Sensitive by default — part one

Five legal requirements every South African website must have

A builder’s reading of what South African law asks of a business website — five obligations explained the way I’d explain them to a client across a table.

I’m a design engineer. I design and build websites as one piece of work, not two separate jobs handed between people — which means when a law asks something of a website, I’m the one who has to make it actually happen on the page, not just write about it.

That’s the seat this article comes from. Not a legal reading of POPIA, but a builder’s one: what the law asks, and what it turns into once you sit down to build it. I’m not an attorney, and nothing here is legal advice. Where any of this touches your specific business, a compliance professional is the right person to ask.

Here are five things South African law asks of a business website, each explained the way I’d explain it to a client across a table.

1. A privacy notice that matches what you actually do

Your website collects information about the people who visit it, and the law says you have to tell them so, in plain language. Most privacy policies fail here — not because anyone is being dishonest, but because nobody checked the policy against what the site actually collects.

What it means when I build it

A privacy notice can only be honest if it lists what your site actually collects — and most of that is simpler than it sounds once you go tool by tool. If you have a contact form, it’s probably collecting a name, a surname, an email address, maybe a phone number. That’s personal information. The moment someone fills it in, you need to tell them you have it, and say plainly what you’ll do with it.

It doesn’t stop at forms. If you use Google Analytics to see how many people visit your site, that tool is quietly collecting information too — which pages someone looked at, roughly where they’re browsing from, what device they used. A booking calendar, a live chat bubble, a newsletter signup box — each one is its own little collector, and each usually sends what it gathers off to a different company that built the tool. All of it needs to be listed in the notice, in plain words, not left out because it happens in the background.

The law also asks when someone is told — “before or as soon as reasonably practicable after collection” — which means the notice needs to be easy to find right where the information is being collected, not only buried in the footer four scrolls down.

2. Cookie consent that actually holds the door

Most cookie banners on South African sites are decoration — they appear, but nothing was ever actually blocked. If your analytics script was already running before someone clicked “Accept,” you didn’t get consent. You got a formality.

What it means when I build it

For the banner to do what it claims, the scripts have to be genuinely held back until a choice is made — kept out of the page entirely, not loaded and then asked to behave. That’s a decision about script-loading order, and no banner fixes it after the fact.

Three things follow from consent having to be real, not decorative. Refusing has to be as easy as accepting — if “Accept all” is one click and refusing takes three clicks through a settings panel, the choice was shaped, not offered. No box comes pre-ticked. And withdrawing consent has to actually work — a reachable way to change your mind, and a site that responds by genuinely switching those cookies off.

Cookies that are strictly necessary — the session that keeps someone logged in, the token that stops a form being forged — don’t need consent. Analytics almost always does. There’s also a way to sidestep the whole question: cookieless analytics. If the measurement tool doesn’t set identifying cookies, the consent problem often disappears rather than needing to be managed.

3. A PAIA manual, published on your website

If you run a business in South Africa, you need a document that tells people how to request your records — no matter how small the business is.

What it means when I build it

This one is closest to being a plain document, but three things about it are still build decisions. It needs a stable, permanent web address — usually /paia — because that address may get cited in correspondence and shouldn’t move the next time the site gets redesigned. It needs to be reachable without hunting, which the standard footer-link convention handles well. And it should be a real, readable page rather than only a PDF — a PDF is fine to also offer, but a page works on a phone and doesn’t force a download on someone who just wants to check whether it exists.

4. An Information Officer, named and registered

Someone at your business is legally responsible for how personal information gets handled — and unless you’ve formally delegated it, that person is you.

What it means when I build it

The Information Officer’s name and contact details go into the privacy notice and the PAIA manual — one of the few places on a DigiTusk-style site where naming a real person is actually correct. And the contact channel has to genuinely work: if the privacy notice gives an address for data subject requests, something needs to be watching that inbox. An address that forwards into a dead mailbox is worse than not having one, because it creates a documented obligation with no way to meet it.

5. ECT Act disclosures, if you sell anything online

If your website takes an order, a booking, or a payment, a separate law kicks in on top of POPIA — and it’s the one most businesses miss, because it isn’t in POPIA at all.

What it means when I build it

Two parts, and only one is a static page. The disclosures themselves — registration number, physical address, a full price with no last-step additions — belong on a terms page and in a properly complete footer. The second part is a flow, not a page: before an order is finally placed, the customer needs a review step showing the whole order, a way to fix mistakes, and a way to back out that isn’t the browser’s back button. Leave that step out, and a customer can cancel the transaction within 14 days of receiving the goods or services — a real commercial risk hiding inside a checkout design decision.

Why this is worth building in, not bolting on

The Information Regulator’s posture has hardened. Its recent enforcement planning names direct marketing and data breach management as priorities, and fines have already landed — R5,000,000 against the Department of Justice, R5,000,000 against the Department of Basic Education, R100,000 against Lancet Laboratories, R100,000 against FT Rams Consulting. The maximum administrative fine under POPIA is R10,000,000, and there’s no blanket exemption for small businesses — size may affect the remedy, not whether the obligation applies.

But the sharper reason, from where I sit, isn’t the fine. It’s that every one of these five things is cheap to build in at the start and expensive to add later. Added after the fact, they mean reopening the parts of a site that are hardest to touch safely.

Compliance isn’t a page you add to a website. It’s a set of behaviours the website performs. Building it that way is simply cheaper.

Next in this series: what POPIA asks of a booking form when the person booking is a patient — and why a health practitioner’s intake form carries obligations a restaurant’s booking never does.

If you’re not sure what your own site currently collects, that’s a short piece of work worth doing regardless of what you decide next. Get in touch and I’ll have a look.

Sources and further reading

Not sure what your site currently collects? Get in touch and I’ll have a look.