POPIA compliance for websites
The Protection of Personal Information Act is South Africa’s data protection law. It commenced on 1 July 2020 and has been enforceable since 1 July 2021, overseen by the Information Regulator. It applies to anyone processing personal information in South Africa, and it is close enough to the GDPR that European teams assume it is identical, which is where the trouble starts.
- South Africa, enforceable since 2021
- Eight conditions for lawful processing
- Information Officer required
From €10 a month. No credit card, no per-visitor billing.
What POPIA asks for
The Act sets eight conditions for lawful processing. Five of them decide what a website has to do.
- Accountability: somebody is answerable for compliance
- Processing limitation: lawful, minimal and justified
- Purpose specification: collected for a defined purpose
- Openness: people are told how their data is processed
- Security safeguards: appropriate technical measures
This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.
What Consent Studio does about it
Asks, and records what was asked
Consent is captured with a timestamp against the wording that was shown, which is what the accountability and openness conditions come down to in practice on a website. A South African visitor can be served the same treatment as a European one.
- Timestamped
- Versioned wording
- Per region
Collects less than the alternative
The processing limitation condition asks for the minimum necessary, and the consent record is built the same way: it evidences a choice without identifying who made it. A compliance record that profiles people works against the condition it exists to satisfy.
- No profile built
- Data minimised
- Retention configurable
Tells you what is running
The weekly scan reports anything setting a cookie or calling a third party without permission, which is how a security safeguards claim stops being an assertion. You cannot safeguard processing you cannot see.
- Weekly crawl
- Every page
- Change alerts
Where POPIA differs from what you expect
Teams that already run a GDPR banner tend to get three things wrong, and all three come from assuming the two laws are the same.
Direct marketing has its own rule
Section 69 requires opt-in consent for electronic direct marketing to people who are not already your customers, and it limits you to approaching a person once for that consent. This is stricter than the general regime and it catches teams who read POPIA as a copy of the GDPR.
Personal information is defined more widely
POPIA covers information about juristic persons, which means companies, not only about living people. A European team that reasons from the GDPR definition will treat business contact data as out of scope when it is not.
Somebody has to be registered
The Act requires an Information Officer, registered with the Information Regulator, who is answerable for compliance. This is an organisational obligation no consent platform can discharge for you, and it is the first thing an auditor asks about.
Essential
€10/month
For a single site that has to be compliant, and stay that way.
- Unlimited pages and displays
- 200,000 consent actions a month
- The full stack, not a starter tier
Professional
€36/month
For growing teams that run on data, and the agencies serving them.
Try Professional for FreeEnterprise
From €250/month
For a volume, or an obligation, a standard plan cannot answer.
Explore EnterpriseAgencies & Resellers
Buy at a partner rate and resell client sites at your own price.
Discover Partner ProgrammePublic Sector
Government, healthcare and education run on Enterprise.
See Enterprise
Running under rules like these, in more than one country
Other rules that may apply to you
Common POPIA questions
Does POPIA apply to my site if I am not in South Africa?
It applies where the processing takes place in South Africa, including where a foreign organisation processes through means located there. If you have South African visitors and use local infrastructure or an establishment there, assume it applies and take advice on the specifics.
Does POPIA require a cookie banner?
The Act does not name cookies, but the processing limitation and openness conditions mean personal information gathered through tracking needs a lawful basis and has to be disclosed. In practice that produces the same answer as the GDPR for most websites: ask, and be able to show what was asked.
How does POPIA differ from the GDPR?
Three ways matter for a website: direct marketing is governed separately and more strictly by section 69, personal information covers companies and not only individuals, and the Act requires a registered Information Officer. The general consent machinery is close enough that one banner configuration serves both.
Who enforces POPIA?
The Information Regulator, which has been able to enforce since 1 July 2021 and can issue enforcement notices and fines. It is also the body an Information Officer registers with, which is the organisational step no software can complete on your behalf.
Does Consent Studio make us compliant?
No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.
Where is our consent data stored?
In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.
Get Started with the Full Consent Stack
Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.
Read the documentation
Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.






