Back to all guides
Compliance & B-BBEE

POPIA and Your Website: What Every SA Business Must Comply With

1 April 2026 8 min readBy Conflated Solutions
POPIA and Your Website: What Every SA Business Must Comply With

If your website has a contact form, you are processing personal information. If you send marketing emails, use analytics, or take bookings online, you are doing it at scale — and the Protection of Personal Information Act (POPIA) has applied to you, in full, since July 2021. The good news: for most small business websites, compliance is a short, concrete checklist.

Does POPIA really apply to small businesses?

Yes. POPIA has no small-business exemption. Every “responsible party” — any business that decides why and how personal information is processed — must comply. Names, email addresses, phone numbers and ID numbers all count as personal information. Your contact form collects three of those before lunch.

The six requirements most websites fail

  1. 1

    Publish a POPIA-compliant privacy policy

    Not a template from the internet — a policy that actually names what you collect, why, who you share it with, and how people can contact your information officer.

  2. 2

    Get consent before marketing

    Newsletter checkboxes must be opt-in, not pre-ticked. Existing customers can be marketed to about similar products; bought lists and scraped addresses cannot.

  3. 3

    Secure what you collect

    HTTPS (the padlock) is the floor, not the ceiling. Form submissions, stored enquiries and customer records must be protected with access controls and up-to-date software.

  4. 4

    Only keep what you need

    POPIA requires minimality: collect what the purpose needs, keep it only as long as needed, then delete. That enquiry from 2019 should not still be in your inbox archive.

  5. 5

    Handle access requests

    Anyone can ask what information you hold about them, and demand correction or deletion. You need a process, not a panic.

  6. 6

    Report breaches

    If personal information is compromised — a hacked site, a leaked spreadsheet — you must notify the Information Regulator and affected people as soon as reasonably possible.

Cookies, analytics and WhatsApp buttons

  • Analytics and tracking cookies need disclosure, and users should be able to refuse non-essential tracking
  • Embedded third-party tools (chat widgets, pixels, maps) send visitor data offshore — your policy must say so
  • A WhatsApp click-to-chat button is fine; adding every person who messages you to a broadcast list is not — that needs separate opt-in
  • Contact form submissions emailed to you are personal information at rest in your mailbox — protect that mailbox

The fines are real

POPIA allows administrative fines up to R10 million and, for some offences, criminal liability. But the everyday risk is more mundane: a complaint to the Information Regulator, a lost customer who asked a question you could not answer, or a corporate client’s compliance checklist you fail.

Compliance is a sales feature

A visible, honest privacy posture wins business. Corporate procurement increasingly asks suppliers about POPIA compliance; being able to answer confidently — policy, security, processes — moves you up the shortlist. Treat compliance as part of your credibility, not just your legal defence.

Websites built compliant from the start

Every website we build ships with HTTPS, a proper privacy policy structure, consent-correct forms and minimal-data design — and our CRM solutions keep customer data POPIA-compliant long after launch.

#POPIA#Compliance#Privacy#Website
Let’s work together

Ready to take your business to the next level?

We would be delighted to help your business reach new heights. Tell us about your project — we reply within one business day.