The Digital Doctor

POPIA and your website, without a lawyer

If your website has a contact form, POPIA applies to you. What it asks of an ordinary small business site is narrower than the reputation of the Act suggests: say what you collect and why, ask before you load anything that tracks people, and be able to answer someone who asks what you hold about them.

This is a plain-English summary of what I see on client sites, not legal advice. Where real money or real risk is involved, an attorney is worth what they charge.

The four things that actually matter

A privacy policy that describes your site. What you collect, why you collect it, how long you keep it, and who else sees it. The most common failure is not the absence of a policy but a copied one describing a business that isn’t yours, mentioning a mobile app you do not have, or naming a company in another country. A policy that does not match the website is evidence you did not read it.

Consent before anything non-essential loads. Analytics, advertising pixels, embedded video that tracks. The test is whether the site works without it. A session cookie that keeps someone logged in is necessary; Google Analytics is not.

A reason for each thing you collect. If your contact form asks for an identity number, be able to say why. Most forms ask for more than they need out of habit, and every extra field is something you now have to protect and justify.

A way to ask. Someone must be able to find out what you hold about them and ask for it to be deleted. For a small business this is an email address that is monitored, named in the privacy policy. It does not require a portal.

The cookie banner most sites get wrong

The common version sets every cookie the moment the page loads, then shows a bar with an Accept button and no way to decline. That is not consent, it is a notification that something has already happened. If yours works that way, it is arguably worse than having no banner, because it demonstrates you knew the obligation existed.

What it should do: load nothing beyond what the site needs to function, ask, and only then load analytics or advertising if the answer was yes. Declining must be as easy as accepting.

You are the Information Officer

Not a role you appoint, one you already hold, as the owner. Registration with the Information Regulator is free and done online, and being registered is the difference between a complaint that gets handled and one that escalates because there was nobody to send it to.

If you are breached

This is the part worth reading before you need it. If personal information is accessed without authorisation, a hacked website, a compromised mailbox, section 22 requires you to notify the Information Regulator and the people affected as soon as reasonably possible.

That duty is yours. Not your developer’s, not your hosting company’s, not the person who cleans up the mess. What they owe you is a clear written account of what was and was not reachable, because your notification is built on it. Anyone who cleans a hacked site for you and does not raise this has left you carrying something they knew about.

Practically: write down what happened and when you learned of it, what information was involved, what you have done, and what the affected people should do. That document is both your notification and your evidence that you acted.

What this costs

A privacy policy written for your actual site and a consent banner that behaves properly is a small job, I charge R1,250, and a decent developer will be in the same range. Registering as Information Officer is free. Neither is a subscription.

What I would not spend money on: a compliance package sold on the strength of the R10 million figure. The realistic risk to a small business is not the maximum penalty. It is a complaint from one annoyed customer, handled badly because nobody had thought about it beforehand.

See where your site stands

The free check looks at your privacy and consent setup along with nine other things, instantly, with no sign up.

Run the free check