What is a website privacy policy?
Is a privacy policy legally required for a website in South Africa?
“When collecting personal information, the responsible party must take reasonably practicable steps to ensure the data subject is aware of the information being collected, the purpose of collection, whether supply is voluntary or mandatory, the consequences of failing to supply it, the responsible party’s identity and contact details, the recipients of the information, and the data subject’s rights — the substance of a privacy policy.”
“Processing requires a lawful basis such as consent, contract, legal obligation or legitimate interest (s 11), and the data subject may object to processing (s 11(3)), request access to their information (s 23) and require correction or deletion of inaccurate or excessive information (s 24); direct marketing by electronic communication generally requires prior opt-in consent (s 69).”
“ECTA section 51 set out voluntary principles a data collector could choose to subscribe to when electronically collecting personal information — collecting only what is necessary, disclosing the purpose, not using the information for other purposes without consent, and keeping a record. These principles were never mandatory and have been overtaken by POPIA, which now governs; they are noted only as historical context, not as a binding privacy-policy requirement.”
When you need a Website Privacy Policy
- When your website or app collects any personal information — names, email addresses, phone numbers, ID numbers, payment details — through contact forms, sign-ups, checkouts, or enquiries.
- When you use cookies, analytics, pixels, or similar tracking technologies that gather information about visitors and their behaviour on the site.
- When you share personal information with operators or third parties — payment gateways, hosting providers, email and marketing platforms, CRM tools — or transfer it outside South Africa.
- When you send electronic direct marketing such as newsletters or promotional emails, where section 69 of POPIA generally requires opt-in consent that the policy and sign-up flow must reflect.
- When you must give data subjects a clear, single place to understand their rights and exercise them, and to find your Information Officer’s contact details and how to complain to the Information Regulator.
What a Website Privacy Policy should contain
Information collected and how
List the categories of personal information you collect — for example contact details, account credentials, payment information, and technical data — and the sources, including forms, accounts, cookies, analytics, and third parties. POPIA’s minimality principle means you should collect only what is necessary, so the policy should be honest about the actual data captured.
Purposes and lawful basis
State why you process each type of information and the lawful basis under section 11 of POPIA — consent, performance of a contract, a legal obligation, protection of a legitimate interest, or your legitimate interests. Tying purposes to a lawful basis is the core of POPIA compliance and prevents “purpose creep” into uses the data subject never agreed to.
Recipients, operators and sharing
Identify who receives the information — internal teams, operators who process on your behalf (hosting, payments, email), and any other third parties — and on what basis. Section 18 requires data subjects to be told who the recipients are, and operators must be bound by a written contract to process only on your instructions and to keep the data secure.
Cross-border transfers
Disclose whether personal information is transferred outside South Africa — for example to overseas cloud or email providers — and the safeguards relied on under section 72 of POPIA, such as the recipient being subject to adequate protection, the data subject’s consent, or the transfer being necessary for the contract. Many common SaaS tools host data abroad, so this is rarely optional.
Retention and security
Explain how long you keep personal information and the basis for those periods, and describe the security safeguards you apply. POPIA requires that information not be kept longer than necessary for the purpose and that the responsible party secure the integrity and confidentiality of personal information through appropriate, reasonable technical and organisational measures.
Data-subject rights and how to exercise them
Set out the data subject’s rights — to be informed, to access their information (section 23), to have it corrected or deleted (section 24), to object to processing (section 11(3)), and to lodge a complaint — and explain the practical steps to exercise each, including any prescribed forms. The policy must not merely list rights but enable them.
Cookies and direct marketing
Describe the cookies and trackers the site uses and how users can manage them (often via a separate cookie policy), and set out your direct-marketing practices. Under section 69 of POPIA, electronic direct marketing to people who are not already your customers generally requires prior opt-in consent, so pre-ticked boxes and assumed consent are non-compliant.
Information Officer and complaints
Give the contact details of your Information Officer (and any deputy), who is responsible for POPIA compliance and for handling requests and complaints. Explain that data subjects may also complain to the Information Regulator, and provide the Regulator’s contact route. This is both a section 18 requirement and the practical channel for resolving concerns.
Privacy policy vs terms of use vs cookie policy
| Feature | Privacy policy | Terms of use | Cookie policy |
|---|---|---|---|
| What it is | A POPIA notice about personal information | A contract governing use of the site | A notice about cookies and trackers |
| Primary law | POPIA (ECTA’s voluntary principles predate it) | Common law of contract, ECTA, CPA | POPIA, plus consent norms |
| Binds the user? | No — it informs; consent is separate | Yes — once assented to | No — it informs and offers choices |
| Key duty met | Transparency under POPIA s 18 | Allocating risk and setting rules | Disclosing and managing trackers |
| Typical placement | Footer link, referenced at every collection point | Footer link, accepted at sign-up | Footer link, surfaced by a cookie banner |
Common South African pitfalls
- Using a generic or copied policy that does not match the site: a privacy policy must accurately describe the information you actually collect, your real purposes, and your true recipients. A template that lists data you do not gather, or omits an overseas processor you do use, fails POPIA section 18 and misleads data subjects.
- No lawful basis for processing: every processing activity needs a basis under section 11 of POPIA. Relying on vague “consent” for everything, or on a legitimate interest that does not exist, leaves the processing unlawful — even if the policy reads well.
- Assuming consent for direct marketing: section 69 of POPIA generally requires prior opt-in consent for electronic direct marketing to non-customers. Pre-ticked boxes, bundled consent, or marketing to people who never agreed are common and serious breaches that the policy and sign-up flow must avoid.
- Ignoring cross-border transfers: many websites use overseas hosting, email, and analytics tools, which means personal information leaves South Africa. Failing to disclose this and to rely on a section 72 safeguard is a frequent gap, especially for small businesses on global SaaS platforms.
- Listing rights without enabling them: it is not enough to recite the rights of access, correction, deletion and objection. The policy must give a working route — an Information Officer contact and a process — so data subjects can actually exercise them, and you must be ready to respond.
- No named Information Officer or complaints route: POPIA requires a responsible party to have an Information Officer, and section 18 requires the responsible party’s identity and contact details to be given. A policy that names no one and gives no path to the Information Regulator is incomplete.
Frequently asked questions
Does my website legally need a privacy policy in South Africa?
If your website collects any personal information, then in substance yes. POPIA does not use the phrase “privacy policy”, but section 18 requires you to make data subjects aware of what you collect, why, who receives it, and their rights — and a privacy policy is the principal way that duty is met. A site that processes personal data without one is exposed to the Information Regulator.
What must a POPIA-compliant privacy policy contain?
At minimum: what personal information you collect and how, the purposes and your lawful basis under section 11, who the recipients and operators are, any cross-border transfers and their safeguards, retention periods, the data-subject rights and how to exercise them, your cookie and direct-marketing practices, and your Information Officer’s contact details plus how to complain to the Information Regulator.
What is the difference between a privacy policy and terms of use?
A privacy policy is a POPIA notice that tells users how their personal information is handled. Terms of use are a contract that governs how people may use the site — permitted conduct, intellectual property, liability and so on. They serve different legal purposes, so a website that collects personal data generally needs both, cross-linked rather than merged.
Do I need consent to send marketing emails under POPIA?
Generally yes. Section 69 of POPIA requires prior opt-in consent for electronic direct marketing to people who are not already your customers, with a narrow exception allowing marketing of similar products to existing customers who were given a chance to opt out. Pre-ticked boxes and assumed consent do not comply, so your sign-up flow must capture genuine opt-in.
Do I need consent to use cookies and analytics?
Where cookies and analytics collect personal information, you must be transparent about them and have a lawful basis under POPIA. Best practice is a clear cookie notice (often a separate cookie policy) and, for non-essential cookies, obtaining consent through a cookie banner. Strictly necessary cookies can usually rely on a legitimate interest rather than consent.
What rights do website users have over their personal information?
Under POPIA data subjects can be informed about processing, access their personal information (section 23), require correction or deletion of inaccurate, irrelevant, excessive or out-of-date information (section 24), object to processing in certain cases (section 11(3)), and complain to the Information Regulator. Your privacy policy must explain these rights and provide a working way to exercise them.
Can I transfer personal information outside South Africa?
Yes, but only with a safeguard under section 72 of POPIA — for example the recipient is subject to a law or binding rules providing adequate protection, the data subject consents, or the transfer is necessary to perform a contract. Because most websites use overseas hosting, email and analytics tools, you should disclose these transfers and the basis relied on in your policy.
Who is the Information Officer and do I need one?
Every responsible party under POPIA has an Information Officer responsible for compliance and for handling requests and complaints; for a company this defaults to the head of the organisation unless someone is designated. Your privacy policy must give their contact details, as section 18 requires the data subject to be told the responsible party’s identity and how to reach it.
Sources & authority
- Protection of Personal Information Act 4 of 2013 (ss 11, 18, 23, 24, 69 & 72)
- Electronic Communications and Transactions Act 25 of 2002 (s 51) — voluntary principles, predating and overtaken by POPIA
This guide is general information, not legal advice. It reflects the law as at June 2026.