HomeBlog

POPIA Compliance Hub

Practical guides and resources to help your South African website achieve and maintain POPIA compliance without the legal jargon.

·10 min read

Is Google Analytics POPIA Compliant?

Analytics is not compliant or non-compliant on its own. Four things decide it: consent, a cross-border transfer, who Google is to you, and your settings.

Read article →
·10 min read

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

WhatsApp is an electronic communication, so section 69 applies in full. But the channel has three problems email does not, starting with groups.

Read article →
·8 min read

Is There Such a Thing as a POPIA Compliance Certificate?

You can buy one. It is not issued by the Information Regulator and certifies nothing under the Act. What to send instead when a client asks for proof.

Read article →
·11 min read

Your Patient Records Sit Under Three Laws, Not One

Patient records fall under POPIA, the National Health Act and the HPCSA guidelines at once. Plus what the March 2026 health regulations do not change.

Read article →
·11 min read

Your WhatsApp Messages Are Records You Must Keep for Five Years

Agents sit under POPIA, FICA and the Property Practitioners Act at once. Two of them demand you keep things POPIA would otherwise have you delete.

Read article →
·10 min read

Your Website Is Hosted Overseas. That Is a Cross-Border Transfer.

Hosting offshore is a cross-border transfer under POPIA. Section 72 sets five gates, and most South African businesses are relying on the wrong one.

Read article →
·11 min read

Reading an Employee's Email Can Be a Criminal Offence

POPIA is the regulatory question. RICA is the criminal one, and it comes first. Clearing RICA does not clear POPIA, and most policies address neither.

Read article →
·9 min read

Acceptable Use Policies: Who Needs One, and What It Must Do

Only sites with user content need one. But the ECT Act safe harbour protecting you from what users post has a condition almost nobody knows about.

Read article →
·11 min read

Website Terms and Conditions in South Africa: What the Law Requires

What South African law requires in your website terms: the 18 disclosures in ECT Act section 43, the cooling-off rules, and the CPA terms that are void.

Read article →
·11 min read

CCTV and POPIA: Signage, Retention, and Who Can Ask for Footage

Your signage, how long you may keep footage, who may request a copy, and why recording audio is a separate offence under RICA. What POPIA requires of CCTV.

Read article →
·9 min read

Website Disclaimers in South Africa: What They Can and Cannot Do

A disclaimer cannot exclude gross negligence, and a footer link fails the CPA notice rule. What actually works, what is void, and where to put it.

Read article →
·8 min read

Is Fingerprint Clocking Legal in South Africa?

Legal, yes. But a fingerprint is special personal information under section 26, and employee consent is the weakest ground you can rely on. What to do instead.

Read article →
·10 min read

Refunds and Returns in South Africa: What the Law Actually Requires

The 7-day online cooling off, the 5-day direct marketing right, and the 6-month defect warranty. Which applies when, and what you may lawfully refuse.

Read article →
·9 min read

Someone Asked for Their Data. Here Is Your 30 Days.

The 30 day deadline, verifying who is asking, protecting other people in the record, when you may refuse, and what you are allowed to charge.

Read article →
·9 min read

Do You Need a Privacy Policy for a One-Person Business in South Africa?

POPIA has no small business exemption, but it also never asks for a document called a privacy policy. What a sole trader with a contact form actually needs.

Read article →
·11 min read

POPIA for Schools: Photos, WhatsApp Groups and Learner Records

Can you post learner photos, run a parents' WhatsApp group, or share a class list? What POPIA allows South African schools to do, and where the limits are.

Read article →
·10 min read

POPIA and Hiring: What You May Ask, Keep, and For How Long

What you may lawfully ask a candidate, what needs consent, and when unsuccessful CVs must be deleted. Section 14 does not let you keep them forever.

Read article →
·9 min read

You Need a Contract With Your Web Host: POPIA Section 21

If someone else processes data for you, section 21 requires a written contract. Which suppliers count, what the agreement must say, and who carries the risk.

Read article →
·12 min read

The 8 Conditions for Lawful Processing, Explained With Examples

Accountability through to accessibility: all eight conditions for lawful processing, each with a plain example of what compliance and a breach look like.

Read article →
·9 min read

What Is POPIA? A Plain-English Guide to the POPI Act

POPIA explained without the legal jargon: who it applies to, what counts as personal information, what you must do, and what happens if you ignore it.

Read article →
·11 min read

POPIA Requirements: The Complete List for SA Businesses

Every obligation POPIA places on a South African business in one list: lawful grounds, security, retention, an Information Officer, and breach reporting.

Read article →
·8 min read

Is Your Cookie Banner POPIA Compliant? How to Check in 5 Minutes

Most South African cookie banners fail on the same three points. Check yours in five minutes against what POPIA actually requires, no legal training needed.

Read article →
·7 min read

PAIA Manual Requirements: What Every South African Business Needs (2026)

Every private body in South Africa needs a PAIA manual, including one-person businesses. What goes in it, where it lives, and the penalty for not having one.

Read article →
·8 min read

What to Do When You Have a Data Breach in South Africa (POPIA Response Plan)

Who to notify, what the notice must contain, and what to do in the first 24 hours. POPIA requires reporting as soon as reasonably possible after discovery.

Read article →
·10 min read

POPIA Compliance for E-Commerce and Online Stores in South Africa

Checkout data, abandoned carts, marketing lists and payment processors. What an online store must do differently, plus the ECT Act rules that also apply.

Read article →
·8 min read

How to Manage User Consent Under POPIA (A Practical Guide)

Consent must be voluntary, specific and informed, and you must be able to prove you have it. How to collect it, record it, and handle a withdrawal properly.

Read article →
·8 min read

The Role of an Information Officer in South Africa (POPIA Guide)

Every business already has one, usually without knowing it. Who holds the role by default, what they are legally responsible for, and how to register them.

Read article →
·9 min read

POPIA Compliance for Web Developers and Agencies

Where your liability starts and your client's ends, what belongs in your contracts, and the compliance work you should be charging for on every build.

Read article →
·10 min read

POPIA and Employee Data: What South African Employers Must Know

Payroll, medical certificates, disciplinary records and monitoring. What you may hold about staff, what needs consent, and how long you may keep it.

Read article →
·8 min read

Can You Cold Email in South Africa? POPIA Section 69 Explained

Section 69 is stricter than most marketers realise, and the rules differ for existing customers. What you may send, to whom, and how consent must be recorded.

Read article →
·5 min read

POPIA vs PAIA: Understanding South Africa's Information Laws

One protects personal information, the other gives access to records, and most businesses must comply with both. How the two acts fit together, explained.

Read article →
·7 min read

How Long Can You Keep Customer Data Under POPIA?

POPIA sets no fixed number of years, which is why so many businesses get this wrong. How to work out a retention period you can actually defend, and record it.

Read article →
·9 min read

How to Write a POPIA Privacy Policy (8 Sections You Must Include)

The eight sections that section 18 requires, what each one must say, and the wording mistakes that make a policy worthless. Written for South African sites.

Read article →
·9 min read

POPIA Checklist: 10 Things Every SA Website Needs

Ten checks that take an afternoon and cover most of what the Information Regulator looks for. Work through them and you will know where you actually stand.

Read article →
·5 min read

Do You Need a Cookie Policy in South Africa?

Almost certainly yes, if you run analytics or ads. When POPIA requires a cookie policy, what it has to cover, and what you risk by not publishing one.

Read article →
·8 min read

POPIA vs GDPR: Key Differences for SA Website Owners

They look similar and are not. Consent, lawful grounds, penalties and breach reporting all differ, and reusing a GDPR policy will leave you exposed.

Read article →
·8 min read

POPIA Fines: Up to R10 Million or 10 Years in Prison (2026)

What the Information Regulator can actually impose, which offences carry prison time, and what enforcement has looked like in practice since 2021.

Read article →