Your digital presence is your biggest unmanaged risk
Most South African businesses treat their digital presence as a marketing asset - a brochure that lives online. That framing is dangerously incomplete. Your website, your social profiles, your Google Business listing, and every piece of indexed content about your brand collectively constitute a legal liability surface, a compliance exposure, and a first-impression machine that operates 24 hours a day without supervision.
The seven things brands consistently get wrong
1. Treating the website as a one-time project
A website built in 2021 has outdated dependencies, likely runs on an end-of-life CMS version, and almost certainly lacks POPIA-compliant consent mechanisms that did not exist at that time. The Information Regulator's 2024 enforcement action targeted a company for exactly this kind of accumulated non-compliance - not a single decision, but years of inaction.[1]
2. No one owns the digital risk function
POPIA requires every organisation to designate an Information Officer responsible for compliance. But beyond that legal requirement, someone in the organisation needs to own the broader question: what is our digital presence saying, and what risk does it create? In most SMBs, the answer is no one. Marketing owns the website aesthetically. IT owns it technically. Legal never looks at it.
3. Third-party scripts running without consent
Google Analytics, Meta Pixel, LinkedIn Insight Tag, Hotjar, Intercom - every third-party script on your website processes personal information. Under POPIA, each one requires prior, informed, voluntary, opt-in consent before loading. The Information Regulator's 2024 Guidance Note on Direct Marketing confirmed there is no "soft opt-in" or "legitimate interest" basis for unsolicited tracking in South Africa.[2]
4. Outdated or missing PAIA manual
The Promotion of Access to Information Act requires every private body to publish a manual describing how individuals can request access to records. Most businesses either have no manual, or have one generated years ago that has never been updated. A PAIA manual must be accessible on your website and kept current.
5. SEO built on tactics, not authority
Google's E-E-A-T framework (Experience, Expertise, Authoritativeness, Trustworthiness) now governs how content ranks, particularly in "Your Money or Your Life" categories that include legal, financial, and health services. Thin content, no author attribution, and no citations are not just bad writing - they are ranking signals that actively suppress visibility.[3]
6. Not showing up in AI-generated answers
Google AI Overviews, Perplexity, ChatGPT, and Claude now answer questions directly - and they draw from structured, authoritative web content to do it. Businesses without structured content (FAQ schema, article schema, clear entity definition) are invisible in these answers even when they rank in traditional search. This is Generative Engine Optimisation (GEO) and Answer Engine Optimisation (AEO) - and most SA brands have not started.
7. Security treated as IT's problem, not the brand's
A data breach under POPIA is not just a technical incident. The Information Regulator can make findings public - and has done so. The reputational consequence of a public enforcement notice or breach notification sent to your clients is a brand event, not an IT event. POPIA's April 2025 amendments tightened breach reporting: all compromises must now be reported via the Regulator's eServices portal.[4]
What unmanaged digital risk actually costs
| Risk category | Potential consequence | Governing framework |
|---|---|---|
| POPIA non-compliance | Fine up to R10m per infringement | POPIA s. 107 |
| Breach without procedure | Criminal liability; public enforcement notice | POPIA s. 22, April 2025 amendments |
| Outdated CMS/plugins | Site compromise; data exposure | POPIA s. 19 |
| No PAIA manual | Non-compliance; regulatory exposure | PAIA s. 51 |
| AI search invisibility | Lost leads; competitor advantage | Commercial risk |
Frequently asked questions
Is this only a problem for large businesses?
No. POPIA has no size exemption. The Information Regulator's enforcement activity in 2024 included assessments of small and medium businesses. Smaller businesses often have more gaps precisely because they have fewer dedicated resources watching these issues.[5]
Where do I start?
A structured gap audit covering privacy, security, legal compliance, SEO, and AI search readiness gives you a ranked list of what to fix first. The goal is not perfection - it is removing the highest-risk exposures first.