What most SA law firm websites get wrong - and why it matters
South African law firm websites fail on three fronts simultaneously: they breach the Legal Practice Council's Code of Conduct on advertising, they expose the firm to POPIA enforcement action, and they convert poorly because they lack the trust signals prospective clients now expect. Most firms are unaware of all three problems at once.
What does the LPC Code of Conduct say about law firm websites?
The Legal Practice Act 28 of 2014 and the LPC's Code of Conduct govern how attorneys advertise and publicise their services. "Publicity" is defined broadly to include any reference to a legal practitioner or firm published or disseminated "in any medium (including electronic and social media)."[1]
Under rule 7.2 of the Code, all publicity must:
- Not bring the legal profession into disrepute
- Not misrepresent the nature of the service offered
- Not disparage, compare with, or claim to be superior to another legal practitioner
- Not refer to a client by name without their prior written consent
- Not claim specialist status unless the LPC Council has formally granted that recognition
These responsibilities cannot be delegated. If your marketing agency publishes non-compliant content on your website, the obligation to rectify it remains yours.[2]
The specialist claims trap
Phrases like "specialist family law attorneys," "expert commercial litigators," or "South Africa's leading property law firm" are common on law firm websites. Most are non-compliant. Claiming specialisation or expertise in any branch of the law requires formal recognition by the LPC Council under rule 8.1. Publishing these claims without that recognition is a conduct breach.
Client testimonials and case results
Publishing a client's name - even with their verbal permission - without their prior written consent is a Code breach. Many firms publish testimonials freely without any documented consent process. Case results such as "won R2.4m in damages for our client" are permissible only where the client cannot be identified, or has given explicit written consent to that specific publication.
What does POPIA require from a law firm website?
POPIA has been in full force since 1 July 2021. The Information Regulator issued its first enforcement notice in February 2024, and confirmed in its 2025/2026 plans that enforcement is a top priority. Fines reach R10 million. Law firms are not exempt - the Regulator conducted over 30 compliance assessments in 2024, including assessments of law firms specifically.[3]
The five POPIA gaps most law firm websites have
- No POPIA-compliant privacy policy. A generic template does not satisfy POPIA's openness requirement (ss. 17–18). The policy must identify your Information Officer by name and contact details, specify exactly what data you collect and why, list third-party recipients, and state how data subjects can exercise their rights.
- No cookie consent mechanism. If your website uses Google Analytics, Facebook Pixel, or any third-party tracking, you need informed, voluntary, opt-in consent before those scripts load. Pre-ticked boxes are non-compliant. The Information Regulator's 2024 Guidance Note on Direct Marketing confirmed there is no soft opt-in under South African law.[4]
- Information Officer not registered. Every organisation must appoint and register an Information Officer on the Regulator's eServices portal. For most firms, the managing partner is the default IO. The April 2025 amendments significantly expanded IO obligations - this is no longer a paper appointment.[5]
- No PAIA manual. The Promotion of Access to Information Act requires organisations to publish a PAIA manual describing how to request access to records. This must be accessible on your website.
- Bundled consent on contact forms. If your enquiry form signs users up for a newsletter in the same action as submitting a query, that consent is invalid. Marketing consent must be separate, unticked, and genuinely optional.[6]
The security obligations attorneys overlook
POPIA's security safeguard condition (s. 19) requires "appropriate, reasonable technical and organisational measures" to protect personal information. For law firms - which hold highly sensitive client data - the bar is higher than for most businesses. The LPC's own Rules also require that all processed information be handled with information security "appropriate, having regard to the nature of the information and the purpose for which it is processed."[7]
At minimum, a law firm website must have:
- A valid SSL/TLS certificate (HTTPS on every page, not just the contact form)
- Up-to-date CMS and plugin versions - outdated WordPress installations are the most common attack vector
- A documented, tested data breach response procedure - the April 2025 amendments require breaches to be reported via the Regulator's eServices portal
- Written operator agreements with all third-party processors: your hosting provider, email platform, CRM
The compliance checklist for SA law firm websites
| Area | Requirement | Governing rule |
|---|---|---|
| Advertising | No specialist claims without LPC recognition | LPC Code rr. 7.2, 8.1 |
| Advertising | No client names without prior written consent | LPC Code r. 7.2.6 |
| Privacy | POPIA-compliant privacy policy in footer | POPIA ss. 17–18 |
| Privacy | Cookie consent before non-essential scripts | POPIA s. 11, IR Guidance Note 2024 |
| Privacy | Information Officer appointed and registered | POPIA s. 55 |
| Privacy | Separate, unticked marketing consent | POPIA s. 69 |
| Access to info | PAIA manual accessible on website | PAIA s. 51 |
| Security | HTTPS / valid SSL certificate sitewide | POPIA s. 19; LPC Rules r. 2.29 |
| Security | Breach notification procedure documented | POPIA s. 22, April 2025 amendments |
| Security | Written operator agreements with processors | POPIA s. 21 |
Frequently asked questions
Does POPIA apply to small law firms?
Yes. There is no SME exemption under POPIA. Any firm that processes personal information - client names, contact details, matter instructions - is a responsible party subject to the full Act. Size affects proportionality of technical measures, not whether the obligations apply.[8]
Can I use a standard privacy policy template?
A template is a starting point, not a final document. POPIA requires your policy to reflect your actual processing activities - the specific data you collect, the specific third parties you share it with, and the name of your Information Officer. A template that does not reflect these specifics does not satisfy the Act's openness requirement.
What happens if the Information Regulator investigates a law firm?
The Regulator can issue an enforcement notice, require remedial action, and impose administrative fines of up to R10 million per infringement. The April 2025 amendments allow fines to be paid in instalments, but do not reduce their maximum amount. Non-compliance can also result in criminal prosecution.[9]
References
- Legal Practice Act: Code of Conduct for Legal Practitioners - Acts Online
- Rules and Regulations - Legal Practice Council
- POPIA South Africa: Data Protection Law Guide - Kukie.io (2026)
- POPIA Website Compliance in South Africa Without Killing Conversions - Vertopia (2025)
- Amendments to the POPIA Regulations: Key Changes - Lexology / Baker McKenzie (May 2025)
- 2025 POPIA Checklist for SA Business Websites - Coolhost (July 2025)
- Rules for the Attorneys' Profession, Government Gazette 39740 - Department of Justice (2016)
- 8 Principles of the POPI Act - Naveg (2026)
- POPIA In Practice: What the Latest Developments Mean for SA Businesses - Mondaq / Mercia Fynn (June 2025)