Is Google Analytics POPIA Compliant?
Analytics is not compliant or non-compliant on its own. Four things decide it: consent, a cross-border transfer, who Google is to you, and your settings.
Read article →Practical guides and resources to help your South African website achieve and maintain POPIA compliance without the legal jargon.
Analytics is not compliant or non-compliant on its own. Four things decide it: consent, a cross-border transfer, who Google is to you, and your settings.
Read article →WhatsApp is an electronic communication, so section 69 applies in full. But the channel has three problems email does not, starting with groups.
Read article →You can buy one. It is not issued by the Information Regulator and certifies nothing under the Act. What to send instead when a client asks for proof.
Read article →Patient records fall under POPIA, the National Health Act and the HPCSA guidelines at once. Plus what the March 2026 health regulations do not change.
Read article →Agents sit under POPIA, FICA and the Property Practitioners Act at once. Two of them demand you keep things POPIA would otherwise have you delete.
Read article →Hosting offshore is a cross-border transfer under POPIA. Section 72 sets five gates, and most South African businesses are relying on the wrong one.
Read article →POPIA is the regulatory question. RICA is the criminal one, and it comes first. Clearing RICA does not clear POPIA, and most policies address neither.
Read article →Only sites with user content need one. But the ECT Act safe harbour protecting you from what users post has a condition almost nobody knows about.
Read article →What South African law requires in your website terms: the 18 disclosures in ECT Act section 43, the cooling-off rules, and the CPA terms that are void.
Read article →Your signage, how long you may keep footage, who may request a copy, and why recording audio is a separate offence under RICA. What POPIA requires of CCTV.
Read article →A disclaimer cannot exclude gross negligence, and a footer link fails the CPA notice rule. What actually works, what is void, and where to put it.
Read article →Legal, yes. But a fingerprint is special personal information under section 26, and employee consent is the weakest ground you can rely on. What to do instead.
Read article →The 7-day online cooling off, the 5-day direct marketing right, and the 6-month defect warranty. Which applies when, and what you may lawfully refuse.
Read article →The 30 day deadline, verifying who is asking, protecting other people in the record, when you may refuse, and what you are allowed to charge.
Read article →POPIA has no small business exemption, but it also never asks for a document called a privacy policy. What a sole trader with a contact form actually needs.
Read article →Can you post learner photos, run a parents' WhatsApp group, or share a class list? What POPIA allows South African schools to do, and where the limits are.
Read article →What you may lawfully ask a candidate, what needs consent, and when unsuccessful CVs must be deleted. Section 14 does not let you keep them forever.
Read article →If someone else processes data for you, section 21 requires a written contract. Which suppliers count, what the agreement must say, and who carries the risk.
Read article →Accountability through to accessibility: all eight conditions for lawful processing, each with a plain example of what compliance and a breach look like.
Read article →POPIA explained without the legal jargon: who it applies to, what counts as personal information, what you must do, and what happens if you ignore it.
Read article →Every obligation POPIA places on a South African business in one list: lawful grounds, security, retention, an Information Officer, and breach reporting.
Read article →Most South African cookie banners fail on the same three points. Check yours in five minutes against what POPIA actually requires, no legal training needed.
Read article →Every private body in South Africa needs a PAIA manual, including one-person businesses. What goes in it, where it lives, and the penalty for not having one.
Read article →Who to notify, what the notice must contain, and what to do in the first 24 hours. POPIA requires reporting as soon as reasonably possible after discovery.
Read article →Checkout data, abandoned carts, marketing lists and payment processors. What an online store must do differently, plus the ECT Act rules that also apply.
Read article →Consent must be voluntary, specific and informed, and you must be able to prove you have it. How to collect it, record it, and handle a withdrawal properly.
Read article →Every business already has one, usually without knowing it. Who holds the role by default, what they are legally responsible for, and how to register them.
Read article →Where your liability starts and your client's ends, what belongs in your contracts, and the compliance work you should be charging for on every build.
Read article →Payroll, medical certificates, disciplinary records and monitoring. What you may hold about staff, what needs consent, and how long you may keep it.
Read article →Section 69 is stricter than most marketers realise, and the rules differ for existing customers. What you may send, to whom, and how consent must be recorded.
Read article →One protects personal information, the other gives access to records, and most businesses must comply with both. How the two acts fit together, explained.
Read article →POPIA sets no fixed number of years, which is why so many businesses get this wrong. How to work out a retention period you can actually defend, and record it.
Read article →The eight sections that section 18 requires, what each one must say, and the wording mistakes that make a policy worthless. Written for South African sites.
Read article →Ten checks that take an afternoon and cover most of what the Information Regulator looks for. Work through them and you will know where you actually stand.
Read article →Almost certainly yes, if you run analytics or ads. When POPIA requires a cookie policy, what it has to cover, and what you risk by not publishing one.
Read article →They look similar and are not. Consent, lawful grounds, penalties and breach reporting all differ, and reusing a GDPR policy will leave you exposed.
Read article →What the Information Regulator can actually impose, which offences carry prison time, and what enforcement has looked like in practice since 2021.
Read article →