Compliance

Why Your Website Needs Policies and Documentation

What South African businesses need on their site — and why it protects you as much as your customers.

Back to Blog

Legal pages are the least interesting part of a website, and usually the last thing anyone thinks about. They are also the part that matters most on the day something goes wrong. In South Africa they are not really optional any more — POPIA changed that — and the good news is they protect you at least as much as they protect your customers.

The Short Version

If your website collects any personal information — a contact form, an email signup, an enquiry, even server logs — South African law expects you to explain what you collect, why, and what you do with it. That explanation is your privacy policy.

Terms and a disclaimer are not legally mandated in the same way, but they define what you have actually promised. Without them, anything on your site can be read as a commitment.

The Three Documents

1. Privacy policy

The one that is genuinely required. Under the Protection of Personal Information Act (POPIA), if you process personal information you must tell people what you collect, why you collect it, who you share it with, how long you keep it, and what rights they have over it.

"Processing" is broader than most people expect. A contact form is processing. So is an email list, a booking system, or analytics that record IP addresses.

2. Terms of service

Sets the rules for using your site and, if you sell or provide services through it, the basis on which you do so. Payment terms, cancellation, what happens if someone misuses the site, who owns the content, and which country's law applies.

3. Disclaimer

Draws a line around what your content actually commits you to. This is the one most businesses skip and most often need.

A concrete example. We publish a blog article with typical website price ranges. Without a disclaimer, someone could reasonably treat those figures as a quotation. With one, it is explicit that they are general guidance and the real number comes from a written quote. That single paragraph prevents a genuinely awkward conversation.

What POPIA Expects

RequirementWhat it means in practice
Say what you collectList it plainly — name, email, phone, message, technical data.
Have a lawful reasonConsent, performing a contract, a legal obligation, or a legitimate interest. Pick the honest one.
Collect only what you needIf a form asks for a birth date you never use, remove the field.
Name who you share it withHosting, email, analytics, payment providers — your processors.
Disclose cross-border storageMost hosting and email sits on overseas servers. Say so.
State retention periodsHow long you keep things, and why.
Explain people's rightsAccess, correction, deletion, objection, and complaining to the Information Regulator.
Give a real contact routeA monitored address where requests actually land.

Why This Protects You

It is easy to read compliance as pure obligation. In practice these pages work in your favour more often than against you.

  • They cap expectations. A disclaimer stops indicative timelines and illustrative pricing being treated as promises.
  • They settle disputes early. When there is disagreement about what was agreed, written terms resolve it far more cheaply than the alternative.
  • They signal legitimacy. Larger clients and procurement processes check for them. Their absence is noticed.
  • They are increasingly expected. Payment providers, app platforms and advertising accounts frequently require a published privacy policy before approving you.
  • They reduce regulatory exposure. POPIA has real enforcement powers. Having made a genuine effort matters.

Common Mistakes

Copying another company's policy

The most common one, and the most dangerous. A copied policy describes someone else's data practices. If it says you use a CRM you do not have, or omits the analytics you do run, it is inaccurate — which is arguably worse than having nothing, because you have now made a false statement.

Writing it once and forgetting it

Add a booking system, a newsletter or a new analytics tool and your policy is out of date the same day.

Hiding it

Convention is a link in the footer on every page. It costs nothing and it is where people look.

Contradicting yourself

If your policy says you keep enquiries for 12 months and your terms say indefinitely, you have created the ambiguity these documents exist to remove.

Website Documentation Checklist

How Much Is Enough?

Proportionate to what you actually do. A five-page brochure site with one contact form needs a short, honest privacy policy, basic terms and a disclaimer. A platform handling payments, accounts and customer records needs considerably more — cookie policy, acceptable use, refund terms, and disclosure of any third-party integrations.

The test is not length. It is whether someone reading it would come away with an accurate picture of what happens to their information.

Nobody reads your privacy policy until the moment they have a reason to. That is exactly when it needs to be accurate.

Need policies for your site?

We write legal pages that reflect how your business actually operates — not copied boilerplate that describes someone else.

Talk To Us

You can see how we apply this to our own site in our privacy policy, terms of service and disclaimer.

To be clear: this article is general information, not legal advice. We are a design studio, not a law firm. For anything involving significant risk — large volumes of personal data, health or financial information, or a complex platform — have a qualified attorney review your documents.

Have a project in mind?

Tell us about your business and we'll get back to you with a tailored price inquiry — no obligation.

Get A Price Inquiry