POPIA (Protection of Personal Information Act) is South Africa's data privacy law, effective 1 July 2021, and it applies to every South African website that collects personal data — including contact forms, newsletter signups, cookies and e-commerce checkouts. Non-compliance can result in fines of up to R10 million or criminal prosecution. Online By Digital builds POPIA compliance into every new website and offers standalone POPIA integration for existing sites from R1,650.

Despite being in force since 2021, the vast majority of South African business websites remain non-compliant. This is a significant legal risk that most business owners are unaware of. This guide explains what POPIA requires for your website and how to fix it.

Quick Answer: POPIA applies to your website if it has a contact form, newsletter signup, cookies or e-commerce. You need a privacy policy, cookie consent banner and form disclosures. Online By Digital's POPIA integration costs R1,650 for existing sites. Contact us to get started.

What is POPIA and Why It Applies to Your Website

The Protection of Personal Information Act (POPIA) is South Africa's comprehensive data protection legislation, modelled partly on the EU's GDPR. It establishes how organisations must collect, use, store and protect personal information about South African residents.

"Personal information" under POPIA is very broadly defined and includes:

  • Names, email addresses, phone numbers and physical addresses
  • IP addresses and device identifiers (collected by analytics tools and cookies)
  • Payment information
  • Account usernames and passwords
  • Health or medical information
  • Any information that could identify a specific person

If your website has a contact form, newsletter signup, Google Analytics (which collects IP addresses), user registration, or any e-commerce functionality — POPIA applies to you, regardless of the size of your business.

What Personal Data Websites Collect

Most South African business owners don't realise how much personal data their website collects. Common collection points include:

  • Contact forms — name, email, phone, message content
  • Newsletter signups — email address, sometimes name and preferences
  • Cookies and analytics — Google Analytics collects IP addresses, device type, browser, pages visited and session duration
  • E-commerce checkouts — full name, billing/shipping address, email, phone, payment information
  • User accounts — login credentials, purchase history, preferences
  • WhatsApp click-to-chat links — technically initiates a communication that may involve personal data exchange

What POPIA Requires for Your Website

POPIA requires the following minimum website compliance measures for any South African business website collecting personal information:

  • Privacy Policy page — a comprehensive, legally accurate privacy policy that explains what data you collect, why, how you process it, who you share it with and how users can exercise their rights
  • Cookie consent banner — if your website uses cookies (including Google Analytics), you must inform users and obtain consent for non-essential cookies before they are placed
  • Form disclosure text — contact forms and signup forms must include a clear statement about how submitted data will be used, with a link to your privacy policy
  • Data subject rights — you must have a process for users to request access to, correction of, or deletion of their personal data
  • Breach notification — if personal data is compromised, you must notify the Information Regulator and affected individuals
  • Data processing agreements — if you use third-party processors (email marketing tools, payment gateways, CRM systems), you need data processing agreements in place

POPIA Penalties for Non-Compliance

The consequences of POPIA non-compliance are serious. The Information Regulator has the power to:

  • Issue administrative fines of up to R10 million
  • Impose criminal penalties of up to 10 years imprisonment for serious breaches (e.g. unlawful processing, failing to notify of a breach, obstructing the Regulator)
  • Issue enforcement notices requiring you to change your data practices
  • Accept civil claims from individuals whose data rights were violated

Beyond legal penalties, non-compliance creates reputational risk. South African consumers are increasingly aware of data privacy rights, and a privacy breach — or simply a non-compliant website — can damage your business reputation significantly.

What Online By Digital Includes in POPIA Compliance Integration

Our POPIA compliance integration package (R1,650 for existing sites) covers the essential website compliance requirements:

  • A customised Privacy Policy page drafted for your specific business and data practices
  • A cookie consent banner that meets POPIA requirements for cookie disclosure and consent
  • Form disclosure text added to all contact and signup forms
  • A basic data subject request process (email contact for access/deletion requests)
  • Documentation of what personal data your website collects and why
Note: While our POPIA compliance integration addresses the most critical website-level requirements, comprehensive POPIA compliance for your entire business (including employee data, customer databases, marketing lists and supplier data) may require additional legal guidance. We recommend consulting a qualified data privacy attorney for complete organisational POPIA compliance.

POPIA Website Compliance Checklist

Use this checklist to assess your current website's POPIA compliance status:

  • Does your website have a Privacy Policy page that explains all data collection and processing?
  • Does your website have a cookie consent banner that appears before cookies are set?
  • Do all contact forms include a POPIA disclosure and link to your privacy policy?
  • Is there a way for users to request access to, correction of, or deletion of their data?
  • Is your Google Analytics configured to anonymise IP addresses?
  • If you have e-commerce, is payment data handled by a POPIA/PCI-compliant payment gateway (PayFast, PayGate)?
  • If you use email marketing, do you have consent from all recipients and a clear unsubscribe option?
  • Are your website forms using HTTPS (SSL) for secure data transmission?

Frequently Asked Questions

POPIA (Protection of Personal Information Act) is South Africa's data privacy law, effective 1 July 2021. It applies to any South African business that processes personal information about SA residents. If your website has a contact form, newsletter signup, cookies or any data collection functionality — POPIA applies to you, regardless of your business size.
Yes — if your website collects any personal information (names, emails, phone numbers, IP addresses via analytics cookies, payment data), it must be POPIA compliant. This includes having a privacy policy, cookie consent, form disclosures and data subject rights processes. Online By Digital can add POPIA compliance to your existing website for R1,650.
Non-compliance with POPIA can result in administrative fines of up to R10 million, criminal prosecution (up to 10 years' imprisonment for serious breaches), civil claims from affected individuals, and significant reputational damage. The Information Regulator actively investigates complaints and has already issued enforcement notices to South African organisations.
Online By Digital's POPIA compliance integration for existing South African websites costs R1,650 as a standalone service. This includes a customised privacy policy, cookie consent banner, form disclosure text and data handling documentation. POPIA compliance is included at no extra charge in new website builds from the Professional package (R10,500) upward.
A POPIA-compliant privacy policy must include: what personal information you collect; the purpose of collection; how you process, store and secure it; who you share it with (third parties, processors); how long you retain it; data subject rights (access, correction, deletion, objection); how to lodge a complaint with the Information Regulator; and your contact details as the responsible party.