Moducraft
Technical 17 July 2026 · 11 min read

POPIA compliance for your website - what South African small businesses actually need to do

POPIA has been fully enforceable since July 2021, but most small business websites in South Africa still aren't properly compliant. Here's a practical, plain-language guide to what your website actually needs - and what you can safely skip.

The law is live, but the panic is overblown

The Protection of Personal Information Act (POPIA) has been fully enforceable since 1 July 2021. If your business has a website that collects any kind of personal information - a contact form, an email signup, an online shop - POPIA applies to you.

That said, the internet is full of scare pieces about POPIA that make it sound like the Information Regulator is waiting to fine every small business into oblivion. The reality is more proportionate than that. POPIA is designed to make sure businesses handle personal information responsibly, not to shut down every bakery with a contact form.

What follows is practical web guidance for small business owners. This is not legal advice - if you have specific legal questions about your obligations, talk to a lawyer. But for the typical small business website, here is what you actually need to do.

What POPIA requires from your website, in plain terms

POPIA is built around a straightforward idea: if you collect someone's personal information, you need to tell them what you're collecting, why, and what you'll do with it. You need to keep it safe, and you need to give them a way to ask what you hold and request its deletion.

For most small business websites, this boils down to a few practical things.

You need a privacy policy

Every website that collects personal information needs a privacy policy. This isn't optional, and it isn't just good practice - POPIA specifically requires that you inform people about how their information is processed.

What it needs to say

Your privacy policy should cover:

  • What information you collect - names, email addresses, phone numbers, delivery addresses, payment details, anything that identifies a person
  • Why you collect it - to respond to enquiries, to process orders, to send marketing emails, to improve your website
  • How you store and protect it - where the data lives, what security measures are in place, who has access
  • How long you keep it - POPIA says you shouldn't keep personal information longer than necessary for the purpose it was collected
  • Who you share it with - payment processors, courier companies, email marketing platforms, your accountant
  • How people can access, correct, or delete their information - you need to provide a way for someone to ask what data you hold on them and request changes or deletion
  • Your Information Officer's contact details - POPIA requires every business to have one, and it's often the business owner for small operations

Where to put it

Link to your privacy policy from the footer of every page on your site. If you have a contact form, link to it near the submit button. If you collect email signups, link to it next to the signup field.

Don't bury it. Don't make it a PDF that downloads. Make it a page on your website that's easy to find and easy to read.

Keep it readable

The biggest mistake we see with privacy policies is that they're written in dense legal language that nobody reads. POPIA specifically encourages clear, understandable language. Write it in plain English (or Afrikaans, or both). Your customers should be able to read it and understand what you do with their information without a law degree.

Contact forms and data collection

If your website has a contact form, you're collecting personal information. A name and an email address count as personal information under POPIA.

What you need to do:

  • Collect only what you need. If you just need to respond to an enquiry, you need a name, an email address, and the message. You don't need their date of birth, ID number, or physical address. POPIA calls this "minimality" - only collect information that's necessary for the purpose
  • Tell people what happens to their submission. A short line near the form works: "We use this information to respond to your enquiry. See our privacy policy for details." You don't need a full legal disclaimer, just transparency
  • Store submissions securely. If form submissions go to your email inbox, that's fine for most small businesses. If they're stored in a database, make sure it's properly secured. Delete old enquiries you no longer need

Cookie consent: what South African sites actually need

This is where POPIA confusion gets worst, because people mix up POPIA requirements with GDPR (the European regulation).

POPIA does not require the same cookie consent banners that GDPR does. South Africa does not have a specific cookie law equivalent to the EU's ePrivacy Directive. POPIA covers "personal information" generally, which can include cookies that track individuals - but it doesn't mandate a specific click-to-accept cookie banner.

What POPIA does require:

  • Disclose what cookies you use in your privacy policy. If you use Google Analytics, mention it. If you use Facebook Pixel, mention it. Explain what these tools do in plain terms
  • Don't use tracking cookies to collect personal information without informing the user. Analytics that track aggregate, anonymous data are generally fine. Cookies that build individual profiles are personal information processing and need disclosure
  • If you target EU visitors, you still need GDPR compliance. If your business serves international customers (some guesthouses, export businesses, online shops that ship overseas), the GDPR cookie requirements may apply regardless of POPIA

For the average South African small business website with Google Analytics and no aggressive tracking, a clear privacy policy that explains your cookie usage is sufficient. You don't need a cookie consent pop-up that covers half the screen. But if you want to add one for extra caution or to build trust, there's no harm in it.

Email lists and marketing

POPIA has direct opt-in requirements for marketing communications:

  • You need consent before adding someone to a marketing email list. This means a deliberate opt-in - a checkbox that isn't pre-ticked, a signup form they chose to fill in, or a clear verbal agreement
  • Every marketing email must include an unsubscribe link. This was already best practice; POPIA makes it a legal requirement
  • Buying email lists is effectively dead. You can't send marketing to people who haven't consented to hear from you. Purchasing a list of "10,000 Cape Town business owners" and emailing all of them is a POPIA violation
  • Existing customers are slightly different. If someone has an existing relationship with your business (they've bought from you, they've used your services), you may be able to market to them under the "legitimate interest" basis - but they still need to be able to opt out easily

If you use a platform like Mailchimp, Brevo, or MailerLite, the unsubscribe functionality is built in. The main thing you need to handle on your website is making sure signups are genuinely voluntary and clearly explained.

E-commerce sites: additional considerations

If you sell online, you're handling more personal information than a brochure site: names, delivery addresses, phone numbers, payment card details (even if processed by a gateway), order history. POPIA requires extra care here.

  • Payment information should be processed through a reputable payment gateway (PayFast, Yoco, Peach Payments) that handles PCI compliance. Don't store card numbers yourself
  • Order history is personal information. Have a retention policy - how long do you keep order records? For tax purposes you might need them for five years, but you should state this in your privacy policy
  • Delivery information shared with courier companies means those couriers are processing personal information on your behalf. Your privacy policy should mention this
  • Customer accounts should allow customers to view and request deletion of their data. If your platform doesn't support this, at minimum provide an email address where they can make requests

What happens if you don't comply

The Information Regulator can issue enforcement notices, impose fines of up to R10 million, and in serious cases, pursue criminal charges with potential imprisonment. That's the maximum.

In practice, enforcement so far has focused on large-scale data breaches, direct marketing abuses (unsolicited communications), and organisations that process sensitive information irresponsibly. The Regulator has made examples of major companies and government departments.

A small business with a contact form and no privacy policy is unlikely to be the Regulator's top priority. But that doesn't mean you should ignore compliance. Beyond the legal risk, there are practical reasons to get it right:

  • Customer trust. A clear privacy policy signals that you take your customers' information seriously
  • Complaints are easy to lodge. Any customer can file a complaint with the Information Regulator. Even if it doesn't result in a fine, dealing with a regulatory complaint is time you could spend running your business
  • It's not hard to fix. For most small business websites, compliance is a few hours of work, not a major project

A practical POPIA compliance checklist for your website

Use this to check where you stand:

  • Privacy policy page exists and is linked from the footer of every page
  • Privacy policy explains what information you collect and why
  • Privacy policy names any third-party services you share data with (analytics, payment gateways, email marketing tools, couriers)
  • Privacy policy includes your Information Officer's name and contact details
  • Privacy policy is written in plain, readable language
  • Contact forms collect only necessary information
  • Contact forms include a link to your privacy policy or a brief data-use statement
  • Email signups use a clear, voluntary opt-in (no pre-ticked boxes)
  • Marketing emails include a working unsubscribe link
  • Cookie usage is disclosed in your privacy policy
  • E-commerce payment processing uses a reputable, PCI-compliant gateway
  • Customer data retention periods are defined and documented
  • There's a way for customers to request access to or deletion of their data (even if it's just an email address)
  • Your business is registered with the Information Regulator (this is a legal requirement, separate from your website)

Getting it sorted

Most of the items on that checklist are straightforward to implement. The privacy policy is the biggest piece of work, and even that is a few hours if you write clearly and know what your business actually does with customer data.

When we build websites for clients, we include a privacy policy page in the site structure and guide them through what it needs to say for their specific business. We can't write the legal content for you - that depends on your business operations - but we can make sure the page exists, is properly linked, and is easy to update.

If your website doesn't have a privacy policy yet, or if the one you have is a copied template from 2019 that doesn't match what your business actually does, now is a good time to sort it out. Not because the Information Regulator is about to knock on your door, but because it's the right thing to do for your customers - and it's easier than you think.

Need help getting your website compliant? Get in touch and we'll walk you through what needs doing.

JP

Johan Pretorius

Johan Pretorius is the founder and lead developer of Moducraft, a Cape Town web studio working with small businesses across the Western Cape. 18 years building for the web.

Want to talk about your project?

Book a 20-minute call. No obligation, no sales pitch.

Book a 20-minute call