If your website has a contact form, an enquiry form, a newsletter signup or a booking system, POPIA almost certainly applies to you. Most South African business owners know the name but not what it actually requires day to day — here's the practical version, focused on what a normal small-business website needs to get right.
What POPIA is, briefly
The Protection of Personal Information Act is South Africa's data protection law. It's been fully in effect since 1 July 2021, and it's enforced by the Information Regulator. It applies to any "responsible party" — which includes almost any business — that processes personal information of people in South Africa. "Processing" is defined broadly: collecting, storing, using or even just holding someone's name and email counts.
Does it apply to your website?
If your site collects a visitor's name, email, phone number or any other personal detail through a form — including a simple "send us a message" box — you are processing personal information, and POPIA applies. There's no small-business exemption that lets you ignore it; the obligations scale with risk, but they don't disappear.
What a normal business website actually needs
1. A real privacy notice
Not a copy-pasted template from an unrelated business — a privacy notice (often combined with a PAIA manual reference) that actually describes what your site collects, why, how long you keep it, and who it might be shared with (your hosting provider, an email tool, a CRM). It should be linked from your footer and from every form.
2. Clear consent wording on every form
Each form that collects personal information should make clear what it will be used for, and — where you're not relying on another lawful basis like a contract — get the visitor's consent. A single unlabelled "Submit" button with no context isn't enough. A short line like "By submitting this form, you agree to be contacted about your enquiry" next to the submit button is the minimum, tied to what your privacy notice actually says.
3. An appointed Information Officer
4. Rules around direct marketing
If you want to email or SMS your website's visitors with marketing — not just reply to their enquiry — POPIA's direct marketing rules (section 69) require opt-in consent for unsolicited electronic communications to individuals, with a narrow exception for your own existing customers marketing similar products. A newsletter signup checkbox that's pre-ticked, or bundled silently into your contact form, doesn't meet this bar.
5. Where your data actually lives
POPIA places conditions on transferring personal information outside South Africa. If your form submissions go to an email platform, CRM or analytics tool hosted overseas, that's worth knowing and disclosing in your privacy notice — it doesn't mean you can't use these tools, but it does mean being upfront about it.
6. What happens if something goes wrong
If personal information you hold is compromised — a breach, a leaked database, an exposed form submissions file — POPIA requires notifying the Information Regulator and the affected individuals as soon as reasonably possible. This is part of why basic security (SSL, a properly secured hosting account, not emailing form submissions in plain text to a shared inbox) isn't optional hygiene, it's a compliance factor.
Common mistakes we see
- A privacy policy page exists, but it was copied from a template and doesn't describe what the site actually collects
- Forms collect information with no consent wording at all
- No Information Officer has ever been appointed or registered
- A newsletter checkbox is pre-ticked by default
- Form submissions are emailed in plain text with no thought given to who else can see that inbox
A practical starting checklist
- Appoint an Information Officer (usually the business owner by default) and register them with the Information Regulator
- Write a privacy notice that actually describes your real data practices, not a generic template
- Add clear, specific consent wording to every form that collects personal information
- Make newsletter/marketing opt-in genuinely opt-in — never pre-ticked
- Know where your form submissions go, and who can access them
- Confirm your site runs on SSL (https) everywhere
- Have your privacy policy reviewed by a legal professional before you rely on it