The POPIA privacy policy your South African online store actually needs
Most SA store privacy policies are copied from a US template, mention the GDPR, and would not survive a single question from the Information Regulator. Here is what POPIA actually requires, section by section, and how to write it.
We audit privacy policies on nearly every store we take over. The pattern is consistent. The policy names a “Data Protection Officer” (a GDPR role that does not exist in South African law), references a right to be forgotten in European terms, and never once names the person legally accountable for personal information at the business. It was pasted from a generator in about ninety seconds.
POPIA has been fully enforceable since July 2021. It applies to you the moment you collect an email address, not when you reach some revenue threshold. And the obligations are specific enough that a generic policy fails them structurally, not just cosmetically.
The four things a generic template always gets wrong
1. It does not name an Information Officer. Under POPIA every responsible party has an Information Officer. In a sole proprietorship or small company, that is the owner by default. The role must be identified, and registration with the Information Regulator is required. A policy that omits this is missing the single most South African thing about POPIA.
2. It does not state a lawful basis for each processing activity. POPIA sets eight conditions for lawful processing. You cannot satisfy them by asserting that you “value your privacy”. You have to say what you collect, why, and on what basis: consent, contractual necessity, legal obligation, or legitimate interest.
3. It does not list operators. Your payment gateway, your courier, your email platform, your analytics provider – each of these processes personal information on your behalf. POPIA calls them operators. They must be disclosed, and you need a written agreement with each one obliging them to secure the data.
4. It ignores cross-border transfer. Section 72 restricts sending personal information outside South Africa. If your store runs on Shopify, your email on a US provider, and your analytics through Google, you are transferring personal information abroad. That is permitted, but it must be disclosed and justified.
The eight conditions, in plain language
| Condition | What it means for your store |
|---|---|
| Accountability | You, personally, are responsible. Not the platform. |
| Processing limitation | Collect the minimum. A checkout does not need a date of birth. |
| Purpose specification | Say why you collect each field, before you collect it. |
| Further processing limitation | Order data collected to ship a parcel cannot silently become a marketing list. |
| Information quality | Keep it accurate. Let customers correct it. |
| Openness | Publish the policy. Tell people you hold their data. |
| Security safeguards | HTTPS, access control, and a plan for a breach. |
| Data subject participation | Customers can ask what you hold, and ask you to delete it. |
The sections your policy needs
- Who we are – registered name, company registration number, physical address. The ECT Act requires these on the site anyway.
- Our Information Officer – name and contact email.
- What we collect – itemised. Name, email, delivery address, phone, order history, IP address, cookie identifiers.
- Why we collect it – mapped one-to-one against the list above, with the lawful basis for each.
- Who we share it with – every operator, named. Your gateway. Your courier. Your email platform.
- Cross-border transfers – which operators are offshore and on what basis.
- How long we keep it – a real number. Tax law requires you keep invoice records for five years. Marketing consent does not need to be kept forever.
- Your rights – access, correction, deletion, objection to direct marketing, and complaint to the Information Regulator, with the Regulator’s contact details.
- Cookies – what you set, and how to refuse non-essential ones.
- Breach notification – your commitment to notify affected parties and the Regulator.
The direct marketing trap
This is where most SA stores are quietly non-compliant. Section 69 of POPIA restricts unsolicited electronic direct marketing. You may market to an existing customer about similar products, provided you gave them the chance to opt out when you first collected the address and in every message since. You may not add someone to a newsletter because they bought a kettle.
Practically: your checkout needs an unticked marketing opt-in box, separate from the terms acceptance. If your Shopify or WooCommerce checkout auto-subscribes buyers, turn that off today. It takes two minutes and it is the most common violation we find.
Do you need a lawyer?
Eventually, yes – and it is cheaper than you think if you arrive with a completed draft rather than a blank page. What costs money is a lawyer writing a policy from scratch while trying to work out what your store actually does. What costs very little is a lawyer reviewing a document you filled in yourself.
The editable template
An editable POPIA privacy policy, a CPA-compliant returns policy, and ECTA site disclosures ship inside the SA eCommerce Bundle 2026 – alongside the 19-chapter playbook, the 29-page market report, the Excel toolkit and 50 AI prompts. R500, instant download.
Compliance is not the interesting part of running an online store. It is also not optional, and it takes an afternoon rather than a quarter if you have the right starting document. Related reading: returns, refunds and the Consumer Protection Act.
This article is general information about the Protection of Personal Information Act, not legal advice. We build stores; we are not attorneys. Have a qualified legal practitioner review any policy before you publish it.



