning or unauthorised access; distributing malware; scraping or harvesting data; circumventing security or rate limits; and harassment. Many of these mirror offences under the Cybercrimes Act 19 of 2020 — such as unlawful access (section 2) and interference with data (section 5) — so a breach can be both a contractual and a criminal matter.
How does the ECTA take-down notice procedure work?
Under section 77 of ECTA, a complainant who believes hosted content is unlawful sends the host (or its designated agent) a written take-down notification containing the prescribed particulars — the complainant’s details, the right infringed, the material and its location, and the required statements. If the host acts expeditiously to remove or disable the content, section 75 protects it from liability. The host has no general duty to monitor content under section 78.
Can I suspend or terminate a user’s account under my AUP?
Yes, if the AUP gives you that right and it was validly accepted. You can suspend, throttle, remove content or terminate for breach. But where the user is a consumer, the clause must be fair under CPA section 48 and cannot remove statutory cancellation rights — an instant, no-notice termination with forfeiture of pre-paid fees for a trivial breach risks being struck down as unreasonable or one-sided.
Does the Cybercrimes Act apply to acceptable-use breaches?
Often, yes. The Cybercrimes Act 19 of 2020 makes unlawful access (section 2), unlawful interception of data (section 3) and unlawful interference with data or a computer program (section 5) criminal offences. So a user who breaches your AUP by hacking, intercepting or tampering with a protected system is not only in breach of contract — they may be committing a crime, which strengthens both your enforcement position and any report to the authorities.
Do I need an Acceptable Use Policy if I already have website terms and conditions?
Not strictly — you can fold acceptable-use rules into your Terms of Use. But a dedicated AUP is clearer, easier to update, and easier to enforce, especially for platforms with user-generated content, ISPs and SaaS providers. It also operationalises the take-down and prohibited-conduct rules that keep your ECTA section 75 host immunity intact, which a general terms document may not address in enough detail.
Should an attorney draft my Acceptable Use Policy?
Yes — because the clauses that matter most (suspension, take-down, liability caps and indemnities) are exactly the ones the CPA polices and on which your ECTA host immunity depends, and a clause that is invalid is worse than none. MJ Kotze Inc drafts and reviews Acceptable Use Policies on a fixed fee, so you know the cost up front and the prohibited-conduct, take-down and enforcement provisions are built to hold under ECTA, the Cybercrimes Act and the CPA.
Sources & authority
- Electronic Communications and Transactions Act 25 of 2002 (consolidated) — ss 22, 71, 75, 77, 78
- Electronic Communications and Transactions Act 25 of 2002 (lawlibrary.org.za)
- Cybercrimes Act 19 of 2020 (lawlibrary.org.za) — ss 2, 3, 5, 14–16
- Cybercrimes Act 19 of 2020 (consolidated) — ss 2–5
- Consumer Protection Act 68 of 2008 (lawlibrary.org.za) — ss 48, 49, 51
- Protection of Personal Information Act 4 of 2013 (consolidated) — s 69 (direct marketing) and the security-safeguards duties
This guide is general information, not legal advice. It reflects the law as at June 2026.