Cookie Policy Generator South Africa
POPIA’s eight conditions, an Information Officer who must be registered, and the PAIA manual nobody remembers.
POPIA does not name cookies, but the ECT Act and POPIA’s processing conditions together produce a consent expectation for tracking, and the Information Regulator has treated undisclosed tracking as a transparency failure under the openness condition.
POPIA sets eight conditions for lawful processing and is enforced by the Information Regulator. Two of its requirements are structural rather than documentary: every responsible party must designate an Information Officer, and that officer must be registered with the Regulator before acting.
The second easily-missed obligation comes from a different statute. PAIA requires most private bodies to compile and make available a manual describing the records they hold and how to request access to them. It is separate from the privacy notice and is frequently absent entirely.
Direct marketing is unusually strict. Section 69 of POPIA requires opt-in consent for electronic marketing to anyone who is not an existing customer, and the consent has to be sought in a prescribed form - once only, if refused.
What a cookie policy in South Africa has to cover
Each cookie and tracker mapped to a POPIA processing condition
Consent for non-essential tracking, obtained before the cookie is placed
Section 72 cross-border implications of advertising and analytics providers
The registered Information Officer as the contact for tracking queries
How a data subject objects to tracking, and what changes when they do
How South Africa actually moves personal data
Customer records and identity numbers
South African ID numbers are widely used and directly identifying, which raises the stakes on access control and retention.
Direct marketing lists
Section 69 splits the world into existing customers and everyone else, with different consent requirements for each.
Cross-border hosting
Most South African businesses use offshore infrastructure, engaging section 72 and its comparable-protection test.
Special personal information
Race, health, biometrics, religion and trade union membership need an authorisation under POPIA, not merely a lawful purpose.
Access requests under PAIA
Requests arrive under PAIA rather than POPIA for many record types, with prescribed forms and fees.
Third parties the draft will ask you about
PayFast or Peach Payments · Stripe · The Courier Guy · Xero or Sage · AWS af-south-1 · Mailchimp
The rules that apply
POPIA and its eight conditions
Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
Information Officer registration
Designation is mandatory and registration with the Information Regulator is required before the officer acts.
PAIA manual
A separate statutory document describing the records held and the access request procedure, made available at the business’s premises and website.
Section 69 direct marketing
Opt-in consent for electronic marketing to non-customers, sought in the prescribed form and only once if declined.
Cross-border transfers (section 72)
Permitted where the recipient is subject to comparable protection, the data subject consents, or another listed condition applies.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
POPIA compliance essentials
Designate and register the Information Officer
Registration with the Information Regulator is required before they act.
Compile and publish a PAIA manual
Describing records held and the access request procedure.
Split your marketing list by customer status
Section 69 treats existing customers differently from everyone else.
Record the section 72 basis for each offshore recipient
Comparable protection, consent, or another listed condition.
Identify authorisations for special personal information
Before processing it, not afterwards.
Where this usually goes wrong
An Information Officer designated but never registered
Registration with the Regulator is a distinct step and is checkable.
No PAIA manual
A separate statutory obligation from the privacy notice, and one of the most commonly missing documents.
Marketing to non-customers without section 69 consent
The prescribed form matters, and repeated requests after a refusal are prohibited.
Special personal information processed without authorisation
POPIA requires a specific authorisation, not just a purpose.
Cross-border transfers with no section 72 analysis
The comparable-protection test has to be applied and recorded.
Frequently asked questions
Do I need to register an Information Officer?
Yes. POPIA requires every responsible party to designate one, and the Information Regulator requires registration before the officer acts. The default holder is the head of the organisation unless delegated.
What is a PAIA manual?
A statutory document required by the Promotion of Access to Information Act describing the records your organisation holds and how someone requests access. It is separate from the POPIA privacy notice.
Can I send marketing emails in South Africa?
To existing customers about similar products, yes with an opt-out. To anyone else, section 69 requires prior opt-in consent sought in the prescribed form, and you may only ask once if the person declines.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator South Africa
Answer a short questionnaire and get a draft written for South Africa. Free to start, no card required.
Generate your cookie policyOther documents for South Africa
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.