Running a business · South Africa

What POPIA actually asks of your website

By Clear Digital Studio

· 4 min read

a golden padlock sitting on top of a keyboard

POPIA has been enforceable for years now, and a great many South African websites are still running the setup they had before it. Usually that means an analytics script firing on page load, a privacy policy copied from a British template, and no Information Officer registered anywhere.

The penalties are not theoretical. Fines run from one million to ten million rand, and serious offences carry the possibility of imprisonment. Here is what the law actually asks of a website.

Cookie consent has to come first, not after

POPIA works on an opt-in model. You need consent before placing any cookie that is not strictly necessary for something the visitor actively asked for.

Strictly necessary is narrow. Keeping someone logged in, holding a shopping basket, balancing server load. Analytics is not strictly necessary. Neither is advertising, remarketing, heatmaps or session recording.

The failure almost every site shares is timing. The banner appears, the visitor has not touched it, and Google Analytics has already loaded and set its cookies. Consent obtained afterwards is not consent. If you fix one thing on this page, fix that one.

Two details people miss. Consent expires after twelve months, so you have to ask again. And you need to keep records of consent, including when it was given, what the person agreed to per purpose, and which version of your policy applied. Those records should be retained for at least twelve months.

Declining has to be as easy as agreeing

A banner with a prominent Accept button and a Manage Preferences link leading to a settings panel does not meet the standard. Refusing must be as straightforward as accepting, which in practice means a Reject All button beside Accept All, equally visible.

Businesses resist this because they assume their analytics will collapse. In practice a clear choice gets answered quickly and a meaningful share of people accept, while a banner that obviously makes declining awkward gets dismissed or ignored. You end up with less data and a worse first impression.

You need a registered Information Officer

This one catches almost everybody. Every organisation must have an Information Officer, and they must be registered with the Information Regulator.

By default it is the head of the organisation, so if you have not appointed anyone, it is you. The role covers handling data subject requests, maintaining your compliance programme, and being the contact point for the Regulator. Their details should appear in your privacy policy.

The privacy policy has to be about you

A generic template referencing GDPR and a company in another country is worse than a short honest page, because it demonstrates that nobody read it.

It needs to say what you collect, why, how long you keep it, who else it goes to, and how someone exercises their rights. POPIA gives data subjects a specific set of rights under section 5, including being informed, accessing their data, correcting it, having it deleted, and objecting to processing. Your policy should tell people those rights exist and how to use them.

It also has to be findable and readable. Linked from the footer and from the cookie banner, written in language an ordinary person can follow.

Forms need a stated purpose

Every form collecting personal information needs to say what the information is for. A contact form gathering name, email and phone is collecting personal data, and the person filling it in should know what happens next.

One line under the form is enough. Something like: we use these details to respond to your enquiry and we do not share them. What you cannot do is collect an email for an enquiry and then add it to a marketing list, because that is a different purpose and it needs its own consent, which means a separate unticked checkbox.

Requests and breaches need a process

Someone can ask what data you hold on them, and you have to be able to answer without requiring them to create an account. Decide now who handles that and how, because the clock starts when the request arrives.

If you suffer a breach, notification goes to the Regulator through its eServices portal, and to affected people. Having a written process beats improvising during a bad week.

A practical checklist

  • No non-essential cookies fire before consent.
  • Reject All is as prominent as Accept All.
  • Consent records are stored, with timestamps and purposes.
  • An Information Officer is appointed and registered.
  • The privacy policy is specific to your business and names the rights.
  • Every form states its purpose, and marketing consent is separate and unticked.
  • There is a documented process for data subject requests and breaches.

Most of this is configuration and writing rather than development. It is a day or two of work, and considerably cheaper than the alternative.

See how we work with South African businesses, or send us your site and we will tell you what fires before consent.

Building something in South Africa?

South AfricaWe design and build fast, POPIA-conscious websites and AI customer experiences for ambitious South African businesses — WhatsApp-native, quick on any connection, and built to convert. Fixed quote, senior people from first call to launch.

What we do in South Africa

Let's talk

Let's build something that earns its keep.

A free 30-minute strategy call. We'll review what you have, tell you what's possible, and give you a straight answer on cost and timeline.