Website security for South African SMEs: what POPIA actually requires
For most South African SMEs, website security sits somewhere between "IT will handle it" and "we haven't thought about it." POPIA changes both of those answers. Section 19 of the Act requires every responsible party to implement "appropriate, reasonable technical and organisational measures" to protect personal information. For a business with a website that collects contact details, that obligation applies to you - regardless of size.[1]
What does "appropriate and reasonable" mean in practice?
The standard is proportionate - a medical practice handling sensitive health data faces a higher bar than a plumber collecting contact details for quotes. But the floor is not zero. Every business that processes personal information must meet a minimum technical standard, and the Information Regulator's enforcement actions provide some guidance on what "minimum" means.
The baseline for any SME website includes:
- HTTPS on every page. Not just the contact form - every URL. An HTTP page that links to an HTTPS form is still non-compliant because session data and referrer headers can be intercepted. A valid SSL/TLS certificate is non-negotiable.
- Up-to-date CMS and plugins. WordPress powers the majority of SMB websites in South Africa. A WordPress installation running plugins with known vulnerabilities is not "appropriate and reasonable" under s. 19. Updates should be applied within the vendor's recommended window - typically within 7–14 days of a security release.
- Access controls. Admin credentials should be unique per user, changed from defaults, and access should be limited to those who need it. Shared "admin/password" credentials are a documented attack vector and a compliance gap.
- Backup and recovery. A documented backup procedure - with tested restoration - is an organisational measure under s. 19. A business that cannot restore its website after an incident has effectively no incident response capability.
The breach notification requirement: April 2025
Section 22 requires notifying the Information Regulator and affected data subjects when a security compromise is discovered. The April 2025 amendments specify that this notification must go through the Regulator's eServices portal. A business without portal access and a written breach response procedure cannot comply with this requirement - and the clock starts running from the moment the compromise is discovered, not from when you figure out the process.[3]
Organisational measures: what does the policy need?
Technical controls alone are not sufficient under s. 19. "Organisational measures" require that the controls are documented, that responsibilities are assigned, and that there is a process for testing and reviewing them. A one-page security policy that identifies who is responsible for updates, who holds admin credentials, and what happens in the event of a breach is a starting point - not a luxury.
SME security baseline checklist
| Control | Standard | POPIA reference |
|---|---|---|
| SSL/TLS certificate | Valid; applied sitewide | s. 19 |
| CMS and plugins | Updated within 14 days of security releases | s. 19 |
| Admin credentials | Unique per user; changed from defaults; MFA where available | s. 19 |
| Backups | Daily or weekly; tested restoration | s. 19 |
| Written security policy | Responsibilities assigned; reviewed annually | s. 19 |
| Breach procedure | Written; eServices portal access confirmed | s. 22; April 2025 amendments |
| Operator agreements | Written agreements with hosting, email, CRM providers | s. 21 |
Frequently asked questions
My website is hosted by a third party - doesn't that make them responsible?
No. Your hosting provider is an "operator" under POPIA - they process data on your instruction. You remain the "responsible party" and bear the compliance obligation. Section 21 requires you to have a written agreement with your hosting provider that prescribes their obligations. Hosting terms of service are not typically sufficient for this purpose.
What if my website was built by an agency?
The agency is an operator at the point of build. Once the site goes live under your control, you become responsible for its ongoing compliance. If the agency continues to maintain the site, you need a written operator agreement with them. If they have handed it over, the compliance responsibility is entirely yours.
How much does it cost to bring a website into compliance?
Most of the baseline technical controls cost very little - SSL certificates are included in most hosting plans, CMS updates are free, and access control changes require time, not budget. The larger investment is in writing and testing the organisational documentation. A full gap audit will identify what is missing and what requires investment.[4]