POPIA Compliance: What Your Website or App Needs to Do
If your organisation processes personal information in South Africa, the Protection of Personal Information Act 4 of 2013 (POPIA) will usually apply. It is South Africa's data-protection law and governs how responsible parties collect, store, use, secure, disclose, and delete personal information.
The good news: most of what POPIA requires is straightforward, and Dev3 Studio builds these protections into every project as standard.
Important: This article is a practical overview, not legal advice. For legal compliance questions specific to your business, consult a qualified attorney.

What Counts as Personal Information?
POPIA's definition of personal information is broader than many people expect and includes information relating to an identifiable living person and, where applicable, an identifiable existing juristic person. Examples include:
- Names, email addresses, and phone numbers
- Physical addresses
- ID numbers and passport numbers
- Financial information (bank details, payment history)
- Online identifiers (IP addresses, cookies, device IDs)
- Employment history
- Biometric data (fingerprints, facial recognition)
- Even opinions and preferences in some cases
The simple test: if it can identify a person, directly or indirectly, it's personal information under POPIA.
The 8 Conditions for Lawful Processing
Chapter 3 of POPIA sets out eight conditions for lawful processing:
- Accountability — Your business is responsible for all the personal data it handles.
- Processing limitation — Only collect what you actually need.
- Purpose specification — Tell people why you're collecting their data, and stick to that purpose.
- Further processing limitation — Don't use data for something the person didn't agree to.
- Information quality — Keep data accurate and up to date.
- Openness — Be transparent. This is where your privacy policy comes in.
- Security safeguards — Protect the data you hold with appropriate measures.
- Data subject participation — People can ask what data you hold on them and request corrections or deletion.
These sound formal, but most translate into practical steps that Dev3 Studio can help you implement.
What Your Website or App Actually Needs
Here's the practical checklist — the things your digital products should have in place.
A Privacy Policy
When you collect personal information, section 18 of POPIA generally requires you to notify the person about the collection and its purpose, subject to the Act's exceptions. A clear, easy-to-find privacy notice is the practical way to explain what you collect, why you collect it, how long you keep it, who receives it, and how people can exercise their rights. Dev3 Studio can help implement the notice, but a qualified legal professional should review its substance.

Cookie Consent
POPIA does not create one blanket rule that every non-essential cookie always needs the same banner. The correct approach depends on what the cookie does, what information it collects, your lawful basis, and whether it supports direct marketing. In practice, a consent tool that blocks optional analytics and advertising cookies until the visitor makes a choice is a clear, defensible pattern. Your legal adviser should confirm the categories and wording for your product.


Consent for Marketing
For unsolicited electronic direct marketing, section 69 and the Information Regulator's direct-marketing guidance generally require consent unless the limited existing-customer exception applies. Use a clear, unticked opt-in, keep evidence of consent, identify the sender, and provide a straightforward way to opt out of every message.

Secure Forms
Section 19 requires appropriate, reasonable technical and organisational safeguards. For web forms, HTTPS is a baseline control for protecting information in transit, alongside access control, secure storage, retention limits, logging, and appropriate handling behind the form.

Data Minimisation
Only collect what you actually need. If you don't need someone's date of birth, don't ask for it. Every field on a form should have a reason. Fewer fields also means better conversion rates — so this is good for business too.
Account Deletion and Data Removal
Section 24 lets data subjects request correction or deletion in specified circumstances, subject to lawful retention duties and other exceptions. Your product should provide a documented request process. Separately, Apple requires apps that support account creation to let users initiate account deletion, and Google Play requires both an in-app path and an external web resource for covered apps.


Data Breach Procedures
Section 22 requires notification to the Information Regulator and affected data subjects when there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, subject to the timing and law-enforcement provisions in the Act. Have an incident-response plan before this happens.

Third-Party Services
If you use analytics, payment gateways, email platforms, or CRM tools, those providers may process personal information for you. Sections 20 and 21 require operators to process with your authority and require a written contract establishing appropriate security measures. Your privacy notice should accurately describe relevant recipients and cross-border transfers, and your team should review each provider's terms and safeguards.

Common Mistakes Businesses Make
These come up regularly — check whether any apply to you:
- No privacy policy at all (more common than you'd think)
- Collecting data "just in case" instead of for a specific purpose
- Pre-ticked marketing consent checkboxes
- Storing personal data in unencrypted spreadsheets or shared drives
- No process for handling data access or deletion requests
- Using personal WhatsApp or Gmail to handle customer data
- Assuming POPIA only applies to big companies (it applies to all businesses, regardless of size)
The Information Regulator
The Information Regulator is the independent authority responsible for enforcing POPIA in South Africa. The Act provides for investigations, enforcement notices, administrative fines of up to R10 million, and criminal penalties for specified offences. The exact consequence depends on the contravention and enforcement process.
Getting Started
If your business doesn't have a privacy policy, cookie consent, or data handling procedures yet, start there. Dev3 Studio can help you audit your current website or app and identify what needs to change. It's usually less work than people expect.
POPIA compliance doesn't have to be overwhelming. Most of the technical requirements — secure connections, cookie consent, proper data handling — are things Dev3 Studio builds into every project as standard. For the legal side, we recommend working with a qualified attorney to make sure your privacy policy and data practices are specific to your business. We're always here to handle the technical implementation.