If your website collects so much as a name and an email address, the Protection of Personal Information Act (POPIA) applies to you. There is a stubborn myth that POPIA is only a worry for banks, medical aids and big corporates. It is not. Every South African business that processes personal information through its website carries legal duties under POPIA, and the Information Regulator has moved from warning people to issuing real fines.
The reassuring part is that POPIA website compliance is mostly a series of practical, once-off tasks rather than an ongoing burden. Work through the checklist in this guide and you will have the essentials covered, protecting your customers and shielding your business from penalties. Everything below is written in plain language for South African business owners, not in legal jargon.
📋 Key Takeaways
Does POPIA apply to my small website?
Yes. POPIA applies the moment you process personal information, and personal information is defined extremely broadly. It covers names, email addresses, phone numbers, ID numbers, physical and delivery addresses, and even technical identifiers like IP addresses. There is no minimum threshold you have to cross first and, crucially, no carve-out for small businesses, sole proprietors or non-profits.
In day-to-day terms, your website almost certainly processes personal information if it has any of the following common features:
ℹ️ Important: There is no exemption for small businesses or sole proprietors. If you collect personal information in any form, POPIA applies to you regardless of your size, sector or turnover.
What POPIA actually requires from your website
POPIA is built on eight conditions for the lawful processing of information, but for a typical business website those conditions translate into a short, manageable list of practical requirements. The table below is the quick version, and the sections that follow unpack each item so you know exactly what to do.
None of these requires a lawyer or a developer for a standard small business site. Most can be handled in an afternoon with the right hosting and a couple of plugins.
Your privacy policy: what to include
Your privacy policy is the document that tells visitors, honestly and clearly, what happens to their information. A compliant policy spells out what you collect, why you collect it, how long you keep it, who you share it with, and how someone can ask to see or delete their data. It must also state whether any information is transferred outside South Africa, for example when you use an overseas email provider or analytics tool.
Write it so a normal customer can understand it, then link it in your website footer so it appears on every page. Reference it again on any form that collects details, with a short line explaining what the information will be used for. This combination of a footer link and form-level notice is what regulators expect to see.
⚠️ Watch Out: Do not copy a generic privacy policy word-for-word from another website. If it describes data practices you do not actually follow, it is not compliant and can create more legal risk than having no policy at all.
Cookie consent done properly
If your site loads non-essential cookies, such as Google Analytics or the Meta pixel, POPIA requires you to get consent before those cookies run. A cookie banner with a simple accept-or-decline choice handles this, and most consent plugins will block the tracking scripts until the visitor chooses. Essential cookies that make the site function do not need consent, but tracking and advertising cookies do.
The standard that trips businesses up is that consent has to be a real, informed choice. A banner that only offers an Accept button, or that says consent is assumed, does not meet the bar.
💡 Pro Tip: Consent must be opt-in, not opt-out. Avoid pre-ticked boxes and vague ‘by using this site you agree’ notices, neither of which counts as valid consent under POPIA.
HTTPS and basic security
POPIA requires you to take reasonable steps to secure personal information, and the baseline for any website is HTTPS, shown by the padlock in the address bar. HTTPS encrypts data such as form submissions and login details so they cannot be intercepted in transit. A site still running on plain http is both a security risk and a visible red flag to customers, who increasingly recognise the Not Secure warning.
You should never pay extra for this. Reputable hosts include a free, auto-renewing SSL certificate as standard. Our guide on SSL certificates and HTTPS explains how to check and switch yours on, and every plan on our web hosting includes free SSL out of the box.
Appointing and registering your Information Officer
Every business must have an Information Officer who is accountable for POPIA compliance. By default this is the business owner, the CEO or another senior person, but the law requires you to formally register that person with the Information Regulator before they can act in the role. This is the single most commonly missed step, even among businesses that have sorted out everything else.
📘 Good to Know: Registering your Information Officer is free and done through the Information Regulator’s online portal in a few minutes. It is a genuine legal requirement, not an optional extra, so do not skip it.
Handling data subject requests
People have the right to ask what information you hold about them, to have it corrected, and in many cases to have it deleted. You need a simple, documented way to receive and act on these requests. For most small businesses that is as straightforward as a dedicated email address and a short paragraph in your privacy policy explaining how to make a request and how quickly you will respond, usually within a reasonable period such as 30 days.
Keep a basic record of requests you receive and how you handled them. If a complaint ever reaches the Regulator, that paper trail is your evidence that you took your obligations seriously.
Common POPIA mistakes SA businesses make
What happens if you ignore POPIA
The Information Regulator can impose administrative fines of up to R10 million, and the most serious breaches can carry criminal liability with imprisonment. Enforcement is no longer theoretical, real fines have been issued to both public and private bodies in the past two years. Even setting the penalty aside, a visible data breach or a public complaint erodes the customer trust you have spent years building.
Viewed the other way, getting compliant is a low-cost insurance policy. The tasks in this guide cost little more than your time, and they remove a real and growing risk.
How the right setup makes compliance easier
A surprising amount of POPIA compliance rests on good foundations. Hosting on South African servers keeps your data in the country and under local jurisdiction, which simplifies your cross-border disclosures. Free SSL gives you the HTTPS you need, and automatic daily backups support the security condition. If your site still needs a privacy policy, a cookie banner or a general tidy-up, our web design team can build compliance in from the ground up.
Frequently asked questions
Is POPIA the same as the GDPR?
They are similar in spirit but not identical. The GDPR is the European regulation; POPIA is South Africa’s own law. If you serve European customers you may need to consider both, but for a South African business with local customers, POPIA is what applies.
Do I need a lawyer to be POPIA compliant?
For a standard small business website, no. A reputable privacy policy template adapted to your actual practices, a cookie banner, HTTPS and a registered Information Officer cover the essentials. A lawyer is worth it only if you handle large volumes of sensitive data.
How much does POPIA compliance cost?
For most small sites the direct cost is minimal: SSL and backups come with good hosting, a consent plugin is free or inexpensive, and registering your Information Officer is free. The main investment is a little time.
Not sure where your site stands? Email us at [email protected] and we will point you to the gaps worth fixing first.