POPIA (Protection of Personal Information Act) is fully in force. For South African businesses with web applications, compliance isn't optional — and the risks of non-compliance are significant.
POPIA is Not Optional
Since July 2021, South Africa's Protection of Personal Information Act (POPIA) has been fully in force. For businesses that collect, process, or store personal information — which is essentially every business with a website, web app, or customer database — compliance is a legal requirement.
The Information Regulator has enforcement powers including fines of up to R10 million and criminal penalties for serious violations.
This is not theoretical risk. It's a real legal obligation that many South African businesses are not adequately meeting.
What Counts as Personal Information?
POPIA's definition is broad:
- Full names, ID numbers, addresses
- Email addresses, phone numbers
- Financial information (bank accounts, credit records)
- Health and medical data
- Biometric information
- Location data
- Online identifiers (IP addresses, cookies)
- Employment and educational history
If your web application collects any of this — and virtually all do — POPIA applies.
The Eight Conditions for Lawful Processing
POPIA's eight conditions form the compliance framework:
1. Accountability
You are responsible for ensuring POPIA compliance. Appoint an Information Officer (required by law for responsible parties).
2. Processing Limitation
Only collect personal information you actually need. Don't hoard data 'just in case'.
3. Purpose Specification
Clearly state why you're collecting information, at the point of collection. Don't use it for anything else.
4. Further Processing Limitation
Data collected for one purpose cannot be used for a different purpose without fresh consent.
5. Information Quality
Keep data accurate, complete, and current.
6. Openness
Have a clear, accessible Privacy Policy. Register your Information Officer with the Information Regulator.
7. Security Safeguards
Implement reasonable security measures to protect personal information from unauthorised access, use, or loss.
8. Data Subject Participation
Individuals have the right to access, correct, and delete their personal information.
What Your Web Application Needs to Be Compliant
Technical Requirements
Consent mechanisms:
- Cookie consent banners with opt-in for non-essential cookies
- Explicit opt-in for marketing communications
- Clear consent language at data collection points
Privacy Policy:
- Clearly explains what data you collect
- Why you collect it
- How it's stored and protected
- Who it's shared with (third parties, processors)
- How users can request access, correction, or deletion
Data Security:
- HTTPS/SSL everywhere
- Encrypted database storage for sensitive fields
- Access controls (users only see their own data)
- Audit logging for sensitive data access
- Multi-factor authentication for administrative access
Data Retention:
- Clear policies on how long data is kept
- Automated deletion of data older than retention period
Breach Response:
- Documented process for identifying and responding to data breaches
- Obligation to notify Information Regulator within 72 hours of a serious breach
Operational Requirements
- Appoint and register an Information Officer
- Document all personal information flows
- Conduct Privacy Impact Assessments for new features
- Third-party data processors must have POPIA-compliant agreements
- Staff training on data handling
GDPR and International Considerations
If your web application processes data from EU residents, GDPR also applies — with its own (broadly similar but stricter) requirements. South African businesses with European clients need to comply with both.
Getting Your Web App Compliant
At UNION Design, we build POPIA compliance into web applications from the foundation:
- Proper consent flows
- Encrypted data storage
- Access control architecture
- Privacy policy template
- Data subject request workflows