Back to BlogCost & Pricing

App Development Cost in South Africa, and POPIA s72 for Offshore Teams

Rupak Amin

Founder & Lead Engineer, RAITHub

14 min read

A custom web app in South Africa costs its engineering hours times the rate: an illustrative 900-hour first version comes to R630,000 at R700 an hour and R1,080,000 at R1,200. If an offshore team will see personal information, POPIA section 72 needs a binding agreement or another listed ground, and section 21 needs a written operator contract.

This guide is for South African founders and operators pricing a web application: a customer portal, a booking or subscription product, a marketplace or an internal tool with payments. It breaks the budget into line items in rand, shows what local payment gateways add, and covers what the Protection of Personal Information Act (POPIA) expects when an offshore team handles your data. RAITHub is a software studio in Dhaka with no office in South Africa, and it builds web applications and PWAs, not native iOS or Android apps. The POPIA sections below are general information, not legal advice. Confirm how they apply to you with your adviser and the Information Regulator.

How much does it cost to build an app in South Africa?

For a web product with sign-in, a few roles, one core workflow, local payments and an admin area, plan for roughly 700 to 1,100 engineering hours. Multiply by the rate and you have the build budget. The hour counts below are assumptions for a mid-sized first version, chosen to show how the line items combine. They are not benchmarks, not quotes and not RAITHub prices.

Line item (illustrative)Assumed hoursAt R700/hourAt R1,200/hour
Discovery and written specification60R42,000R72,000
UX and interface design for the core flows90R63,000R108,000
Sign-in, roles and account management80R56,000R96,000
Core workflow (what customers pay for)280R196,000R336,000
Payments: cards, instant EFT or pay-by-bank, reconciliation90R63,000R108,000
Admin area and reporting80R56,000R96,000
POPIA features: consent records, access requests, retention, incident log50R35,000R60,000
Automated tests and QA130R91,000R156,000
Deployment, monitoring and handover40R28,000R48,000
Total900R630,000R1,080,000

A smaller first version, such as one role and card payments only, can land well under half of this. The MVP cost estimator lets you change the scope and watch the hours move. Hosting, gateway fees and upkeep come on top of the build.

Where do the R700 and R1,200 hourly rates come from?

From published agency rate bands, converted at a published exchange rate. Clutch's South Africa developer directory shows listed firms in hourly bands of US$25–$49 and US$50–$99, with minimum project sizes from US$1,000 to US$50,000. The European Central Bank's reference rates on 29 September 2026 were R18.5887 and US$1.1355 per euro (ECB: ZAR; ECB: USD), which is about R16.37 to the dollar.

Clutch band (as listed)In rand at about R16.37/US$Illustrative point used above
US$25–$49 an hourAbout R409–R802 an hourR700
US$50–$99 an hourAbout R819–R1,621 an hourR1,200

Directory bands are self-reported and wide, and the rand moves, so treat these as a way to sanity-check a quote rather than a price list. The rate matters less than the hours: a vendor that quotes low hours for payments and tests is usually the one that ends up more expensive. How to compare fixed and hourly quotes is covered in fixed price vs time and materials.

What do PayFast and Ozow cost, and what do they add to scope?

Both publish their fees. On a R1,500 monthly subscription, PayFast's card rate is R50.00 and its Instant EFT rate R30.00, excluding VAT; Ozow's pay-by-bank rate is R22.50.

Gateway and methodPublished feeOn R1,500
PayFast, card3.2% + R2.00, excluding VATR50.00
PayFast, Instant EFT2.0% (minimum R2.00), excluding VATR30.00
Ozow, local card2.85% (minimum R1.00) in its lowest volume tierR42.75
Ozow, Pay By Bank, PayShap Request, Capitec Pay1.5% (minimum R1.00)R22.50

Sources: PayFast fees and Ozow pricing, checked 30 September 2026. PayFast lists no monthly fee and invites merchants processing over R50,000 a month to ask for custom rates; Ozow lists no setup fee for its standard package. Check whether each figure includes VAT before you compare them.

The software work is the same pattern for both: the customer pays on the gateway's page, the gateway sends a server-to-server notification, and your app must treat that notification as untrusted until verified, apply it once even if it arrives twice, and check the amount against what you asked for. A provider-agnostic sketch in TypeScript with node-pg, as engineering guidance:

import { Pool } from 'pg'

const pool = new Pool({ connectionString: process.env.DATABASE_URL })

export type VerifiedNotice = {
  provider: 'payfast' | 'ozow'
  eventId: string
  orderId: string
  amountCents: number // rand in integer cents
  paid: boolean
}

// Call only after the provider's own signature or status check has passed.
export async function applyNotice(n: VerifiedNotice): Promise<'duplicate' | 'mismatch' | 'applied'> {
  const client = await pool.connect()
  try {
    await client.query('BEGIN')
    const seen = await client.query(
      'INSERT INTO payment_notice (provider, event_id, order_id, amount_cents, paid) VALUES ($1, $2, $3, $4, $5) ON CONFLICT (provider, event_id) DO NOTHING',
      [n.provider, n.eventId, n.orderId, n.amountCents, n.paid],
    )
    if (seen.rowCount === 0) {
      await client.query('ROLLBACK')
      return 'duplicate' // the gateway retried; already handled
    }
    const { rows } = await client.query('SELECT amount_cents FROM orders WHERE id = $1 FOR UPDATE', [n.orderId])
    if (rows.length === 0 || Number(rows[0].amount_cents) !== n.amountCents) {
      await client.query('COMMIT') // keep the notice for a human to investigate
      return 'mismatch'
    }
    if (n.paid) {
      await client.query("UPDATE orders SET status = 'paid' WHERE id = $1 AND status <> 'paid'", [n.orderId])
    }
    await client.query('COMMIT')
    return 'applied'
  } catch (err) {
    await client.query('ROLLBACK')
    throw err
  } finally {
    client.release()
  }
}

RAITHub has built this pattern against local gateways before: TheSkinProof, the founder's own marketplace venture, takes bKash, Nagad, SSLCommerz and cash on delivery, with 750+ automated tests. RAITHub has not shipped a PayFast or Ozow integration, so that work is priced and tested as new, and each gateway's own verification steps come from its documentation. The Bangladesh integrations are written up in the bKash and SSLCommerz integration guide, and the test cases every gateway needs are in testing payments and webhooks.

Can a South African company send personal information to developers in Bangladesh under POPIA?

Yes, if one of the grounds in section 72 applies. Section 72(1) says a responsible party in the Republic may not transfer personal information to a foreign third party unless one of five conditions is met (POPIA section 72).

Section 72(1) groundWhat the Act says (summarised)How it fits a development vendor
(a) Adequate protectionThe recipient is subject to "a law, binding corporate rules or binding agreement" giving an adequate level of protection, substantially similar to POPIA's conditions, including on onward transfersThe usual route: a binding agreement with the vendor
(b) ConsentThe data subject consents to the transferRarely practical for a product with many users
(c) Contract with the data subjectNecessary to perform a contract between the data subject and youHard to argue for a build or maintenance vendor
(d) Contract in the data subject's interestNecessary for a contract concluded in the data subject's interest with a third partyAsk your adviser; not a default
(e) Benefit of the data subjectFor their benefit, where consent is not reasonably practicable and they would likely give itNarrow; not a basis to plan around

Two details in ground (a) matter for the contract. The protection must be "substantially similar" to POPIA's conditions for lawful processing, and it must include provisions on "the further transfer of personal information from the recipient to third parties who are in a foreign country". In plain terms, the agreement should cover the vendor's own sub-processors and hosting, not only the vendor. Whether Bangladesh's own data protection law gives adequate protection is a legal judgement; most companies rely on the binding agreement rather than on the other country's law. Confirm the current position with your adviser.

What must an operator contract include under POPIA sections 19 to 22?

POPIA calls a vendor that processes personal information for you an operator. Four sections set the floor for that relationship, and the table maps each to what you should ask an offshore team for.

SectionWhat it requiresWhat to ask the vendor for
s19The responsible party must take "appropriate, reasonable technical and organisational measures", identify foreseeable risks, maintain safeguards, verify them regularly and update themA written list of measures: MFA, access logging, encryption, device rules, backup and deletion practice
s20The operator processes only "with the knowledge or authorisation of the responsible party" and treats the information as confidentialA written scope of systems, data and purpose; confidentiality terms for every engineer with access
s21(1)A "written contract" ensuring the operator "establishes and maintains the security measures referred to in section 19"The operator agreement itself, with the s19 measures as a schedule
s21(2)The operator must notify you "immediately" where there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised personA notification window in hours, a named contact and the facts you need to assess an incident
s22You notify the Regulator and, in most cases, the data subjects "as soon as reasonably possible" after discovering a compromiseIncident cooperation: logs, a timeline and help with the notification

Sources: POPIA section 19, section 20, section 21 and section 22. Add the commercial clauses a software engagement needs anyway: full IP assignment, return or deletion of data at the end, and a named list of sub-processors. RAITHub signs operator agreements and DPAs on your template and follows your controls. It is not SOC 2 or ISO 27001 certified and makes no compliance claim; whether your arrangement meets POPIA is for you and your adviser to decide.

Can personal information stay in South Africa while the team works from Dhaka?

Yes, and it is the most effective step you have, because it limits what crosses the border in the first place. Code travels; customers do not.

  • Production in your own cloud account, in South Africa if you choose. AWS runs Africa (Cape Town), af-south-1 (AWS Regions). The account, billing and root credentials are yours.
  • Synthetic seed data in development and staging, so engineers build and test without real customers.
  • Deploys through your CI pipeline. Human access to production is an exception: approved, time-limited and logged.
  • Access through your identity provider with MFA, so every account can be switched off in one place.
  • No production exports on laptops, written into the operator agreement.

This does not remove the section 72 question if the team ever needs production access, for example during a live incident. It makes that access rare, visible and easy to describe. Customer security questionnaires will ask about exactly this; answering your first security questionnaire without SOC 2 shows how to answer honestly.

How many working hours do Johannesburg and Dhaka share?

About 5. Johannesburg and Cape Town are on South African Standard Time, UTC+2, and Dhaka is UTC+6; neither observes daylight saving, so the gap is 4 hours all year.

CityDhaka ahead byShared hours (9:00–18:00 both ends)Window in local timeWindow in Dhaka time
Johannesburg, Cape Town, Durban4 hours509:00–14:0013:00–18:00

The shared window is your morning and early afternoon, every working day of the year, which suits a daily stand-up, a weekly demo and same-day answers to morning questions. Questions raised after 14:00 in Johannesburg get an answer, with working code, the next morning, through a written daily handoff. The working week is agreed per client when the engagement starts, including around South African public holidays.

South African agency, freelancer or offshore team?

FactorSouth African agencyFreelancerRAITHub (Dhaka)
Live overlapFull working dayDepends on the personAbout 5 hours, then async with written handoffs
POPIA transfer paperworkOperator agreement; usually no s72 question if hosting and staff are in South AfricaOperator agreementOperator agreement plus a s72 basis if the team can see personal information
PricingHourly or fixed, variesUsually hourlyFixed written quote after a free 15-minute audit; no public rates
On-site meetingsPossiblePossible if localNo; RAITHub has no South African office
LanguagesOften severalVariesEnglish only
IPPer contractPer contractAssigned to you; NDA standard

For sourced offshore rates and how to vet a team, see the cost to hire developers in Bangladesh and whether it is safe to hire a Bangladesh software agency.

Why RAITHub for this

  • A fixed number before you commit. A free 15-minute technical audit, then a fixed written quote with its assumptions listed, as fixed scope or a dedicated monthly team. See pricing and engagement models.
  • Local-gateway experience, stated honestly. bKash, Nagad and SSLCommerz in production on TheSkinProof, the founder's own venture; Stripe rent collection on PropDesk, with 1,024 automated tests. PayFast and Ozow would be new work, and the quote says so.
  • Data stays with you by design. Production in your account, in Cape Town if you choose, with synthetic data in development.
  • A useful overlap. Five shared hours with Johannesburg every working day, with no daylight-saving shifts on either side.
  • Tests in the price. The MVP development service includes a real test suite gated in CI, not as an extra.

When you don't need us

  • Personal information must never be accessible from outside South Africa, even to debug an incident. Choose a local vendor.
  • You need a native iOS or Android app. RAITHub builds web applications and PWAs, not native mobile apps.
  • You need delivery in Afrikaans, isiZulu or another language. RAITHub works in English only.
  • Your buyers require a SOC 2 or ISO 27001 certified supplier. RAITHub holds neither.
  • You need someone on site or all-day live collaboration. A South African team fits better.
  • An existing product covers 90% of the job. Pay for it and spend the difference on the business.

Sources checked on 30 September 2026. Fees and exchange rates change; check the linked pages before you budget. POPIA points are general information; confirm with your adviser and the Information Regulator.

To turn your scope into a fixed number in rand, book the free 15-minute technical audit. Bring the list of user roles, how customers will pay, and what personal information the product will hold.

Frequently asked questions

How much does it cost to build an app in South Africa?

It is engineering hours times the rate. An illustrative 900-hour web app with roles, local payments and an admin area comes to R630,000 at R700 an hour or R1,080,000 at R1,200 an hour. Smaller first versions cost much less; a fixed quote after an audit gives the real number.

What does POPIA section 72 say about sending data abroad?

It bars a responsible party from transferring personal information to a foreign third party unless a ground applies, such as a law, binding corporate rules or a binding agreement giving adequate protection, or the data subject's consent. For a development vendor the usual route is a binding agreement. Confirm with your adviser.

Do I need an operator agreement with an offshore developer under POPIA?

Section 21(1) requires a written contract ensuring the operator maintains the section 19 security measures, and section 21(2) requires the operator to notify you immediately of suspected unauthorised access. Any vendor processing personal information for you should sign one, wherever it is based.

What does PayFast charge per transaction?

PayFast lists 3.2% plus R2.00 for cards and 2.0% with a R2.00 minimum for Instant EFT, both excluding VAT, with no monthly fee. On a R1,500 payment that is R50.00 by card or R30.00 by Instant EFT. Check its fees page for current rates.

What time-zone overlap does a Dhaka team have with Johannesburg?

About 5 working hours. Johannesburg is UTC+2 and Dhaka UTC+6, with no daylight saving on either side, so a 9:00 to 18:00 day overlaps from 09:00 to 14:00 Johannesburg time all year. The working week is agreed per client.

Has RAITHub integrated PayFast or Ozow before?

Not in production. RAITHub has shipped bKash, Nagad and SSLCommerz on TheSkinProof, the founder's own venture, and Stripe on PropDesk. PayFast or Ozow work would be scoped, priced and tested as new, and the quote states that.

Can South African customer data be hosted in South Africa with an offshore team?

Yes. AWS runs an Africa (Cape Town) region, af-south-1. Keep production in your own account there, give the offshore team synthetic data, and deploy through your pipeline, so developers rarely or never see real personal information.

app development cost south africasoftware development cost randPOPIA section 72POPIA operator agreementPayFast integrationOzow integrationoffshore development south africa

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.