A privacy policy is no longer an optional extra for South African websites, it is a legal requirement and a basic mark of a trustworthy business. Under POPIA, if your site collects any personal information at all, and almost every site does, you need a clear policy explaining what you collect and why. The reassuring news is that a solid privacy policy is quick to put together once you know what it must contain, and having one in place protects both your customers and your business.
This guide explains whether you actually need a privacy policy, what it must include under POPIA, how to create one that genuinely reflects your business, and where to place it on your site. It is written in plain language for South African business owners rather than lawyers, so you can get compliant without the jargon.
📋 Key Takeaways
Do you actually need a privacy policy?
Yes, in almost every case. The moment your website has a contact form, a newsletter signup, an online store, or even analytics cookies, you are collecting personal information, and that triggers your obligations under POPIA. There is no exemption for small businesses, so the size of your operation does not change the requirement. If in doubt, assume you need one, because the bar for collecting personal information is very low.
Beyond the legal obligation, a privacy policy is something customers increasingly look for. Its presence signals that you take their information seriously and handle it responsibly, which builds the trust that underpins every online interaction. Its absence, by contrast, can make a cautious visitor think twice before sharing their details with you.
What POPIA requires
POPIA, the Protection of Personal Information Act, governs how South African businesses may collect, use and store personal information. For your website, the practical upshot is that you must be transparent about your data practices, collect only what you need, keep it secure, and give people a way to exercise their rights over their own information. A privacy policy is the document that demonstrates this transparency.
Your privacy policy works alongside the other POPIA essentials, such as cookie consent and HTTPS, which we cover in our full POPIA website compliance guide. Together they form the baseline that keeps a typical small business website on the right side of the law.
What your privacy policy must include
A compliant privacy policy is specific to your business rather than a vague catch-all. At minimum, it should clearly cover the following points, written in language an ordinary customer can understand:
The principles behind a good policy
Keeping these principles front of mind makes writing the policy much easier, because each section simply answers an honest question about how your business actually treats personal information. The policy is really just those answers, written down clearly.
How to create your privacy policy
You have a few options, and the right one depends on your comfort level and the complexity of your data handling. You can adapt a reputable template to your specific business, use a trustworthy policy generator, or have one written for you. Whichever route you choose, the non-negotiable is that the final policy must accurately describe what your website really does with personal information.
Generators and templates are a fine starting point, but they are only a skeleton. Take the time to edit them so every clause is true for your business, removing anything that does not apply and adding anything specific to how you operate. An accurate, tailored policy is both more compliant and more reassuring than a generic one.
⚠️ Watch Out: Do not simply copy another website’s privacy policy. If it describes data practices you do not follow, it is not compliant and can create more legal risk than having no policy at all. Always tailor it to your actual business.
The link to your cookie policy
Closely related to your privacy policy is your cookie consent. If your site uses non-essential cookies, such as analytics or advertising trackers, POPIA expects you to obtain consent before they run, usually via a cookie banner. Many businesses combine a short cookie notice with their main privacy policy so visitors can see the full picture in one place.
The key standard is that consent must be a genuine, informed choice, not a pre-ticked box or an assumption. Pairing a clear cookie banner with your privacy policy covers both halves of this obligation neatly.
Where to put your privacy policy
Placement matters as much as content. Link your privacy policy in your website footer so it appears on every single page, which is exactly where visitors and regulators expect to find it. It is the universal convention, and following it makes your policy easy to locate at any time.
It is also good practice to reference the policy on any form that collects personal information, with a short line explaining what the details will be used for. This form-level notice, combined with the footer link, shows that you are being transparent at the actual point of data collection.
💡 Pro Tip: Set a reminder to review your privacy policy once a year, or whenever you add a new tool that handles customer data, such as a new analytics platform or email service. An out-of-date policy quietly stops being accurate.
Common privacy policy mistakes
Quick recap
Frequently asked questions
Do I need a privacy policy for a small website?
Yes. If your site collects any personal information, including via a contact form, newsletter or analytics cookies, POPIA requires a privacy policy. There is no exemption based on business size.
Can I use a free privacy policy template?
You can use a reputable template as a starting point, but you must edit it to accurately reflect your actual data practices. A generic, unedited policy is not properly compliant.
Where should my privacy policy go on my website?
Link it in your website footer so it appears on every page, and reference it on any form that collects personal information. That is where visitors and regulators expect to find it.
How a privacy policy builds customer trust
Compliance is the obvious reason to have a privacy policy, but trust is the underrated one. South African consumers have grown more aware of how their data is used, and a clear, honest privacy policy reassures them that you handle their information responsibly. That reassurance lowers the hesitation people feel before filling in a form or completing a purchase, which has a direct, if quiet, effect on your conversions.
A good policy also signals professionalism. It tells visitors that you run a proper business that takes its obligations seriously, which sets you apart from the many sites that ignore the requirement entirely. In a market where trust is hard-won, that small signal of credibility is well worth the modest effort of getting your policy right.
How often should I update my privacy policy?
Review it at least once a year, and whenever you add a new tool that handles customer data, such as a new email platform or analytics service. An outdated policy that no longer matches your practices is not compliant.
What is the difference between a privacy policy and terms of service?
A privacy policy explains how you handle personal information and is required under POPIA. Terms of service set the rules for using your website or buying from you, such as payment, delivery and liability. They are separate documents that serve different purposes, and many businesses have both.
Can I be fined for not having a privacy policy?
POPIA non-compliance can carry significant penalties, and a missing or inadequate privacy policy is a clear compliance gap. Beyond any fine, it undermines customer trust, so a proper policy is well worth the small effort it takes.
Need a compliant, well-built website? Our web design team builds POPIA-ready sites with privacy policies and consent in place. email us at [email protected].