Search legal guides

Search MJ Kotze Inc legal guides and articles

Data, Privacy & Website

Website Privacy Policy (POPIA) in South Africa

A POPIA-compliant privacy notice that actually meets section 18 — covering what you collect, your lawful basis, sharing and cross-border transfers, data-subject rights, cookies, and your Information Officer.

Written by

Martin Kotze

Attorney, Conveyancer & Notary Public

Last reviewed:

Quick answer

What is a website privacy policy?

A website privacy policy — also called a privacy notice — is the document a website or app publishes to tell people (in POPIA terms, data subjects) how their personal information is collected, used, shared, stored and protected. It explains what information you gather and how (through forms, accounts, cookies, and analytics), the purposes you use it for, the lawful basis you rely on, who you share it with (including operators and third parties), whether it leaves South Africa, how long you keep it, and the rights data subjects have over their information. In South Africa the privacy policy is the principal way a responsible party (the business that determines why and how personal information is processed) discharges its transparency duty under the Protection of Personal Information Act 4 of 2013 (POPIA). It is distinct from a site’s terms of use: the terms are a contract about how the site may be used, while the privacy policy is a statutory notice about how personal information is handled. Most sites need both, and the two should cross-link rather than duplicate one another.

Is a privacy policy legally required for a website in South Africa?

In substance, yes. POPIA does not use the words “publish a privacy policy”, but it imposes duties that, for a website collecting personal information, are met principally through one. Section 18 requires that, when personal information is collected, the responsible party take reasonably practicable steps to ensure the data subject is aware of the information being collected, the purpose of collection, whether supply is voluntary or mandatory, the consequences of not supplying it, the identity and contact details of the responsible party, who the recipients are, and the data subject’s rights — the very content of a privacy policy. Section 11 requires a lawful basis for processing: consent, performance of a contract, compliance with a legal obligation, protection of a legitimate interest, or the pursuit of the responsible party’s legitimate interests. Where the site does electronic direct marketing, section 69 generally requires the data subject’s prior opt-in consent (a narrow exception applies to existing customers for similar products), so the policy and the sign-up flow must reflect opt-in rather than pre-ticked boxes. The Act also confers data-subject rights the policy must explain and enable: access to one’s information (section 23), correction or deletion of information that is inaccurate, irrelevant, excessive or out of date (section 24), and the right to object to processing (section 11(3)). Earlier, before POPIA, section 51 of the Electronic Communications and Transactions Act 25 of 2002 (ECTA) set out voluntary data-collection principles that a website operator could choose to subscribe to — but those principles were never binding by default and have effectively been overtaken by POPIA, which became fully enforceable on 1 July 2021 and now governs how a website handles personal information. The privacy policy should be built on POPIA, not on ECTA’s voluntary principles. Non-compliance is enforced by the Information Regulator, so a website that processes personal information without a compliant privacy notice is exposed.
When collecting personal information, the responsible party must take reasonably practicable steps to ensure the data subject is aware of the information being collected, the purpose of collection, whether supply is voluntary or mandatory, the consequences of failing to supply it, the responsible party’s identity and contact details, the recipients of the information, and the data subject’s rights — the substance of a privacy policy.
Protection of Personal Information Act 4 of 2013, s 18
Processing requires a lawful basis such as consent, contract, legal obligation or legitimate interest (s 11), and the data subject may object to processing (s 11(3)), request access to their information (s 23) and require correction or deletion of inaccurate or excessive information (s 24); direct marketing by electronic communication generally requires prior opt-in consent (s 69).
Protection of Personal Information Act 4 of 2013, ss 11, 23, 24 & 69
ECTA section 51 set out voluntary principles a data collector could choose to subscribe to when electronically collecting personal information — collecting only what is necessary, disclosing the purpose, not using the information for other purposes without consent, and keeping a record. These principles were never mandatory and have been overtaken by POPIA, which now governs; they are noted only as historical context, not as a binding privacy-policy requirement.
Electronic Communications and Transactions Act 25 of 2002, s 51 (voluntary principles, predating and overtaken by POPIA)

When you need a Website Privacy Policy

  • When your website or app collects any personal information — names, email addresses, phone numbers, ID numbers, payment details — through contact forms, sign-ups, checkouts, or enquiries.
  • When you use cookies, analytics, pixels, or similar tracking technologies that gather information about visitors and their behaviour on the site.
  • When you share personal information with operators or third parties — payment gateways, hosting providers, email and marketing platforms, CRM tools — or transfer it outside South Africa.
  • When you send electronic direct marketing such as newsletters or promotional emails, where section 69 of POPIA generally requires opt-in consent that the policy and sign-up flow must reflect.
  • When you must give data subjects a clear, single place to understand their rights and exercise them, and to find your Information Officer’s contact details and how to complain to the Information Regulator.

What a Website Privacy Policy should contain

1

Information collected and how

List the categories of personal information you collect — for example contact details, account credentials, payment information, and technical data — and the sources, including forms, accounts, cookies, analytics, and third parties. POPIA’s minimality principle means you should collect only what is necessary, so the policy should be honest about the actual data captured.

2

Purposes and lawful basis

State why you process each type of information and the lawful basis under section 11 of POPIA — consent, performance of a contract, a legal obligation, protection of a legitimate interest, or your legitimate interests. Tying purposes to a lawful basis is the core of POPIA compliance and prevents “purpose creep” into uses the data subject never agreed to.

3

Recipients, operators and sharing

Identify who receives the information — internal teams, operators who process on your behalf (hosting, payments, email), and any other third parties — and on what basis. Section 18 requires data subjects to be told who the recipients are, and operators must be bound by a written contract to process only on your instructions and to keep the data secure.

4

Cross-border transfers

Disclose whether personal information is transferred outside South Africa — for example to overseas cloud or email providers — and the safeguards relied on under section 72 of POPIA, such as the recipient being subject to adequate protection, the data subject’s consent, or the transfer being necessary for the contract. Many common SaaS tools host data abroad, so this is rarely optional.

5

Retention and security

Explain how long you keep personal information and the basis for those periods, and describe the security safeguards you apply. POPIA requires that information not be kept longer than necessary for the purpose and that the responsible party secure the integrity and confidentiality of personal information through appropriate, reasonable technical and organisational measures.

6

Data-subject rights and how to exercise them

Set out the data subject’s rights — to be informed, to access their information (section 23), to have it corrected or deleted (section 24), to object to processing (section 11(3)), and to lodge a complaint — and explain the practical steps to exercise each, including any prescribed forms. The policy must not merely list rights but enable them.

7

Cookies and direct marketing

Describe the cookies and trackers the site uses and how users can manage them (often via a separate cookie policy), and set out your direct-marketing practices. Under section 69 of POPIA, electronic direct marketing to people who are not already your customers generally requires prior opt-in consent, so pre-ticked boxes and assumed consent are non-compliant.

8

Information Officer and complaints

Give the contact details of your Information Officer (and any deputy), who is responsible for POPIA compliance and for handling requests and complaints. Explain that data subjects may also complain to the Information Regulator, and provide the Regulator’s contact route. This is both a section 18 requirement and the practical channel for resolving concerns.

Privacy policy vs terms of use vs cookie policy

FeaturePrivacy policyTerms of useCookie policy
What it isA POPIA notice about personal informationA contract governing use of the siteA notice about cookies and trackers
Primary lawPOPIA (ECTA’s voluntary principles predate it)Common law of contract, ECTA, CPAPOPIA, plus consent norms
Binds the user?No — it informs; consent is separateYes — once assented toNo — it informs and offers choices
Key duty metTransparency under POPIA s 18Allocating risk and setting rulesDisclosing and managing trackers
Typical placementFooter link, referenced at every collection pointFooter link, accepted at sign-upFooter link, surfaced by a cookie banner

Common South African pitfalls

  • Using a generic or copied policy that does not match the site: a privacy policy must accurately describe the information you actually collect, your real purposes, and your true recipients. A template that lists data you do not gather, or omits an overseas processor you do use, fails POPIA section 18 and misleads data subjects.
  • No lawful basis for processing: every processing activity needs a basis under section 11 of POPIA. Relying on vague “consent” for everything, or on a legitimate interest that does not exist, leaves the processing unlawful — even if the policy reads well.
  • Assuming consent for direct marketing: section 69 of POPIA generally requires prior opt-in consent for electronic direct marketing to non-customers. Pre-ticked boxes, bundled consent, or marketing to people who never agreed are common and serious breaches that the policy and sign-up flow must avoid.
  • Ignoring cross-border transfers: many websites use overseas hosting, email, and analytics tools, which means personal information leaves South Africa. Failing to disclose this and to rely on a section 72 safeguard is a frequent gap, especially for small businesses on global SaaS platforms.
  • Listing rights without enabling them: it is not enough to recite the rights of access, correction, deletion and objection. The policy must give a working route — an Information Officer contact and a process — so data subjects can actually exercise them, and you must be ready to respond.
  • No named Information Officer or complaints route: POPIA requires a responsible party to have an Information Officer, and section 18 requires the responsible party’s identity and contact details to be given. A policy that names no one and gives no path to the Information Regulator is incomplete.

Frequently asked questions

Does my website legally need a privacy policy in South Africa?

If your website collects any personal information, then in substance yes. POPIA does not use the phrase “privacy policy”, but section 18 requires you to make data subjects aware of what you collect, why, who receives it, and their rights — and a privacy policy is the principal way that duty is met. A site that processes personal data without one is exposed to the Information Regulator.

What must a POPIA-compliant privacy policy contain?

At minimum: what personal information you collect and how, the purposes and your lawful basis under section 11, who the recipients and operators are, any cross-border transfers and their safeguards, retention periods, the data-subject rights and how to exercise them, your cookie and direct-marketing practices, and your Information Officer’s contact details plus how to complain to the Information Regulator.

What is the difference between a privacy policy and terms of use?

A privacy policy is a POPIA notice that tells users how their personal information is handled. Terms of use are a contract that governs how people may use the site — permitted conduct, intellectual property, liability and so on. They serve different legal purposes, so a website that collects personal data generally needs both, cross-linked rather than merged.

Do I need consent to send marketing emails under POPIA?

Generally yes. Section 69 of POPIA requires prior opt-in consent for electronic direct marketing to people who are not already your customers, with a narrow exception allowing marketing of similar products to existing customers who were given a chance to opt out. Pre-ticked boxes and assumed consent do not comply, so your sign-up flow must capture genuine opt-in.

Do I need consent to use cookies and analytics?

Where cookies and analytics collect personal information, you must be transparent about them and have a lawful basis under POPIA. Best practice is a clear cookie notice (often a separate cookie policy) and, for non-essential cookies, obtaining consent through a cookie banner. Strictly necessary cookies can usually rely on a legitimate interest rather than consent.

What rights do website users have over their personal information?

Under POPIA data subjects can be informed about processing, access their personal information (section 23), require correction or deletion of inaccurate, irrelevant, excessive or out-of-date information (section 24), object to processing in certain cases (section 11(3)), and complain to the Information Regulator. Your privacy policy must explain these rights and provide a working way to exercise them.

Can I transfer personal information outside South Africa?

Yes, but only with a safeguard under section 72 of POPIA — for example the recipient is subject to a law or binding rules providing adequate protection, the data subject consents, or the transfer is necessary to perform a contract. Because most websites use overseas hosting, email and analytics tools, you should disclose these transfers and the basis relied on in your policy.

Who is the Information Officer and do I need one?

Every responsible party under POPIA has an Information Officer responsible for compliance and for handling requests and complaints; for a company this defaults to the head of the organisation unless someone is designated. Your privacy policy must give their contact details, as section 18 requires the data subject to be told the responsible party’s identity and how to reach it.

Sources & authority

This guide is general information, not legal advice. It reflects the law as at June 2026.

Get your Website Privacy Policy reviewed or drafted

Upload an existing document for a fixed-fee review, or have a bespoke Website Privacy Policy drafted for your business — personally, by a senior corporate and commercial attorney. No obligation to proceed.

Review: Fixed fee from R8 325 (excl. VAT) · 24-hour turnaroundDraft: Fixed fee from R8 175 (excl. VAT)

For the businesses we act for

The Keystone Workspace

The attorney-designed platform the businesses we act for use to run their contracts, e-signatures and company secretarial work in one place.

Why you can trust this: Martin Kotze has been an admitted Attorney of the High Court of South Africa, registered Conveyancer, and Notary Public since 2014, practising from Pretoria. The firm is regulated by the Legal Practice Council under firm registration 17444.

This guide is general information, not legal advice for your specific matter.