The stakes: Under POPIA, the Information Regulator can impose administrative fines of up to R10 million per violation. Criminal penalties include fines and imprisonment. Non-compliance is not a "small business exemption" situation — the Act applies to any organisation that processes personal information, regardless of size.

Who Needs to Be POPIA Compliant?

Any South African business or individual that collects, stores, uses, or shares personal information. If your website has any of the following, you are processing personal information under POPIA:

If any of these apply to you, every item below is a legal requirement, not a suggestion.

The Complete POPIA Website Checklist

1. Privacy Policy

2. Consent Collection

3. Information Officer

4. Data Security (Technical Measures)

5. Cookies and Tracking

6. Data Breach Response Plan

7. PAIA Manual (Public Access to Information)

Common Mistakes South African Websites Make

Using a GDPR template as a POPIA policy

GDPR (Europe's privacy law) and POPIA share principles but have different requirements, different authorities, and different enforcement mechanisms. A GDPR template will not satisfy the Information Regulator. POPIA specifically requires reference to your Information Officer and compliance with the Promotion of Access to Information Act — neither of which appears in GDPR templates.

Pre-ticked marketing consent checkboxes

This is explicitly unlawful under POPIA. Consent must be "voluntary, specific, informed, and unambiguous." A pre-ticked box satisfies none of these criteria. The fine for this alone can be substantial — and it's trivially easy for the Regulator to detect.

Storing personal data in shared spreadsheets

If your contact form submissions go to a shared Google Sheet or an email inbox that multiple people can access, you are likely in violation of POPIA's security safeguards requirements. Access must be controlled and logged.

No cookie consent for analytics

Google Analytics sets cookies that track individual users across sessions. This is processing of personal information. Under POPIA, you need consent before setting these cookies — and that consent must come before the cookie fires, not after.

How we can help: ASi Imperium conducts full POPIA website compliance audits. We review your data collection points, your privacy documentation, your technical security measures, and your consent flows — then provide a written remediation report with prioritised action items. Learn about our POPIA audit service →

Not sure if your website is POPIA compliant?

Book a free 30-minute website compliance review. We'll flag the critical gaps before the Information Regulator does.