POPIA, the Protection of Personal Information Act, has been fully enforceable in South Africa since July 2021. The Information Regulator, the body responsible for enforcement, has been issuing notices, conducting investigations, and in some cases imposing fines on organisations that have not taken their obligations seriously. This is no longer a theoretical compliance requirement.
For businesses with a website that collects personal information, whether through a contact form, a booking system, a newsletter signup, or an e-commerce checkout, the obligations are specific and practical. This guide explains what your website needs to have in place and what the most common gaps are.
What POPIA actually requires from your website
POPIA requires that any organisation processing the personal information of South African data subjects has a lawful basis for doing so, notifies individuals about how their information is being processed, implements appropriate security measures, and provides a mechanism for individuals to exercise their rights, including the right to access their information and the right to object to its processing.
Applied to a website, these requirements translate into several specific obligations that are common across almost every South African business site.
A current, specific privacy policy
A privacy policy is not optional. POPIA requires that individuals be informed about how their personal information is collected, what it is used for, whether it is shared with third parties, how long it is retained, and how they can exercise their rights. A generic template policy copied from another website, or a policy that has not been updated since 2021, does not meet this standard.
Your privacy policy should specifically cover the types of personal information collected through your website, the purpose of each collection, which third parties receive the data (including analytics tools like Google Analytics, marketing tools like Mailchimp, and payment processors), the retention period for different categories of data, and the contact details of your Information Officer, which is the person responsible for POPIA compliance in your organisation.
An Information Officer
Every organisation processing personal information under POPIA must designate an Information Officer. For most South African SMEs, this is the business owner or a senior staff member. The Information Officer is responsible for ensuring POPIA compliance, handling requests from data subjects, and liaising with the Information Regulator if required. You are required to register your Information Officer with the Information Regulator. The registration process is online and takes roughly thirty minutes.
Consent where consent is required
POPIA requires consent for certain categories of processing, particularly marketing communications. If your website collects email addresses for a newsletter, a promotional database, or any form of direct marketing, you need explicit, informed consent from the individual at the point of collection, not buried in terms and conditions, not pre-ticked, and not implied by virtue of them submitting a contact form about something else.
A contact form asking for a name and email to respond to an enquiry does not require separate marketing consent for the response itself, since the processing is necessary to respond to the request. Subsequent marketing communications to that same contact do require consent unless you have a separate legitimate interest basis that you can justify.
Cookie consent for non-essential cookies
If your website uses cookies beyond those strictly necessary for the site to function, POPIA's requirements around informed consent and transparency apply. Analytics cookies (Google Analytics, for example) and marketing cookies (Facebook Pixel, Google Ads remarketing) are non-essential and require user consent before being placed. A simple, honest cookie notice with a genuine option to decline non-essential cookies meets the requirement. A banner that does not actually offer a meaningful choice, or that places non-essential cookies on page load before any consent is given, does not.
Secure data handling for form submissions
Personal information collected through your website, contact forms, booking requests, application forms, and checkout details, must be handled securely. In practice this means the forms should submit over HTTPS (your site must have a valid SSL certificate), the data should be stored in a secure system rather than sitting in a shared inbox indefinitely, access to customer data should be limited to staff who need it, and there should be a process for responding to a data breach if one occurs.
A process for data subject requests
POPIA gives individuals the right to request access to their personal information, to request corrections to inaccurate data, and to request deletion of their data in certain circumstances. Your website's privacy policy should include a contact mechanism for these requests, and your organisation should have a process for responding to them within the timeframes POPIA specifies. Most small businesses handle these via a dedicated email address referenced in the privacy policy.
What the Information Regulator is actually enforcing
The Information Regulator's enforcement activity to date has focused primarily on larger organisations with systemic failures: data breaches that were not reported within the required timeframe, organisations that had no privacy policy at all, and marketing practices involving purchased lists sent without consent. Small businesses with a genuine, well-maintained privacy policy, reasonable consent practices for marketing, and a designated Information Officer are unlikely to be primary enforcement targets, but they are not exempt from the requirements.
The practical risk for a small business is not primarily a regulatory fine. It is the reputational and relationship damage that comes from a data breach handled poorly, or from a customer discovering that their information is being used in a way they did not agree to. POPIA compliance, done properly, is as much a trust signal to customers as a legal obligation. For businesses using WhatsApp, read our guide on POPIA and WhatsApp Business as well.
The practical steps to take this week
Register your Information Officer with the Information Regulator at their online portal. Review your privacy policy against the checklist of requirements above, and update it if it does not currently meet them. Audit the cookies your website uses and ensure your cookie notice reflects what is actually running and offers a genuine choice. Check that any marketing communication lists were built with proper consent. None of these steps require significant investment, and all of them reduce both regulatory and reputational risk materially.
If you need help ensuring your website meets POPIA requirements, or want compliance built in from the start, get in touch with CodeLab One. Every business website we build includes the privacy policy structure, cookie consent, and data handling practices that meet current requirements.



