Free POPIA website check · no signup

Is your website showing the Regulator a compliance gap?

We check the eight POPIA essentials a visitor — or the Information Regulator — can see from outside your site: your privacy notice, your PAIA manual, your Information Officer details, how someone exercises their data-subject rights, whether your forms are secure, and whether tracking scripts fire before anyone consents. Results on screen in under a minute.

Free POPIA website check

Enter your website address.

We read only what your site already publishes — the same pages any visitor can open. No signup: you get your score, all eight checks marked, and one finding in full — free, on screen and by email. The complete report, the fixes and the document templates are R19 once-off.

We scan publicly visible pages only and email the report to you. No signup needed.

What a POPIA gap actually costs

The fines are real — and they land after the warning is ignored.

R10m
Maximum administrative fine

The ceiling under POPIA. The two fines issued so far are exactly half that — R5 million each, against the Department of Justice in 2023 and the Department of Basic Education in December 2024.

40%
Rise in breach notifications

Year-on-year growth in reported security compromises in the Regulator’s 2024–2025 period, with over 2,000 notifications. Its spokesperson has said publicly that more fines are coming.

0
Fines for the breach alone

In every case so far the penalty followed an enforcement notice that was not acted on. Businesses that close the gap when it is flagged tend not to be fined. The risk sits with those who never knew the gap was there.

What we found across 4,221 SA business websites

You are almost certainly not the exception. Most sites fail the same checks.

95%

Publish no Information Officer

The single most-missed obligation. Every South African company already has an Information Officer by default — usually the owner — whether anyone has been told or not.

91%

Have no PAIA manual

Section 51 of PAIA requires a private body to compile one and make it available. It is the gap with the clearest fix — a document, published once.

88%

Run a GDPR notice, not a POPIA one

A privacy notice adapted from a European template names the wrong law, the wrong regulator, and the wrong rights. It reads as compliance and is not.

From our own scan of 4,221 live South African business websites on 5 August 2026. Average score: 31.8 out of 100. Read the full methodology.

Want to read up first? Our POPIA guides.

All compliance guides
4,221
SA business websites scanned for our benchmark
8
POPIA and PAIA checks run against your site
<1 min
From your address to results on screen
Free
The check, your score and one finding — no signup, no card
Questions business owners ask us

The honest answers.

Is this a legal audit or a certification?

No, and we will not pretend otherwise. This is an automated read of what your website publishes — the pages any visitor can open. It cannot see how you actually handle personal information inside your business, which is the larger part of POPIA. For a legal opinion you need a qualified attorney or a POPIA specialist. What this gives you is a fast, honest first look at whether the basics are in place.

Does POPIA really apply to a small business?

Yes. POPIA applies to every business that processes personal information about South Africans, regardless of size. A contact form, a newsletter sign-up, a booking system or analytics running in the background all count. The enforcement cases so far have involved large organisations, but the law itself draws no line at company size.

What do you do with my website address and email?

We scan the address you give us and email you the report. Your address is not sold or shared with third parties for marketing. You can reply to any email from us and ask to be removed, and we act on it.

Will scanning my site break anything?

No. We only fetch pages the same way a visitor’s browser does, and we do not submit forms, log in, or write anything. The scan is read-only.

My site scored badly. What now?

Start with the cheapest fixes. Registering an Information Officer with the Regulator is free and takes under 30 minutes. A PAIA manual is a document you publish once. A privacy notice written against POPIA rather than GDPR is a rewrite, not a rebuild. The report walks each gap in the order worth doing them.

Are you the Information Regulator?

No. ClearComply is a private software company. We are not the Information Regulator and this check is not a finding by any regulator — it is our own automated read of your published pages.

One minute, no signup

Find out where your website stands before someone else does.

Check my website →