Why a cookie banner alone doesn't satisfy POPIA
Most SA law firm websites ship a cookie banner that says "By continuing to browse, you accept cookies" and loads every tracking script regardless of what the visitor clicks. POPIA requires prior, voluntary, specific, and informed consent before processing begins - which means before the script fires, not after the visitor scrolls past the banner.[1]
What "prior" actually means technically
| Pattern | Compliant? | Why |
|---|---|---|
| Scripts load on page load; banner is informational only | No | Processing begins before any consent is given |
| "Continuing to browse = consent" | No | Not a specific, opt-in action - it's implied by inaction |
| Scripts blocked until "Accept" is clicked | Yes | Consent is genuinely prior to processing |
| Granular toggle per category (analytics, marketing) | Yes - best practice | Meets the "specific" element of valid consent |
The scripts firms don't think of as "tracking"
Google Fonts loaded from Google's CDN, embedded YouTube videos, LinkedIn Insight Tag, and live chat widgets all set cookies or make cross-site requests that process personal information. A cookie audit needs to look past the obvious analytics/ad-pixel scripts.
Frequently asked questions
Does this mean every firm needs a consent management platform?
Not necessarily - a lightweight, self-built banner that genuinely blocks scripts until consent is given can satisfy the requirement. What matters is the blocking behaviour, not the tooling.
What about essential/functional cookies?
Strictly necessary cookies (session, security) generally don't require the same opt-in consent, but they should still be disclosed in the privacy policy.