Guides · Updated 06 Aug 2026
What POPIA requires on your law firm's website
If your website has a contact form, you are collecting personal information, and Section 18 of POPIA requires you to tell people specific things when you do. Most law firm websites we review either have no privacy notice, or one that describes a business the firm isn't.
There's an obvious irony here, and it's worth saying out loud: attorneys advise clients on POPIA compliance more often than most professions, and law firm websites fail it about as often as anyone else's.
Not through negligence. Through the same reason most website faults exist — somebody built it once and nobody looked again.
This article is not legal advice. You'll appreciate the absurdity of that sentence more than most readers would. It's a description of what the Act requires, written by people who build websites, and it's a starting point for a conversation with someone qualified — which, in your case, may well be the person at the next desk.
The trigger is lower than firms assume
POPIA applies when you process personal information. A name and an email address in a contact form is personal information.
So the threshold isn't "do we run a database." It's "does anything on our site collect anything about anybody."
That includes:
- Contact and enquiry forms
- Newsletter signups
- Consultation booking forms
- Analytics that identifies users
- Cookies that track behaviour
- Live chat
Most firm websites do at least two of these.
What Section 18 requires you to disclose
Section 18 requires a responsible party to take reasonably practicable steps to make the data subject aware of the following at the point of collection:
- What information is being collected, and where it isn't collected from the person themselves, the source it came from
- The name and address of the responsible party — your firm
- The purpose the information is being collected for
- Whether supplying it is voluntary or mandatory
- The consequences of not supplying it
- Any law that authorises or requires the collection
- Whether you intend to transfer the information outside South Africa, and the level of protection there
- Further information as is necessary in the circumstances — including who receives the information, the right of access and correction, the right to object, and the right to complain to the Information Regulator
A privacy notice on your website is the ordinary way of satisfying this.
Point 7 catches nearly everyone. If your website is hosted outside South Africa, if you use Google Analytics, if your email runs on Google Workspace or Microsoft 365, or if your form sends through an international service — information is leaving the country. That has to be disclosed.
Most law firm privacy policies we read don't mention it, usually because the person who supplied the template didn't know where the site was hosted.
Cookies need consent, not notice
POPIA works on an opt-in basis. Where cookies collect personal information, you need permission before setting them — not a banner announcing that you have.
The practical difference:
| Not sufficient | Sufficient |
|---|---|
| "By using this site you accept cookies" | A choice, made before non-essential cookies load |
| A banner with only an "OK" button | Accept and decline both available |
| Analytics running before any choice is made | Analytics loading only after acceptance |
A banner where "decline" does nothing is worse than no banner. It documents that you knew the requirement existed.
The PAIA manual
Separate from POPIA, and frequently missed on websites.
The Promotion of Access to Information Act requires organisations to maintain a manual, and its requirements were amended to align with POPIA — including recording the details of the information officer and deputy information officers.
The website obligation is straightforward: it needs to be available. Most firms that have one keep it in a folder rather than on the site.
If you have a manual, link it in your footer. If you don't, that's a separate conversation with someone who does PAIA work.
Your Information Officer
Every organisation subject to POPIA must have an Information Officer. For a firm, that defaults to the head of the firm unless someone else is designated.
Two practical points that catch people:
The role must be registered with the Information Regulator. It's a real administrative step, and it's the one most commonly skipped.
The name and contact details should appear in your privacy notice. A notice telling people they have a right of access, without telling them who to ask, doesn't achieve much.
The bit specific to law firms
Everything above applies to any South African business. This part doesn't.
Your contact form receives more than a name. A person filling in "tell us about your matter" may describe a divorce, a retrenchment, an assault, or a debt. Under POPIA that's special personal information, and it arrives before anyone is your client.
Three things worth thinking about:
Where does the message actually go? If enquiries land in a shared inbox that four people read, that is a processing decision you've made without recording it.
Say what happens to it. A line under the form — what it's used for, who reads it, how long it's kept — costs one sentence and does most of the work of building trust with someone about to describe something difficult.
Don't ask for more than you need. A form requesting ID number, address and date of birth before a first conversation collects information you have no purpose for yet. Minimisation isn't just good practice; it's a condition of lawful processing.
What to check on your own site
| Check | |
|---|---|
| 1 | Is there a privacy notice, and can you find it in ten seconds? |
| 2 | Does it name your firm, your address, and your Information Officer? |
| 3 | Does it mention cross-border transfer? |
| 4 | Does it describe your firm, or a business you aren't? |
| 5 | Is there a cookie consent mechanism, and does declining actually decline? |
| 6 | Does the contact form say what happens to the message? |
| 7 | Is your PAIA manual linked? |
| 8 | Is your Information Officer registered with the Regulator? |
Numbers 3 and 4 are where most templated policies fail. A policy referring to "our products" or "customers" was written for a shop.
Where to check the Act yourself
The full text of POPIA is publicly available, and Section 18 is short enough to read in five minutes. The Information Regulator publishes guidance notes and the Information Officer registration portal.
Given who you are, you'll get more out of reading the section than out of reading us describing it.
We check all eight of the above on every site we review, alongside about fifty other things. Send us your URL and we'll email you what we find — free, whether you hire us or not.
Related guides
Check your own law firm website in twenty minutes
Twelve checks from our sixty-check audit — the ones that need nothing but a phone. Most firms find three or four faults they didn't know about.
Who actually owns your law firm's website?
Four separate questions. Most firms have never asked any of them, and find out the answers at the worst possible moment.
How to tell whether your contact form is actually working
Submit it yourself. Most firms never have. Here are the four ways a contact form fails without telling anybody.