POPIA has been fully enforceable since 1 July 2021. Five years on, we wanted to know what South African business websites actually look like against it — not what owners say they do, but what a machine reading the site can verify.
So we ran an automated scan of 157 live South African business websites and scored each one against eight checks drawn from POPIA and PAIA. The result is not close.
The average score was 33 out of 100. Three-quarters of the sites scored under 40. Only 3% scored above 80. And one failure was almost universal.
How we ran it
We scanned 200 domains and completed 157. The sample was drawn from South African companies in our own database, taking every 26th domain from an alphabetical list rather than hand-picking, so the spread is not biased toward any sector or region.
Each scan fetched the homepage and up to seven further pages, following links to privacy, PAIA, terms and contact pages, and checking the fallback paths those documents usually live on. The scanner identifies itself as ClearComplyBot and respects robots.txt on everything beyond the homepage.
Of the 43 sites not completed, 10 were genuinely unreachable — dead DNS, or a server returning 403 to any automated request. The remaining 33 simply ran past the time limit we set for this particular batch. They are excluded from every percentage below rather than counted as failures.
Two honest limits. This is an automated scan, not a legal audit: it reports what is published and machine-readable on a website, and a business can hold perfectly good internal POPIA documentation while publishing none of it. And a sample of 157 tells you the shape of the problem, not a national statistic.
The results
| Check | Failed | What it maps to |
|---|---|---|
| Information Officer contact published | 95% | POPIA s55 & s56 |
| PAIA manual available | 90% | PAIA s51 |
| Privacy notice written for POPIA, not a GDPR template | 89% | POPIA s18 |
| Data-subject rights explained, with a way to exercise them | 85% | POPIA s23–s25 |
| Privacy notice present at all | 59% | POPIA s18 |
| Trackers paired with a consent platform | 40% | POPIA s11 · RICA |
| Cookie or consent notice present | 29% | POPIA s11 |
| HTTPS enforced, forms submit securely | 0% | POPIA s19 |
Read the last row first, because it is the control. Every single site passed on HTTPS. That is what a solved problem looks like: browsers started shaming unencrypted sites, hosting providers made certificates free and automatic, and the behaviour changed without anyone reading the statute.
Nothing else on that list has had the same forcing function. Which is why the other seven rows look the way they do.
The 95% failure: nobody names an Information Officer
Under POPIA, every private body already has an Information Officer. It is not a role you create — it defaults to the head of the organisation, which for most small companies means the owner or managing director, whether or not they know it.
That person carries real duties: registering with the Information Regulator, ensuring a compliance framework exists, dealing with requests from data subjects, and acting as the point of contact for the Regulator itself. Under PAIA, the same person is responsible for the access-to-information manual.
On 149 of the 157 sites we scanned, there was no way for a member of the public to find out who that person is or how to reach them. Not a wrong name — no name.
This is the single most fixable item on the list. It is a contact block on a page, and it converts an invisible obligation into a visible one. We have written separately on registering your Information Officer with the Regulator, which is the step most businesses skip entirely.
The GDPR template problem
59% of sites had no privacy notice at all. That number is bad but unsurprising.
The more interesting number is 89% — the share whose privacy notice does not read as a POPIA document. Put those two together and it means that of the roughly four in ten sites that do publish a notice, most are publishing something written for a different law.
These are the notices that talk about “legitimate interests” and “the GDPR” and a “supervisory authority”, and never mention the Information Regulator, the eight conditions for lawful processing, or a data subject’s right to lodge a complaint under POPIA. They were bought from a template site, or copied from a UK competitor, and they describe obligations that do not apply and omit the ones that do.
A South African business with a GDPR privacy policy has done the work and still does not have what POPIA asks for.
Trackers running ahead of consent
40% of the sites we scanned load tracking scripts with no consent platform anywhere on the page. 27% load trackers and show no cookie notice at all.
The scripts involved are the ordinary ones — Google Analytics, Google Tag Manager, the Meta Pixel, TikTok, LinkedIn Insight, Hotjar, Microsoft Clarity. They are installed once by whoever built the site, and they start collecting from the first visitor onward.
The uncomfortable part is that this is the failure most likely to generate an actual complaint. An Information Officer nobody has named is an omission the public cannot see. A pixel firing before anyone agreed to it is something a single irritated visitor can screenshot and report.
What the pattern actually says
55% of the sites failed all fourof: privacy notice, Information Officer, PAIA manual, and data-subject rights. That is not a compliance gap, it is an absence — those businesses have not started.
And yet all of them enforce HTTPS. The capability is there. What is missing is the same forcing function that made encryption automatic: nobody has told them, in terms they can act on, what is missing from their own website.
If you run a South African business with a website, the honest reading of this data is that you are probably in the 75% — and that the fix for the biggest single item is an afternoon, not a project.
Check your own site
Our POPIA website checker runs the same eight checks used in this study against any South African website and returns a score with the specific items that failed. It is free, and it does not require an account.
If you would rather work through the wider obligations first, the POPIA self-assessment covers the operational side that a website scan cannot see.
Methodology note: scans were run on 5 August 2026 against live production websites, fetching the homepage plus up to seven linked or fallback pages per site. Scoring treats each non-errored check as pass (1), warn (0.5) or fail (0). This is an automated assessment of publicly published material and is not a legal audit, a certification, or advice on your specific circumstances.