Most POPIA advice is written for lawyers. This one is written for whoever has to change the website. There is no small-business exemption, so this applies to you.
The privacy policy
It has to name POPIA, say what you collect, say why, say how long you keep it, and list the rights people have over it. A generic policy copied from a template site usually fails on the last two. It also has to be reachable from every page — footer link is standard for a reason.
Every form needs a purpose
If a form collects a name and an email, the page should say what you will do with them. “We use this to reply to your enquiry” is enough. What is not enough is collecting a phone number you never call, or a company name you never use — collect only what you actually need, because holding data you do not use is a liability with no upside.
Cookies and analytics
Analytics and advertising pixels set cookies, and those need consent before they fire — not a banner that sets them anyway and tells you afterwards. If you only run basic analytics, say so plainly rather than deploying a consent wall designed for an ad network.
Name an Information Officer
Every South African business has one whether they know it or not — by default it is the owner or CEO, and the role should be registered with the Information Regulator. Put the contact route on the privacy page so a request has somewhere to go.
The parts people miss
- Third parties. Your form processor, your mailing list, your analytics — each one receives personal information and should be named.
- HTTPS. Not optional. A form posting over plain http is a problem before you get to policy wording.
- A deletion route. Someone has the right to ask you to delete their data. There should be an address that reaches a human.
- Old data. Enquiries from 2019 sitting in an inbox are still personal information you are holding.
What this looks like in practice
For most small business sites it is an afternoon: rewrite the policy properly, add purpose text to the forms, sort out consent, name the officer, force HTTPS. Our own privacy page is written the way we would write yours — plain, specific, and naming the processors. If you want it handled as part of a build or a fix, say so in the brief.