Privacy Policy Generator South Africa
POPIA’s eight conditions, an Information Officer who must be registered, and the PAIA manual nobody remembers.
A POPIA privacy notice has to name a registered Information Officer and address section 69 marketing consent and section 72 transfers explicitly. It also has to coexist with a PAIA manual, which is a separate document most South African businesses have never produced.
POPIA sets eight conditions for lawful processing and is enforced by the Information Regulator. Two of its requirements are structural rather than documentary: every responsible party must designate an Information Officer, and that officer must be registered with the Regulator before acting.
The second easily-missed obligation comes from a different statute. PAIA requires most private bodies to compile and make available a manual describing the records they hold and how to request access to them. It is separate from the privacy notice and is frequently absent entirely.
Direct marketing is unusually strict. Section 69 of POPIA requires opt-in consent for electronic marketing to anyone who is not an existing customer, and the consent has to be sought in a prescribed form - once only, if refused.
What a privacy policy in South Africa has to cover
The registered Information Officer, with contact details and registration status
The purpose and lawful justification for each processing operation under the eight conditions
Special personal information and the authorisation relied on
Section 69 direct marketing consent, split by customer status
Section 72 cross-border transfer basis for each offshore recipient
How South Africa actually moves personal data
Customer records and identity numbers
South African ID numbers are widely used and directly identifying, which raises the stakes on access control and retention.
Direct marketing lists
Section 69 splits the world into existing customers and everyone else, with different consent requirements for each.
Cross-border hosting
Most South African businesses use offshore infrastructure, engaging section 72 and its comparable-protection test.
Special personal information
Race, health, biometrics, religion and trade union membership need an authorisation under POPIA, not merely a lawful purpose.
Access requests under PAIA
Requests arrive under PAIA rather than POPIA for many record types, with prescribed forms and fees.
Third parties the draft will ask you about
PayFast or Peach Payments · Stripe · The Courier Guy · Xero or Sage · AWS af-south-1 · Mailchimp
The rules that apply
POPIA and its eight conditions
Accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
Information Officer registration
Designation is mandatory and registration with the Information Regulator is required before the officer acts.
PAIA manual
A separate statutory document describing the records held and the access request procedure, made available at the business’s premises and website.
Section 69 direct marketing
Opt-in consent for electronic marketing to non-customers, sought in the prescribed form and only once if declined.
Cross-border transfers (section 72)
Permitted where the recipient is subject to comparable protection, the data subject consents, or another listed condition applies.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
POPIA compliance essentials
Designate and register the Information Officer
Registration with the Information Regulator is required before they act.
Compile and publish a PAIA manual
Describing records held and the access request procedure.
Split your marketing list by customer status
Section 69 treats existing customers differently from everyone else.
Record the section 72 basis for each offshore recipient
Comparable protection, consent, or another listed condition.
Identify authorisations for special personal information
Before processing it, not afterwards.
Where this usually goes wrong
An Information Officer designated but never registered
Registration with the Regulator is a distinct step and is checkable.
No PAIA manual
A separate statutory obligation from the privacy notice, and one of the most commonly missing documents.
Marketing to non-customers without section 69 consent
The prescribed form matters, and repeated requests after a refusal are prohibited.
Special personal information processed without authorisation
POPIA requires a specific authorisation, not just a purpose.
Cross-border transfers with no section 72 analysis
The comparable-protection test has to be applied and recorded.
Frequently asked questions
Do I need to register an Information Officer?
Yes. POPIA requires every responsible party to designate one, and the Information Regulator requires registration before the officer acts. The default holder is the head of the organisation unless delegated.
What is a PAIA manual?
A statutory document required by the Promotion of Access to Information Act describing the records your organisation holds and how someone requests access. It is separate from the POPIA privacy notice.
Can I send marketing emails in South Africa?
To existing customers about similar products, yes with an opt-out. To anyone else, section 69 requires prior opt-in consent sought in the prescribed form, and you may only ask once if the person declines.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator South Africa
Answer a short questionnaire and get a draft written for South Africa. Free to start, no card required.
Generate your privacy policyOther documents for South Africa
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.