What a POPIA website audit actually reveals
A POPIA website audit examines how your business collects, processes, and stores personal information through its digital presence. It consistently reveals gaps between what the Act requires and what most SA business websites actually do. With the Information Regulator issuing its first enforcement notice in February 2024 and substantially increasing enforcement activity through 2025, the cost of those gaps is no longer theoretical.[1]
What does POPIA require from a business website?
POPIA applies to any organisation that processes personal information in South Africa, regardless of size. "Processing" includes collecting, storing, using, or sharing data - which means any website with a contact form, analytics, or newsletter signup is subject to the Act.[2]
The eight conditions for lawful processing in Chapter 3 of the Act require that personal information is:
- Processed lawfully and with accountability
- Collected for a specific, clearly defined purpose
- Minimised to only what is necessary for that purpose
- Accurate and kept up to date
- Not kept longer than necessary
- Processed with regard to the data subject's integrity and confidentiality
- Processed only within the scope of reasonable expectation
- Protected by appropriate security measures
What are the five most common POPIA gaps on SA business websites?
1. Inadequate privacy policy
Most SA business websites have a privacy policy - but most do not meet the POPIA standard. A compliant policy must name the Information Officer, list every category of personal information collected, state the specific purpose for each, disclose every third-party recipient (including Google Analytics, Mailchimp, payment gateways), and explain data subject rights.[3]
2. Non-compliant cookie handling
If your website sets any non-essential cookies before obtaining informed consent, it is non-compliant. The Information Regulator's 2024 Guidance Note confirmed there is no "legitimate interest" basis for unsolicited electronic marketing tracking in South Africa. This means:
- Google Analytics may only load after explicit opt-in consent
- Facebook Pixel and advertising trackers require the same
- Pre-ticked consent boxes are invalid
- Cookie walls that block content until visitors consent are non-compliant
A full cookie audit requires inventorying every cookie your site sets - first and third party - with its purpose, duration, and the data it collects.[4]
3. Information Officer not appointed or registered
Every organisation must designate an Information Officer and register that person with the Information Regulator via the eServices portal (launched April 2025). By default, this role falls to the CEO. The April 2025 amendments significantly expanded IO obligations - the role now requires active ongoing oversight of a compliance framework that must be "continuously improved."[5]
4. Direct marketing consent issues
The Regulator's first enforcement notice targeted a company that continued sending marketing emails to data subjects who had opted out. The April 2025 amendments tightened this: opt-out does not constitute consent for electronic marketing. You need explicit, opt-in consent for each communication channel.[6]
5. Security safeguards not documented
POPIA's security condition (s. 19) requires "appropriate, reasonable technical and organisational measures." Since April 2025, security compromises must be reported via the Regulator's eServices portal - making an undocumented incident response procedure a direct compliance gap.[3]
What happens when the Information Regulator investigates?
The Regulator can:
- Issue an enforcement notice requiring remedial action within a specified period
- Impose administrative fines of up to R10 million per infringement
- Refer matters for criminal prosecution (imprisonment of up to 10 years for certain offences)
- Make investigations and findings public - causing significant reputational damage
The April 2025 amendments introduced instalment payments for administrative fines, but do not reduce the maximum penalty.[7]
The POPIA website audit checklist
| Area | What to check | POPIA reference |
|---|---|---|
| Privacy policy | IO named, processors listed, retention stated | ss. 17–18 |
| Cookies | Inventory complete, opt-in consent before loading | s. 11, IR Guidance 2024 |
| Contact forms | Separate, unticked marketing consent | s. 69 |
| IO registration | Registered on eServices portal | s. 55 |
| Security | HTTPS, update policy, access controls documented | s. 19 |
| Breach procedure | Written, tested, portal access confirmed | s. 22, 2025 amendments |
| Operator agreements | Written agreements with all data processors | s. 21 |
| PAIA manual | Available on website | PAIA s. 51 |
| Data subject rights | Process to handle requests within 30 days | ss. 23–25, 2025 amendments |
Frequently asked questions
Does POPIA apply to small businesses?
Yes. There is no size exemption. Any business processing personal information in South Africa - including any website with a contact form - is subject to the full Act.
How long does a POPIA website audit take?
A structured gap audit covering the areas above can be completed in under an hour. Remediation depends on what is found - a missing IO registration and a compliant cookie banner can both be addressed within days.
Can I use a standard privacy policy template?
A template is a starting point only. POPIA requires your policy to reflect your actual processing activities - the specific data you collect, the specific third parties you share it with, and the name of your Information Officer. A template that omits these specifics does not satisfy the Act's openness requirement.
References
- POPIA In Practice: Latest Developments - Mondaq (June 2025)
- 8 Principles of the POPI Act - Naveg (2026)
- POPIA South Africa: Data Protection Law Guide - Kukie.io (2026)
- POPIA Website Compliance Without Killing Conversions - Vertopia (2025)
- Amendments to the POPIA Regulations - Lexology / Baker McKenzie (May 2025)
- POPIA Regulations Get a Makeover - The Media Online (April 2025)
- POPI Act 2025 Compliance for Small Business - AirCounsel (2025)