Web Insights

Home | Insights

ECTA Section 43: The Ecommerce Disclosures Required

Ecommerce website compliance

If you sell online to consumers in South Africa, Section 43 of the Electronic Communications and Transactions Act legally requires a specific set of information to appear on your website. Most South African online stores are missing part of it. The consequence is not theoretical: if you fail to make the required disclosures, the consumer is entitled to cancel the transaction within 14 days of receiving the goods or services, with no reason required and no penalty to them. This article sets out exactly what Section 43 requires, the subsections that catch people out, and how to bring a WooCommerce store into compliance.

A note before we start: this is a practical operational guide, not legal advice. For advice on your specific situation, consult a qualified attorney with ecommerce expertise. What follows is the framework every South African online store owner should understand, informed by the Act itself.


What ECTA is, and why Section 43 matters

The Electronic Communications and Transactions Act 25 of 2002 (ECTA, or the ECT Act) is South Africa’s foundational ecommerce statute. It came into force on 30 August 2002 and gives electronic transactions, contracts and signatures full legal recognition. Despite its age it remains the primary law governing online selling in South Africa, and Chapter VII of the Act deals specifically with consumer protection in electronic transactions.

Within that chapter, Section 43 is headed “Information to be provided”. It prescribes the information a supplier operating a website for the sale of goods or services must make available to consumers. It is the closest thing South African ecommerce has to a mandatory disclosure checklist, and it sits alongside Section 44 (the cooling-off period) and Section 46 (performance obligations). Section 43 is the one that shapes what actually goes on your website, which is why it is the one worth understanding in detail.


Who Section 43 applies to

Section 43 applies to electronic transactions with consumers, where a consumer is a natural person who enters into the transaction as the end user. In practice, that means almost every business-to-consumer online store selling to South African buyers falls squarely within it. If you run a WooCommerce store selling to the public, this applies to you.

Pure business-to-business transactions, where both parties are businesses, sit differently, and some of ECTA’s consumer-protection provisions are less directly applicable. But two cautions apply. First, many stores sell to a mix of consumers and businesses, and the moment a natural-person end user buys from you, the protections engage. Second, even where ECTA’s consumer provisions do not strictly bind you, the Consumer Protection Act 68 of 2008 imposes overlapping obligations, and transparent disclosure is simply good practice that builds buyer trust. The safe operating assumption for any public-facing online store is that Section 43 applies.


The Section 43(1) disclosure list, in practice

Section 43(1) sets out a list of information the supplier must make available on the website where the goods or services are offered. It is a substantial list, and rather than reciting it as legal text, it helps to group it by what it actually asks you to publish.

Who you are: identity and legal status

The Act requires you to disclose your full name and legal status, your physical address and telephone number, and your website address and email address. If you are a legal person (a company or close corporation), you must also disclose your registration number, the names of your office bearers, and your place of registration. You must additionally provide a physical address where you will accept legal service of documents. In plain terms: a consumer must be able to find out exactly who they are dealing with and where to reach or serve you. An online store trading behind nothing but a contact form and a first name does not meet this.

What you are selling and what it costs

You must provide a sufficient description of the main characteristics of the goods or services, enough for the consumer to make an informed decision. You must disclose the full price, and critically, that means the full price including transport costs, taxes and any other fees. Hidden costs that only appear at the final checkout step are precisely what this provision exists to prevent. You must also disclose the manner of payment you accept.

The terms, the timing and the record

The Act requires you to make available the terms of the agreement, including any guarantees that apply, and how the consumer can access and store them. You must disclose the time within which the goods will be dispatched or the services rendered. And you must tell the consumer the manner and period in which they can access and maintain a full record of the transaction. This is why a proper order confirmation, retained and accessible, is not just good service but part of your compliance posture.

Returns, disputes and privacy

You must disclose your return, exchange and refund policy. If you subscribe to any code of conduct or any alternative dispute resolution mechanism, you must disclose it and how it can be accessed electronically, along with your membership of any self-regulatory or accreditation body. You must disclose the security procedures and privacy policy that apply to payment, payment information and personal information. Where the agreement is for ongoing or recurring goods or services, you must disclose the minimum duration of that agreement. And where the cooling-off right applies, you must disclose the consumer’s rights under Section 44.

Taken together, that is roughly eighteen distinct categories of information the Act expects to be available on a compliant ecommerce website. Very few South African online stores carry all of them.


The three subsections that trip people up

The disclosure list in Section 43(1) is the part most people know exists. The subsections around it are where the real operational obligations, and the real risk, sit.

Section 43(2): the review-and-correct requirement. Before the consumer finally places the order, the supplier must give them an opportunity to review the entire transaction, to correct any mistakes, and to withdraw from the transaction. In practical terms this is your checkout flow. A checkout that lets a customer review their full order, edit quantities and details, and back out before committing satisfies this. A checkout that rushes a customer to payment without a clear review-and-confirm step does not. Most well-built WooCommerce checkouts handle this by default, but custom or heavily-modified checkouts sometimes break it.

Section 43(5): the secure payment requirement. The supplier must use a payment system that is sufficiently secure with reference to accepted technological standards at the time and the type of transaction. This is why running payments through a reputable, properly integrated South African payment gateway matters legally, not just commercially. And Section 43(6) adds teeth: if you fail to meet the secure-payment standard, the consumer is not liable for any damage arising from unauthorised use of their payment details. The risk of a payment breach shifts to you.

Section 43(3): the 14-day cancellation right. This is the one that surprises store owners. If you fail to provide the information required by Section 43(1), or fail to give the review opportunity required by Section 43(2), the consumer may cancel the transaction within 14 days of receiving the goods or services, without penalty. This is a direct consequence of non-disclosure. It is not the cooling-off period, and it does not carry the cooling-off period’s exclusions.

If your website is missing required disclosures, every consumer transaction is potentially unwound at the buyer’s discretion for 14 days after delivery.

Section 43 is not the cooling-off period

It is worth separating these clearly, because they are constantly confused. Section 44 gives consumers a cooling-off right: for most distance-sold goods and services, the consumer may cancel within seven days, for goods measured from delivery and for services from conclusion of the agreement, subject to a list of exclusions (perishables, personalised items, certain digital content and others). That is a standalone consumer right that exists regardless of your disclosures.

The Section 43(3) right is different. It is a penalty for your non-compliance, it runs for 14 days from receipt, and it is triggered specifically by your failure to disclose. A store can be fully compliant on disclosure and still owe customers the seven-day cooling-off right. A non-compliant store owes both, and the 14-day cancellation right is the more dangerous of the two because it is entirely within your control to avoid, and entirely your fault if you do not.


Where South African ecommerce websites actually fail

In our experience building and inheriting WooCommerce stores, the common Section 43 gaps are predictable:

  • No clear legal identity: a store trading with no company registration number, no physical address, and no address for legal service of documents.
  • Incomplete pricing disclosure: shipping, VAT or fees that only surface at the final checkout step rather than being clearly disclosed up front.
  • No accessible terms and conditions, or terms that exist but cannot easily be saved or referenced by the customer.
  • A missing or inadequate returns, exchange and refund policy.
  • No privacy policy, or a generic overseas template that does not address payment and personal-information handling as the Act and POPIA require.
  • No stated dispatch or delivery timeframe.
  • A checkout that does not give a genuine review-and-correct step before payment.

None of these is difficult to fix. What makes them common is that most stores are built for the sale and not for the disclosure obligations around it, so the legal layer is simply never assembled.


How Section 43 fits with POPIA and the CPA

Section 43 does not exist in isolation. Its requirement for a privacy policy covering personal information now dovetails directly with the Protection of Personal Information Act (POPIA), which imposes its own detailed obligations on how you collect, use and protect customer data. A compliant ecommerce website satisfies both: the Section 43 disclosure that you have a privacy policy, and the POPIA substance of what that policy must contain and how you must actually handle data.

The Consumer Protection Act overlaps too, reinforcing obligations around fair pricing, accurate description, and the consumer’s right to fair dealing. The practical takeaway is that these frameworks stack rather than compete. A store built to satisfy Section 43 properly is most of the way to satisfying the disclosure-facing elements of all three.


A practical compliance approach for WooCommerce

Bringing a WooCommerce store into Section 43 compliance is a defined piece of work, not a vague aspiration. In practice it means:

  • Publish a complete legal identity: full business name, registration number, physical address, an address for legal service, phone and email, accessible from the website (typically footer and a dedicated page).
  • Make full pricing transparent, with shipping, VAT and fees disclosed clearly rather than only at the final checkout step.
  • Publish proper terms and conditions, a returns, exchange and refund policy, and a privacy policy that reflects your actual data practices and aligns with POPIA.
  • State dispatch and delivery timeframes clearly on the website.
  • Confirm the checkout gives a genuine review, correct and withdraw step before payment is taken.
  • Run payments through a reputable, properly integrated South African payment gateway to meet the secure-payment standard.
  • Ensure order confirmations give the customer an accessible, storable record of the transaction.

Done properly, this is a one-time setup that then needs keeping current as your policies, pricing and practices change. It is also the difference between a store that quietly carries a 14-day cancellation exposure on every sale and one that does not.


Frequently Asked Questions

What information does ECTA Section 43 require on my ecommerce website?

Section 43(1) requires roughly eighteen categories of information, including your full name and legal status, registration number and office bearers, physical address and an address for legal service, contact details, a description of the goods or services, the full price including all costs and taxes, payment methods, terms and guarantees, dispatch or delivery timeframes, your returns and refund policy, your privacy and payment security policy, and the consumer’s cooling-off rights where applicable.

What happens if I do not comply with Section 43?

Under Section 43(3), if you fail to provide the required information or fail to give the consumer an opportunity to review and correct the order before payment, the consumer may cancel the transaction within 14 days of receiving the goods or services, without reason and without penalty. This cancellation right is a direct consequence of non-disclosure and is separate from the standard cooling-off period.

Is Section 43 the same as the seven-day cooling-off period?

No. The cooling-off period under Section 44 is a standalone right that lets consumers cancel most distance-sold goods within seven days of delivery, subject to exclusions, regardless of your disclosures. The Section 43(3) right is a 14-day cancellation triggered specifically by your failure to disclose the required information. A store can owe both, and the 14-day non-disclosure right is entirely avoidable by complying.

Does Section 43 apply to business-to-business sales?

Section 43’s consumer protections apply to transactions with consumers, meaning natural persons buying as end users. Pure business-to-business sales sit differently and some provisions are less directly applicable. However, most public-facing stores sell to at least some consumers, and the Consumer Protection Act imposes overlapping obligations, so the safe approach for any public online store is to comply fully.

Do I need a privacy policy under Section 43?

Yes. Section 43(1) requires you to disclose the security procedures and privacy policy applicable to payment, payment information and personal information. This requirement now works alongside POPIA, which sets out in detail what your privacy policy must contain and how you must handle customer data. A compliant store needs a genuine privacy policy reflecting its actual data practices, not a generic overseas template.

Get the Legal Layer Built In, Not Bolted On

If you are building or reviewing a WooCommerce store and want the Section 43 disclosure layer built in from the start rather than patched on later, we build compliant ecommerce websites for South African businesses.

Reach out through our contact page, or get a detailed quote to get started.

Get a Quotation

Scroll to Top