The Protection of Personal Information Act (POPIA) has been fully enforceable since July 2021, yet many South African websites still aren't compliant. Here's what you actually need to do—without the legal jargon.
What POPIA Means for Your Website
If your website collects any personal information—names, email addresses, phone numbers, even IP addresses—you have obligations under POPIA.
Essential Website Requirements
1. Privacy Policy
You need a clear, accessible privacy policy that explains:
- What information you collect
- Why you collect it
- How you use it
- Who you share it with
- How long you keep it
- How people can access or delete their data
This must be written in plain language, not legal speak.
2. Consent Mechanisms
Before collecting personal information, you need explicit consent. This means:
- Unchecked opt-in boxes for marketing communications
- Clear explanations of what people are signing up for
- Cookie consent banners that allow genuine choice
3. Data Security
Your website must use HTTPS (SSL certificate). Forms should be secure. Data should be stored safely. If you have a data breach, you're legally required to notify affected individuals and the Information Regulator.
4. Right to Access and Delete
You need a way for people to request their data or ask for it to be deleted. This could be as simple as a dedicated email address, but you need a process to handle these requests within the legal timeframe.
Getting Compliant
POPIA compliance isn't a once-off checkbox—it's an ongoing practice. But getting the basics right isn't as difficult or expensive as many businesses fear.
BrightSync helps South African businesses build POPIA-compliant websites from the ground up. Need to update an existing site? We can help with that too. Protect your business and your customers.