Compliant
POPIA and your dental website: the gap almost everyone has
The most common POPIA gap on a dental website is hiding in plain sight: the contact form. It quietly collects a patient's name, phone number and email — and often a few lines describing their dental problem — and on most practice sites there is no privacy notice anywhere explaining what happens to that information. POPIA, South Africa's data-protection law, has been enforceable since July 2021; the Information Regulator can fine up to R10 million, has already issued R5 million fines, and has named data handling and direct marketing priority areas for enforcement. This is not a box-ticking nicety.
It matters more for a dental practice than for most small businesses, because of what you collect. Health information is treated as "special personal information" under POPIA, which carries a higher bar than ordinary contact details. A contact form that asks "what is the problem?" is gathering exactly that — special, protected information — and a site that collects it with no notice, no consent and no thought to where it is stored is exposed in a way a plumber's contact form is not.
Start with what goes on the site itself:
On your website
- Put a clear privacy policy on the site. A plain page stating what you collect, why, how long you keep it, who can see it, and the patient's rights. If you collect personal information — and a contact form does — this is the baseline.
- Make the consent real. It must be specific, informed, separate from your general terms, and something the patient can withdraw. No pre-ticked boxes, and nothing buried in fine print.
- Add a cookie notice if you need one. If the site runs analytics or other cookies that collect personal information, POPIA expects a consent mechanism, not silent tracking.
A privacy policy is the visible, easy part — and the part everyone eventually adds. The obligation almost everyone skips sits off the website entirely, and it is the one the Regulator actually checks when it investigates:
The part almost everyone misses
- Register your Information Officer. Every practice must appoint an Information Officer (by default the practice owner), register that person with the Information Regulator, and keep a PAIA manual. People assume the website privacy policy is the whole job. It is not — and unregistered Information Officers are exactly what the Regulator finds when a complaint comes in.
- Get consent before marketing to patients. Emailing or texting patients with promotions needs their consent under POPIA's direct-marketing rules — an area the Regulator has flagged for enforcement.
In the sites we audit, this is close to universal: a contact form collecting personal and often health details, with no privacy policy anywhere on the site, and — almost always — no Information Officer registered behind the scenes. The practice is not being careless on purpose; it simply does not know the form is a liability. Do both parts, not only the one that shows.
We build the privacy notice and proper consent into a site as standard, so the website side is handled the day it goes live. The registration itself is yours to do — it is a legal appointment, not a web setting — but it is quick, and we will point you to exactly where it happens.
General guidance on POPIA as it applies to a website, not legal advice. POPIA compliance reaches well beyond your site, so treat this as a starting point and get proper advice for the rest.