All articles

Average POPIA score across 157 live South African business websites: 33 out of 100.

95% publish no Information Officer contact · 90% have no PAIA manual · 59% have no privacy notice at all · 40% run tracking pixels with no consent platform · only 3% scored above 80.

We Scanned 157 South African Business Websites for POPIA. 95% Fail the Same Check.

5 August 20268 min read·Compliance intelligence

POPIA has been fully enforceable since 1 July 2021. Five years on, we wanted to know what South African business websites actually look like against it — not what owners say they do, but what a machine reading the site can verify.

So we ran an automated scan of 157 live South African business websites and scored each one against eight checks drawn from POPIA and PAIA. The result is not close.

The average score was 33 out of 100. Three-quarters of the sites scored under 40. Only 3% scored above 80. And one failure was almost universal.


How we ran it

We scanned 200 domains and completed 157. The sample was drawn from South African companies in our own database, taking every 26th domain from an alphabetical list rather than hand-picking, so the spread is not biased toward any sector or region.

Each scan fetched the homepage and up to seven further pages, following links to privacy, PAIA, terms and contact pages, and checking the fallback paths those documents usually live on. The scanner identifies itself as ClearComplyBot and respects robots.txt on everything beyond the homepage.

Of the 43 sites not completed, 10 were genuinely unreachable — dead DNS, or a server returning 403 to any automated request. The remaining 33 simply ran past the time limit we set for this particular batch. They are excluded from every percentage below rather than counted as failures.

Two honest limits. This is an automated scan, not a legal audit: it reports what is published and machine-readable on a website, and a business can hold perfectly good internal POPIA documentation while publishing none of it. And a sample of 157 tells you the shape of the problem, not a national statistic.


The results

CheckFailedWhat it maps to
Information Officer contact published95%POPIA s55 & s56
PAIA manual available90%PAIA s51
Privacy notice written for POPIA, not a GDPR template89%POPIA s18
Data-subject rights explained, with a way to exercise them85%POPIA s23–s25
Privacy notice present at all59%POPIA s18
Trackers paired with a consent platform40%POPIA s11 · RICA
Cookie or consent notice present29%POPIA s11
HTTPS enforced, forms submit securely0%POPIA s19

Read the last row first, because it is the control. Every single site passed on HTTPS. That is what a solved problem looks like: browsers started shaming unencrypted sites, hosting providers made certificates free and automatic, and the behaviour changed without anyone reading the statute.

Nothing else on that list has had the same forcing function. Which is why the other seven rows look the way they do.


The 95% failure: nobody names an Information Officer

Under POPIA, every private body already has an Information Officer. It is not a role you create — it defaults to the head of the organisation, which for most small companies means the owner or managing director, whether or not they know it.

That person carries real duties: registering with the Information Regulator, ensuring a compliance framework exists, dealing with requests from data subjects, and acting as the point of contact for the Regulator itself. Under PAIA, the same person is responsible for the access-to-information manual.

On 149 of the 157 sites we scanned, there was no way for a member of the public to find out who that person is or how to reach them. Not a wrong name — no name.

This is the single most fixable item on the list. It is a contact block on a page, and it converts an invisible obligation into a visible one. We have written separately on registering your Information Officer with the Regulator, which is the step most businesses skip entirely.


The GDPR template problem

59% of sites had no privacy notice at all. That number is bad but unsurprising.

The more interesting number is 89% — the share whose privacy notice does not read as a POPIA document. Put those two together and it means that of the roughly four in ten sites that do publish a notice, most are publishing something written for a different law.

These are the notices that talk about “legitimate interests” and “the GDPR” and a “supervisory authority”, and never mention the Information Regulator, the eight conditions for lawful processing, or a data subject’s right to lodge a complaint under POPIA. They were bought from a template site, or copied from a UK competitor, and they describe obligations that do not apply and omit the ones that do.

A South African business with a GDPR privacy policy has done the work and still does not have what POPIA asks for.


Trackers running ahead of consent

40% of the sites we scanned load tracking scripts with no consent platform anywhere on the page. 27% load trackers and show no cookie notice at all.

The scripts involved are the ordinary ones — Google Analytics, Google Tag Manager, the Meta Pixel, TikTok, LinkedIn Insight, Hotjar, Microsoft Clarity. They are installed once by whoever built the site, and they start collecting from the first visitor onward.

The uncomfortable part is that this is the failure most likely to generate an actual complaint. An Information Officer nobody has named is an omission the public cannot see. A pixel firing before anyone agreed to it is something a single irritated visitor can screenshot and report.


What the pattern actually says

55% of the sites failed all fourof: privacy notice, Information Officer, PAIA manual, and data-subject rights. That is not a compliance gap, it is an absence — those businesses have not started.

And yet all of them enforce HTTPS. The capability is there. What is missing is the same forcing function that made encryption automatic: nobody has told them, in terms they can act on, what is missing from their own website.

If you run a South African business with a website, the honest reading of this data is that you are probably in the 75% — and that the fix for the biggest single item is an afternoon, not a project.

Check your own site

Our POPIA website checker runs the same eight checks used in this study against any South African website and returns a score with the specific items that failed. It is free, and it does not require an account.

If you would rather work through the wider obligations first, the POPIA self-assessment covers the operational side that a website scan cannot see.

Methodology note: scans were run on 5 August 2026 against live production websites, fetching the homepage plus up to seven linked or fallback pages per site. Scoring treats each non-errored check as pass (1), warn (0.5) or fail (0). This is an automated assessment of publicly published material and is not a legal audit, a certification, or advice on your specific circumstances.

ClearComply is a private commercial software provider and is not affiliated with, authorized by, or an official agency of CIPC or any government entity. We are not the Information Regulator. Our website check is an automated scan of what a site publishes — it is not a legal audit, a certification, or a finding by any regulator.

ClearComply

All your compliance, tracked in one place

Check your status, follow a step-by-step fix, and track every CIPC, SARS, UIF, COIDA, B-BBEE and POPIA deadline from one dashboard — with automatic reminders before each one. Check, fix, comply, track — from R99/month.

Behind on COIDA? Get expert COIDA help →·Filing CIPC yourself? Try the Co-Pilot →

Got questions?

Pick a question or type your own below.