What is a cookie policy?
Is a cookie policy legally required in South Africa?
“Section 1 defines "consent" as "any voluntary, specific and informed expression of will in terms of which permission is given for the processing of personal information". Section 11 requires a lawful basis (such as consent) to process; section 18 requires the responsible party to notify the data subject of the information collected and the purpose; section 69 requires prior consent for direct marketing by unsolicited electronic communication. A cookie that identifies a person is personal information, so these duties apply to non-essential cookies.”
“Section 43(1): "A supplier offering goods or services for sale, for hire or for exchange by way of an electronic transaction must make the following information available to consumers on the web site where such goods or services are offered" — and the list includes, at s 43(1)(p), "the security procedures and privacy policy of that supplier in respect of payment, payment information and personal information". (ECTA's old data-protection sections 50 and 51 were repealed by section 110 of the Protection of Personal Information Act 4 of 2013, which now governs the collection of personal information.)”
When you need a Cookie Policy
- When your website runs Google Analytics, Meta Pixel, Hotjar, or any analytics or behaviour-tracking tool that sets cookies or identifiers linked to a visitor — these are non-essential cookies that need prior consent and a clear cookie policy.
- When you run advertising, retargeting or remarketing pixels (Google Ads, Facebook, LinkedIn) — these feed direct marketing, so they trigger both the general POPIA consent duty and the stricter section 69 opt-in requirement.
- When you embed third-party content — YouTube videos, social share buttons, live-chat widgets, payment iframes, or maps — that can drop their own cookies, because you remain responsible for disclosing them to your visitors.
- When you sell goods or services online and ECTA requires you to disclose your privacy and security practices before the consumer transacts, of which cookies are a part.
- When you publish or refresh your privacy policy and POPIA notice, since the cookie policy is the companion notice that explains the tracking technologies the privacy policy refers to.
What a Cookie Policy should contain
What cookies are and which technologies are covered
Explain in plain language what cookies are and confirm the policy also covers equivalent technologies — pixels, tags, web beacons, software development kits, local and session storage, and device fingerprinting. Naming the wider set matters because POPIA looks at whether a person can be identified, not at the technical label, so a policy limited to "cookies" can leave tracking pixels undisclosed.
Categories: strictly-necessary vs analytics vs marketing
Split the cookies into clear categories — strictly-necessary, functional/preferences, performance/analytics, and advertising/marketing — and state the lawful basis for each. Strictly-necessary cookies can usually run without consent because the visitor asked for the service; analytics and marketing cookies need prior opt-in consent. This split is the heart of a POPIA-aligned policy and drives how the banner behaves.
Per-cookie table: name, purpose, provider, duration
List the actual cookies with their name, what each does, whether it is first-party or third-party, the provider, and how long it lasts. POPIA’s openness condition (section 18) requires specific, informed disclosure — a vague "we use cookies to improve your experience" line does not meet the standard. The table is what makes the notice genuinely informed.
Consent mechanism and how it is recorded
Describe how consent is obtained and proven: a banner that loads non-essential cookies only after the visitor opts in, with granular accept/reject controls and no pre-ticked boxes. POPIA places the burden of proving consent on the responsible party, so the policy should explain that consent choices are logged (date, version, categories chosen) and can be produced if the Information Regulator asks.
How to refuse, change or withdraw consent
Tell visitors how to refuse cookies up front, revisit their choices later (a persistent "cookie settings" link), and withdraw consent — and confirm that withdrawal is as easy as giving consent and does not affect the lawfulness of earlier processing. POPIA gives the data subject the right to withdraw consent at any time, so a usable, ongoing control is essential, not a one-time banner.
Third parties and cross-border transfers
Name the third parties whose cookies you allow (analytics and ad networks) and flag that some of them process data outside South Africa. POPIA section 72 restricts transfers of personal information across borders, so the policy should disclose the transfer and the basis for it, letting the visitor make an informed choice before opting in to those cookies.
Direct-marketing and retargeting cookies (section 69)
Where cookies build profiles used for advertising or remarketing, call this out and align it with POPIA section 69, which requires prior consent for direct marketing by unsolicited electronic communication. Treat advertising cookies as a distinct, separately-consented category rather than bundling them with analytics, because the consent standard for marketing is stricter.
Link to the privacy policy, contact and review date
Cross-reference the full privacy policy and POPIA notice, give the responsible party’s name and contact details (including the information officer), and state when the policy was last reviewed. This ties the cookie policy into the wider compliance framework, satisfies ECTA section 43 disclosure, and shows the notice is kept current as tools change.
Cookie policy vs privacy policy vs consent banner
| Feature | Cookie policy | Privacy policy / POPIA notice | Consent banner |
|---|---|---|---|
| What it is | Focused notice on tracking technologies | Wide notice on all processing of personal information | The interactive opt-in/opt-out control |
| Scope | Cookies, pixels, tags, storage, fingerprints | Every category of personal information and processing | The choice for non-essential cookies |
| Main POPIA hook | Openness (s 18) + the cookie detail | Notification (s 18) + all eight conditions | Consent (s 11), recorded and provable |
| Does it collect consent? | No — it informs | No — it informs | Yes — it captures and logs the choice |
| When it must show | Linked in footer, referenced by the banner | Linked in footer; ECTA s 43 for online sellers | On first visit, before non-essential cookies load |
Common South African pitfalls
- Treating "continued browsing" as consent: a banner that says "by using this site you accept cookies", or that loads analytics and ad cookies before the visitor chooses, does not meet POPIA’s "voluntary, specific and informed" standard. Consent is opt-in — non-essential cookies must wait until the visitor actively accepts.
- Pre-ticked boxes and "accept all" with no real "reject": offering a prominent Accept button but burying or omitting an equally easy Reject option undermines voluntariness. POPIA requires a genuine choice, and a banner engineered to nudge acceptance is vulnerable to challenge by the Information Regulator or a complainant.
- Mislabelling marketing cookies as necessary: advertising, retargeting and many analytics cookies are not strictly necessary to deliver the service, so they cannot ride on the "necessary" exemption. Putting them in the wrong bucket to avoid asking for consent is a common and risky shortcut.
- A generic, copied-and-pasted policy: a cookie policy lifted from a GDPR template that lists cookies the site does not use, or omits the ones it does, fails POPIA’s requirement for specific, informed notice. The per-cookie detail must match the site’s actual tags, audited and kept current.
- Ignoring direct-marketing consent under section 69: where cookies feed unsolicited electronic marketing, a single blanket "accept cookies" click does not satisfy the separate, stricter section 69 opt-in. Marketing and remarketing cookies should be a distinct, separately-consented category.
- No record of consent: POPIA puts the burden of proving consent on the responsible party. A banner that captures a click but logs nothing leaves you unable to show what each visitor agreed to, when, and to which version of the policy — which is exactly what an enforcement enquiry will ask for.
Frequently asked questions
Are cookies regulated by POPIA in South Africa?
Yes, where they identify a person. POPIA does not use the word "cookie", but a cookie that can be linked to an identifiable person — through a cookie ID, advertising ID, IP address or behavioural profile — is personal information, and setting it is processing. So POPIA’s notification and consent rules apply to non-essential cookies, even though there is no standalone cookie law.
Do I need consent before setting cookies on my website?
For non-essential cookies, yes — and the consent must come first. Analytics, advertising and tracking cookies need the visitor’s prior, opt-in consent under POPIA, which means they should not load until the visitor accepts. Strictly-necessary cookies (session, security, shopping-cart) can run without consent because they deliver the service the visitor asked for, but they must still be disclosed.
What is the difference between a cookie policy and a privacy policy?
A privacy policy is the broad POPIA notice covering all the personal information your business processes and why. A cookie policy is the focused notice about the tracking technologies on your website — which cookies you use, what they do, and how to control them. They work together: the privacy policy refers to the cookie policy, and the cookie policy links back to it.
Is "by continuing to browse you accept cookies" valid consent under POPIA?
No. POPIA defines consent as a "voluntary, specific and informed expression of will", which requires an active opt-in choice. Implied consent from continued browsing, pre-ticked boxes, or cookies that load before the visitor chooses do not meet that standard. You need a banner that loads non-essential cookies only after the visitor actively accepts.
Which cookies count as strictly necessary and need no consent?
Cookies that are essential to deliver the service the visitor has asked for — session management, authentication, security, load-balancing, and shopping-cart cookies. These can rely on a lawful basis other than consent and need not be pre-blocked. Analytics, preference, advertising and social-media cookies are not strictly necessary and do require prior consent.
Do advertising and retargeting cookies need extra consent?
Yes. Beyond the general POPIA consent rule, section 69 of POPIA requires prior, opt-in consent for direct marketing by unsolicited electronic communication, and the Information Regulator’s 2024 Guidance Note on Direct Marketing reinforces this. So advertising, remarketing and profiling cookies should be a separate, separately-consented category, not bundled into a single "accept all" click.
What happens if my website has no compliant cookie policy?
You risk a complaint to or investigation by the Information Regulator, which can issue an enforcement notice requiring you to fix the processing, and POPIA provides for administrative fines and, for serious offences, criminal penalties. Beyond regulatory risk, a missing or misleading cookie notice damages trust and can expose you to civil claims by affected data subjects.
Does ECTA also apply to cookies on my site?
Yes, alongside POPIA. The Electronic Communications and Transactions Act 25 of 2002 requires an online seller to make its security procedures and privacy policy available on the site before a consumer transacts (section 43). ECTA’s own personal-information sections (50 and 51) were repealed by POPIA, so the collection of personal information is now governed by POPIA itself — but for an e-commerce site, the cookie policy still forms part of the disclosure ECTA section 43 expects, working together with the POPIA notice.
Sources & authority
- Protection of Personal Information Act 4 of 2013 (POPIA), ss 1, 11, 18 and 69
- Electronic Communications and Transactions Act 25 of 2002 (ECTA), s 43
This guide is general information, not legal advice. It reflects the law as at June 2026.