Guide
What your privacy policy must include under POPIA (with template)
A POPIA privacy policy must tell people who you are, what personal information you collect and from where, why you collect it, whether supplying it is voluntary or mandatory and what happens if they refuse, who you share it with, whether it leaves South Africa, how long you keep it, how you secure it, and what rights they have, including how to reach your Information Officer and how to complain to the Information Regulator. That list is not best practice; it comes almost clause for clause from section 18 of the Act. This article maps each required clause to the section it comes from, walks through the eight conditions behind them, and covers the items most policies miss.
New to the Act? Start with who must comply - the short answer is almost every business - and the seven-step compliance checklist.
Where the requirement actually comes from
POPIA never prescribes a document called a "privacy policy". The duty sits in section 18, under the openness condition: when you collect personal information, you must take reasonably practicable steps to make the data subject aware of a specific list of things. A published privacy policy is the standard, practical way to do that once, in one place, for everyone you collect from. Get section 18 right and the policy largely writes itself.
The required clauses, mapped to Section 18
- What you collect, and its source - the information being collected and, where it does not come from the data subject directly, where you got it (section 18(1)(a)).
- Who you are - the name and address of the responsible party (section 18(1)(b)).
- Why you collect it - the purpose of collection (section 18(1)(c)).
- Voluntary or mandatory - whether supplying the information is voluntary or mandatory (section 18(1)(d)), and the consequences of not providing it (section 18(1)(e)). This pair is the most commonly missing content in policies we see.
- Any law requiring collection - name the particular law where one authorises or requires the collection, such as FICA or tax legislation (section 18(1)(f)).
- Cross-border transfers - whether you intend to send the information outside South Africa, and the level of protection it will have there (section 18(1)(g)).
- Recipients, rights, and recourse - the further information needed to make processing reasonable: who receives the information, the right of access and correction, the right to object, and how to lodge a complaint with the Information Regulator (section 18(1)(h)).
To those, add two items that come from elsewhere in the Act: your retention approach (records may not be kept longer than necessary, section 14) and a description of your security measures (section 19). A policy that ends at the section 18 list but says nothing about retention or security answers the openness condition while leaving readers in the dark on the two things they ask about most.
How the eight conditions show up as clauses
POPIA's eight conditions for lawful processing are the skeleton of the whole Act, and a complete policy touches each one:
- Accountability (section 8) - the clause naming the responsible party and the Information Officer's contact details.
- Processing limitation (sections 9-12) - your legal basis clause: consent, contract, legal obligation, or legitimate interest per section 11, plus a commitment to collect only what is adequate and relevant (minimality, section 10).
- Purpose specification (sections 13-14) - the purposes clause and the retention clause.
- Further processing limitation (section 15) - a statement that information is used only in ways compatible with the purposes you stated.
- Information quality (section 16) - a commitment to keep information accurate and updated, and how people can correct theirs.
- Openness (sections 17-18) - the policy itself is this condition in action.
- Security safeguards (sections 19-22) - the security-measures clause, and what happens if information is compromised.
- Data subject participation (sections 23-25) - the rights clause: request access (section 23), correction or deletion (section 24), object to processing (section 11(3)), and withdraw consent where consent is the basis (section 11(2)(b)).
Writing it: five practical steps
- Inventory your processing. List every category of personal information you hold, where each came from, and why you have it. Staff records and B2B contact lists count.
- Assign a legal basis to each purpose. Most business processing rests on contract, legal obligation, or legitimate interest; reserve consent for where it is genuinely voluntary.
- Draft the clauses above in plain language. Section 18 is satisfied by clear sentences, not legal jargon. Write so the customer who reads it understands it.
- Publish it where you collect. Link it from your website footer, order forms, and sign-up flows, so the notification happens at the moment of collection.
- Review it when your practices change. A new tool, a new marketing channel, or a new operator changes the answers; version the policy and date it.
The template route
A generic template from an overseas website usually fails the test above: most are written for the GDPR, whose legal bases and disclosures do not line up with section 11 and section 18, and none of them carry the South African specifics. POPIAdesk's privacy policy generator asks for each section 18 item by name - including the voluntary/mandatory split, the particular laws, and the cross-border safeguard - and produces a policy aligned with the current requirements, versioned so you can regenerate it when your practices change.
Frequently asked questions
Is a privacy policy legally required under POPIA?
The Act requires the section 18 notification, not a document by that name. In practice a published policy is how businesses meet that duty for every data subject at once, and the Information Regulator expects to see one.
Is a privacy policy the same as a PAIA manual?
No. The PAIA manual is a separate, mandatory document under section 51 of PAIA covering access to your records; every private body must have one. You need both, and they must not contradict each other.
Can I just translate my GDPR privacy notice?
Not safely. POPIA protects juristic persons, defines its own legal bases in section 11, and has its own marketing-consent and cross-border rules, with recourse running to the Information Regulator rather than a European authority. A GDPR notice reworded for South Africa tends to miss exactly the clauses section 18 requires.
Check what yours is missing
The free POPIA assessment takes about five minutes and shows where your policy and the rest of your compliance stand.
This is general information, not legal advice. For your specific situation, consult an attorney.