Compliance, WordPress
|

POPIA for Websites: Forms, Analytics, and AI Tools (2026)

POPIA applies whether your website uses a contact form or an AI chatbot. If you collect names, emails, behaviour data, or chat logs, you need a lawful basis, clear purpose, and security — AI does not exempt you.

This guide covers practical POPIA steps for South African business sites using forms, analytics, and optional AI tools. See web design South Africa and pricing.

What counts as personal information

  • Names, phone, email, ID numbers on forms
  • IP addresses and cookies used to identify users
  • Chat transcripts with customer details
  • Newsletter and marketing lists
  • CCTV or biometric data if you collect it — high sensitivity

POPIA basics for websites

  • Accountability — assign someone responsible internally
  • Purpose limitation — collect only what you need for a stated reason
  • Consent — for marketing cookies and newsletters; clear opt-in
  • Security — HTTPS, access control, backups
  • Retention — delete old leads and logs you no longer need

AI chatbots and forms

If you use ChatGPT widgets or similar:

  • Disclose in privacy policy that chats may be processed by third-party AI
  • Do not paste ID numbers or medical/financial data into public bots
  • Prefer providers with data processing terms suitable for SA
  • Offer a human contact alternative
  • Disable training on your data where the vendor allows

Chat realism: WordPress automation guide.

Analytics and personalisation

Google Analytics, Meta Pixel, and heatmaps process user data. Use cookie consent banners aligned to your actual tags. Anonymise IP where possible. Do not enable every tracker because a plugin suggested it.

Privacy policy essentials

  • Who you are and how to contact you
  • What data you collect and why
  • Third parties (host, email, payments, AI vendor)
  • How long you keep data
  • Data subject rights — access, correction, deletion requests

Ecommerce and POPIA

Orders store addresses and payment references — gateways hold card data, not you. Retain invoices per tax law; delete marketing data when asked. WhatsApp order chats are personal data too.

WhatsApp: WhatsApp sales guide.

Breach response

Have a simple plan: contain, assess impact, notify the Information Regulator and affected people when required, document what happened. Cheap hosting with no backups makes breaches worse.

Security: WordPress security guide.

Cookie banners and marketing

Separate consent for essential cookies vs marketing pixels. Pre-ticked marketing consent is risky. Record when and how users opted in to newsletters — export from your email tool if asked.

What we do on builds

G Web Design adds POPIA-ready privacy pages, consent on forms, SSL, and sensible plugin choices — not legal advice; we recommend a lawyer for complex processing. Sites from R8,000 – R25,000.

Frequently asked questions

Does POPIA apply to small business websites?

Yes, if you process personal information — which most business sites do via contact forms alone.

Can I send customer data to ChatGPT?

Only with disclosure, a lawful basis, and vendor terms you accept — avoid sensitive personal information in prompts.


Need a POPIA-aware WordPress site?

G Web Design helps South African businesses grow online with professional WordPress websites and SEO. Explore our Web Design South Africa service or request a quote.

Similar Posts