Compliance & Legal5 min read

POPIA and Your Website: What South African Businesses Actually Need

POPIA applies to almost every business website

The Protection of Personal Information Act came into full force in July 2021, and a surprising number of South African business owners still assume it is something only banks and big corporates need to worry about. It is not.

POPIA governs what happens when you collect, store, or use someone's personal information. A name and an email address in a contact form is personal information. So is a phone number, an IP address, or a WhatsApp number. If your website has a contact form, an enquiry form, or a newsletter signup, you are processing personal information and POPIA applies to you.

The good news is that for a typical small business website, compliance is far less painful than the acronym suggests. It is mostly about being honest and specific about what you do with the information people give you.

The four things your website actually needs

Most small business sites need the same handful of things in place.

  • A privacy policy that says what you collect, why you collect it, how long you keep it, and who else sees it. Vague boilerplate copied from a template site is worse than useless, because it will not match what you actually do.
  • A lawful reason for collecting each piece of information. For a contact form the reason is obvious: someone asked you to get back to them. For a marketing list it is not, which is why marketing needs its own explicit opt-in.
  • A way for people to reach you about their data. POPIA gives people the right to ask what you hold about them and to ask you to delete it. You need a working contact route for that, and someone who reads it.
  • Security appropriate to what you hold. For most sites this means HTTPS, a reputable host, and not emailing spreadsheets of customer details around.

Consent is narrower than people think

The most common mistake we see is treating a single tick box as blanket permission. It is not.

If someone fills in your enquiry form, you have permission to reply to their enquiry. You do not automatically have permission to add them to a monthly newsletter, share their details with a partner business, or message them on WhatsApp about an unrelated promotion two years later. Each of those is a different purpose, and POPIA works on the basis that consent is specific.

The practical version: keep a separate, unticked opt-in for marketing, and honour it.

Cookies and analytics

If you run Google Analytics, a Meta Pixel, or any advertising tracking, you are collecting information about visitors before they have typed anything. That needs disclosing in your privacy policy, and in most cases it needs a cookie notice that lets people decline non-essential tracking.

A cookie banner that offers no way to say no is not consent. It is a notification.

What happens if you ignore it

The Information Regulator can issue enforcement notices, and non-compliance can carry administrative fines or, in serious cases, criminal liability. In practice, small businesses are rarely the first target of a regulator with limited capacity.

The more realistic risk is commercial. Larger clients increasingly ask about POPIA compliance during procurement, and a missing privacy policy is an easy reason to be passed over. It also does you no favours with customers who are, quite reasonably, more careful about their data than they were a few years ago.

Getting it sorted

None of this requires a lawyer for a straightforward small business site. It requires someone to write a privacy policy that reflects what your site genuinely does, add a cookie notice if you are running tracking, and make sure your forms only ask for what you need.

We include POPIA setup as an add-on when we build a site, because it is far easier to do properly at build time than to retrofit later.

One caveat worth stating plainly: this article is general guidance, not legal advice. If you process sensitive information, handle children's data, or move personal information outside South Africa, talk to someone qualified.

Get a free quote and we will tell you what your site needs.

Common questions

Does POPIA apply to a small business website?
Yes. POPIA governs any collection of personal information, and a name and email address in a contact form counts. If your site has an enquiry form or a newsletter signup, it applies to you regardless of company size.
What does a POPIA-compliant website actually need?
A privacy policy that accurately describes what you collect and why, a lawful reason for collecting each item, a working contact route for data requests, and security appropriate to what you hold — HTTPS and a reputable host for most small sites.
Do I need a cookie banner in South Africa?
If you run Google Analytics, a Meta Pixel or any advertising tracking, you are collecting data before a visitor types anything. That needs disclosing, and in most cases a cookie notice that genuinely lets people decline non-essential tracking. A banner with no way to say no is a notification, not consent.
What happens if I ignore POPIA?
The Information Regulator can issue enforcement notices and fines. In practice the more immediate risk for a small business is commercial: larger clients increasingly ask about compliance during procurement, and a missing privacy policy is an easy reason to be passed over.