free wordpress plugin POPIA compliance

POPIA compliance
for WordPress.

Add a compliant cookie consent banner, privacy notices, and data subject rights to your WordPress site, in minutes, no developer needed.

What is POPIA?

The Protection of Personal Information Act (POPIA) is a data-protection law that applies to organisations collecting or processing personal data from residents of South Africa. If your WordPress site receives visitors from South Africa, through organic search, ads, or direct traffic, you are subject to POPIA, regardless of where your business is based.

Under POPIA, websites must lawful processing of personal information, data subject rights, and mandatory breach notification. No pre-ticked boxes, no bundled consent, no tracking before the user agrees. Violations can result in fines of up to ZAR 10 million or 10 years imprisonment for responsible parties.

Most WordPress sites are not compliant by default. Analytics scripts, advertising pixels, and embedded content often fire before any consent is given. Cirv Comply fixes this, it blocks all non-essential scripts until the user actively consents, with a documented audit trail.

what cirv comply does

Technical POPIA coverage, built for WordPress.

cookie consent banner

A fully customisable consent banner that appears before any non-essential scripts load. Visitors choose their preferences, analytics, marketing, functional, and Cirv Comply respects that choice site-wide.

privacy policy generator

Generate a compliant privacy policy template tailored to POPIA requirements. Auto-update when you add new data processing activities.

script blocking

Automatically blocks Google Analytics, Meta Pixel, HotJar, and other tracking scripts until consent is granted. No manual code changes, works with any plugin or theme.

data subject rights

Provides opt-out mechanisms and data request forms so visitors can exercise their POPIA rights. Consent records are stored with timestamps for your audit trail.

The cost of non-compliance

POPIA regulators are actively enforcing penalties. Fines can reach up to ZAR 10 million or 10 years imprisonment for responsible parties. Enforcement actions target sites of every size, not just large corporations. Beyond fines, non-compliance erodes visitor trust; a missing consent banner signals a site doesn't take privacy seriously.

setup

POPIA compliant in 3 steps.

01

install cirv comply

Search "Cirv Comply" in your WordPress plugins dashboard, install, and activate. No configuration files or server access required.

02

configure your banner

Select POPIA as your compliance mode. Customise the banner text, colours, and cookie categories to match your site's data practices.

03

verify & go live

Preview the consent flow on your site, confirm scripts are blocked before consent, and publish. Cirv Comply handles the rest automatically.

faq

POPIA + WordPress questions.

Does my WordPress site need POPIA compliance?

If you receive visitors from South Africa and collect any personal data, including via analytics or contact forms, yes. POPIA applies to data controllers worldwide, not just those based in South Africa.

Does Cirv Comply work with Google Analytics and Meta Pixel?

Yes. Cirv Comply automatically blocks Google Analytics, Google Tag Manager, Meta Pixel, and other common tracking scripts until the visitor grants consent. Scripts load normally after consent.

Is the free version enough for POPIA?

The free version covers the core requirements: consent banner, script blocking, and basic cookie categorisation. Pro adds consent logging, geo-targeting, and A/B testing for banner copy.

ship it

Get POPIA compliant today.

Cirv Comply is free and takes under five minutes to configure. Stop leaving your site exposed, get compliant before a complaint lands.