Where e-commerce POPIA exposure concentrates
Online stores collect more personal information, in more places, than a typical brochure site - checkout forms, payment processors, account creation, marketing opt-ins, and behavioural tracking for cart abandonment. Each is a separate processing activity requiring its own lawful basis.
| Data point | Where it's collected | Common gap |
|---|---|---|
| Payment details | Checkout / payment gateway | No written operator agreement with the payment processor |
| Delivery address | Checkout | Retained indefinitely with no retention schedule |
| Marketing consent | Newsletter signup, checkout opt-in checkbox | Pre-ticked opt-in boxes - not valid consent |
| Cart abandonment tracking | Third-party remarketing pixels | Pixel fires before consent is given |
Payment processors are operators, not exempt third parties
A common misconception is that once payment data passes through a gateway like Payfast or PayGate, the store's POPIA responsibility ends. It doesn't - the processor is an operator acting on the store's instruction, and a written operator agreement covering their obligations is still required.
Frequently asked questions
Can we pre-tick the marketing consent checkbox to improve signup rates?
No. Pre-ticked boxes don't constitute valid, voluntary, opt-in consent under POPIA regardless of the conversion benefit - the checkbox must start unticked.