The usual caveat: we’re website people, not lawyers — treat this as a practical orientation, and get legal advice for anything high-stakes.
POPIA (the Protection of Personal Information Act) applies to basically every South African business website, because basically every website collects personal information: contact forms, order details, analytics, newsletter signups. The good news is that for a typical small-business site, compliance is mostly a short list of concrete things.
What counts as personal information on your site
Names and emails from your contact form. Delivery addresses and phone numbers from your checkout. Analytics identifiers and cookies. If your site has a form or a shopping cart, you’re processing personal information.
The practical checklist
- Have a real privacy policy. Not a template pasted blind — it must describe what you actually collect, why, where it’s stored, and who it’s shared with (your email service, your payment gateway, Google Analytics). A wrong policy is arguably worse than none.
- Collect only what you need. If your quote form asks for a birth date “just in case”, delete the field. Minimisation is a core POPIA principle and also just good form design.
- Get real consent for marketing. A checkout or contact form must not silently add people to your mailing list. Unticked opt-in checkbox, plain wording.
- Appoint your information officer. For most small businesses this is automatically the owner/head — but you’re expected to register with the Information Regulator and be reachable for data requests.
- Secure the data. This is where POPIA meets maintenance: SSL on the site, software kept updated, strong admin passwords with 2FA, and backups. A breach through a known, unpatched plugin vulnerability is a hard thing to defend as “reasonable security measures”.
- Know your breach duty. If personal data is compromised, POPIA requires notifying the Regulator and affected people. Have a one-paragraph plan for who does that.
The maintenance connection
Point 5 is the one website owners control most directly and neglect most often. An outdated WordPress site isn’t just a technical risk anymore — it’s a compliance risk. Keeping software patched, access controlled and backups running is the unglamorous core of “appropriate, reasonable technical measures”, and it’s exactly what a maintenance plan does on schedule.