Search legal guides

Search MJ Kotze Inc legal guides and articles

Data, Privacy & Website

Cookie Policy in South Africa

A POPIA-aligned cookie policy and consent banner that does the legal work — distinguishing strictly-necessary cookies from analytics and marketing cookies, capturing real opt-in consent, and linking cleanly to your privacy policy.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

What is a cookie policy?

A cookie policy is the notice a website publishes to tell visitors which cookies and similar tracking technologies (pixels, tags, local storage, device fingerprints) it uses, what each one does, how long it lasts, and how a visitor can accept, refuse or withdraw consent. It is normally paired with a consent banner — the pop-up that asks the visitor to choose before non-essential cookies load — and it sits alongside, and is cross-referenced by, the site’s privacy policy. The privacy policy is the wide notice about all processing of personal information; the cookie policy is the focused notice about the tracking technologies specifically. In South Africa, a cookie that can be linked to an identifiable person — through a cookie ID, an advertising ID, an IP address, or a behavioural profile — is personal information as defined in the Protection of Personal Information Act 4 of 2013 (POPIA), and setting it is processing of that personal information. POPIA does not mention the word “cookie”, but because cookies routinely process personal information, the Act applies: you must give notice of what you collect and, for cookies that are not strictly necessary, obtain the visitor’s consent first. The cookie policy and banner are the practical tools that discharge those duties.

Is a cookie policy legally required in South Africa?

There is no standalone "cookie law" in South Africa, but a cookie policy is, in practice, legally required for any website whose cookies process personal information — which is almost every commercial site running analytics or advertising. The duty flows from POPIA (Act 4 of 2013). Because a cookie that identifies a person is personal information, the responsible party must satisfy two POPIA conditions: processing limitation (you need a lawful basis — for non-essential cookies that means the data subject’s consent under section 11) and openness (you must notify the data subject of the collection and its purpose under section 18). POPIA defines consent as a “voluntary, specific and informed expression of will”, so a pre-ticked box, a “by continuing to browse you accept” line, or cookies that load before the visitor chooses are not valid consent — the model is opt-in, not opt-out. Strictly-necessary cookies (those needed to deliver the service the visitor asked for — session, security, load-balancing, shopping-cart) can usually rely on a lawful basis other than consent and need not be pre-blocked, but they must still be disclosed. The Electronic Communications and Transactions Act 25 of 2002 (ECTA) reinforces this: section 43 requires an online seller to make its security procedures and privacy policy available on the site before the consumer transacts. (ECTA’s former personal-information sections 50 and 51 were repealed by POPIA, which now governs that collection.) Where cookies feed direct marketing — advertising or remarketing pixels — section 69 of POPIA adds a separate, stricter opt-in consent requirement for unsolicited electronic marketing. The Information Regulator enforces all of this and can issue enforcement notices and fines, so a clear cookie policy backed by a genuine opt-in banner is both a compliance duty and a practical shield.
Section 1 defines "consent" as "any voluntary, specific and informed expression of will in terms of which permission is given for the processing of personal information". Section 11 requires a lawful basis (such as consent) to process; section 18 requires the responsible party to notify the data subject of the information collected and the purpose; section 69 requires prior consent for direct marketing by unsolicited electronic communication. A cookie that identifies a person is personal information, so these duties apply to non-essential cookies.
Protection of Personal Information Act 4 of 2013 (POPIA), ss 1, 11, 18 and 69
Section 43(1): "A supplier offering goods or services for sale, for hire or for exchange by way of an electronic transaction must make the following information available to consumers on the web site where such goods or services are offered" — and the list includes, at s 43(1)(p), "the security procedures and privacy policy of that supplier in respect of payment, payment information and personal information". (ECTA's old data-protection sections 50 and 51 were repealed by section 110 of the Protection of Personal Information Act 4 of 2013, which now governs the collection of personal information.)
Electronic Communications and Transactions Act 25 of 2002 (ECTA), s 43

When you need a Cookie Policy

  • When your website runs Google Analytics, Meta Pixel, Hotjar, or any analytics or behaviour-tracking tool that sets cookies or identifiers linked to a visitor — these are non-essential cookies that need prior consent and a clear cookie policy.
  • When you run advertising, retargeting or remarketing pixels (Google Ads, Facebook, LinkedIn) — these feed direct marketing, so they trigger both the general POPIA consent duty and the stricter section 69 opt-in requirement.
  • When you embed third-party content — YouTube videos, social share buttons, live-chat widgets, payment iframes, or maps — that can drop their own cookies, because you remain responsible for disclosing them to your visitors.
  • When you sell goods or services online and ECTA requires you to disclose your privacy and security practices before the consumer transacts, of which cookies are a part.
  • When you publish or refresh your privacy policy and POPIA notice, since the cookie policy is the companion notice that explains the tracking technologies the privacy policy refers to.

What a Cookie Policy should contain

1

What cookies are and which technologies are covered

Explain in plain language what cookies are and confirm the policy also covers equivalent technologies — pixels, tags, web beacons, software development kits, local and session storage, and device fingerprinting. Naming the wider set matters because POPIA looks at whether a person can be identified, not at the technical label, so a policy limited to "cookies" can leave tracking pixels undisclosed.

2

Categories: strictly-necessary vs analytics vs marketing

Split the cookies into clear categories — strictly-necessary, functional/preferences, performance/analytics, and advertising/marketing — and state the lawful basis for each. Strictly-necessary cookies can usually run without consent because the visitor asked for the service; analytics and marketing cookies need prior opt-in consent. This split is the heart of a POPIA-aligned policy and drives how the banner behaves.

3

Per-cookie table: name, purpose, provider, duration

List the actual cookies with their name, what each does, whether it is first-party or third-party, the provider, and how long it lasts. POPIA’s openness condition (section 18) requires specific, informed disclosure — a vague "we use cookies to improve your experience" line does not meet the standard. The table is what makes the notice genuinely informed.

4

Consent mechanism and how it is recorded

Describe how consent is obtained and proven: a banner that loads non-essential cookies only after the visitor opts in, with granular accept/reject controls and no pre-ticked boxes. POPIA places the burden of proving consent on the responsible party, so the policy should explain that consent choices are logged (date, version, categories chosen) and can be produced if the Information Regulator asks.

5

How to refuse, change or withdraw consent

Tell visitors how to refuse cookies up front, revisit their choices later (a persistent "cookie settings" link), and withdraw consent — and confirm that withdrawal is as easy as giving consent and does not affect the lawfulness of earlier processing. POPIA gives the data subject the right to withdraw consent at any time, so a usable, ongoing control is essential, not a one-time banner.

6

Third parties and cross-border transfers

Name the third parties whose cookies you allow (analytics and ad networks) and flag that some of them process data outside South Africa. POPIA section 72 restricts transfers of personal information across borders, so the policy should disclose the transfer and the basis for it, letting the visitor make an informed choice before opting in to those cookies.

7

Direct-marketing and retargeting cookies (section 69)

Where cookies build profiles used for advertising or remarketing, call this out and align it with POPIA section 69, which requires prior consent for direct marketing by unsolicited electronic communication. Treat advertising cookies as a distinct, separately-consented category rather than bundling them with analytics, because the consent standard for marketing is stricter.

8

Link to the privacy policy, contact and review date

Cross-reference the full privacy policy and POPIA notice, give the responsible party’s name and contact details (including the information officer), and state when the policy was last reviewed. This ties the cookie policy into the wider compliance framework, satisfies ECTA section 43 disclosure, and shows the notice is kept current as tools change.

Cookie policy vs privacy policy vs consent banner

FeatureCookie policyPrivacy policy / POPIA noticeConsent banner
What it isFocused notice on tracking technologiesWide notice on all processing of personal informationThe interactive opt-in/opt-out control
ScopeCookies, pixels, tags, storage, fingerprintsEvery category of personal information and processingThe choice for non-essential cookies
Main POPIA hookOpenness (s 18) + the cookie detailNotification (s 18) + all eight conditionsConsent (s 11), recorded and provable
Does it collect consent?No — it informsNo — it informsYes — it captures and logs the choice
When it must showLinked in footer, referenced by the bannerLinked in footer; ECTA s 43 for online sellersOn first visit, before non-essential cookies load

Common South African pitfalls

  • Treating "continued browsing" as consent: a banner that says "by using this site you accept cookies", or that loads analytics and ad cookies before the visitor chooses, does not meet POPIA’s "voluntary, specific and informed" standard. Consent is opt-in — non-essential cookies must wait until the visitor actively accepts.
  • Pre-ticked boxes and "accept all" with no real "reject": offering a prominent Accept button but burying or omitting an equally easy Reject option undermines voluntariness. POPIA requires a genuine choice, and a banner engineered to nudge acceptance is vulnerable to challenge by the Information Regulator or a complainant.
  • Mislabelling marketing cookies as necessary: advertising, retargeting and many analytics cookies are not strictly necessary to deliver the service, so they cannot ride on the "necessary" exemption. Putting them in the wrong bucket to avoid asking for consent is a common and risky shortcut.
  • A generic, copied-and-pasted policy: a cookie policy lifted from a GDPR template that lists cookies the site does not use, or omits the ones it does, fails POPIA’s requirement for specific, informed notice. The per-cookie detail must match the site’s actual tags, audited and kept current.
  • Ignoring direct-marketing consent under section 69: where cookies feed unsolicited electronic marketing, a single blanket "accept cookies" click does not satisfy the separate, stricter section 69 opt-in. Marketing and remarketing cookies should be a distinct, separately-consented category.
  • No record of consent: POPIA puts the burden of proving consent on the responsible party. A banner that captures a click but logs nothing leaves you unable to show what each visitor agreed to, when, and to which version of the policy — which is exactly what an enforcement enquiry will ask for.

Frequently asked questions

Are cookies regulated by POPIA in South Africa?

Yes, where they identify a person. POPIA does not use the word "cookie", but a cookie that can be linked to an identifiable person — through a cookie ID, advertising ID, IP address or behavioural profile — is personal information, and setting it is processing. So POPIA’s notification and consent rules apply to non-essential cookies, even though there is no standalone cookie law.

Do I need consent before setting cookies on my website?

For non-essential cookies, yes — and the consent must come first. Analytics, advertising and tracking cookies need the visitor’s prior, opt-in consent under POPIA, which means they should not load until the visitor accepts. Strictly-necessary cookies (session, security, shopping-cart) can run without consent because they deliver the service the visitor asked for, but they must still be disclosed.

What is the difference between a cookie policy and a privacy policy?

A privacy policy is the broad POPIA notice covering all the personal information your business processes and why. A cookie policy is the focused notice about the tracking technologies on your website — which cookies you use, what they do, and how to control them. They work together: the privacy policy refers to the cookie policy, and the cookie policy links back to it.

Is "by continuing to browse you accept cookies" valid consent under POPIA?

No. POPIA defines consent as a "voluntary, specific and informed expression of will", which requires an active opt-in choice. Implied consent from continued browsing, pre-ticked boxes, or cookies that load before the visitor chooses do not meet that standard. You need a banner that loads non-essential cookies only after the visitor actively accepts.

Which cookies count as strictly necessary and need no consent?

Cookies that are essential to deliver the service the visitor has asked for — session management, authentication, security, load-balancing, and shopping-cart cookies. These can rely on a lawful basis other than consent and need not be pre-blocked. Analytics, preference, advertising and social-media cookies are not strictly necessary and do require prior consent.

Do advertising and retargeting cookies need extra consent?

Yes. Beyond the general POPIA consent rule, section 69 of POPIA requires prior, opt-in consent for direct marketing by unsolicited electronic communication, and the Information Regulator’s 2024 Guidance Note on Direct Marketing reinforces this. So advertising, remarketing and profiling cookies should be a separate, separately-consented category, not bundled into a single "accept all" click.

What happens if my website has no compliant cookie policy?

You risk a complaint to or investigation by the Information Regulator, which can issue an enforcement notice requiring you to fix the processing, and POPIA provides for administrative fines and, for serious offences, criminal penalties. Beyond regulatory risk, a missing or misleading cookie notice damages trust and can expose you to civil claims by affected data subjects.

Does ECTA also apply to cookies on my site?

Yes, alongside POPIA. The Electronic Communications and Transactions Act 25 of 2002 requires an online seller to make its security procedures and privacy policy available on the site before a consumer transacts (section 43). ECTA’s own personal-information sections (50 and 51) were repealed by POPIA, so the collection of personal information is now governed by POPIA itself — but for an e-commerce site, the cookie policy still forms part of the disclosure ECTA section 43 expects, working together with the POPIA notice.

Sources & authority

This guide is general information, not legal advice. It reflects the law as at June 2026.

Get your Cookie Policy reviewed or drafted

Upload an existing document for a fixed-fee review, or have a bespoke Cookie Policy drafted for your business — personally, by a senior corporate and commercial attorney. No obligation to proceed.

Review: Fixed fee from R3 000 (excl. VAT) · 24-hour turnaroundDraft: Fixed fee from R2 925 (excl. VAT)

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.