POPIA and Your Website: What Every SA Business Must Comply With

If your website has a contact form, you are processing personal information. If you send marketing emails, use analytics, or take bookings online, you are doing it at scale — and the Protection of Personal Information Act (POPIA) has applied to you, in full, since July 2021. The good news: for most small business websites, compliance is a short, concrete checklist.
Does POPIA really apply to small businesses?
Yes. POPIA has no small-business exemption. Every “responsible party” — any business that decides why and how personal information is processed — must comply. Names, email addresses, phone numbers and ID numbers all count as personal information. Your contact form collects three of those before lunch.
The six requirements most websites fail
- 1
Publish a POPIA-compliant privacy policy
Not a template from the internet — a policy that actually names what you collect, why, who you share it with, and how people can contact your information officer.
- 2
Get consent before marketing
Newsletter checkboxes must be opt-in, not pre-ticked. Existing customers can be marketed to about similar products; bought lists and scraped addresses cannot.
- 3
Secure what you collect
HTTPS (the padlock) is the floor, not the ceiling. Form submissions, stored enquiries and customer records must be protected with access controls and up-to-date software.
- 4
Only keep what you need
POPIA requires minimality: collect what the purpose needs, keep it only as long as needed, then delete. That enquiry from 2019 should not still be in your inbox archive.
- 5
Handle access requests
Anyone can ask what information you hold about them, and demand correction or deletion. You need a process, not a panic.
- 6
Report breaches
If personal information is compromised — a hacked site, a leaked spreadsheet — you must notify the Information Regulator and affected people as soon as reasonably possible.
Cookies, analytics and WhatsApp buttons
- Analytics and tracking cookies need disclosure, and users should be able to refuse non-essential tracking
- Embedded third-party tools (chat widgets, pixels, maps) send visitor data offshore — your policy must say so
- A WhatsApp click-to-chat button is fine; adding every person who messages you to a broadcast list is not — that needs separate opt-in
- Contact form submissions emailed to you are personal information at rest in your mailbox — protect that mailbox
The fines are real
POPIA allows administrative fines up to R10 million and, for some offences, criminal liability. But the everyday risk is more mundane: a complaint to the Information Regulator, a lost customer who asked a question you could not answer, or a corporate client’s compliance checklist you fail.
Compliance is a sales feature
A visible, honest privacy posture wins business. Corporate procurement increasingly asks suppliers about POPIA compliance; being able to answer confidently — policy, security, processes — moves you up the shortlist. Treat compliance as part of your credibility, not just your legal defence.
Websites built compliant from the start
Every website we build ships with HTTPS, a proper privacy policy structure, consent-correct forms and minimal-data design — and our CRM solutions keep customer data POPIA-compliant long after launch.
Related services



