POPIA Compliance for Your Website

POPIA Compliance: What Your Website or App Needs to Do

If your organisation processes personal information in South Africa, the Protection of Personal Information Act 4 of 2013 (POPIA) will usually apply. It is South Africa's data-protection law and governs how responsible parties collect, store, use, secure, disclose, and delete personal information.

The good news: most of what POPIA requires is straightforward, and Dev3 Studio builds these protections into every project as standard.

Important: This article is a practical overview, not legal advice. For legal compliance questions specific to your business, consult a qualified attorney.

Live POPIA guidance page from South Africa's Information Regulator
The Information Regulator's current POPIA page is the primary reference for official guidance, forms, complaints, and security-compromise reporting.

What Counts as Personal Information?

POPIA's definition of personal information is broader than many people expect and includes information relating to an identifiable living person and, where applicable, an identifiable existing juristic person. Examples include:

  • Names, email addresses, and phone numbers
  • Physical addresses
  • ID numbers and passport numbers
  • Financial information (bank details, payment history)
  • Online identifiers (IP addresses, cookies, device IDs)
  • Employment history
  • Biometric data (fingerprints, facial recognition)
  • Even opinions and preferences in some cases

The simple test: if it can identify a person, directly or indirectly, it's personal information under POPIA.

The 8 Conditions for Lawful Processing

Chapter 3 of POPIA sets out eight conditions for lawful processing:

  1. Accountability — Your business is responsible for all the personal data it handles.
  2. Processing limitation — Only collect what you actually need.
  3. Purpose specification — Tell people why you're collecting their data, and stick to that purpose.
  4. Further processing limitation — Don't use data for something the person didn't agree to.
  5. Information quality — Keep data accurate and up to date.
  6. Openness — Be transparent. This is where your privacy policy comes in.
  7. Security safeguards — Protect the data you hold with appropriate measures.
  8. Data subject participation — People can ask what data you hold on them and request corrections or deletion.

These sound formal, but most translate into practical steps that Dev3 Studio can help you implement.

What Your Website or App Actually Needs

Here's the practical checklist — the things your digital products should have in place.

A Privacy Policy

When you collect personal information, section 18 of POPIA generally requires you to notify the person about the collection and its purpose, subject to the Act's exceptions. A clear, easy-to-find privacy notice is the practical way to explain what you collect, why you collect it, how long you keep it, who receives it, and how people can exercise their rights. Dev3 Studio can help implement the notice, but a qualified legal professional should review its substance.

Live Dev3 Studio privacy policy page
Dev3 Studio's real, publicly accessible privacy notice. Its content is specific to Dev3 Studio and should not be copied as a legal template for another business.

Cookie Consent

POPIA does not create one blanket rule that every non-essential cookie always needs the same banner. The correct approach depends on what the cookie does, what information it collects, your lawful basis, and whether it supports direct marketing. In practice, a consent tool that blocks optional analytics and advertising cookies until the visitor makes a choice is a clear, defensible pattern. Your legal adviser should confirm the categories and wording for your product.

Live Google privacy policy page
Google's public privacy notice is an example of layered, web-accessible disclosure. Your notice and consent controls must reflect your own processing.
Live Google Safety Center page explaining privacy controls
Google's real privacy-controls reference. Give users meaningful controls appropriate to the data and technologies your own site uses.

Consent for Marketing

For unsolicited electronic direct marketing, section 69 and the Information Regulator's direct-marketing guidance generally require consent unless the limited existing-customer exception applies. Use a clear, unticked opt-in, keep evidence of consent, identify the sender, and provide a straightforward way to opt out of every message.

Mailchimp documentation explaining double opt-in
Mailchimp's live double-opt-in guide illustrates an auditable email-confirmation pattern. Confirm the lawful basis and wording for your own campaign.

Secure Forms

Section 19 requires appropriate, reasonable technical and organisational safeguards. For web forms, HTTPS is a baseline control for protecting information in transit, alongside access control, secure storage, retention limits, logging, and appropriate handling behind the form.

Live Dev3 Studio contact page
Dev3 Studio's real contact form. Tell people what information is required, why it is collected, and how it will be handled; use consent only where consent is the appropriate basis.

Data Minimisation

Only collect what you actually need. If you don't need someone's date of birth, don't ask for it. Every field on a form should have a reason. Fewer fields also means better conversion rates — so this is good for business too.

Account Deletion and Data Removal

Section 24 lets data subjects request correction or deletion in specified circumstances, subject to lawful retention duties and other exceptions. Your product should provide a documented request process. Separately, Apple requires apps that support account creation to let users initiate account deletion, and Google Play requires both an in-app path and an external web resource for covered apps.

Google Account Help page explaining how to delete an account
Google's current account-deletion help is a real example of documenting a consequential data-control action and its effects.
Google Account Help page explaining how to download account data
Google's current data-export help illustrates a documented way for users to obtain a copy of account data.

Data Breach Procedures

Section 22 requires notification to the Information Regulator and affected data subjects when there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, subject to the timing and law-enforcement provisions in the Act. Have an incident-response plan before this happens.

Information Regulator fact sheet on handling security compromises
The Information Regulator's current fact sheet on security compromises—not a mock email—sets out official reporting and notification guidance.

Third-Party Services

If you use analytics, payment gateways, email platforms, or CRM tools, those providers may process personal information for you. Sections 20 and 21 require operators to process with your authority and require a written contract establishing appropriate security measures. Your privacy notice should accurately describe relevant recipients and cross-border transfers, and your team should review each provider's terms and safeguards.

Information Regulator page listing official POPIA forms
The Regulator's live POPIA forms page includes the prescribed objection, correction or deletion, complaint, consent, and security-compromise forms.

Common Mistakes Businesses Make

These come up regularly — check whether any apply to you:

  • No privacy policy at all (more common than you'd think)
  • Collecting data "just in case" instead of for a specific purpose
  • Pre-ticked marketing consent checkboxes
  • Storing personal data in unencrypted spreadsheets or shared drives
  • No process for handling data access or deletion requests
  • Using personal WhatsApp or Gmail to handle customer data
  • Assuming POPIA only applies to big companies (it applies to all businesses, regardless of size)

The Information Regulator

The Information Regulator is the independent authority responsible for enforcing POPIA in South Africa. The Act provides for investigations, enforcement notices, administrative fines of up to R10 million, and criminal penalties for specified offences. The exact consequence depends on the contravention and enforcement process.

Getting Started

If your business doesn't have a privacy policy, cookie consent, or data handling procedures yet, start there. Dev3 Studio can help you audit your current website or app and identify what needs to change. It's usually less work than people expect.

POPIA compliance doesn't have to be overwhelming. Most of the technical requirements — secure connections, cookie consent, proper data handling — are things Dev3 Studio builds into every project as standard. For the legal side, we recommend working with a qualified attorney to make sure your privacy policy and data practices are specific to your business. We're always here to handle the technical implementation.