You Need a Contract With Your Web Host: POPIA Section 21
If a supplier touches your customer data, POPIA requires a written contract with them. Most South African businesses have never signed one. Here is who counts as an operator, what the contract must say, and how to fix it.
The requirement almost nobody knows about
Ask a South African business owner about POPIA and they will usually mention a privacy policy, maybe a cookie banner. Ask whether they have a written agreement with their web host, their accounting software, or the company that sends their newsletters, and the answer is almost always no.
Section 21 of POPIA is not optional and it is not vague:
A responsible party must, in terms of a written contract between the responsible party and the operator, ensure that the operator which processes personal information for the responsible party establishes and maintains the security measures referred to in section 19.
A written contract. With every operator. Requiring them to maintain proper security. Most businesses fail this one without ever realising it exists.
What is an operator?
Section 1 defines an operator as a person who processes personal information for a responsible party in terms of a contract or mandate, without coming under the direct authority of that party. GDPR calls the same role a processor.
The distinction that matters: a responsible party decides why and how information is processed. An operator just does what it is told with it. Your employees are not operators, because they are under your direct authority. Outside suppliers usually are.
Businesses are consistently surprised by how many they have. A typical small South African company uses:
- A web host or cloud platform storing the site and its database
- An email provider such as Google Workspace or Microsoft 365
- An email marketing tool such as Mailchimp
- Accounting software such as Xero or Sage, holding customer and employee details
- A payroll bureau or outsourced HR provider
- A CRM or helpdesk
- Cloud backup and file storage
- An external bookkeeper, IT support company or marketing agency
- A payment gateway, though most act as responsible parties in their own right
Every one of those handles personal information on your behalf. Every one needs a written contract satisfying section 21.
What the contract has to do
Sections 20 and 21 together set the requirements. The operator must:
- Process only with your knowledge or authorisation. They may not decide to do something else with your customer data, including using it to improve their own products, unless you have agreed.
- Treat the information as confidential and not disclose it, unless required by law or in the proper performance of their duties.
- Establish and maintain the section 19 security measures, meaning appropriate technical and organisational safeguards, risk identification, and verification that the safeguards work.
- Notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. Section 21(2) makes this explicit, and it matters because your own section 22 breach notification clock depends on finding out.
Beyond the statutory minimum, a sensible agreement also covers where the data is stored, whether sub-operators may be used and on what terms, what happens to the data when the contract ends, and cooperation if a data subject makes a request.
The good news: you may already have one
Before you start emailing suppliers, check. Most international providers publish a data processing addendum that forms part of their standard terms, and it usually satisfies section 21 in substance even though it is written for GDPR.
Google, Microsoft, Amazon Web Services, Mailchimp, Xero and most large platforms have one. Sometimes it applies automatically when you accept the terms of service. Sometimes you have to actively opt in through an account setting, which is worth checking rather than assuming.
The gap is usually with smaller local suppliers: the freelance developer with database access, the local hosting company, the bookkeeper who receives your payroll spreadsheet, the marketing agency running your ads. These rarely have a standard addendum, and they are frequently the ones with the weakest security.
Cross-border transfers ride along with this
If your operator stores data outside South Africa, and most cloud services do, section 72 also applies. Transfers are permitted where the recipient is subject to a law, binding rules or an agreement providing an adequate level of protection, or where the data subject consents, or where it is necessary for a contract.
In practice, a signed data processing agreement with adequate protection commitments is what carries the transfer. Your privacy policy should also tell people it happens.
How to fix this without stopping everything
Work through it in an afternoon:
- List every supplier that touches personal information. Go through your bank statement or accounting system rather than trying to remember. Software subscriptions are usually the fastest way to find them all.
- Check for an existing addendum. Search the supplier's name plus "data processing agreement" or "DPA". For large platforms it usually exists, and you may only need to accept it in your account settings.
- Prioritise by sensitivity. The payroll bureau holding ID numbers and salaries matters more than the tool that schedules your social posts.
- Ask the rest in writing. A short email requesting their data processing agreement is normal and professional. A supplier who cannot produce one, and cannot answer basic questions about where data is stored, has told you something useful.
- Record what you found. Condition 1, accountability, means being able to show this. A simple table of supplier, what they process, where it is stored, and whether an agreement is in place is enough.
Why this one is worth the effort
Two reasons beyond the legal obligation.
First, you remain responsible. If your operator loses your customers' data, it is still your breach to notify and your reputation. The contract is how you set the standard you are relying on.
Second, the exercise itself is valuable. Most businesses that list their operators discover at least one they had forgotten, still holding data, still being paid for. Some discover a former developer with live database credentials. The audit tends to pay for itself in a way most compliance work does not.
For the rest of your obligations, see POPIA requirements and the eight conditions explained. If your privacy policy does not yet mention who you share data with or that it may leave South Africa, POPIA Ready generates one that does, based on the services you actually use.
General guidance on the Act as at July 2026, not legal advice. Contract terms with significant commercial exposure deserve a professional review.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview