By country

Cookie Policy Generator South Africa

POPIA’s eight conditions, an Information Officer who must be registered, and the PAIA manual nobody remembers.

Generate your cookie policy Read the cookie policy guide

POPIA does not name cookies, but the ECT Act and POPIA’s processing conditions together produce a consent expectation for tracking, and the Information Regulator has treated undisclosed tracking as a transparency failure under the openness condition.

POPIA sets eight conditions for lawful processing and is enforced by the Information Regulator. Two of its requirements are structural rather than documentary: every responsible party must designate an Information Officer, and that officer must be registered with the Regulator before acting.

The second easily-missed obligation comes from a different statute. PAIA requires most private bodies to compile and make available a manual describing the records they hold and how to request access to them. It is separate from the privacy notice and is frequently absent entirely.

Direct marketing is unusually strict. Section 69 of POPIA requires opt-in consent for electronic marketing to anyone who is not an existing customer, and the consent has to be sought in a prescribed form - once only, if refused.

What a cookie policy in South Africa has to cover

How South Africa actually moves personal data

Customer records and identity numbers

South African ID numbers are widely used and directly identifying, which raises the stakes on access control and retention.

Direct marketing lists

Section 69 splits the world into existing customers and everyone else, with different consent requirements for each.

Cross-border hosting

Most South African businesses use offshore infrastructure, engaging section 72 and its comparable-protection test.

Special personal information

Race, health, biometrics, religion and trade union membership need an authorisation under POPIA, not merely a lawful purpose.

Access requests under PAIA

Requests arrive under PAIA rather than POPIA for many record types, with prescribed forms and fees.

Third parties the draft will ask you about

PayFast or Peach Payments · Stripe · The Courier Guy · Xero or Sage · AWS af-south-1 · Mailchimp

The rules that apply

POPIA and its eight conditions

Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.

Information Officer registration

Designation is mandatory and registration with the Information Regulator is required before the officer acts.

PAIA manual

A separate statutory document describing the records held and the access request procedure, made available at the business’s premises and website.

Section 69 direct marketing

Opt-in consent for electronic marketing to non-customers, sought in the prescribed form and only once if declined.

Cross-border transfers (section 72)

Permitted where the recipient is subject to comparable protection, the data subject consents, or another listed condition applies.

What the generated cookie policy contains

POPIA compliance essentials

  1. Designate and register the Information Officer

    Registration with the Information Regulator is required before they act.

  2. Compile and publish a PAIA manual

    Describing records held and the access request procedure.

  3. Split your marketing list by customer status

    Section 69 treats existing customers differently from everyone else.

  4. Record the section 72 basis for each offshore recipient

    Comparable protection, consent, or another listed condition.

  5. Identify authorisations for special personal information

    Before processing it, not afterwards.

Where this usually goes wrong

An Information Officer designated but never registered

Registration with the Regulator is a distinct step and is checkable.

No PAIA manual

A separate statutory obligation from the privacy notice, and one of the most commonly missing documents.

Marketing to non-customers without section 69 consent

The prescribed form matters, and repeated requests after a refusal are prohibited.

Special personal information processed without authorisation

POPIA requires a specific authorisation, not just a purpose.

Cross-border transfers with no section 72 analysis

The comparable-protection test has to be applied and recorded.

Frequently asked questions

Do I need to register an Information Officer?

Yes. POPIA requires every responsible party to designate one, and the Information Regulator requires registration before the officer acts. The default holder is the head of the organisation unless delegated.

What is a PAIA manual?

A statutory document required by the Promotion of Access to Information Act describing the records your organisation holds and how someone requests access. It is separate from the POPIA privacy notice.

Can I send marketing emails in South Africa?

To existing customers about similar products, yes with an opt-out. To anyone else, section 69 requires prior opt-in consent sought in the prescribed form, and you may only ask once if the person declines.

Do I need a cookie policy as well as a privacy policy?

In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.

Do analytics cookies need consent?

In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.

Does a cookie policy need updating when I add a tool?

Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.

What about cookies set by embedded video and maps?

They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.

Cookie Policy Generator South Africa

Answer a short questionnaire and get a draft written for South Africa. Free to start, no card required.

Generate your cookie policy

Other documents for South Africa

Each one is written for the same context, not a generic template.

The same document, by country

Go deeper

PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.