Is your website legally compliant? You may have a lot of questions in regards to the POPI Act, Privacy Policies, Terms & Conditions, Disclaimers, Impressum’s, Cookie Banner Policies & more. Contact us to let us help you get compliant.
FAQ
FREQUENTLY ASKED QUESTIONS
- All
- Cookies
- Datenschutz
- Disclaimer
- DSGVO
- GDPR
- Germany
- Impressum
- Legal Complaince
- PAIA
- POPI
- Privacy Policy
- Terms & Conditions
A website disclaimer is used to limit a website owner’s legal liability and to clarify the terms and conditions under which users access and use the website. While it’s not compulsory to have a website disclaimer in all cases, it is highly recommended for the following reasons:
- Limiting Liability: A disclaimer can help protect the website owner from legal claims and lawsuits. It can clarify that the information on the website is for informational purposes only and not a substitute for professional advice, reducing the risk of users relying on the information and then suing if it leads to unfavorable outcomes.
- Accuracy of Information: Disclaimers can state that the website owner is not responsible for the accuracy, completeness, or timeliness of the information provided on the website. This can protect the owner from claims related to inaccuracies in content.
- External Links: If the website contains links to external websites or resources, a disclaimer can make it clear that the website owner is not responsible for the content or actions of those external sites.
- Personal Opinions: If the website contains personal opinions, reviews, or commentary, a disclaimer can make it clear that these are the opinions of the author and not necessarily the official stance of the website owner.
- Legal Compliance: It can communicate that the website owner is making an effort to comply with relevant laws and regulations, especially if the website deals with sensitive topics or user-generated content.
While a website disclaimer is not always compulsory, it is a valuable tool to protect website owners from legal issues and to provide clarity to users about the limitations and terms of using the website. The specific content and wording of the disclaimer may vary based on the nature of the website and its content. It’s advisable to consult with a legal professional to ensure that the disclaimer is tailored to the website’s needs and complies with applicable laws.
POPIA (The Protection of Personal Information Act), is a law in South Africa that aims to protect people’s personal information. It applies to anyone who collects, uses, or shares personal information, whether they are a person or a business. There are eight rules that must be followed to use personal information legally, such as getting permission and making sure it’s accurate and secure.
People have the right to access and change their personal information, and can object to it being used. If businesses don’t follow the rules, they can face serious penalties and even be sued for damages. It’s important to follow POPIA to avoid these consequences and protect people’s privacy.
If your website collects, processes, or stores personal data of individuals who are in the European Union (EU), you are subject to the General Data Protection Regulation (GDPR) and need to comply with its requirements. The GDPR aims to protect the privacy and personal data of individuals within the EU and applies to all companies that collect and process personal data of these individuals, regardless of where the company is based. Again please note DSGVO applies to legal compliance in Germany. See this FAQ for more info on what is DSGVO.
The GDPR requires companies to obtain valid consent from individuals for the collection and processing of their personal data, to provide individuals with the right to access, correct, and delete their data, to implement appropriate security measures to protect personal data from unauthorized access or disclosure, and to report personal data breaches to the relevant authorities and affected individuals.
By complying with the GDPR, you can demonstrate to your website visitors and customers that you take their privacy and personal data seriously and are committed to protecting their rights. Failure to comply with the GDPR can result in consequences, significant fines and penalties, damage to your reputation, and erode customer trust. Therefore, it’s important to ensure that your website is GDPR compliant if it collects and processes personal data of individuals in the EU.
Contact us to get help setting up your DSGVO Compliance for your Germany-based business website. Not only do we help with setting up your DSGVO but also your website Impressum, Cookie banner, and websites SSL . You will need to have the correct website hosting partner to help supply you with a valid SSL certificate.
If a company is subject to the GDPR or DSGVO (in Germany) and fails to comply with its requirements, it may face severe consequences, including fines and penalties. The GDPR provides for administrative fines of up to €20 million or 4% of a company’s global annual revenue, whichever is higher. These fines can be imposed for various violations of the GDPR, including:
- Failure to obtain valid consent from individuals for the collection and processing of their personal data
- Failure to implement appropriate technical and organizational measures to ensure the security of personal data
- Failure to notify the relevant authorities and affected individuals of a personal data breach
- Failure to provide individuals with access to their personal data or to rectify inaccurate data upon request
In addition to the fines and penalties, non-compliance with the GDPR can also damage a company’s reputation and erode customer trust. It can also result in legal action and civil claims for damages by individuals whose personal data has been mishandled or compromised. Therefore, it’s essential for companies subject to the GDPR to comply with its requirements to avoid these consequences.
The laws from country to country will/may differ as well as penalties for non-compliance. Find out WHAT DSGVO is in this article here. Find out Why your website needs to have legal compliance – DSGVO in this article here.
DSGVO stands for “Datenschutz-Grundverordnung”, which is the German term for the General Data Protection Regulation (GDPR) in the European Union (EU). The GDPR is a comprehensive privacy and data protection law that came into effect on May 25, 2018, and applies to all companies that collect and process personal data of individuals within the EU, regardless of where the company is based.
The GDPR aims to give individuals more control over their personal data by requiring companies to be transparent about how they collect, use, and share personal data, obtain consent from individuals for the collection and processing of their data, and provide individuals with the right to access, correct, and delete their data. The DSGVO / GDPR also requires companies to implement appropriate security measures to protect personal data from unauthorized access or disclosure.
Failure to comply with the DSGVO / GDPR can result in significant fines and penalties. Find out Why you need DSGVO for your website in this FAQ article here.
It is a legal requirement in terms of section 43(1) of the Electronic Communications and Transactions Act 25 of 2002 (“ECTA”) to place your company’s Ts&Cs on the company’s website.
In addition to being legally mandated by ECTA to do so, it is important to have your Ts&Cs on your company’s website for the following reasons:
- the Ts&Cs act as a legally binding contract between the company and website users, and set the rules and guidelines that users must agree to and follow in order to use and access the website and/or mobile app;
- the Ts&Cs can inform website users that all intellectual property in the form of logos, taglines, photos etc. included on the website are the property of the company;
- the Ts&Cs can limit the company’s liability in situations where errors are found in the content that is presented on the website; and
- the Ts&Cs set the jurisdiction and thus the law that would govern any disputes.
Having a Terms and Conditions (T&C) page on your website is important for several reasons, both for your protection as a website owner and for the clarity and protection of your users. Here are some of the key reasons why you should have a T&C on your website:
- Legal Protection:
a. Limiting Liability: T&C can help limit your liability by specifying the terms under which users can access and use your website. This can be important in case of disputes, lawsuits, or claims.
b. Dispute Resolution: It can define the methods for resolving disputes, which may include arbitration or mediation, reducing the likelihood of costly litigation. - User Expectations:
a. Clarity: T&C provide clear guidelines on how your website should be used and what users can expect. This reduces confusion and potential disputes.
b. User Agreement: By using your website, users agree to abide by the terms and conditions, which can help protect your rights and interests. - Privacy and Data Collection:
a. Data Usage: You can outline how user data is collected, stored, and used, including details about cookies, analytics, and data sharing practices.
b. GDPR Compliance: If your website collects data from European Union users, T&C can help you comply with GDPR requirements by explaining data processing and user rights. - Intellectual Property:
a. Copyright: You can assert your copyright over website content, protecting it from unauthorized use or reproduction.
b. User-Generated Content: Specify ownership and usage rights for content submitted by users, such as comments, reviews, or forum posts. - Terms of Use:
a. Acceptable Use: Define what behavior is considered acceptable on your website, including prohibitions on spam, hate speech, or other harmful activities.
b. Termination: Clarify circumstances under which you can terminate or suspend user accounts. - E-commerce and Sales:
a. Payment Terms: If you sell products or services online, you can specify payment terms, refund policies, and delivery details.
b. Return and Refund: Clearly outline the process for returns and refunds, which can protect both you and your customers. - Compliance with Regulations:
a. Compliance: Ensure your website complies with relevant laws and regulations by including necessary disclaimers, disclosures, and policies.
b. Industry Standards: Align your T&C with industry-specific regulations, such as financial, healthcare, or e-commerce standards. - Dispute Resolution:
a. Governing Law: Specify the jurisdiction or legal system governing your T&C, which can be crucial in case of legal disputes.
b. Mediation or Arbitration: Set out methods for resolving disputes outside of court, which can save time and money. - Changes and Updates:
a. Revision Policy: Explain how and when you can make changes to the T&C, and how users will be notified of updates. - Enforceability: T&C can help demonstrate that you’ve made a good-faith effort to inform users of your website’s rules and policies, which may be important in legal proceedings.
Having clear and well-crafted Terms and Conditions on your website is essential for legal protection, setting user expectations, and ensuring compliance with applicable laws and regulations. It helps establish a transparent and mutually beneficial relationship between you and your users, while also protecting your website and its content. It’s advisable to consult with a legal professional to create T&C that are tailored to your specific website and legal requirements.
A Privacy Policy is a policy that is required to appear on a company’s website and that must be drafted in such a way as to make the following clear to a data subject browsing the website:
● what personal data is collected
● why and how the private data is being stored and processed
● what the legal basis for that data usage is
● if the data is being shared with third parties and if so, who they are
Privacy Policies are legally required in terms of various legislations enacted throughout the world in circumstances where organizations process personal information from individuals.
A head of a private body who wilfully or in a grossly negligent manner fails to comply with the PAIA provisions commits an offence and is liable on conviction to a fine, or to imprisonment for a period of up to two years.
The Minister has extended the PAIA manual exemption period until 30 June 2021; so if your organisation is not exempt from having a PAIA manual, your PAIA manual would be expected to be published by such time.
Yes. POPI requires a responsible party to maintain a record of all the company’s processing operations (or activities or functions) under its responsibility in a PAIA manual.
The manual must contain the following information:
- the postal and street address, phone and fax number, and e-mail address of the head of the body
- a description of, and how to obtain access to, a guide on how to use the Act to get information from bodies
- what records are available to an interested party without having to request access in terms of PAIA
- a description of the records of the body, which are available in accordance with any other legislation
- how to request records from the body in terms of the Act
- other information as may be prescribed by the Minister
All public companies, and any private companies that do business in any of the specified industries or sectors and have 50 or more employees, are required to compile a PAIA manual (unless they have been exempted by the Minister of Justice and Correctional Services).
PAIA refers to Section 32 of the Constitution, which stipulates that everyone has the right to access information that is held by the State, as well as information held by another person (or private body), when such privately-held information is required for the exercise and protection of one’s human rights.
The Promotion of Access to Information Act No. 2 of 2000.
The GDPR accounts for hefty fines for non-compliance (up to 4% of the company’s worldwide total annual turnover – capped at €20 million).
72 hours from the moment the company becomes aware of the data breach.
Yes. If a company that is based in South Africa processes the data of EU/UK citizens and residents, it would be expected to comply with both the local legislation (POPI) as well as the GDPR. It is therefore very important that companies are aware of what both sets of legislation require from them.
GDPR defines personal data as any data that relates to, identifies, describes, or could be associated with a person (the ‘data subject’) and includes the following: a person’s name, his/her ID number, a customer code created by the company that processes the data, online information such as IP addresses and/or cookies, GPS or other map data, and any reference to a person’s biographical information such as their race, sexuality, philosophical beliefs or religion, economic background etc.
Website Legal Compliance Frequently Asked Questions
Is your website legally compliant? You may have a
Website Privacy Policy – Is My Website Legally Compliant
All websites are required by law to have a
What are the consequences of POPIA – NON-compliance?
POPIA Non-Compliance, List of Offences, Penalties and Administrative Fines





