Skip to main content

The Bloc Studio (Pty) Ltd

DISCLAIMER: General information only, not legal advice. Privacy law changes frequently and your obligations depend on your specific circumstances. Speak to a qualified attorney before acting on anything here.

Have you noticed the crackdown? Governments are implementing strong laws that dictate how you collect and use people’s data. Non-compliance can mean serious fines and, in South Africa’s case, a criminal offence.  

In this article we will look at the United Kingdom and Europe (GDPR), United States (CCPA/CPRA), and South Africa (POPIA) privacy policy laws, requirements and penalties for not having one.  

Looking for something specific?

Subscribe to
The Bloc Journal

Stay in the loop of what’s happening and how it affects YOUR website.

In just 7 Days

You could have your own website that will be found by Google, seen by Ai and is compliant!

What is a Privacy Policy?

A privacy policy is a public statement of what personal information you (personally and as a business) collect, why you collect it, who you share it with, how long you keep it, how you protect it, and what rights people have over it.

It is not your terms and conditions for use of your website. Let’s just clear that up first and foremost. This is a totally separate document. While your Ts & Cs cover your commercial relationship, a privacy policy governs that data you collect from your users/clients/customers. Combining these two documents together is common mistake, especially amoung smaller businesses. 

The Privacy Policy is also not your Cookie Banner although the two do need to agree with each other.

And for South Africans, it is not your PAIA manual either. PAIA governs access to records held by your business while your privacy policy (which should be POPIA compliant) governs how you handle personal information. Both are required, and both are enforced by the same Information Regulator

And lastly, a privacy policy is not optional. Your privacy policy is legally binding and it can be help against you should poop hit the fan. Whatever you have stated (whether you thought through it or not) is legally binding. 

Why Does the Law Require a Privacy policy?

You can’t consent or object to something you were never told about. These laws help you to do that. The privacy policy helps with your rights within your country and what happens with your data. 

United States

A notice of collection and a yearly update of your policy is required by the US CCPA/CPRA. On top of that you have to explicitly state whether the information you are gathering from your users is going to be shared with third-parties or sold. 

United Kingdom & Europe

Articles 13 and 14 in the UK and EU’s GDPR states that a “concise, transparent, intelligible and easily accessible form, using clear and plain language” is expected. Regulators have actually fined companies for having unclear or unreadable policies.

South Africa

POPIA’s Section 18 requires you to let your users know what you’re collecting. This will include (but not limited to), why you’re collecting this data, who you are, whether collection of this data is voluntary or mandatory, and the consequences of not supplying it.

A Minimum Consent Checklist 

Since the privacy policy is the only place where those getting ready to submit data on your website can actually see, this is definitely where the regulators are going to look first. 

The following checklist is applicable to all the above policies. Make sure you have the following in your policy:

  • Who you are and how to contact you (plus your Information Officer / DPO)
  • What categories of personal information you collect
  • Where you got it, if not directly from the person
  • Why you collect it — the purpose, and the lawful basis
  • Who you share it with, including third-party processors and cross-border transfers
  • How long you keep it
  • How you secure it
  • What rights the person has, and exactly how to exercise them
  • How to complain to the relevant regulator
  • When the policy was last updated

Penalties & Fines  

While the GDPR and the CCPA/CRPA are most likely just to fine you with non-compliance, South Africa has taken the go big or go home approach and will simply jail you for up to 10 years!

I’m being dramatic. They warn you… and THEN jail you for up to 10 years for non-compliance. It’s that or a R10mil fine (about $617 000). 

In a nutshell, in EU, UK and USA just take your money. In SA it’s a criminal offence. 

We love a good table. Here’s one to keep you up at night:

 

POPIA (South Africa)

GDPR (EU/EEA)

CCPA/CPRA (California)

Max penalty

R10m + 10 yrs prison

€20m or 4% of global annual turnover, whichever is higher

$7,988 per violation, per consumer

Legal basis needed to process?

Yes, consent or another lawful ground

Yes, one of six lawful bases

No, opt-out model, not opt-in

Core consumer right

Access, correction, deletion, objection

Access, erasure, portability, objection

Know, delete, correct, opt out of sale/sharing

Who it protects

Data subjects (incl. juristic persons. A POPIA quirk)

Data subjects in the EU/EEA

California residents

Breach notification

To Regulator and data subjects, as soon as reasonably possible

To supervisory authority within 72 hours

Varies; private right of action attaches

But I’m Just a Tiny Home Business

It still applies to you, Felicia. 

POPIA has no revenue threshold. If you process personal information in South Africa, it applies. Klaar! A single person business with a Mailchimp list is a responsible party.

GDPR follows the customer, not the company. Article 3 extends it to any business anywhere that offers goods/services or monitors the behaviour of people in the EU. One EU client or customer that is being tracked makes you eligible.

You’ve got about 172 jurisdictions that now have either something of or a comprehensive list of data laws. That makes about 85% of the world. 

About 172 jurisdictions now have comprehensive data protection laws, covering roughly 85% of the world’s population. Operating “outside” privacy law is no longer a real option.

Disclaimer

This article is provided by The Bloc Studio for general information and educational purposes only. It does not constitute legal advice, and it is not a substitute for advice from a qualified attorney admitted to practise in your jurisdiction. No attorney–client relationship. Reading this article, or contacting us about it, does not create an attorney–client or any other professional advisory relationship between you and The Bloc Studio. We are not a law firm and we do not provide legal services. Your circumstances are specific. Data protection obligations depend heavily on facts we cannot know — the nature of your business, the categories of personal information you process, your lawful basis for processing, where your data subjects are located, where your data is stored and transferred, your sector-specific regulations, and your contractual commitments. General guidance cannot account for any of these. Do not act, or refrain from acting, on the basis of this article alone. Information may be out of date. Privacy law moves quickly. Penalty amounts are adjusted for inflation, regulators issue new guidance and codes of conduct, courts reinterpret existing provisions, and new legislation is enacted regularly. Figures and enforcement examples cited here were accurate as at the date of publication and may since have changed. Always verify current requirements against primary sources — the Information Regulator of South Africa, the relevant EU supervisory authority or the EDPB, and the California Privacy Protection Agency. Multiple jurisdictions, simplified. This article summarises POPIA, the GDPR and the CCPA/CPRA at a high level and unavoidably omits exceptions, exemptions, derogations, sector-specific rules and national variations. GDPR in particular is implemented differently across EU and EEA member states. A summary is not the law.

On penalties

References to maximum fines and terms of imprisonment describe the statutory ceilings available to regulators and courts. They are not predictions of outcome in any particular case. Actual penalties depend on the nature of the contravention, the regulator’s discretion, mitigating and aggravating factors, and judicial process. No liability. To the fullest extent permitted by law, The Bloc Studio accepts no liability for any loss or damage — direct, indirect, or consequential — arising from reliance on this article or on any third-party resource linked from it. Links to external sources do not constitute endorsement. If in doubt, get advice. If you are uncertain about your obligations, or you have experienced or suspect a data breach, consult a qualified privacy or data protection attorney promptly. Breach notification deadlines are short and begin running from awareness, not from the date you finish investigating.

Not sure if your website is Compliant?

We give free audits!

Frequently Asked Questions

If you don’t see your answer in the list then you are welcome to ask us your questions by filling in the fields below.

Do I legally need a privacy policy on my website?

Yes, if your site collects any personal information, even just through a contact form or email signup. In the EU and UK this falls under GDPR, in South Africa under POPIA, and in the US under whichever state privacy laws apply to your visitors. There’s no small business exemption for having the policy itself, only for some of the more detailed obligations.