
The Protection of Personal Information Act (POPIA) is South Africa's data protection law. It came fully into force on 1 July 2021 and applies to any organisation in South Africa that processes the personal information of identifiable people - which is essentially every business with a website that has a contact form, mailing list or e-commerce.
What POPIA actually requires
POPIA establishes 8 conditions for lawful processing of personal information. The practical implications for a typical business website are:
- You need a lawful basis to collect personal info. Usually this is consent (a tick-box) or legitimate business need (delivering an order).
- You must tell people what you collect and why, via a Privacy Policy linked from your site footer.
- You can only use the info for the purpose you stated. Collecting an e-mail "to send order confirmations" doesn't let you spam-blast newsletters to it.
- You must keep it secure. SSL on your site, secure passwords, backups - the basics. Hosting in South Africa simplifies the cross-border data transfer arguments.
- Data subjects have rights: to know what you hold, to correct it, to ask you to delete it. You must respond.
- Notify the Information Regulator (and the affected people) within 72 hours of a data breach.
Who is the responsible party?
POPIA calls the data collector the "Responsible Party" - that is your business. The Information Regulator at inforegulator.org.za enforces compliance and processes complaints.
Practical checklist for a small business website
- Publish a Privacy Policy. Link it from your footer and from any form that collects info.
- Add a tick-box on every form: "I agree to be contacted regarding this enquiry. I have read the Privacy Policy."
- Add a cookie consent banner if you use Google Analytics, Facebook Pixel, or similar trackers.
- Use SSL on your site (free with every Trinico Cloud hosting plan).
- Keep daily backups (included with our hosting).
- Have a written incident response plan: who is notified, in what order, when a breach happens.
- Register an Information Officer (any business of any size has one - by default it is the head of the business).
What POPIA is NOT
POPIA is NOT GDPR (the EU equivalent), though they overlap. POPIA is generally less strict on consent and easier to comply with as a small business.
SA hosting + free SSL Need help with POPIA setup?
Need a hand?
The Trinico Cloud team is in South Africa and replies during local business hours. Reach us via WhatsApp, e-mail or a support ticket - whichever suits you best.