What is a website development agreement?
Is a website development agreement legally binding in South Africa?
“No assignment of copyright and no exclusive licence to do an act which is subject to copyright shall have effect unless it is in writing signed by or on behalf of the assignor, the licenser or, in the case of an exclusive sublicence, the exclusive sublicenser, as the case may be.”
“a computer program, the person who exercised control over the making of the computer program”
“Where a person commissions the taking of a photograph, the painting or drawing of a portrait, the making of a gravure, the making of a cinematograph film or the making of a sound recording and pays or agrees to pay for it in money or money’s worth, and the work is made in pursuance of that commission, such person shall, subject to the provisions of paragraph (b), be the owner of any copyright subsisting therein by virtue of section 3 or 4.”
“the mere provision of functional requirements and a periodic review of progress being made in the development of the program and testing it finally to see if it met its purpose, without more, does not establish control over the making of it or vest authorship therein.”
“a person may because of his control over the making of a computer program be the author of that program even if the creator of the program is an independent contractor.”
“A supplier offering goods or services for sale, for hire or for exchange by way of an electronic transaction must make the following information available to consumers on the web site where such goods or services are offered … If a supplier fails to comply with the provisions of subsection (1) or (2), the consumer may cancel the transaction within 14 days of receiving the goods or services under the transaction.”
“Where the signature of a person is required by law and such law does not specify the type of signature, that requirement in relation to a data message is met only if an advanced electronic signature is used.”
“A responsible party must, in terms of a written contract between the responsible party and the operator, ensure that the operator which processes personal information for the responsible party establishes and maintains the security measures referred to in section 19.”
When you need a Website Development Agreement
- When you are paying a web agency or freelancer to design and build a new website, or to redesign an existing one — whether a five-page brochure site, a WordPress or other content-management site, or an online store.
- When the build includes a custom theme, custom plugins or bespoke features (online bookings, a members’ area, a link to your CRM or accounting system) that you want to own and be free to hand to another developer later.
- When you will sell online, so the checkout must be built to meet ECTA section 43: the required disclosures, a chance for the buyer to review and correct the order before paying, and a secure payment system.
- When the site will collect personal information through contact forms, newsletter sign-ups, analytics or cookies, and the developer or host will be able to see that information — POPIA then requires a written contract with them.
- When the developer will register your domain, set up hosting or look after the site after launch, and you need the accounts, logins and renewals to stay in your business’s name.
- When you are the agency or freelancer, and want clear scope, payment milestones and change control so that “one small extra” does not turn into weeks of unpaid work.
What a Website Development Agreement should contain
Scope, deliverables and what the client must supply
List what is being built: the number of pages and page templates, the features, the content-management system, integrations, and the browsers and devices it must work on. Say how many design concepts and rounds of changes are included, and what is excluded (copywriting, photography, ongoing SEO, hosting). Record what you must provide — text, images, product data, logins — and by when, because late content is the most common reason a website launch slips.
Fees, milestones and change control
Tie payments to milestones — for example a deposit, design sign-off, and launch — rather than dates, so money follows progress. Any change to the agreed scope should go through a short written change request that states the extra cost and time before the work starts. Without this, both sides end up arguing about whether a feature was “always included”.
Design sign-off and acceptance testing
Set out how designs are approved and how the finished site is tested before launch: a fixed review period (often 10 business days), objective acceptance criteria, a list of defects to be fixed, and a set number of re-tests. Many agreements treat silence at the end of the review period as acceptance, so the client must diarise it. Agree whether going live counts as acceptance, so the final payment is neither rushed nor withheld indefinitely.
Ownership of the code, design and content
The heart of the agreement. The developer should assign to you, in writing and signed by it, the copyright in everything made specially for you — custom code, design, graphics and copy — with ownership passing once the related fees are paid. The developer usually keeps its own pre-existing tools and code libraries, so take a permanent licence to those. Because section 20 of the Copyright Act leaves the creator’s moral rights (to be named, and to object to changes that harm their reputation) in place even after an assignment, also get the designer’s written consent to future changes, and require the agency to secure the same rights from any freelancers it used.
Third-party and open-source components
Require a list of every premium theme, paid plugin, web font, stock image and open-source component in the site, with its licence terms. Paid licences should be bought in your business’s name or transferred to you, and the agreement should say who pays renewals, because many plugins stop receiving security updates when the licence lapses. Open-source software is free to use but comes with conditions, so require disclosure and your approval before any component is used whose licence could force you to publish your own code.
Domain, hosting and admin accounts
Your business should be the registered holder of the domain name and the owner of the hosting, CMS administrator, analytics, search-console, email and payment-gateway accounts. The developer gets its own login that you can switch off. If form submissions or customer data will be stored on servers outside South Africa, check that POPIA section 72, which limits sending personal information abroad, is satisfied.
Privacy, e-commerce and security build requirements
Make the legal must-haves part of the scope: a cookie banner that holds back analytics and advertising cookies until the visitor agrees; privacy-notice links on every form (POPIA section 18); opt-in boxes for marketing emails (section 69); and, for a store, the ECTA section 43 disclosures, an order-review step and a reputable payment gateway. Where the developer or host can access personal information for you, it is an operator, and section 21 of POPIA requires a written contract binding it to keep that information secure — a data protection addendum does this. If accessibility or SEO matters to you, name the standard (for example WCAG 2.2 level AA) and the SEO tasks, such as redirects from old page addresses.
Warranty, support, termination and handover
Agree a period after launch during which the developer fixes defects in its own work free of charge, and put ongoing updates, backups and security patching in a separate support and maintenance agreement. Give yourself the right to end the agreement if the developer does not perform, paying only for completed work, and limit the developer’s right to walk away mid-project. On completion or termination the developer must hand over the source files, design files, database, documentation and every login.
Who owns each part of your website if the contract is silent
| Part of the website | Owner if the contract says nothing | What the agreement should do |
|---|---|---|
| Custom code (theme, plugins and features built for you) | Usually the developer — the author of code is whoever controlled its making, and a client who briefs, reviews and tests is not in control (Bergh) | Assign it to you once paid, in writing signed by the developer |
| Visual design, logo and graphics | The designer who created them — they are not on the commissioned-works list in s 21(1)(c) | Assign them to you, with the designer’s consent to future changes |
| Copy written by the agency | The writer | Assign it to you with the rest of the bespoke work |
| Text, photos and data you supply | You, or whoever created them | License them to the developer for the project only; you confirm you hold the rights |
| Photos you commission and pay for yourself | You, under s 21(1)(c), unless the photographer’s terms exclude it — but if the agency commissions the shoot, the agency is the commissioner | Confirm ownership in writing, or have the agency assign the photos to you |
| Premium theme, paid plugins, web fonts and stock images | The third-party supplier — you hold only the licence that was bought, often in the agency’s name | List each one, put the licence in your name and agree who pays renewals |
| Open-source software (such as WordPress core and many plugins) | Its authors, licensed to everyone on the open-source licence’s conditions | Disclose every component and its licence; no licence that could force you to publish your own code without approval |
| Domain name, hosting and admin accounts | Whoever is recorded as the registrant or account holder | Register them in your business’s name and give the developer access you can revoke |
Common South African pitfalls
- Assuming that paying the final invoice makes you the owner. Unless the developer has signed a written assignment, it usually keeps the copyright in the code, design and copy, and you are left relying on an informal right to use the site that is on shaky ground if the relationship sours. Fix this in the agreement before work starts, not after a dispute.
- Letting the agency register the domain, hosting and plugin licences in its own name. When the relationship ends — or a fee dispute starts — you may be unable to move the site, renew licences or even keep your email running. Your business should hold every account from day one, with the developer as an authorised user.
- A vague brief and “unlimited revisions”. A quote for “a modern, SEO-friendly website” means different things to each side. Without a page list, a feature list, a set number of change rounds and a change-request process, scope creep turns into unpaid work for the agency or surprise invoices for the client.
- No acceptance process. Without a test period and clear criteria, the agency says the site was accepted when it went live, and the client withholds the last payment until every small issue is fixed. A fixed review window, a defect list and a limited number of re-tests end both arguments.
- Treating POPIA and ECTA as someone else’s problem. A contact form with no privacy notice, analytics cookies that load before the visitor agrees, or a checkout that skips the order-review step are build defects with legal consequences — under ECTA section 43(3) a consumer can cancel within 14 days of receiving the goods or services if the required disclosures or review step are missing. Put these requirements in the scope so the developer builds them in.
- No exit plan if the developer disappears. If the code sits only on the developer’s laptop, the site runs on its private framework and the admin passwords are in its hands, you may have to rebuild from scratch. Require a code repository in your name, regular handover of files and logins, and the right to take work in progress to a new developer.
Frequently asked questions
Who owns my website once I have paid the web developer?
Usually not you, unless the contract says so. Under the Copyright Act 98 of 1978 the developer or designer normally keeps the copyright in the code, design and any copy it wrote, leaving you with only an implied right to use the site. Ownership passes to you through a written assignment signed by the developer under section 22(3), so the agreement should assign all bespoke work to you once the related fees are paid.
Should the domain name and hosting be in my name or the agency’s?
In your business’s name, always. Whoever is recorded as the registrant of the domain and the holder of the hosting account controls them, so if the agency registers them in its own name you may struggle to move your site or email when the relationship ends. Let the agency be a technical contact or authorised user, and keep the main login, the renewal dates and the payment method with your business.
Can the web developer reuse my website’s design or code for other clients?
It depends on what the contract assigns to you. Developers normally keep their pre-existing tools, frameworks and code libraries and license them to you, so they can reuse those building blocks; the custom design and code made for you should be assigned to you and not reused without your permission. The agreement should spell out which elements are bespoke and which are background tools, and make your licence to the background tools permanent.
What happens if my web developer disappears halfway through the project?
Without a proper contract you may be left with a half-built site that you are not clearly free to finish elsewhere, because the developer still owns the code and design and may hold your logins. A well-drafted agreement lets you end it for non-performance, pay only for completed milestones, and take the work in progress, source files and credentials to a new developer. The best practical protection is to keep the domain, hosting and code repository in your own name from the start.
Can we sign a website development agreement electronically in South Africa?
Yes, for the agreement itself: section 22(1) of the Electronic Communications and Transactions Act 25 of 2002 confirms that a contract concluded by email or online sign-off is not without legal force for that reason. The copyright assignment is different, because the Copyright Act requires it to be signed by the assignor, and ECTA section 13(1) says a signature required by law is met electronically only by an advanced electronic signature. No court has yet settled how that applies to a copyright assignment, so sign that part in ink or with an advanced electronic signature.
Does the Consumer Protection Act protect my small business when I hire a web developer?
It can. The Consumer Protection Act 68 of 2008 does not apply to a juristic person whose asset value or annual turnover equals or exceeds the Minister’s threshold — R2 million, the figure the Supreme Court of Appeal applied in 2026 — so smaller companies, and sole proprietors contracting in their own name, can be consumers. If it applies, section 54 gives you the right to timely work of the quality people are generally entitled to expect, and to require the developer to fix defects or refund a reasonable part of the price.
Is my web developer responsible for POPIA and cookie compliance on my website?
Your business carries the legal duty, because it decides why and how visitors’ information is collected, which makes it the responsible party under POPIA. The developer builds the tools you need to comply: a cookie banner that holds back non-essential cookies until the visitor agrees, privacy-notice links on forms, opt-in boxes for marketing emails and secure handling of form data. If the developer or host can access personal information on your behalf, it is an operator, and section 21 of POPIA requires a written contract binding it to keep that information secure.
What should be agreed about the website after it goes live?
Agree two things before launch: a warranty period during which the developer fixes defects in its own work for free, and whether it will maintain the site afterwards. Maintenance should cover updates to the content-management system, theme and plugins, security patches, backups, monitoring, response times and how many hours of changes are included each month. A site that is never updated quickly becomes a security risk, and without a maintenance agreement nobody is bound to fix it.
Sources & authority
- Copyright Act 98 of 1978 (ss 1, 2, 20, 21 and 22)
- Electronic Communications and Transactions Act 25 of 2002 (ss 13, 22 and 43)
- Protection of Personal Information Act 4 of 2013 (ss 1, 18, 19, 21, 69 and 72)
- Consumer Protection Act 68 of 2008 (ss 5 and 54)
- Haupt t/a Softcopy v Brewers Marketing Intelligence (Pty) Ltd and Others (118/05) [2006] ZASCA 40; 2006 (4) SA 458 (SCA)
- Bergh and Others v Agricultural Research Council (93/2019) [2020] ZASCA 30; [2020] 2 All SA 637 (SCA)
- Spring Forest Trading 599 CC v Wilberry (Pty) Ltd t/a Ecowash and Another (725/13) [2014] ZASCA 178; 2015 (2) SA 118 (SCA)
- Dr Darren Levin Inc and Another v Promenade Centre (Pty) Ltd (1149/2024) [2026] ZASCA 70; [2026] 3 All SA 51 (SCA)
This guide is general information, not legal advice. It reflects the law as at October 2026.