Search legal guides

Search MJ Kotze Inc legal guides and articles

Data, Privacy & Website

Acceptable Use Policy (AUP) in South Africa

The rulebook behind every website, app, network and SaaS platform — and the South African law (ECTA, the Cybercrimes Act and the take-down regime) that decides when your suspension, termination and content-removal rights actually hold.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

What is an Acceptable Use Policy (AUP)?

An Acceptable Use Policy (AUP) is a set of rules that govern how users may and may not use a website, online platform, application, network or IT service. It lists the prohibited conduct — things like sending spam, posting unlawful or infringing content, hacking or probing the system, distributing malware, harvesting data, harassment, or reselling access — and sets out the operator’s right to suspend or terminate access and remove content when those rules are broken. You see an AUP as a standalone "Acceptable Use Policy" or "Fair Use Policy", as a clause inside a website’s Terms of Use or a SaaS subscription agreement, in an internet service provider’s (ISP) or hosting provider’s customer terms, or as the staff IT/email/internet policy in an employer’s workplace. In South African law an AUP is not created by a single dedicated statute — it is, at base, a piece of contract: a set of terms that becomes binding once the user accepts them. What gives it real teeth is the surrounding statutory framework. The Electronic Communications and Transactions Act 25 of 2002 (ECTA) recognises electronic agreements and click-wrap acceptance, regulates unsolicited commercial communications, and gives hosts and intermediaries a take-down mechanism for unlawful content. The Cybercrimes Act 19 of 2020 turns much of the conduct a typical AUP forbids — unauthorised access, interception, interference with data — into criminal offences. And where the user is a consumer, the Consumer Protection Act 68 of 2008 controls how harshly you can word the suspension, liability and indemnity provisions.

Is an Acceptable Use Policy legally binding and enforceable in South Africa?

Yes — an AUP is enforceable in South Africa provided the user accepted it and its terms are not contrary to public policy. An AUP has no special standing of its own; it binds because it forms part of a contract between the operator and the user. The Electronic Communications and Transactions Act 25 of 2002 removes any doubt that an electronically concluded agreement is valid: section 22 provides that "an agreement is not without legal force and effect merely because it was concluded partly or in whole by means of data messages", so a click-wrap "I accept the Acceptable Use Policy" tick-box, or a browse-wrap notice that continued use signifies acceptance, can validly incorporate the AUP into the contract. The usual common-law incorporation rules still apply: terms in a signed or clearly accepted document bind the user (the caveat subscriptor principle), while unsigned terms (a link in a footer, a notice on a sign-up page) bind only if the operator took reasonable steps to bring them to the user’s attention before contracting. Beyond contract, an AUP’s prohibitions track the criminal law: the Cybercrimes Act 19 of 2020 makes unlawful access (section 2), unlawful interception of data (section 3) and unlawful interference with data or a computer program (section 5) offences — so a user who breaches an AUP by hacking or scraping a protected system is not just in breach of contract but potentially committing a crime. ECTA’s Chapter XI gives hosts and intermediaries a powerful enforcement and protection layer: a host that hosts user content is shielded from liability for that content under section 75 provided it acts to remove or disable unlawful material on receiving a valid take-down notification under section 77, and section 78 confirms there is no general duty to monitor. There is a limit on enforceability where the user is a consumer: under the Consumer Protection Act 68 of 2008, any clause limiting the operator’s liability, demanding an indemnity, or imposing a one-sided suspension right must be fair (section 48) and, where it limits risk or liability, must be drawn to the consumer’s attention in plain language before they contract (section 49). The practical bottom line: a properly accepted, fairly worded AUP is fully enforceable — the operator can suspend, terminate and remove content for breach — but the suspension and liability clauses must be accepted and fair, not buried or punitive.
An agreement is not without legal force and effect merely because it was concluded partly or in whole by means of data messages. [s 75] A service provider that provides a service that consists of the storage of data provided by a recipient of the service, is not liable for damages arising from data stored at the request of the recipient of the service, as long as the service provider … does not have actual knowledge that the data message or an activity relating to the data message is infringing the rights of a third party … and … upon receipt of a take-down notification referred to in section 77, acts expeditiously to remove or to disable access to the data.
Electronic Communications and Transactions Act 25 of 2002, s 22 (validity of electronic agreements) and ss 75–78 (host liability limitation and take-down)
Any person who unlawfully and intentionally accesses a computer system or a computer data storage medium, is guilty of an offence. [s 3] Any person who unlawfully and intentionally intercepts data … within or which is transmitted to or from a computer system, is guilty of an offence.
Cybercrimes Act 19 of 2020, ss 2–5 (unlawful access, interception of data, and interference with data or a computer program)
A supplier must not … supply … any goods or services … on terms that are unfair, unreasonable or unjust. [s 49] The fact, nature and effect of [a limitation, assumption-of-risk or indemnity] provision … must be drawn to the attention of the consumer … in a conspicuous manner and form that is likely to attract the attention of an ordinarily alert consumer … before … the consumer enters into the transaction.
Consumer Protection Act 68 of 2008, ss 48–49 (unfair terms; notice required for limitation, risk and indemnity provisions)

When you need a Acceptable Use Policy

  • You run a website, online platform, marketplace, forum or SaaS application where users can sign up, post content, upload data or interact with each other — and you need clear, enforceable rules about what they may and may not do, plus the right to suspend or remove on breach.
  • You host user-generated content (comments, listings, reviews, files) and want to rely on ECTA’s section 75 host liability shield — which depends on having a take-down mechanism and acting on valid section 77 notifications, both of which an AUP operationalises.
  • You provide an internet, hosting, connectivity or telecommunications service (an ISP or network operator) and must define prohibited use — spam, illegal content, network abuse, bandwidth limits — and the conditions for throttling, suspension or disconnection.
  • You are an employer giving staff access to company email, internet, devices or systems, and need a workplace AUP (IT / email / internet-use policy) that sets the rules, supports lawful monitoring and grounds disciplinary action for misuse.
  • You licence an API, app or developer platform and need to bind users to rate limits, anti-scraping, anti-reverse-engineering, AI-training restrictions and security rules, with suspension as the remedy for abuse.

What a Acceptable Use Policy should contain

1

Scope and definitions

States exactly what the AUP covers — the website, app, network, account or service — and who is bound (registered users, visitors, the account holder and everyone using its credentials). A clear scope clause prevents arguments that a particular user, sub-user or use was never covered, and ties the AUP to the main Terms of Use or subscription agreement.

2

Prohibited conduct (the heart of the AUP)

Lists the banned uses in concrete terms: sending spam or unsolicited commercial communications (electronic direct marketing is regulated by POPIA section 69), posting unlawful, defamatory, infringing or harmful content, hacking, scanning or unauthorised access, distributing malware, scraping or harvesting data, circumventing security or rate limits, and harassment. Mapping these to the Cybercrimes Act offences makes clear that breach can be both a contractual and a criminal matter.

3

User-generated content and intellectual property

Allocates ownership and licence of content users post, requires users to warrant they have the rights to it, and prohibits infringing or unlawful material. This clause underpins your ECTA Chapter XI position: it is the contractual basis for removing content and for the take-down workflow that keeps your section 75 host immunity intact.

4

Take-down and reporting (ECTA section 77) mechanism

Explains how a complainant can report unlawful or infringing content and how the operator will respond. A take-down notification under section 77 of ECTA must, among other things, identify the complainant, the right infringed, the material and its location, and contain the prescribed statements — so the AUP should signpost the operator’s designated agent (often via its recognised industry body, such as ISPA) and the process for acting expeditiously on a valid notice.

5

Suspension, termination and other enforcement remedies

Sets out the operator’s right to remove content, suspend or throttle, or terminate accounts for breach — and whether warning is given first. For consumers this right must be fair under CPA section 48 and cannot strip statutory cancellation rights; a clause allowing immediate, no-notice termination for any trivial breach risks being struck down as unreasonable or one-sided.

6

Monitoring, fair-use and acceptable-use thresholds

Reserves the operator’s right to monitor and investigate suspected breaches (subject to POPIA and, in an employment setting, the Regulation of Interception of Communications Act), and sets fair-use or capacity limits for "unlimited" plans. ECTA section 78 confirms an intermediary has no general duty to monitor, so this is a discretionary right, not an obligation that defeats the host immunity.

7

Limitation of liability and indemnity

Caps the operator’s exposure for user conduct and requires users to indemnify the operator for claims arising from their breach. Against a consumer these are exactly the clauses CPA section 49 polices: they must be in plain language and conspicuously flagged before acceptance, and section 51 makes any attempt to exclude liability for the operator’s own gross negligence void.

8

Changes, incorporation and acceptance

Records how the user accepts the AUP (click-wrap "I accept", or notice that continued use means acceptance — valid under ECTA section 22), how the operator may amend it, and how changes are notified. Without a workable acceptance and amendment mechanism, an updated AUP may never bind existing users.

9

Governing law, jurisdiction and dispute resolution

Chooses South African law and a forum, and may add a notice-and-cure or arbitration step before suspension or litigation. The CPA still cannot be contracted out of for consumers, and a clause forcing a consumer into an unduly inconvenient forum may be challenged as unfair under section 48.

Acceptable Use Policy vs Terms of Use / Terms of Service in South African law

FeatureAcceptable Use Policy (AUP)Terms of Use / Terms of Service
Core purposeDefines permitted and prohibited conduct and the enforcement remedies (suspension, take-down, termination)The full contract governing the relationship — accounts, fees, IP, liability, warranties, termination
FocusBehaviour: what users may and may not do with the serviceThe whole deal: rights, obligations and commercials between operator and user
Where it sitsOften a standalone policy referenced by, or a section inside, the Terms of UseThe umbrella agreement the AUP plugs into
Statutory anchorsECTA (take-down, spam), Cybercrimes Act (offences it mirrors), POPIA (monitoring/data)ECTA (e-contracts), CPA (consumer fairness, ss 48–51), common law of contract
Typical remedy for breachContent removal, account suspension, throttling or terminationDamages, cancellation and the general contractual remedies

Common South African pitfalls

  • Treating the AUP as a notice rather than accepted contract terms. An AUP only binds a user if it was accepted — a signed or click-wrapped "I accept", or reasonable notice before use. ECTA section 22 validates electronic acceptance, but an AUP merely linked in a footer that the user never engaged with may not be incorporated, leaving you unable to enforce suspension or termination.
  • Drafting a one-sided or punitive suspension/termination clause against consumers. CPA section 48 prohibits terms that are unfair, unreasonable or unjust, and section 49 requires limitation, risk and indemnity clauses to be conspicuously flagged in plain language. A clause allowing instant, no-notice termination plus forfeiture of pre-paid fees for any breach is a classic candidate to be struck down.
  • Relying on ECTA’s host immunity without operating a take-down process. The section 75 liability shield for user content is conditional: it depends on not having actual knowledge of unlawful content and acting expeditiously once a valid section 77 take-down notice is received. An AUP that promises a take-down mechanism the operator does not actually run can forfeit the very protection it was meant to secure.
  • Confusing a take-down notice with a court order. A section 77 notification triggers a private removal process; it does not itself make content unlawful. Acting on an abusive or bad-faith notice — or refusing a valid one — carries risk, so the AUP and internal process should require notices to contain the prescribed particulars before content is removed.
  • Ignoring POPIA and interception law when you reserve monitoring rights. Logging, scanning or intercepting user or staff communications engages the Protection of Personal Information Act 4 of 2013 and, for live interception, the Regulation of Interception of Communications Act. A blanket "we may monitor everything" line will not displace those statutory duties — monitoring must have a lawful basis and proportionate safeguards.
  • Forgetting the spam and direct-marketing rules. Prohibiting users from sending spam is good, but the operator’s own electronic direct marketing must comply with POPIA section 69 (consent / existing-customer rules for direct marketing by unsolicited electronic communication). An AUP that polices users while the operator itself spams undermines both compliance and credibility.

Frequently asked questions

Is an Acceptable Use Policy legally binding in South Africa?

Yes, once the user has accepted it. An AUP binds as part of your contract terms — through a click-wrap "I accept", a signature, or reasonable notice that using the service means accepting the rules. ECTA section 22 confirms an electronically concluded agreement is valid, so a properly presented and accepted AUP lets you enforce suspension, content removal and termination for breach.

What is the difference between an Acceptable Use Policy and Terms of Use?

Terms of Use are the full contract governing the relationship — accounts, fees, intellectual property, liability and termination. An Acceptable Use Policy is narrower: it focuses on user behaviour, listing prohibited conduct and the operator’s enforcement remedies. In practice the AUP is often a standalone policy referenced by, or a section within, the Terms of Use; both should be drafted to work together.

What conduct should an Acceptable Use Policy prohibit?

Typically: spam and unsolicited commercial communications; unlawful, defamatory or infringing content; hacking, scanning or unauthorised access; distributing malware; scraping or harvesting data; circumventing security or rate limits; and harassment. Many of these mirror offences under the Cybercrimes Act 19 of 2020 — such as unlawful access (section 2) and interference with data (section 5) — so a breach can be both a contractual and a criminal matter.

How does the ECTA take-down notice procedure work?

Under section 77 of ECTA, a complainant who believes hosted content is unlawful sends the host (or its designated agent) a written take-down notification containing the prescribed particulars — the complainant’s details, the right infringed, the material and its location, and the required statements. If the host acts expeditiously to remove or disable the content, section 75 protects it from liability. The host has no general duty to monitor content under section 78.

Can I suspend or terminate a user’s account under my AUP?

Yes, if the AUP gives you that right and it was validly accepted. You can suspend, throttle, remove content or terminate for breach. But where the user is a consumer, the clause must be fair under CPA section 48 and cannot remove statutory cancellation rights — an instant, no-notice termination with forfeiture of pre-paid fees for a trivial breach risks being struck down as unreasonable or one-sided.

Does the Cybercrimes Act apply to acceptable-use breaches?

Often, yes. The Cybercrimes Act 19 of 2020 makes unlawful access (section 2), unlawful interception of data (section 3) and unlawful interference with data or a computer program (section 5) criminal offences. So a user who breaches your AUP by hacking, intercepting or tampering with a protected system is not only in breach of contract — they may be committing a crime, which strengthens both your enforcement position and any report to the authorities.

Do I need an Acceptable Use Policy if I already have website terms and conditions?

Not strictly — you can fold acceptable-use rules into your Terms of Use. But a dedicated AUP is clearer, easier to update, and easier to enforce, especially for platforms with user-generated content, ISPs and SaaS providers. It also operationalises the take-down and prohibited-conduct rules that keep your ECTA section 75 host immunity intact, which a general terms document may not address in enough detail.

Should an attorney draft my Acceptable Use Policy?

Yes — because the clauses that matter most (suspension, take-down, liability caps and indemnities) are exactly the ones the CPA polices and on which your ECTA host immunity depends, and a clause that is invalid is worse than none. MJ Kotze Inc drafts and reviews Acceptable Use Policies on a fixed fee, so you know the cost up front and the prohibited-conduct, take-down and enforcement provisions are built to hold under ECTA, the Cybercrimes Act and the CPA.

Sources & authority

This guide is general information, not legal advice. It reflects the law as at June 2026.

Get your Acceptable Use Policy reviewed or drafted

Upload an existing document for a fixed-fee review, or have a bespoke Acceptable Use Policy drafted for your business — personally, by a senior corporate and commercial attorney. No obligation to proceed.

Review: Fixed fee from R5 250 (excl. VAT) · 24-hour turnaroundDraft: Fixed fee from R5 100 (excl. VAT)

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.