I’m a design engineer. I design and build websites as one piece of work, not two separate jobs handed between people — which means when a law asks something of a website, I’m the one who has to make it actually happen on the page, not just write about it.
That’s the seat this article comes from. Not a legal reading of POPIA, but a builder’s one: what the law asks, and what it turns into once you sit down to build it. I’m not an attorney, and nothing here is legal advice. Where any of this touches your specific business, a compliance professional is the right person to ask.
Here are five things South African law asks of a business website, each explained the way I’d explain it to a client across a table.
1. A privacy notice that matches what you actually do
Required by law: Yes — POPIA, Section 18.
Why: Your site collects personal details the moment someone fills in a form, or through analytics tools like Google Analytics that track how visitors browse.
Your website collects information about the people who visit it, and the law says you have to tell them so, in plain language. Most privacy policies fail here — not because anyone is being dishonest, but because nobody checked the policy against what the site actually collects.
What it means when I build it
A privacy notice can only be honest if it lists what your site actually collects — and most of that is simpler than it sounds once you go tool by tool. If you have a contact form, it’s probably collecting a name, a surname, an email address, maybe a phone number. That’s personal information. The moment someone fills it in, you need to tell them you have it, and say plainly what you’ll do with it.
It doesn’t stop at forms. If you use Google Analytics to see how many people visit your site, that tool is quietly collecting information too — which pages someone looked at, roughly where they’re browsing from, what device they used. A booking calendar, a live chat bubble, a newsletter signup box — each one is its own little collector, and each usually sends what it gathers off to a different company that built the tool. All of it needs to be listed in the notice, in plain words, not left out because it happens in the background.
The law also asks when someone is told — “before or as soon as reasonably practicable after collection” — which means the notice needs to be easy to find right where the information is being collected, not only buried in the footer four scrolls down.
3. A PAIA manual, published on your website
Required by law: Yes — the Promotion of Access to Information Act. The exemption for smaller companies ended on 31 December 2021; since 2022 there’s no size threshold.
Why: Every private body, from a sole proprietor to a large company, has to be able to show anyone how to formally ask for its records.
If you run a business in South Africa, you need a document that tells people how to request your records — no matter how small the business is.
What it means when I build it
This one is closest to being a plain document, but three things about it are still build decisions. It needs a stable, permanent web address — usually /paia — because that address may get cited in correspondence and shouldn’t move the next time the site gets redesigned. It needs to be reachable without hunting, which the standard footer-link convention handles well. And it should be a real, readable page rather than only a PDF — a PDF is fine to also offer, but a page works on a phone and doesn’t force a download on someone who just wants to check whether it exists.
4. An Information Officer, named and registered
Required by law: Yes — POPIA requires every business to appoint an Information Officer, and that includes responsibility for how the business’s website handles personal information. In a company, that responsibility sits with the person who runs the business by default, unless it’s formally handed to someone else. That person also has to be registered with the Information Regulator.
Why: An Information Officer is simply the named person who’s accountable for how your business collects, stores, and looks after personal information — the person a customer can approach with a question or concern about their own details, and the one making sure the business is actually following the rules day to day.
Someone at your business is legally responsible for how personal information gets handled — and unless you’ve formally delegated it, that person is you.
What it means when I build it
The Information Officer’s name and contact details go into the privacy notice and the PAIA manual — one of the few places on a DigiTusk-style site where naming a real person is actually correct. And the contact channel has to genuinely work: if the privacy notice gives an address for data subject requests, something needs to be watching that inbox. An address that forwards into a dead mailbox is worse than not having one, because it creates a documented obligation with no way to meet it.
5. ECT Act disclosures, if you sell anything online
Required by law: Yes, if you sell goods or services online — Electronic Communications and Transactions Act, Section 43.
Why: If you’re taking money or orders through your site, the law requires you to disclose who you are, the full price with nothing hidden, and to give the buyer a chance to review the order before it’s final.
If your website takes an order, a booking, or a payment, a separate law kicks in on top of POPIA — and it’s the one most businesses miss, because it isn’t in POPIA at all.
What it means when I build it
Two parts, and only one is a static page. The disclosures themselves — registration number, physical address, a full price with no last-step additions — belong on a terms page and in a properly complete footer. The second part is a flow, not a page: before an order is finally placed, the customer needs a review step showing the whole order, a way to fix mistakes, and a way to back out that isn’t the browser’s back button. Leave that step out, and a customer can cancel the transaction within 14 days of receiving the goods or services — a real commercial risk hiding inside a checkout design decision.
Why this is worth building in, not bolting on
The Information Regulator’s posture has hardened. Its recent enforcement planning names direct marketing and data breach management as priorities, and fines have already landed — R5,000,000 against the Department of Justice, R5,000,000 against the Department of Basic Education, R100,000 against Lancet Laboratories, R100,000 against FT Rams Consulting. The maximum administrative fine under POPIA is R10,000,000, and there’s no blanket exemption for small businesses — size may affect the remedy, not whether the obligation applies.
But the sharper reason, from where I sit, isn’t the fine. It’s that every one of these five things is cheap to build in at the start and expensive to add later. Added after the fact, they mean reopening the parts of a site that are hardest to touch safely.
Compliance isn’t a page you add to a website. It’s a set of behaviours the website performs. Building it that way is simply cheaper.
Next in this series: what POPIA asks of a booking form when the person booking is a patient — and why a health practitioner’s intake form carries obligations a restaurant’s booking never does.
If you’re not sure what your own site currently collects, that’s a short piece of work worth doing regardless of what you decide next. Get in touch and I’ll have a look.
Sources and further reading
- POPIA — Section 26: Prohibition on processing of special personal information
- Information Regulator — Guidance Note on Processing of Special Personal Information
- Mayet & Associates — POPIA enforcement in South Africa: key 2026 developments
- ClearComply — POPIA Information Officer registration
- ClearComply — PAIA annual report 2026 submission window
- Bass Gordon — PAIA manuals compulsory for all public and private bodies
- Barter McKellar — The role of the Electronic Communications and Transactions Act
- Werksmans — Privacy Day 2026: moving beyond the consent myth under POPIA