Search legal guides

Search MJ Kotze Inc legal guides and articles

Software & Technology

Cloud Services Agreement (Clickwrap) in South Africa

The click-accepted master terms behind a SaaS or cloud product — a subscription right, not a sale; drafted to hold up under ECTA, kept on the right side of the CPA, and built to carry a Data Protection Addendum and SLA.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

What is a cloud services agreement?

A cloud services agreement is the core online contract a SaaS or cloud provider uses to govern a customer’s access to and use of a hosted service. In its most common form it is a clickwrap — a standard-form set of terms the customer accepts by ticking a box or clicking “I agree” before using the product — as opposed to a negotiated, signed master services agreement (MSA). The agreement grants a limited right to access and use the service for the subscription term: it is a licence or subscription, not a sale of software and not a perpetual licence. It typically sets the subscription fees and billing, an acceptable-use policy, the provider’s ownership of the platform and IP, the customer’s ownership of its own data, warranties and disclaimers, a limitation and exclusion of liability with a liability cap, and rights to suspend or terminate. Crucially, the cloud agreement is the master frame to which the operational addenda attach — a Data Protection Addendum dealing with personal information, a service level agreement (SLA) dealing with uptime and credits, and support terms — rather than burying those regimes inline. In South Africa the agreement is governed by the ordinary common law of contract, given electronic force by the Electronic Communications and Transactions Act 25 of 2002 (ECTA), and — where the customer is a “consumer” within its reach — constrained by the Consumer Protection Act 68 of 2008 (CPA).

Is a clickwrap cloud services agreement legally binding in South Africa?

Yes. A clickwrap cloud services agreement is binding in South Africa, both as an ordinary contract and by force of statute. The Electronic Communications and Transactions Act 25 of 2002 (ECTA) resolves the question that used to dog online terms: under section 11, information is not without legal force merely because it is in the form of a data message or is incorporated only by reference; under section 22, an agreement may be concluded wholly or partly by data messages, and an offer or acceptance can be expressed by a data message; and under section 24, a person’s assent is shown by a data message — so clicking “I agree” is valid acceptance. The practical consequence is that a clickwrap is enforceable provided the ordinary requirements of contract are met (consensus, lawful purpose, certainty) and the terms are reasonably accessible and genuinely assented to — terms hidden behind a buried link the customer never had a fair chance to read are vulnerable. Two SA-specific constraints then shape what the provider can actually enforce. First, the Consumer Protection Act 68 of 2008 (CPA) applies where the customer is a “consumer” within its reach — including a juristic person whose annual turnover or asset value is below the R2 million threshold — and then sections 48 to 52 strike down terms that are unfair, unreasonable or unjust, while section 49 requires that clauses limiting liability, assuming risk, or imposing indemnities be drawn to the consumer’s attention in plain language before acceptance. Pure business-to-business SaaS above that threshold is largely outside the CPA, which is itself a reason the clickwrap should record the customer’s status. Second, where the provider processes the customer’s personal information it acts as an “operator” under the Protection of Personal Information Act 4 of 2013 (POPIA) — which is exactly why a clickwrap cloud agreement is paired with a Data Protection Addendum rather than left to absorb the data terms inline.
Information is not without legal force merely because it is in a data message or incorporated by reference (s 11); an agreement may be concluded wholly or partly by data messages, and acceptance expressed by a data message (s 22); and a person’s assent may be expressed by a data message (s 24) — so a clickwrap "I agree" is valid acceptance of electronically presented terms.
Electronic Communications and Transactions Act 25 of 2002 (ECTA), ss 11, 22 and 24
Where the customer is a consumer (including a juristic person below the R2 million turnover/asset threshold), ss 48–52 prohibit unfair, unreasonable or unjust terms, and s 49 requires that terms limiting liability, assuming risk or imposing indemnities be brought to the consumer’s attention in plain and understandable language.
Consumer Protection Act 68 of 2008 (CPA), ss 48–52 and s 49
A cloud provider that processes a customer’s personal information on the customer’s behalf is an "operator", which must process only with the responsible party’s knowledge or authorisation and keep the information secure — duties handled in a Data Protection Addendum to the cloud agreement.
Protection of Personal Information Act 4 of 2013 (POPIA)

When you need a Cloud Services

  • When you launch a SaaS or cloud product and need standard-form terms every customer accepts by clicking "I agree" at sign-up — scalable, self-service onboarding without a signed contract per customer.
  • When you sell a hosted service to many small and mid-market customers and want one consistent, click-accepted rulebook governing access, fees, acceptable use, IP and liability.
  • When you need a master frame that a Data Protection Addendum, an SLA, and support terms can attach to, rather than burying data, uptime and support obligations inline.
  • When you must record the customer’s status — consumer or business — because that decides whether the Consumer Protection Act constrains your liability and unfair-terms clauses.
  • When your service processes customers’ personal information and you act as a POPIA operator, so the clickwrap must point to a Data Protection Addendum that sets the operator terms.
  • When a larger or regulated customer pushes back and wants to negotiate — that is the trigger to fall back from clickwrap to a signed master services agreement instead.

What a Cloud Services should contain

1

Grant of subscription right (licence, not sale)

Grant a limited, non-exclusive, non-transferable right to access and use the hosted service for the subscription term — expressly a subscription, not a sale of software and not a perpetual licence. Tie the right to the plan, user count or usage tier paid for, and confirm it ends when the subscription ends so the customer cannot claim a lasting entitlement to the platform.

2

Fees, billing and price changes

State the subscription fees, the billing cycle (monthly or annual), payment method, and what happens on non-payment. Set out how and when prices may change — typically on renewal with notice — and address taxes (VAT) and currency. For CPA-reach customers, price-increase and auto-renewal mechanics must be fair and clearly disclosed up front, not sprung on the customer.

3

Acceptable use and prohibited conduct

Define how the service may and may not be used — barring unlawful content, security circumvention, reverse engineering, resale, excessive load, and use that harms the platform or other customers. Link breach of acceptable use to the suspension and termination rights so the provider can act quickly against abuse without first proving loss.

4

IP ownership and customer data ownership

Confirm the provider owns the platform, software and all IP in it, and that the subscription grants no ownership. Equally confirm the customer owns its own data and content uploaded to the service, with the provider holding only the limited licence needed to host and operate the service. This split is what keeps a SaaS deal clean: provider keeps the product, customer keeps its data.

5

Data protection addendum and POPIA operator terms

Where the provider processes personal information for the customer it is a POPIA operator, so the clickwrap should incorporate a Data Protection Addendum rather than carry data terms inline. The addendum sets the operator obligations — processing only on instruction, security safeguards, sub-processors, breach notification, and return or deletion of data — and keeps the master agreement readable.

6

SLA, support and service commitments

Reference the service level agreement and support terms as addenda: uptime targets, service credits as the remedy for downtime, maintenance windows, and support response times. Keeping these in an SLA addendum lets the provider tune service commitments without reopening the whole agreement, and makes clear that credits — not open-ended damages — are the agreed remedy for missed targets.

7

Warranties, disclaimers and liability cap

Give a measured warranty (for example that the service will materially perform as described), then disclaim implied warranties to the extent permitted, exclude indirect and consequential loss, and cap aggregate liability — commonly at fees paid over a recent period. For CPA-reach customers these clauses must be brought to attention under s 49 and must not be unfair under ss 48–52, so the cap and exclusions need plain-language presentation, not fine print.

8

Term, renewal, suspension and effect of termination

Set the initial term and whether it auto-renews and how to cancel. Reserve the right to suspend for non-payment or acceptable-use breach, and to terminate for material breach or insolvency. On termination, deal with the effect: access ends, fees fall due, and — critically — the customer gets a defined window to export its data, after which the provider deletes it. A clear data-export-then-deletion clause aligns with POPIA retention duties and avoids hostage-data disputes.

Clickwrap cloud agreement vs negotiated master services agreement (MSA)

FeatureClickwrap cloud agreementNegotiated MSA
How acceptedClick "I agree" — assent by data message under ECTASigned (wet ink or e-signature) after negotiation
FormStandard-form, take-it-or-leave-it, same for allBespoke, tailored to the specific customer
NegotiationNone — terms are fixedEach side marks up and negotiates terms
Scales toMany self-service customers at sign-upA small number of larger or regulated customers
CPA exposureHigher — small/consumer customers more likely in CPA reachLower — usually large B2B customers above the R2m threshold
Typical useSelf-service SaaS onboardingEnterprise, public-sector or high-value deals

Common South African pitfalls

  • Terms that are not reasonably accessible: ECTA validates incorporation by reference, but only if the customer can actually find and read the terms before clicking "I agree". Hiding the agreement behind a buried link, or letting the customer accept without a genuine opportunity to read it, undermines assent and weakens enforceability.
  • Ignoring the customer’s CPA status: treating every customer as pure B2B is risky. A consumer — or a juristic person below the R2 million turnover/asset threshold — falls within the Consumer Protection Act, so the clickwrap should capture the customer’s status and not assume the CPA never applies.
  • Liability caps and exclusions not drawn to attention: for CPA-reach customers, s 49 requires that clauses limiting liability, assuming risk, or imposing indemnities be brought to the customer’s attention in plain language before acceptance. A buried, unhighlighted cap can be unenforceable against a consumer even though it would bind a business.
  • Burying personal-information terms inline instead of in a DPA: where the provider is a POPIA operator, cramming data-processing obligations into the body of the clickwrap makes the agreement unreadable and the operator terms incomplete. The fix is a dedicated Data Protection Addendum the clickwrap incorporates.
  • No data export-and-deletion mechanism on termination: a cloud agreement that ends access without giving the customer a window to export its data — and without committing the provider to delete it afterwards — invites hostage-data disputes and clashes with POPIA retention and disposal duties.
  • Using a clickwrap where a signed MSA is needed: forcing a large, regulated or negotiation-minded customer through take-it-or-leave-it clickwrap terms can cost the deal or leave key risks unaddressed. Know when to fall back to a signed master services agreement.

Frequently asked questions

Is a clickwrap "I agree" cloud agreement legally binding in South Africa?

Yes. The Electronic Communications and Transactions Act 25 of 2002 gives an electronically concluded contract full legal force and treats a click as valid assent (sections 11, 22 and 24). Provided the ordinary requirements of contract are met and the terms were reasonably accessible before the customer clicked "I agree", a clickwrap cloud services agreement is enforceable.

What is the difference between a clickwrap and a signed master services agreement?

A clickwrap is a standard-form set of terms every customer accepts by clicking "I agree" — it is scalable and not negotiated, ideal for self-service SaaS. A master services agreement (MSA) is a signed, bespoke contract negotiated with a particular customer. Providers use clickwrap for the many and an MSA for large, regulated or negotiation-minded customers.

Does the Consumer Protection Act apply to my SaaS customers?

Sometimes. The Consumer Protection Act applies where the customer is a "consumer" within its reach — including a juristic person whose annual turnover or asset value is below R2 million. For those customers, sections 48 to 52 prohibit unfair terms and section 49 requires liability limits and indemnities to be drawn to their attention. Pure B2B SaaS above the threshold is largely outside the CPA.

Why is a Data Protection Addendum separate from the cloud agreement?

Because the provider is usually a POPIA "operator" — it processes the customer’s personal information on the customer’s behalf — and the operator obligations (processing only on instruction, security, sub-processors, breach notification, return or deletion) are detailed enough to belong in a dedicated Data Protection Addendum. Keeping them out of the clickwrap keeps the master agreement readable and the data terms complete.

Can I limit my liability in a cloud services agreement in South Africa?

Yes, with care. Liability caps and exclusions are common and generally enforceable in business-to-business deals. But where the customer is within the Consumer Protection Act’s reach, those clauses must not be unfair under sections 48 to 52 and must be brought to the customer’s attention in plain language under section 49 — otherwise a buried cap can be unenforceable against a consumer.

Does a cloud services agreement transfer ownership of the software to the customer?

No. It grants a limited subscription right to access and use the hosted service for the term — a licence, not a sale and not a perpetual licence. The provider keeps ownership of the platform and all intellectual property in it, while the customer keeps ownership of its own data. The right ends when the subscription ends.

What should happen to the customer’s data when the subscription ends?

The agreement should give the customer a defined window to export its data after termination, and then commit the provider to delete it. This avoids hostage-data disputes and aligns with POPIA, which requires personal information not to be kept longer than necessary and to be disposed of securely. A clear export-then-deletion clause protects both sides.

When should I use a signed master services agreement instead of clickwrap?

Use a signed MSA when a customer is large, regulated, or wants to negotiate the terms — for example an enterprise or public-sector buyer with its own procurement, security and data requirements. Clickwrap suits high-volume, self-service onboarding; an MSA suits a smaller number of high-value deals where bespoke terms and a signature are expected.

Sources & authority

This guide is general information, not legal advice. It reflects the law as at June 2026.

Get your Cloud Services reviewed or drafted

Upload an existing document for a fixed-fee review, or have a bespoke Cloud Services drafted for your business — personally, by a senior corporate and commercial attorney. No obligation to proceed.

Review: Fixed fee from R12 300 (excl. VAT) · 48-hour turnaroundDraft: Fixed fee from R12 150 (excl. VAT)

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.