POPIA compliance and data protection for South African accounting firm websites — legal and cybersecurity requirements
Compliance10 min read

POPIA Compliance for Accounting Firm Websites: 2026 Checklist

Zubair Moerat

Zubair Moerat

Co-Founder & Chief Technical Officer

Quick answer

To make an accounting firm website POPIA-compliant: publish a plain-language privacy policy linked from every page, run a genuine-choice cookie consent banner (no pre-ticked boxes), serve all forms over HTTPS, enforce data retention limits (purge unconverted enquiries after 12–24 months), and register your Information Officer with the Information Regulator. Client portals need 2FA, encryption, and access logs on top. Non-compliance risks fines up to R10 million.

The Protection of Personal Information Act (POPIA) came into full effect in South Africa on 1 July 2021. For accounting firms, which routinely collect and process significant amounts of personal and financial information, POPIA compliance on your website is both a legal obligation and a client trust signal. Non-compliance can result in fines of up to R10 million or 10 years imprisonment.

What Personal Information Do Accounting Websites Collect?

Most accounting firm websites collect personal information through: contact and enquiry forms (name, email, phone number, company details), newsletter subscriptions, booking forms, client portal registrations, and tracking cookies (via Google Analytics and similar tools). All of this data is subject to POPIA requirements.

The POPIA Compliance Checklist for Your Website

1. Privacy Policy: Your website must have a clear, accessible privacy policy explaining what data you collect, why you collect it, how long you retain it, who you share it with, and how data subjects can exercise their rights (access, correction, deletion). The policy must be written in plain language and linked from every page of your website.

2. Cookie Consent: Cookies that collect personal data (including analytics cookies from Google Analytics) require informed consent from South African visitors. You need a POPIA-compliant cookie consent banner that gives users a genuine choice and records their preference. Pre-ticked boxes or consent buried in terms and conditions do not comply.

3. Secure Data Transmission: All forms on your website that collect personal information must be served over HTTPS. Enquiry form submissions must be transmitted and stored securely. If you use third-party form tools, verify their POPIA compliance.

4. Data Retention Limits: You cannot retain personal information indefinitely. Your website's privacy policy and backend systems should specify and enforce retention limits. Client enquiries not converted to engagements, for example, should typically be purged after 12–24 months.

5. Information Officer Registration: Under POPIA, South African organisations that process personal information must register their Information Officer with the Information Regulator. This is a free, mandatory registration for any business with a website collecting personal data.

Special Considerations for Accounting Firms

Accounting firms handle special categories of personal information — including financial records, tax numbers, and identity documents — which attract heightened protections under POPIA. Client portals must implement additional security measures: two-factor authentication, encryption at rest and in transit, access logs, and clear data processing agreements with any third-party portal providers.

Need a POPIA-compliant website for your accounting firm? Every Zar Media Group website is built to meet these requirements.

See Compliance & Trust

Frequently asked questions

What does POPIA require on an accounting firm website?

Five things: a clear, plain-language privacy policy linked from every page; a compliant cookie consent banner for any cookies collecting personal data; HTTPS on all forms that collect personal information; enforced data retention limits; and registration of your Information Officer with the Information Regulator.

What are the penalties for POPIA non-compliance?

POPIA non-compliance can result in fines of up to R10 million or up to 10 years imprisonment for serious offences. For accounting firms, which process financial records, tax numbers, and identity documents, the exposure is heightened.

Do Google Analytics cookies need consent under POPIA?

Yes. Analytics cookies collect personal data, so they require informed consent from South African visitors — a banner that gives users a genuine choice and records their preference. Pre-ticked boxes or consent buried in terms and conditions do not comply.

How long can a firm keep website enquiry data?

Not indefinitely. POPIA requires specified, enforced retention limits — client enquiries that never convert to engagements should typically be purged after 12–24 months, and your privacy policy must state the limits you apply.

What extra POPIA measures do client portals need?

Because portals handle special categories of personal information — financial records, tax numbers, identity documents — they need two-factor authentication, encryption at rest and in transit, access logs, and clear data processing agreements with any third-party portal provider.

Zubair Moerat

Written by Zubair Moerat

Co-Founder & Chief Technical Officer, Zar Media Group

Zar Media Group helps accountants and financial service providers reduce admin, attract clients online, and build compliant digital presences — serving financial professionals across South Africa.