Legal pages are the least interesting part of a website, and usually the last thing anyone thinks about. They are also the part that matters most on the day something goes wrong. In South Africa they are not really optional any more — POPIA changed that — and the good news is they protect you at least as much as they protect your customers.
The Short Version
If your website collects any personal information — a contact form, an email signup, an enquiry, even server logs — South African law expects you to explain what you collect, why, and what you do with it. That explanation is your privacy policy.
Terms and a disclaimer are not legally mandated in the same way, but they define what you have actually promised. Without them, anything on your site can be read as a commitment.
The Three Documents
1. Privacy policy
The one that is genuinely required. Under the Protection of Personal Information Act (POPIA), if you process personal information you must tell people what you collect, why you collect it, who you share it with, how long you keep it, and what rights they have over it.
"Processing" is broader than most people expect. A contact form is processing. So is an email list, a booking system, or analytics that record IP addresses.
2. Terms of service
Sets the rules for using your site and, if you sell or provide services through it, the basis on which you do so. Payment terms, cancellation, what happens if someone misuses the site, who owns the content, and which country's law applies.
3. Disclaimer
Draws a line around what your content actually commits you to. This is the one most businesses skip and most often need.
A concrete example. We publish a blog article with typical website price ranges. Without a disclaimer, someone could reasonably treat those figures as a quotation. With one, it is explicit that they are general guidance and the real number comes from a written quote. That single paragraph prevents a genuinely awkward conversation.
What POPIA Expects
| Requirement | What it means in practice |
|---|---|
| Say what you collect | List it plainly — name, email, phone, message, technical data. |
| Have a lawful reason | Consent, performing a contract, a legal obligation, or a legitimate interest. Pick the honest one. |
| Collect only what you need | If a form asks for a birth date you never use, remove the field. |
| Name who you share it with | Hosting, email, analytics, payment providers — your processors. |
| Disclose cross-border storage | Most hosting and email sits on overseas servers. Say so. |
| State retention periods | How long you keep things, and why. |
| Explain people's rights | Access, correction, deletion, objection, and complaining to the Information Regulator. |
| Give a real contact route | A monitored address where requests actually land. |
Why This Protects You
It is easy to read compliance as pure obligation. In practice these pages work in your favour more often than against you.
- They cap expectations. A disclaimer stops indicative timelines and illustrative pricing being treated as promises.
- They settle disputes early. When there is disagreement about what was agreed, written terms resolve it far more cheaply than the alternative.
- They signal legitimacy. Larger clients and procurement processes check for them. Their absence is noticed.
- They are increasingly expected. Payment providers, app platforms and advertising accounts frequently require a published privacy policy before approving you.
- They reduce regulatory exposure. POPIA has real enforcement powers. Having made a genuine effort matters.
Common Mistakes
Copying another company's policy
The most common one, and the most dangerous. A copied policy describes someone else's data practices. If it says you use a CRM you do not have, or omits the analytics you do run, it is inaccurate — which is arguably worse than having nothing, because you have now made a false statement.
Writing it once and forgetting it
Add a booking system, a newsletter or a new analytics tool and your policy is out of date the same day.
Hiding it
Convention is a link in the footer on every page. It costs nothing and it is where people look.
Contradicting yourself
If your policy says you keep enquiries for 12 months and your terms say indefinitely, you have created the ambiguity these documents exist to remove.
Website Documentation Checklist
How Much Is Enough?
Proportionate to what you actually do. A five-page brochure site with one contact form needs a short, honest privacy policy, basic terms and a disclaimer. A platform handling payments, accounts and customer records needs considerably more — cookie policy, acceptable use, refund terms, and disclosure of any third-party integrations.
The test is not length. It is whether someone reading it would come away with an accurate picture of what happens to their information.
Nobody reads your privacy policy until the moment they have a reason to. That is exactly when it needs to be accurate.
Need policies for your site?
We write legal pages that reflect how your business actually operates — not copied boilerplate that describes someone else.
Talk To UsYou can see how we apply this to our own site in our privacy policy, terms of service and disclaimer.
To be clear: this article is general information, not legal advice. We are a design studio, not a law firm. For anything involving significant risk — large volumes of personal data, health or financial information, or a complex platform — have a qualified attorney review your documents.
Keep Reading
More From The Blog
What Is a CRM, and Does Your Small Business Actually Need One?
Spreadsheets, WhatsApp and a notebook work fine — until they don't. Here's what a CRM actually does and how to tell if you need one.
Read ArticleIntroducing Alba Business Desk: A CRM Built for South African SMEs
Customers, deals, tasks, invoicing and reporting in one workspace — R699 a month for the whole business, not per user.
Read Article