HomeBlogAcceptable Use Policies: Who Needs One, and What It Must Do

Acceptable Use Policies: Who Needs One, and What It Must Do

Only sites with user content need one. But the ECT Act safe harbour protecting you from what users post has a condition almost nobody knows about.

The one document you might genuinely not need

Most legal pages on a website apply to everyone. An acceptable use policy is the exception, and it is worth saying so plainly before you spend time on one.

You need one if users can put anything on your site. Comments, reviews, forum posts, profile pages, uploaded images, listings on a marketplace, messages between users, or anything a customer types into a hosted application you run.

You probably do not need one if your site is a brochure, or a shop where the only thing a customer submits is a delivery address. In that case your terms and conditions already cover what little there is to cover.

If you are in the first group, the policy earns its place quickly, because South African law gives you a real protection against liability for what your users post, and that protection comes with a condition almost nobody knows about.

What the policy actually does

An acceptable use policy is not a moral statement. It is the contractual basis for two specific actions:

  • Removing content without being in breach of your own agreement with the user.
  • Suspending or terminating an account, for a stated reason, in a way you can defend.

Without a policy, both become awkward. A user whose post you delete or whose paid account you close can reasonably ask what rule they broke and where it was published. "We did not like it" is a weaker answer than a clause they agreed to.

It also protects you in the other direction. If someone demands you remove a competitor's honest negative review, a published policy that does not prohibit honest criticism is a clean reason to decline.

The safe harbour, and the condition nobody mentions

This is the part worth reading even if you skip everything else.

Chapter XI of the Electronic Communications and Transactions Act limits the liability of service providers for unlawful content that passes through or sits on their systems. It covers acting as a mere conduit, caching, and hosting. In broad terms, you are not liable for user content you did not create, select or modify, provided you did not know it was unlawful and you act expeditiously to remove it once you do.

That is a substantial protection. Here is the catch.

Section 72 says those limitations apply only to a service provider that is a member of a recognised industry representative body and has adopted and implemented that body's code of conduct.

The recognised body in practice is the Internet Service Providers' Association, recognised by the Minister in 2009. If you are not a member and have not adopted the code, the argument is that the Chapter XI protections simply do not apply to you, and you fall back on ordinary common law liability for publishing.

Two honest qualifications. First, "service provider" is defined broadly, as a person providing information system services, and there is genuine debate about how far it reaches beyond traditional ISPs to, say, a small site with a comments section. Second, not being a member does not automatically make you liable for everything, it removes a statutory shield you would otherwise have.

The practical conclusion is unchanged. If your business depends on hosting user content, membership is inexpensive relative to the protection, and this is the single most useful thing on this page. Almost no South African site running user content has considered it.

What a takedown notification must contain

The hosting protection turns on acting once you know. Knowledge usually arrives as a takedown notification, and section 77 sets out what a valid one looks like. It must:

  • Be in writing and addressed to the service provider
  • Give the complainant's full name and contact details, and be signed
  • Identify the material and where it is
  • State the remedial action required
  • State that the complainant is acting in good faith and that the information is true and correct

Two things follow. Publish an address for notifications, since a protection triggered by receiving notice works better if people know where to send it. And know that a person who knowingly and materially misrepresents the facts in a notification is liable for damages for wrongful takedown. That is a useful thing to be able to point at when someone sends an aggressive demand about content that is merely unflattering.

Complying with a valid notification is not an admission that the content was unlawful. Treat it as a process, not a judgement.

You are not required to monitor

Section 78 states that a service provider has no general obligation to monitor the data it transmits or stores, or to actively seek facts indicating unlawful activity.

This matters for how you write the policy. Do not promise to review everything. A commitment to pre-moderate every post is a commitment you will fail, and failing your own published standard is worse than never having claimed it, for the same reason a copied privacy policy is worse than a short accurate one.

Say that you may remove content and may act on reports, not that you check everything.

What to prohibit

Keep it specific enough to enforce. A workable list covers:

  • Unlawful content, including material that is defamatory, infringes copyright or trade marks, or breaches someone's privacy
  • Harassment, threats and hate speech. Note that some user conduct attracts criminal liability in its own right, including the unlawful distribution of intimate images and messages inciting violence or damage to property under the Cybercrimes Act
  • Impersonation of another person or of your business
  • Spam and unsolicited marketing, particularly where users can message each other
  • Other people's personal information, posted without a basis for doing so
  • Malware, scraping, and attempts to circumvent security or access other accounts
  • Automated or excessive use that degrades the service for others
  • Commercial use you have not permitted, if that matters to your model

Resist the urge to prohibit anything that annoys you. A clause banning criticism of your business is unenforceable in substance and reputationally poor, and it undermines the clauses next to it.

The clauses that actually do the work

Prohibitions are half the document. The operative half is what you may do about them:

  • That you may remove or disable content, with or without notice, and that removal is not an admission about its lawfulness
  • That you may suspend or terminate accounts, with the grounds stated
  • A graduated response, so that a first-time minor breach and repeated deliberate abuse are not treated identically
  • How a user can dispute a removal. Worth including even though nothing requires it, because it reduces disputes and reads well if you are ever challenged
  • A licence to host their content, since you need permission to display and store what users upload. Keep it to what you actually need. A broad licence to exploit user content commercially is a common overreach and reads badly
  • How to report a problem, aligned with the section 77 requirements above

User content contains other people's personal information

The moment users can post about identifiable people, POPIA is engaged and you are the responsible party for what sits on your systems.

Practically that means your privacy notice should cover user-generated content, you need a route for someone to ask you to remove information about them, and you should think about how long content stays up after an account is deleted. If users can message each other, section 69 on direct marketing becomes relevant too, which is covered in is cold emailing legal in South Africa.

A request to remove personal information from a user's post is also, potentially, a request you have to answer on a deadline. See how to respond to a POPIA access request.

Your liability clauses are still limited by the CPA

Acceptable use policies usually end with an exclusion of liability for user content. Everything in the disclaimer article applies here: you cannot exclude liability for gross negligence, unfair terms are prohibited, and a clause limiting liability or requiring an indemnity must be in plain language and drawn to the user's attention before they sign up, not buried in a page they never opened.

An indemnity from users is common and reasonable in principle. Whether it is enforceable against a consumer depends on how it was presented, which is a design question as much as a drafting one.

Common mistakes

  • Assuming the ECT Act protections apply automatically. Section 72 says otherwise.
  • Promising to moderate everything. You are not obliged to, and claiming it creates a standard you will miss.
  • No takedown address. A protection that depends on being notified needs somewhere to receive notice.
  • Vague prohibitions. "Inappropriate content" is not a rule anyone can apply consistently, including you.
  • No stated consequence. A list of prohibitions with no removal or termination right leaves you enforcing nothing.
  • Over-broad content licences, claiming rights over user content far beyond running the service.
  • Removing honest negative reviews because someone complained loudly. Check whether your own policy actually prohibits it.
  • Never applying it. A policy contradicted by your own practice is weak evidence in your favour.

A short checklist

  • Can users post, upload, review or message on your site? If not, you can stop here.
  • Have you looked into membership of a recognised industry body, given what section 72 requires?
  • Is there a published address for takedown notifications?
  • Does the policy state that you may remove content and close accounts, and on what grounds?
  • Have you avoided promising to monitor everything?
  • Does your privacy notice cover user-generated content?
  • Are your liability and indemnity clauses shown before sign-up, in plain language?
  • Is the content licence limited to what running the service requires?
  • Does the policy agree with your terms and conditions?

POPIA Ready generates an acceptable use policy, terms of service, a privacy policy and four other documents customised to your business and drafted for South African law, free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at August 2026, not legal advice. Liability for user content involves the ECT Act, the common law of defamation and the criminal law, and a platform hosting significant user content deserves a professional opinion.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Your WhatsApp Messages Are Records You Must Keep for Five Years

Read article →

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →