How to Write a POPIA Privacy Policy (8 Sections You Must Include)
The eight sections that section 18 requires, what each one must say, and the wording mistakes that make a policy worthless. Written for South African sites.
POPIA never uses the words "privacy policy"
Search the Act and you will not find an obligation to publish one. What section 18 requires is notification: when you collect someone's personal information, you must make them aware of specific things. A privacy policy is simply the practical way to do that on a website.
That matters, because it tells you what the document is for. It is not a legal shield or a disclaimer. It is a notice, and it is judged on whether it accurately tells people what you do.
Below is what section 18 actually asks for, arranged as sections you can write.
1. Who you are
Section 18(1) requires the name and address of the responsible party. Give the trading name, the legal entity behind it, and a contact address that works.
Add your Information Officer. Section 55 makes the role mandatory, and for a small business it is the owner by default. See Information Officer duties under POPIA.
2. What you collect, and where it came from
Be specific. "We collect data" tells nobody anything. "We collect your name, email address, delivery address and IP address" does.
Section 18 also requires you to state the source where the information is not collected directly from the person. If you buy or enrich data, or receive it from a partner, say so. This is the requirement most often missed entirely.
3. Why you collect it
Section 13 requires collection for a specific, explicitly defined and lawful purpose, and section 18 requires you to state it. Break it down by purpose rather than giving one blanket sentence: fulfilling orders is a different purpose from sending a newsletter, and a person may be content with one and not the other.
4. Your lawful ground
Section 11 gives six grounds, and most website advice wrongly treats consent as the default. Consent is the weakest of them: it must be voluntary, and it can be withdrawn.
For an ordinary business, the honest answer is usually a mix. Fulfilling an order rests on section 11(1)(b), necessary for a contract. Keeping invoices rests on section 11(1)(c), a legal obligation. Analytics and marketing may rest on legitimate interests under section 11(1)(f), or on consent. State which applies to what. See how to manage user consent under POPIA.
5. Whether providing it is voluntary or mandatory
An explicit section 18 requirement, and one almost no South African privacy policy contains. You must say whether supplying the information is voluntary or mandatory, and what happens if the person does not provide it.
In practice: "Your name and delivery address are required to fulfil an order. Without them we cannot complete your purchase. Your phone number is optional and is used only to contact you about a delivery."
6. Who else sees it
Name the recipients or, at minimum, the categories. Your email provider, payment gateway, courier, accountant, hosting company and analytics provider are all recipients.
Most of these are operators, and section 21 requires a written contract with each. See operator agreements under section 21.
7. Whether it leaves South Africa
Section 18 requires you to say whether you intend to transfer information to a third country and what level of protection applies there. Section 72 governs the transfer itself.
Almost every small business does this without noticing: Google Workspace, Mailchimp, most hosting, most analytics. Saying "we do not transfer your data internationally" while running on overseas infrastructure is a false statement in a document whose whole purpose is accuracy.
8. Their rights, and how to complain
Section 18 requires you to set out the existence of the right of access and the right to correct, the right to object, and the right to lodge a complaint with the Information Regulator.
Most policies list access, correction and deletion and stop. Include:
- Access, under section 23
- Correction or deletion, under section 24
- Objection to processing, under section 11(3), which is separate from withdrawing consent
- Withdrawal of consent, under section 11(2)(b), where consent was the ground
- Complaint to the Information Regulator, with its actual contact details
Then say how someone exercises these with you: an address, and who handles it. See how to respond to a POPIA access request.
Also worth including
- Retention. Section 14 requires you not to keep records longer than necessary. Give real periods rather than "as long as necessary".
- Security. Section 19 requires appropriate technical and organisational measures. Describe them briefly and truthfully.
- Cookies, or a separate cookie policy, if you run analytics or advertising.
- Children. Section 34 prohibits processing children's information by default.
The mistake that undoes all of it
A copied policy that misdescribes your business fails section 18 regardless of length, because the notification is not accurate. It is also a public statement about how you handle data, so the gap between the document and reality becomes the evidence against you.
A short policy that is true beats a long one that is not. If you are a one-person business wondering whether you need one at all, see does a small business need a privacy policy.
POPIA Ready generates a privacy policy from answers about your actual business, so the result describes what you do rather than what a template assumed. Free to preview. The free checklist will show you what else is missing.
General guidance on South African law as at August 2026, not legal advice. What section 18 requires in your case depends on what you collect and why, and a specific situation deserves a professional opinion.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview