Web Design

How Does POPIA Affect the Contact Forms and Cookies on My Website?

Forms need purpose, minimal fields and separate marketing consent. Tracking cookies need consent before they fire. A practical POPIA checklist for a business website.

What POPIA actually requires from a South African business website's forms, cookies and privacy notice.

How Does POPIA Affect the Contact Forms and Cookies on My Website?, Juicy Designs

TL;DR: Quick Answer

Forms need purpose, minimal fields and separate marketing consent. Tracking cookies need consent before they fire. A practical POPIA checklist for a business website.

Key takeaways

  • Very cheap quotes (under R5,000) almost always exclude copywriting, SEO, custom design and post-launch support
  • Professional copywriting can represent 20-35% of a total website project cost, and is worth it for search visibility
  • On-page SEO built into the website at launch costs a fraction of what it costs to retrofit after the site is live
  • Hosting, SSL, domain and maintenance add R3,000-R10,000 per year on top of build cost
  • E-commerce adds significant cost due to payment gateway integrations, product data, security requirements and checkout UX
  • Timeline and client responsiveness directly affect cost: slow feedback rounds extend agency hours

Two things on a website collect personal information: forms and tracking. POPIA governs both, and the requirements are more practical than most compliance writing suggests.

This is a plain summary of what a small business website needs, not legal advice.

Contact forms

Collect only what you need. POPIA requires that collection be minimal and relevant to a stated purpose. If you do not need a physical address to reply to an enquiry, do not ask for one. Shorter forms comply better and convert better, which is a rare alignment.

Say what it is for. A line near the form explaining what you will do with the information, and a link to your privacy notice.

Separate the marketing consent. This is the one most often got wrong. If you want to add the person to a mailing list, that needs its own unticked box, worded specifically. Bundling it into "I accept the terms" is not consent, and neither is a pre-ticked box.

Keep a record. Store the date, time and wording of what the person agreed to. Most form plugins can log this, and it is the evidence you would need if consent were ever questioned.

Secure it. Form submissions should travel over HTTPS and land somewhere access-controlled. Emailing enquiries to a shared inbox everyone can read is worth reconsidering.

Cookies and tracking

Not all cookies need consent. The ones that keep a shopping cart working or remember a login are necessary for a service the visitor asked for.

What needs consent is tracking that can identify or profile a person: analytics with identifiers, advertising pixels, remarketing tags, heat-mapping tools.

The requirement that catches people out is that consent has to come first. A banner that announces "we use cookies" while the tags have already fired does not meet the standard. The banner must hold the marketing and analytics tags until the visitor accepts.

Most consent platforms support this directly, and configuring it is a settings change rather than a development project. Google Tag Manager can also be set up to fire tags only after consent is recorded.

The privacy notice

A page on your site, linked from the footer and from every form, that says:

What personal information you collect. Why you collect it. How long you keep it. Who you share it with, including any overseas processors such as your email platform or analytics provider. How someone can request access to their data, correct it, or have it deleted. Who your Information Officer is and how to reach them.

The Information Officer for most small businesses is the owner, and the appointment should be registered with the Information Regulator.

A practical checklist

ItemStatus to aim for
Form fieldsOnly what you genuinely need
Marketing opt-inSeparate, unticked, specifically worded
Consent recordDate, time and wording stored
Privacy noticeLinked from footer and every form
Cookie consentHolds tags until accepted
HTTPSSite-wide
Information OfficerAppointed and registered
Data retentionA stated period, actually applied

Why it is worth doing properly

Beyond the legal position, consent-based lists perform better. People who chose to hear from you open, click and buy at rates purchased lists never approach, and a visible privacy notice is itself a trust signal for a cautious South African buyer.

The enforcement risk for a small business is real but usually starts with an enforcement notice rather than a fine. The bigger practical cost is a complaint from a customer you were emailing without permission.

Juicy Designs builds compliant forms and consent handling into every site. See web design and website maintenance. Related: POPIA and email marketing and website security and legal requirements.

Frequently asked questions

How does POPIA affect my website's contact forms and cookies?

Forms need a clear purpose, only the fields you genuinely need, and a separate unticked opt-in if you intend to market to the person afterwards. Tracking cookies that identify a person need consent before they fire, which means a consent banner that actually holds the tags rather than one that only announces them.

Do I need a cookie banner in South Africa?

If you run analytics or advertising tracking that can identify a person, yes, and it needs to withhold those tags until the visitor accepts. A banner that says "we use cookies" and sets them anyway does not meet the requirement.

What must a contact form include?

Only the fields you need, a link to your privacy notice, and a separate unticked box if you want marketing consent. Bundling marketing consent into "I accept the terms" does not count as consent.

Do I need a privacy policy page?

Yes. It must say what personal information you collect, why, how long you keep it, who you share it with, and how someone can ask to see or delete their data.

What are the penalties for getting it wrong?

The Information Regulator can issue enforcement notices, and non-compliance can attract fines up to R10 million or imprisonment in serious cases. For most small businesses the realistic risk is an enforcement notice and the reputational cost.

Wynand van der Westhuizen

Creative Director & Co-founder, Juicy Designs, Pretoria

Wynand co-founded Juicy Designs in 2015 and leads creative direction and client strategy. A Meta Business Partner, he owns client relationships across automotive, entertainment, retail and professional services, and reviews published content for accuracy and brand fit.

  • Co-founder & Creative Director, Juicy Designs, established 2015
  • Meta Business Partner
  • 64+ South African clients, 4.9-star Google rating
  • Specialist in brand, creative & paid social
  • Reviewed and updated June 2026