If you run a business in South Africa with a website that collects any information from visitors — even something as simple as a contact form — POPIA applies to you. Here’s what it means in plain language and what you need to do to make sure your website is compliant.
What Is POPIA?
POPIA stands for the Protection of Personal Information Act — South Africa’s primary data protection law. It came into full effect on 1 July 2021 and governs how businesses collect, store, use, and share personal information belonging to individuals.
Personal information under POPIA includes anything that can identify a person: names, email addresses, phone numbers, physical addresses, ID numbers, and even IP addresses or browsing behaviour tracked on your website.
How Does POPIA Affect Your Website?
If your website does any of the following, POPIA applies directly to how you handle that activity:
- Has a contact form where visitors submit their name, email, or phone number.
- Uses Google Analytics or similar tools that track visitor behaviour.
- Sends marketing emails or newsletters to subscribers.
- Has an e-commerce function where customers submit personal and payment details.
- Uses cookies that collect or store information about visitors.
What POPIA Requires From Your Website
Your website must have a Privacy Policy that clearly explains what personal information you collect, why you collect it, how you store and protect it, how long you keep it, and whether you share it with any third parties. This must be easily accessible — typically linked in the footer of every page.
You must obtain clear consent before collecting personal information. On a contact form, this means including a tick box or clear statement indicating that the person agrees to their information being used to respond to their enquiry. Pre-ticked boxes do not constitute valid consent under POPIA.
If your website uses cookies — and most WordPress websites do, through analytics or contact form plugins — you need a cookie notice that informs visitors of this and, where legally required, asks for their consent.
You are responsible for taking reasonable steps to protect the personal information you collect from loss, damage, or unauthorised access. This includes using secure hosting, maintaining an SSL certificate (HTTPS), keeping your website software updated, and not storing sensitive information unnecessarily.
Individuals have the right to request access to the information you hold about them, request corrections, or request deletion. Your Privacy Policy should explain how people can exercise these rights.
The Consequences of Non-Compliance
POPIA is enforced by the Information Regulator of South Africa. Penalties for non-compliance can include fines of up to R10 million and, in serious cases, imprisonment. Beyond the legal penalties, a data breach or privacy complaint can cause significant reputational damage — particularly for small businesses where trust is central to the customer relationship.
Practical Steps to Make Your Website POPIA-Compliant
- Add a Privacy Policy page to your website and link to it in the footer.
- Add a consent statement or tick box to every contact form.
- Install a cookie consent notice.
- Ensure your website has a valid SSL certificate (HTTPS).
- Keep your WordPress, theme, and plugins updated for security.
- Review what personal information you collect and delete anything you no longer need.
Final Thoughts
POPIA compliance doesn’t need to be complicated or expensive for most small business websites. The key steps — a clear Privacy Policy, a consent mechanism on your forms, and a cookie notice — can be implemented relatively quickly and give you a solid foundation for compliance.
At Webling Web Design, we build POPIA-compliant websites for businesses across Nelspruit and Mpumalanga, including Privacy Policies, consent forms, and cookie notices as standard. Get in touch for a free, no-obligation quote.



