1. What the document is

A cookie policy is a public statement of what cookies and cookie-like tracking technologies your website sets, what category each one falls into, which third parties are behind them, and how a visitor can refuse or withdraw consent. It usually lives at a URL like /cookie-policy or /cookies, and it is paired with a consent banner that fires on first visit and actually blocks non-essential cookies until the user clicks accept.

A real one has four moving parts:

Terminology varies. Some sites fold the cookie policy into the privacy policy as a section; others keep it standalone and link out from the privacy policy. Nigeria's regulatory language talks about a "Privacy Policy" that must disclose the "method of collection" of personal data, which cookies fall under. South Africa's POPIA doesn't use the word "cookie" at all, it treats a cookie identifier as personal information subject to the same processing conditions as any other data point, so South African sites typically fold cookie disclosure into a "Privacy Notice" plus a separate cookie consent tool. Egypt's PDPL and its 2025 executive regulations use "Privacy Notice" in the GDPR sense. For a founder, the safe move is: have a standalone cookie policy, and cross-reference it from your privacy policy, because that's the structure investors and diligence lawyers expect to see regardless of which jurisdiction's label you use.

If your site scanner flagged "cookie consent" as missing, it almost always means one of two things: there's no banner blocking non-essential cookies before consent, or there's a banner but no linked policy explaining what's actually being set. Both are separately checkable and both get checked.

2. What an investor is actually checking for

Nobody at Series A reads your cookie policy for pleasure. The diligence lawyer opens it to answer a narrow set of questions, and if the answers aren't there, it becomes a flagged item in the diligence report that either delays close or gets priced into the deal as risk.

Here's what they're actually doing:

Cross-checking the policy against what the site actually does. A diligence associate (or increasingly, an automated scanner the fund's counsel runs) loads your site, captures the network requests, and compares the cookies actually set against what your policy discloses. If your site fires a Meta Pixel and a TikTok Pixel but your cookie policy only mentions Google Analytics, that's an immediate red flag: it means either the policy is stale, or nobody at the company is tracking what marketing has bolted onto the site. Both readings are bad, because they suggest the same gap exists in how you handle actual customer data, not just cookies.

Checking whether consent is a genuine choice or theater. A banner that says "we use cookies" with only an "Accept" button and no "Reject" or "Manage preferences" option is not valid consent under NDPA, POPIA, Kenya's DPA 2019, or GDPR-adjacent frameworks generally. Lawyers know this pattern immediately because it is the single most common cookie-compliance failure on the internet, and it signals the company treated compliance as decorative rather than functional.

Looking for auditability. "We may share your data with partners" with no defined partner list cannot be checked against anything. A diligence lawyer can't verify it, can't map it to your actual vendor list, and can't tell you whether it's even true. The fix they want to see is a named list: "Google LLC (analytics), Meta Platforms Inc (advertising), Intercom Inc (support chat)," each tied to a specific cookie and a specific purpose. Unnamed "partners" reads as either sloppy drafting or an attempt to obscure a longer vendor list than the founders want to admit to.

Checking the policy is dated and versioned. If the cookie policy has no "last updated" date, or the date is from before your last product pivot, it tells the lawyer nobody owns this document. Ownership matters because a policy that nobody maintains is a policy that will drift out of sync with the product, and that drift is exactly the kind of latent liability that shows up as a warranty breach after close.

For an acquirer's CFO, the lens is different but related. They're pricing integration risk and indemnity exposure. A missing or non-functional cookie consent flow, especially for a company doing business with EU or UK customers (GDPR extraterritorial reach) or planning to, means the acquirer inherits an active compliance gap the day the deal closes. That gets modeled as either a purchase-price adjustment or an escrow holdback, not as a footnote.

The pattern across all of this: the document is being checked as evidence of an operating discipline, not as a legal artifact in isolation. A clean cookie policy that matches the live site tells an investor the company can be trusted to say what it does and do what it says, on data generally, not just cookies.

3. What it costs to get done properly, by African jurisdiction

Two separate costs are usually being conflated when founders ask "what does this cost": the cost of drafting the policy itself (a legal document), and any government registration fee for being a data controller under local law. They are not the same line item, and in most of these jurisdictions the registration fee is public and fixed while the drafting fee is negotiated privately with a law firm and rarely published.

Country Primary law Regulator Registration/licence fee Drafting cost Self-serve options
Nigeria Nigeria Data Protection Act 2023 (NDPA), built on the NDPR 2019 framework Nigeria Data Protection Commission (NDPC) Tiered annual fee: ₦10,000 (Ordinary High Level, 200–999 data subjects/6 months), ₦100,000 (Extra High Level), ₦250,000 (Ultra High Level, e.g. banks, telcos, 5,000+ subjects) [1] Not publicly standardized. One compliance-automation vendor estimates full NDPA compliance programs (not just a policy) at $5,000–$80,000 depending on scope [2] No official free government template; commercial generators like Termly offer a free-tier policy generator not built for NDPA specifically [3]
Kenya Data Protection Act, 2019 Office of the Data Protection Commissioner (ODPC) Initial registration: KES 4,000 (micro/small, under 50 staff and under KES 5m turnover) to KES 40,000 (large orgs); renewal every 24 months at roughly half those rates [4] Not publicly published by Kenyan firms; local data-protection practices (e.g. TripleOKLaw, CR Advocates, Bowmans Kenya) quote per engagement No official ODPC template for a cookie policy; ODPC publishes guidance notes, not fill-in-the-blank documents [5]
South Africa Protection of Personal Information Act, 2013 (POPIA) Information Regulator Information Officer registration is free, done via the Regulator's e-services portal [6] Not publicly published; firms like Michalsons and Legalese offer fixed-fee POPIA bundles but list pricing only on request Legalese's "Online Compliance Bundle" packages a privacy policy and website terms for South African SMEs, priced on inquiry [7]
Egypt Personal Data Protection Law No. 151 of 2020 (PDPL), with Executive Regulations under Decree No. 816 of 2025 Personal Data Protection Center (PDPC) Licence fees scale with data volume; full compliance deadline is 31 October 2026; separate consultation-service licence fees of EGP 50,000 (legal entities, 3-year validity) or EGP 5,000 (individuals) are published in the regulations [8] Not publicly standardized; the PDPC's licence application portal is scheduled to launch in May 2026, so most firms are quoting compliance programs rather than single-document drafting right now None official yet; wait for PDPC portal guidance before relying on any template
Ghana Data Protection Act, 2012 (Act 843) Data Protection Commission Registration is mandatory and renews every 2 years; the Commission does not publish its fee schedule online, so the current figure has to be confirmed directly with the Commission [9] Not publicly published None official; Ghana's DPC has published compliance guidelines but not a fill-in template [10]

A few honest caveats on these numbers. First, the government registration fees are the most reliable figures here because they're published by the regulators themselves. Second, law firm drafting fees for a cookie policy specifically are almost never quoted as a standalone line item anywhere in Africa, they get bundled into a broader "data protection compliance" or "startup legal pack" engagement, which is why the table above mostly says "not publicly published" rather than making up a number. As a rough non-African anchor point: ContractsCounsel's US marketplace data puts the average flat fee for a lawyer to draft a privacy policy at around $960, with privacy lawyer hourly rates running $225–$300 [11]. African market rates for the equivalent work are generally lower than US big-firm rates but higher than that number would suggest once you factor in that most African data-protection specialist firms are boutique practices billing at a premium for a scarce specialty, not commodity generalist work.

4. Where to get it

Do not use a Delaware-templated cookie policy or privacy policy off the shelf for an African-registered entity and assume it covers you. The specific risk: US templates are written around CCPA and sometimes GDPR, neither of which maps cleanly onto NDPA's data subject rights, POPIA's "operator" versus "responsible party" distinction, or Egypt's licence-tiered PDPL regime. The gap doesn't show up at signing, because nobody checks a cookie policy at signing. It shows up in diligence, when a lawyer notices the policy references CCPA's "Do Not Sell My Info" right and nothing about NDPC registration, and asks why a Lagos-incorporated company's cookie policy reads like it was written for California. It also shows up in a dispute, if a user or regulator complains and your policy's stated legal basis for processing doesn't match the basis your actual law requires you to have used.

Regulator guidance (start here, it's free and authoritative on what must be disclosed):

Pan-African legal guidance and comparisons:

Named firms with published African data-protection practice pages (to shortlist for a quote, not to copy from):

Self-serve template generators (useful for a first draft to hand your lawyer, not a substitute for jurisdiction-specific review):

The honest bottom line for a founder reading this because a scanner flagged "cookie consent" missing: fix the banner and the policy text yourself this week using a generator as a starting draft, because that closes the diligence flag fastest, and then get five minutes of a local lawyer's time to check the legal-basis language before your next raise, because that's the part a template genuinely cannot get right for you.


Sources