15 requirements, one checklist
LPC conduct rules and POPIA obligations get treated as two separate problems - legal marketing sign-off for one, an IT ticket for the other. In practice they overlap on the same pages: your homepage, your team bios, your contact form, and your footer. This checklist merges both into a single pass so you can audit your site once instead of twice.[1]
LPC conduct rules (publicity, rule 7)
| # | Requirement | Common failure |
|---|---|---|
| 1 | No claim of specialisation without LPC Council recognition | "Specialist family law attorneys" in the hero heading |
| 2 | No comparison with or disparagement of other practitioners | "Better than the rest" copy on service pages |
| 3 | No client named without prior written consent | Testimonials with full names and no consent record |
| 4 | Nothing that could bring the profession into disrepute | Aggressive guarantees of case outcomes |
| 5 | Fee statements must be accurate and not misleading | "From R500" pricing with no basis or conditions shown |
| 6 | Practitioner and firm details match LPC registration | Trading names not matching the registered firm name |
POPIA controls (ss. 19–24)
| # | Requirement | Common failure |
|---|---|---|
| 7 | Prior, opt-in consent before any tracking script loads | Google Analytics/Meta Pixel firing before consent banner is actioned |
| 8 | Privacy policy naming the Information Officer | No policy, or a generic template with no IO named |
| 9 | Published PAIA manual | Missing entirely, or last updated pre-2021 |
| 10 | Written operator agreements with hosting/CRM/email providers | Standard ToS treated as sufficient |
| 11 | SSL/TLS applied sitewide, not just on forms | Mixed-content warnings on secondary pages |
| 12 | Documented breach procedure with eServices portal access | No written procedure; no one has portal credentials |
| 13 | Contact/intake forms state processing purpose | Forms collect data with no purpose statement |
| 14 | Retention schedule for client and lead data | No defined retention period - data kept indefinitely |
| 15 | Data subject rights process (access, correction, deletion) | No published process for a data subject to exercise these rights |
Frequently asked questions
Do I need to fix all 15 before I'm "compliant"?
There's no single compliance certificate to earn. What matters is that you can show a documented, good-faith process addressing each item, with the highest-risk gaps (consent, breach procedure, IO designation) closed first. A gap audit ranks these for you rather than treating all 15 as equally urgent.
Who is responsible if my website was built by an agency?
You are. The agency is an operator at build time; once the site is live under your control, the compliance obligation - both LPC and POPIA - sits with the firm, not the agency.