Website compliance south africa is not a single checkbox — it is a stack of four overlapping legal obligations: POPIA's data protection rules, the ECT Act's mandatory disclosures, the Consumer Protection Act's cancellation rights, and an emerging accessibility standard grounded in the Constitution.

Every commercial site serving South African customers must satisfy all four simultaneously, which is why our web design in Johannesburg practice embeds this compliance framework into every build from the architecture stage — retrofitting legal requirements onto a live site costs substantially more than getting them right at the start.

The gap between knowing a privacy policy exists and knowing what it must actually say — and what else must sit beside it — is where South African businesses are exposed right now. The Information Regulator received an average of 284 breach notifications per month from April 2025 — a 40% year-on-year increase. Private businesses are already in the enforcement record: Lancet Laboratories and FT Rams Consulting each received R100,000 fines in 2025. Public bodies faced larger penalties — a government department R5 million, a municipality R500,000 — but enforcement reaches all sectors.

Quick Answer

Website compliance south africa requires meeting four legal frameworks simultaneously: POPIA (data privacy, cookie consent, and breach notification), the Electronic Communications and Transactions Act (mandatory business disclosures and a seven-day cooling-off right), the Consumer Protection Act (fair-practice obligations for online sellers), and accessibility requirements grounded in the Constitution and PEPUDA. A compliant South African site has a current privacy policy, a working cookie consent mechanism, full pricing disclosure, a returns process, and no barriers that exclude users with disabilities.

Is Your Site Exposing You to Regulatory Risk?

Send us your URL and we'll run it against the SA compliance checklist — POPIA, ECT Act, CPA, and accessibility — and flag the gaps before they become enforcement notices.

Request a Compliance Audit

What Does Website Compliance South Africa Actually Require?

Website compliance south africa sits at the intersection of four pieces of legislation, each administered by a different body and each carrying its own enforcement teeth.

LawWhat It GovernsWho Enforces It
POPIA (Act 4 of 2013)Data collection, cookie consent, privacy policy, breach notificationInformation Regulator
ECT Act (Act 25 of 2002)Business identity disclosures, pricing transparency, cooling-off rightDTCC / courts
Consumer Protection Act (Act 68 of 2008)Fair marketing, direct marketing cancellation rights, returnsNCC / courts
Constitution + PEPUDAEqual access for persons with disabilitiesEquality Court

The mistake most SA businesses make is treating POPIA as the only compliance obligation and ignoring the ECT Act's disclosure requirements — which apply even to a simple brochure site, not just online shops.

POPIA Requirements for South African Websites

POPIA's Protection of Personal Information Act 4 of 2013 applies to every South African business — and to any foreign business that processes the personal data of South African residents, regardless of where that business is based. The moment a contact form collects a name and email address, POPIA applies.

The Act establishes eight conditions that every instance of personal data processing must satisfy:

  1. Accountability — you take responsibility for complying with the Act.
  2. Processing Limitation — you collect only data you have a lawful basis for, and only as much as you need.
  3. Purpose Specification — you know why you are collecting each field and you tell the data subject.
  4. Further Processing Limitation — you use collected data only for the stated purpose.
  5. Information Quality — you keep data accurate and current.
  6. Openness — you maintain a privacy policy and notify people how their data is used.
  7. Security Safeguards — you protect personal data from unauthorised access or loss.
  8. Data Subject Participation — you honour requests to access, correct, or delete personal information.

Note: consent is one of several lawful bases for processing under POPIA — contractual necessity, legal obligation, and legitimate interests are also valid. "Consent is always required" is a common misstatement that overstates the rule.

POPIA Privacy Policy: What Yours Must Say

A POPIA-compliant privacy policy discloses: what personal information is collected and from where; the identity and contact details of the collector; why the information is used; the consequences of not providing it; which third parties receive it; the data subject's rights and how to exercise them; whether data is transferred internationally and what protections apply; and how to complain to the Information Regulator. A policy that says "we value your privacy" without these specifics is not compliant.

Cookie Consent Under POPIA

POPIA requires an opt-in model for non-essential cookies — analytics, advertising, and retargeting trackers all require active user consent before firing. Pre-ticked boxes are non-compliant. The default state for every cookie category except "necessary" must be off. Consent must be as easy to withdraw as it was to give, and you must keep a timestamped record of consent choices for each user.

The Information Regulator's current enforcement emphasis (2024–2026) has shifted from checking whether a consent banner exists to verifying that the tracker scripts actually stop loading when a user declines. A banner that looks correct but allows scripts to fire regardless is a functional failure.

Breach Notification

When a security compromise occurs, POPIA requires notification to the Information Regulator and to affected data subjects "as soon as reasonably possible." The Regulator's own guidance note sets a practical expectation of 72 hours.

Since 1 April 2025, all breach notifications must be submitted through the Regulator's eServices portal (accessible from inforegulator.org.za) — email submissions are no longer accepted. An Information Officer must be registered with the Regulator before assuming duties; this is not a formality the Regulator overlooks.

Information Officer registration: Every private and public body must register their Information Officer on the Regulator's portal. This person carries personal accountability for the organisation's POPIA compliance — including breach notification timelines and processing assessments. Registration is completed through the Information Regulator's online portal; both the IO and a Deputy IO must be registered before assuming duties.

ECT Act and CPA: What Online Sellers Must Display

The Electronic Communications and Transactions Act 25 of 2002 (ECTA) applies to every commercial website — not just online stores. Section 43 requires businesses to make specific disclosures accessible before a transaction is concluded. If these are buried in a footer nobody reads, you still qualify as non-compliant.

ECTA RequirementWhat It Means in Practice
Section 43: Full business identityLegal name, physical address (not just a PO box), registration number, and contact details — visible before purchase
Section 43: Full price disclosureTotal cost including all taxes, shipping fees, and additional charges — no revealing the delivery fee at checkout for the first time
Section 44: Seven-day cooling-off rightConsumers can cancel most electronic transactions within seven days of receiving goods — this right must be communicated, not hidden in T&Cs
Section 46: 30-day fulfillmentYou must dispatch within 30 days of a confirmed order unless both parties agree to a different timeline in writing

The Consumer Protection Act adds a separate five-business-day cancellation right specifically for direct marketing transactions. When both ECTA and the CPA apply, the ECTA seven-day right takes precedence — but both must be communicated to the customer.

The ECTA Disclosure Trap

The ECTA Section 43 disclosures are often missing from sites built without legal input. The requirement is not just a T&Cs page — it is the active display of your legal business identity and full pricing before the customer commits. A "complete your purchase" button presented before these disclosures are visible creates contractual invalidity risk, not just regulatory exposure.

Not Sure Which Compliance Gaps to Fix First?

We'll review your current site against each legislative requirement and give you a prioritised action list — starting with the obligations that carry the highest enforcement risk right now.

Get a Priority Assessment

Web Accessibility: The Legal Layer Most SA Sites Ignore

South Africa does not yet have a single statute that explicitly mandates web accessibility for private-sector sites. What it does have is a Constitution that prohibits discrimination on the basis of disability, and PEPUDA — the Promotion of Equality and Prevention of Unfair Discrimination Act — that extends that prohibition to digital services.

For government and public-sector sites, the Government Communication and Information System (GCIS) formally requires conformance to at least WCAG 2.2 Level A. Private businesses are not subject to the same formal mandate, but a site that creates barriers for users with disabilities is arguable as unfair discrimination under PEPUDA — with the Equality Court as the enforcement mechanism.

The practical standard that SA developers benchmark against is WCAG 2.1 Level AA, organised around four principles: content must be Perceivable, Operable, Understandable, and Robust (POUR). The most common failures on SA sites are insufficient colour contrast, missing alt text on images, forms that are not keyboard-navigable, and video content without captions.

For a complete accessibility audit framework, our post on web accessibility in South Africa covers WCAG compliance in detail — including automated testing tools and manual audit steps.

Accessibility Is a Business Case, Not Just a Legal One

Excluding users with disabilities from a digital property narrows your addressable market and exposes you to reputational and legal risk. WCAG compliance also tends to improve overall usability — keyboard navigation benefits power users; alt text powers image SEO; sufficient contrast helps users in bright sunlight. Accessibility and performance improvements often move together.

The SA Website Compliance Checklist

Work through each area below before launch — or use it as an audit against your live site:

POPIA

  • Privacy policy live and linked from every page (footer)
  • Privacy policy covers all 10 required disclosures
  • Cookie consent banner present; opt-in only for non-essential trackers
  • Pre-ticked boxes absent from all consent mechanisms
  • Information Officer identified and registered with the Information Regulator
  • Data breach response procedure documented and breach notification portal tested
  • Third-party processors (CRM, email, analytics) documented in your policy

ECT Act

  • Legal business name, physical address, registration number displayed before checkout
  • Full price including VAT and shipping shown before payment page
  • Seven-day cooling-off right communicated to customers in writing
  • 30-day fulfillment commitment confirmed or alternate timeline agreed in writing

Consumer Protection Act

  • Returns and refund policy accessible from the product/service page
  • Direct marketing cancellation rights disclosed (5 business days)
  • No misleading pricing or "bait and switch" product availability claims

Accessibility

  • All images have descriptive alt text
  • Colour contrast ratio meets WCAG 2.1 AA (4.5:1 for body text, 3:1 for large text)
  • All interactive elements reachable by keyboard
  • Forms have visible labels (not placeholder text only)
  • Videos have captions or transcripts

Why South African Businesses Choose Growth Pulse Media for Compliant Web Design

Most web design agencies hand over a site and leave compliance to your legal team. The problem is that legal teams do not always know what is technically possible in WordPress or Shopify, and developers do not always know which ECT Act disclosures are required in which position on the page. The gap between the two is where most SA compliance failures live.

Our web design service is built on Dirk's direct operating experience running and scaling South African e-commerce — having personally navigated POPIA compliance, PayFast and Peach Payments integrations, SARS VAT obligations, and fulfilment logistics with The Courier Guy and Aramex. We build compliance into the IA and copywriting brief, not as a post-launch checklist.

We work with a limited number of clients at a time. Every project is reviewed by senior practitioners who have built sites that actually generate revenue in the South African market — not templated by a junior account team.

If you need a site that is both commercially effective and compliant with SA law from day one, we can assess whether we are the right fit. Our web design process covers how we structure discovery, compliance review, and delivery.

Correct: Compliance embedded at IA stage — privacy policy structure built into sitemap, ECTA disclosures planned in checkout flow, cookie categories mapped to actual trackers before a line of code is written.

Avoid: Site launched, then a cookie banner bolted on, then a privacy policy pasted from a template that does not match the actual data flows. This is the pattern most enforcement actions are built on.

Who This Is NOT For

You want a one-page compliance document that covers everything. There is no single document — POPIA, the ECT Act, the CPA, and accessibility standards are four distinct frameworks, each requiring specific implementation. A single generic "compliance policy" satisfies none of them properly.

You believe compliance is a once-off task. POPIA's regulations were amended in April 2025. The Information Regulator's enforcement emphasis shifts regularly. Cookie consent requirements evolve as tracking technology changes. Compliance is an ongoing maintenance obligation, not a checkbox at launch.

You only trade B2B and assume consumer law doesn't apply. POPIA applies to the personal information of every individual whose data you process — employees, directors, contacts — not only customers. The ECT Act applies to any commercial electronic communication. B2B status does not remove the obligation.

You host offshore and assume SA law can't reach you. POPIA explicitly applies to any foreign entity that processes the personal data of South African residents. The Information Regulator has signalled increasing willingness to pursue cross-border enforcement. Where your server sits does not determine which law applies.

Building a New Site and Want Compliance Built In From Day One?

Tell us your brief and we'll scope a build that delivers commercial performance and full SA legal compliance — without retrofitting either one onto the other.

Start the Conversation

Frequently Asked Questions: Website Compliance South Africa

Does every South African website need a privacy policy?

Yes — any site that collects personal information (contact forms, newsletter sign-ups, analytics cookies) must have a POPIA-compliant privacy policy. Website compliance south africa under POPIA applies from the moment personal information is processed, regardless of business size. The policy must be accessible from every page, typically via the footer, and must cover all ten required disclosures.

What are the POPIA penalties for website non-compliance?

The Information Regulator can issue an administrative fine of up to R10 million for POPIA non-compliance. For more serious offences — obstructing the Regulator, ignoring enforcement notices, or unlawfully processing account data — imprisonment of up to ten years applies. Real fines are already landing: R5 million (Department of Basic Education), R500,000 (Blouberg Municipality), and R100,000 (Lancet Laboratories and FT Rams Consulting) were all issued in 2025.

What does the ECT Act require a South African website to display?

Section 43 of the ECT Act requires every commercial website to display the business's full legal name, physical address (not a PO box), registration number, and contact details before a transaction is concluded. Full pricing — including all taxes, shipping, and additional fees — must also be disclosed before the customer pays. Section 44 gives consumers a seven-day right to cancel most electronic transactions after receiving goods.

Is web accessibility a legal requirement for South African private businesses?

There is no single statute that explicitly mandates WCAG compliance for private-sector sites in South Africa. However, the Constitution prohibits discrimination based on disability, and PEPUDA extends that to digital services — meaning a site that creates barriers for users with disabilities is arguable as unfair discrimination. Government sites must comply with WCAG 2.2 Level A as a formal standard. Private businesses benchmarking against WCAG 2.1 Level AA are well-positioned against current and likely future legal exposure.

How quickly must a South African business notify the Information Regulator after a data breach?

POPIA requires notification "as soon as reasonably possible." The Information Regulator's guidance sets a practical expectation of 72 hours. Since April 2025, all breach notifications must be submitted through the eServices portal — email is no longer accepted. Both the Regulator and affected data subjects must be notified separately, with specific information including the nature of the compromise, the categories of data involved, and the remedial steps taken.

Build a Site That's Commercially Strong and Legally Sound

Growth Pulse Media designs and builds South African websites with POPIA compliance, ECT Act disclosures, and accessible UX built into the architecture — not added after the fact. We work with PayFast, Peach Payments, and SA-specific fulfilment integrations, and we understand the Rand-denominated realities of running a local business. No obligation — we'll get back to you within 24 hours.

Request a Web Design Consultation
Dirk van Greuning — Founder, Growth Pulse Media
Dirk van Greuning Founder, Growth Pulse Media

Founder of Growth Pulse Media and a specialist in South African search dominance. Dirk translates his experience in scaling South African businesses into high-velocity digital strategies for B2B and retail leaders. He writes about SEO, lead generation, and paid media from an operator's perspective — prioritising pipeline value over impressions.

Connect on LinkedIn