POPIA Doesn't Care How Small Your Website Is
The Protection of Personal Information Act applies the moment your website collects anyone's personal information — a name and email on a contact form, an IP address logged by Google Analytics, a cellphone number typed into a WhatsApp click-to-chat link. There's no small-business carve-out. A five-page site for a one-person consultancy is a "responsible party" under POPIA in exactly the same way a bank is, just with a much smaller compliance budget. The good news: for most small businesses, getting the essentials right is a solvable problem, not a legal project.
We say this having built and audited enough SA business sites to know the pattern: almost nobody sets out to be non-compliant. The legal pages simply get treated as an afterthought — copy-pasted from a template built for a different country, or skipped entirely because "we're too small for anyone to notice." Neither approach holds up, and both are cheap to fix once you know what's actually required.
The 7 Legal Pages Every SA Website Needs
These aren't seven separate legal projects. Most SA business sites can cover all of them in two or three pages, provided the content is actually correct for how your site works.
- Privacy Policy (POPIA). Explains what personal information you collect — via contact forms, newsletter signups, cookies — why you collect it, how it's stored, who it's shared with, and how a visitor can access, correct, or ask you to delete it. This is the page POPIA cares about most.
- Terms of Use / Service. Governs how visitors may use your site and services, limits your liability for the advice or content you publish, and states who owns the content and design. For online stores, this extends to order and delivery terms.
- Cookie Consent Notice. If you run Google Analytics, a Meta Pixel, or Microsoft Clarity — as most modern SA business sites do — you're processing identifiable data through cookies. A short notice and a linked cookie policy is expected, and non-negotiable once you're running remarketing ads.
- POPIA / PAIA Manual. A simplified statement of what information your business holds and how someone can request access to it. Larger entities must publish a full manual; small businesses can cover this in a few honest paragraphs.
- Disclaimer. Limits your liability for advice, opinions, or general information published on your site — especially important for professional-services and blog content that reads as guidance rather than a formal engagement.
- Refund & Return Policy. Required under the Consumer Protection Act for any business taking online payment. Sets clear expectations before a dispute happens, not during one.
- Visible business details. Your registered company name, registration number, and physical address, easy to find rather than buried three clicks deep — a Companies Act expectation that also happens to build trust with a first-time visitor.
Here's the same seven pages laid out as a checklist, and where most existing SA sites currently stand:
What Non-Compliant Sites Usually Get Wrong
The same handful of mistakes show up again and again, usually because the legal pages were added once, years ago, and never revisited as the site — or the tools running on it — changed:
- A copy-pasted GDPR template — references the EU's regulators and legislation, not South Africa's
- No Information Officer named — visitors have no idea who to contact about their own data
- Cookie tracking with no cookie notice — Meta Pixel or Analytics running silently, unmentioned
- Legal pages buried or missing from the footer — technically present, practically undiscoverable
- Pages written for your actual data flows — which forms, which cookies, which tools
- A named Information Officer — registered with the Regulator, referenced in your policy
- A short cookie notice — linked wherever tracking scripts first fire on the page
- All 7 pages linked in the footer — and from checkout or booking flows, where relevant
A Pretoria-based online store came to us after PayFast paused their merchant application — the site had no Privacy Policy, Terms of Service, or Refund Policy, and payment gateways check for all three automatically during onboarding. We wrote and published all three, POPIA-aligned and specific to how the store actually processed orders and customer data, and linked them from the footer and checkout flow. The merchant account was approved within 48 hours of resubmission, and the store hasn't had a compliance flag since.
Before you keep reading: does your site's footer actually link to a Privacy Policy right now? If you have to go and check, so does every visitor — and so does every payment gateway or ad platform reviewing your account.
What Happens If You Ignore This?
For most small businesses, the realistic risk isn't a knock on the door from the Information Regulator — it's the quieter, more immediate friction. Meta and Google Ads both require a linked privacy policy before they'll approve certain ad account features, and payment gateways like PayFast and Yoco check for Privacy Policy, Terms, and Refund pages during merchant onboarding, exactly as in the example above. Increasingly, corporate clients run basic POPIA due-diligence on any small supplier before signing a contract — a missing Privacy Policy can quietly cost you the deal before anyone mentions it out loud.
The Information Regulator can and does act on serious, wilful, or repeated contraventions, with penalties up to R10 million or imprisonment in the most severe cases. That's not the everyday risk for a five-page business site with a decent Privacy Policy — but it's exactly the outcome that having one, done properly, protects you from.
| Page | Who actually needs it | Priority |
|---|---|---|
| Privacy Policy | Every site with a contact form, newsletter, or analytics cookies | Required |
| Terms of Use | Every business site, especially those offering paid services | Required |
| Refund & Return Policy | Any site taking online payment for goods or services | Required |
| Cookie Consent Notice | Any site running Analytics, a Meta Pixel, or remarketing ads | Strongly recommended |
| PAIA Manual (simplified) | All businesses; full manuals apply mainly to larger entities | Recommended |
| Disclaimer | Professional services and any site publishing advice or opinion | Recommended |
How to Get This Sorted Without Hiring a Lawyer
You don't need a law firm on retainer to get these seven pages right — you need them written correctly, once, for how your specific site actually works. That means naming your real Information Officer, listing the actual forms and cookies on your site rather than a generic list, and referencing South Africa's Information Regulator and the actual legislation (POPIA, the CPA, PAIA) rather than a template built for GDPR. Every site CJX Studios builds ships with these pages included from day one, and we retrofit them onto existing sites just as often — usually inside the same 48-hour turnaround as everything else we build.
Go Deeper: Related Guides
Get your 7 legal pages sorted properly, in one afternoon.
Send Chris your business details and a link to your current site on WhatsApp, or use the contact page — we'll write POPIA-aligned Privacy, Terms, Cookie and Refund pages built around how your site actually works, live within 48 hours.
Zero deposit · No lock-in · Pay only if you love it · From R1,200/mo
Frequently Asked Questions
Does POPIA apply to my small business website even if I don't sell anything online?
Yes. POPIA applies the moment your site processes anyone's personal information — a contact form, a newsletter signup, or even analytics cookies that log an IP address all count. There's no small-business exemption; the Act covers any responsible party processing personal information in South Africa, regardless of turnover or headcount.
What happens if I just use a generic GDPR privacy policy template?
It will reference the wrong regulator, the wrong legislation, and often the wrong user rights. A GDPR template names the EU's data protection authorities, not South Africa's Information Regulator, and it won't reference POPIA's specific conditions for lawful processing. It looks like compliance without actually being it — which is arguably worse than having no policy at all.
Do I need a cookie consent pop-up if I only use Google Analytics?
Strictly, analytics cookies still process personal information such as IP addresses, so a cookie notice and policy are best practice under POPIA. It becomes non-negotiable the moment you add remarketing tools like a Meta Pixel or Google Ads conversion tag, both of which track individuals across sessions for advertising purposes.
Who is my website's "Information Officer", and do I need to register one?
By default, it's you — the owner or a director — unless you formally appoint someone else. POPIA requires every responsible party to register their Information Officer with the Information Regulator's online portal, and that name (or role) should also appear in your website's Privacy Policy as the contact point for data requests.
Can CJX Studios add these legal pages to my existing website?
Yes — we retrofit all 7 pages onto existing sites, not just new builds. We draft them around your actual data flows (which forms, which cookies, which third-party tools you run) rather than dropping in a generic template, and the update is typically live within 48 hours.
- Seven pages cover almost everything: Privacy Policy, Terms of Use, Cookie Notice, POPIA/PAIA Manual, Disclaimer, Refund Policy, and visible business details.
- Generic GDPR templates don't count — they name the wrong regulator and skip POPIA's actual requirements entirely.
- The everyday risk isn't a fine, it's a paused payment gateway approval, a rejected ad account, or a corporate client's due-diligence check.