Skip to main content
Reverie Digital
Digital Marketing

POPIA compliance for marketers: what it actually means for your list, your forms and your pixels

Reverie Digital26 July 202612 min read
POPIAComplianceEmail MarketingDirect MarketingSouth Africa
South African marketing manager reviewing an email consent record on a laptop

POPIA compliance is not a governance project for someone else in your organisation. It is a specification for the artefacts you own: the lead form, the list, the sequence, the pixel and the CRM field.

Almost every POPIA guide ranking in South Africa was written by a compliance consultant for a compliance officer: appoint an Information Officer, write a policy, run a data inventory. None of it tells you whether you can email the people who downloaded a guide two years ago, whether a WhatsApp broadcast counts, or what happens to your retargeting audience.

This is practical marketing-operations guidance, not legal advice. Confirm your position with a qualified attorney and with the Information Regulator. Several points below are untested in South African courts, and this post says so where that is true.

What POPIA is, and the date it stopped being optional

The Protection of Personal Information Act 4 of 2013 governs how any organisation in South Africa collects, stores, uses and shares personal information. It commenced on 1 July 2020 by proclamation, and section 114(1) gave one year to comply, so the runway closed on 30 June 2021.

Enforcement sits with the Information Regulator. In December 2024 it published something that matters more to marketers than the Act itself: the Guidance Note on Direct Marketing. It is advisory rather than binding, but it is the clearest statement of how the regulator reads the law. The Act sets eight conditions for lawful processing, from accountability to data subject participation, and that is the last abstract sentence here.

Section 69 is the only section most marketers need to memorise

Section 69(1) prohibits processing personal information for direct marketing by any form of electronic communication, including automatic calling machines, fax machines, SMSs or email, unless the person has given consent or is already a customer of yours. Two doors, no third one.

Electronic communication is broader than most teams assume. The Guidance Note lists telephone calls, email, SMS, automatic calling machines, fax, push notifications, direct messages on Instagram and LinkedIn, and the use of cookies. Telephone calls are in because telephony is now predominantly voice over IP, a reading stated in advisory guidance and untested in court.

WhatsApp is not named in the Act or in the Guidance Note, but it is named in the Regulations. The amendment to the POPIA Regulations, published in Government Gazette 52523 on 17 April 2025, lists SMS or WhatsApp among the channels for obtaining section 69(2) consent (regulation 6.1.3) and for lodging an objection (regulation 2.3). Treat a WhatsApp broadcast as caught by section 69.

Section 69(4) requires every marketing message to carry the identity of the sender, or of the party on whose behalf it was sent, and a contact detail for a request that the messages cease. A real from-name, a real reply path, a working unsubscribe: a floor, not a defence.

The existing-customer exception, and the three conditions people skip

Section 69(3) is where most South African email programmes live, and where most are quietly non-compliant. The exception applies only if all three of these are true:

  • The contact details were obtained in the context of a sale of a product or service. Not a webinar registration, not a competition entry, not a business card.
  • You are marketing your own similar products or services. Not a partner's, not a new business line, not the group's other companies.
  • The person was given a reasonable opportunity to object, free of charge and without unnecessary formality, at the time of collection and on the occasion of every communication since.

The third is the one that fails audits. Adding an unsubscribe link in 2024 does not retrospectively create the objection opportunity that should have existed at collection in 2021.

On similar products or services, the regulator gives the clearest worked example South African marketers have: in a clothing retail store, shoes and belts are similar products, whereas funeral insurance cover is not. For a services business the boundary is vaguer: website builds to hosting is probably fine, website builds to a bookkeeping product is past the line, and between those, document your reasoning.

The regulator also closes the common workaround: a customer who was never asked cannot be deemed to have consented, because silence cannot mean consent. A dormant list is not a consented list. The Act also says "is a customer" without defining how long that lasts, so whether a once-off buyer from 2019 still counts is unresolved.

Consent that counts: Form 4, once only, and who carries the burden

POPIA defines consent as a voluntary, specific and informed expression of will. Pre-ticked boxes are not voluntary. "By submitting this form you agree to receive marketing", bundled into a service enquiry, is not specific.

For non-customers, section 69(2) allows you to approach a person whose consent you need, and who has not previously refused, only once, to request that consent. The consequence: the first communication you send to a non-customer must be the one asking permission to market to them. Not a newsletter with an unsubscribe link at the bottom.

The 2025 amendment substituted regulation 6 outright. Under the new regulation 6.1 you take that written consent on a form substantially similar to Form 4, or in any other manner that may be expedient, free of charge and reasonably accessible, including email, telephonically, SMS or WhatsApp, fax or an automated calling machine. Form 4 asks you to specify the goods or services to be marketed, and the person to specify their preferred communication method, which you must then adhere to. Consent taken telephonically or by automated calling machine must be electronically recorded, and that recording, including a transcription, must be made available free of charge on request (regulations 6.2 and 6.3).

Regulation 6.4 settles an argument the industry has been having since 2021: for direct marketing through unsolicited electronic communications, an opt-out does not constitute consent under section 69(2). That now sits in the Regulations, not only in guidance.

Section 11(2)(a) puts the burden of proving consent on you, so every consent record needs the timestamp, the exact wording shown at the time, the source form, the channel selected, and a system identifier. A spreadsheet column that says "yes" proves nothing. Section 11(2)(b) lets the person withdraw at any time, so withdrawal must be as easy to capture as the original grant.

Legitimate interest is real, but it is not a shortcut

Section 11(1)(f) allows processing necessary for pursuing your legitimate interests, and marketers arriving from GDPR reach for it immediately. The Guidance Note treats it as a viable ground for direct marketing that is not by unsolicited electronic communication, meaning post and in-person approaches. It does not override section 69: email, SMS and WhatsApp still need consent or the customer exception.

Where you do rely on it, the regulator expects a documented three-stage Legitimate Interest Assessment before processing begins: a purpose test, a necessity test, and a balancing test against the rights of the person. Fail it and you cannot use this ground. You are back to consent or another section 11 basis, and for electronic channels back to section 69 regardless.

Section 11(3)(b) separately lets a person object to non-electronic direct marketing at any time, on Form 1 or something substantially similar and free of charge. The regulator expects you to keep a database of everyone who has objected and never contact them. That suppression database is an operational artefact, not a policy paragraph.

What your lead capture form has to say before the submit button

Section 18(1) reads like a form design brief once you stop treating it as legal text. When you collect personal information you must take reasonably practicable steps to make the person aware of:

  • What you are collecting, and where it came from if not from them.
  • Who you are, by name and address.
  • The purpose, stated specifically. If direct marketing is a purpose, say direct marketing.
  • Whether supply is voluntary or mandatory, and the consequences of not supplying.
  • Any transfer to a third country, and the level of protection there.
  • Who else will receive the information.
  • Their rights to access, correct and object, and to complain to the Information Regulator, with its contact details.

Section 13 requires that purpose to be specific and defined at collection, which is why "we may contact you about relevant offers" is weaker than naming the programme. You do not have to print all of this beside the email field: a short honest sentence at the point of collection, a linked privacy notice carrying the full section 18 detail, and a separate unticked consent box that is not a condition of the enquiry.

Purchased lists, lead-gen partners and scraped B2B data

A purchased list gives you no consent. Consent under POPIA is specific, and consent given to a third party for that third party's marketing is not consent for yours.

The Guidance Note defines lead generation to include obtaining contact details from third parties who sell or rent lists, and treats sharing, selling or renting contact lists as further processing under section 15, which pulls in the section 18 notification duty. Its illustrations, adopted from the Hong Kong privacy regulator, extend that to your own group: a bank customer who consented to marketing of banking products needs fresh consent before their details go to the bank's insurance subsidiary.

Section 12(2) does permit collection from another source in defined cases, including where the information is in a public record or has deliberately been made public by the person. A visible LinkedIn profile is not someone deliberately publishing their details for your cold outreach, and a bought CSV rarely clears any exception. If your pipeline depends on rented data, rebuild it around consented first-party capture, which is the premise behind how we run digital marketing.

Cookies, pixels and retargeting audiences

The most surprising line in the Guidance Note: the regulator lists the use of cookies among the methods of direct marketing by unsolicited electronic communication.

POPIA has no equivalent of the European ePrivacy cookie regime and there is no South African case law behind that position, but it is the stated view of the body that investigates complaints. The defensible posture is a consent gate that blocks non-essential tracking until the visitor accepts, rather than a banner that fires the pixels on page load and asks afterwards.

Uploading a customer list to build a custom or lookalike audience is further processing under section 15 and, because the platform is almost always offshore, a cross-border transfer under section 72 at the same time.

Your CRM, your ESP and everyone offshore

Section 72 prohibits transferring personal information to a recipient in a foreign country unless a listed ground applies. Most businesses rely on the ground that the recipient is bound by a law or agreement providing protection substantially similar to POPIA, including onward-transfer provisions. Translated into procurement: signed data processing terms with your email service provider, CRM, ad platforms and any offshore agency. Most publish them, and someone has to accept them and file the record. While you are there, kill the myth that POPIA requires local hosting. Section 72 expressly permits cross-border transfer on stated grounds, and a vendor telling you otherwise is selling hosting.

The consequence for a marketing team is that consent state, objection state and suppression cannot live in a spreadsheet. They belong in the platform that sends the messages, which is a marketing automation problem, and they need one system of record when the same person exists in your CRM, your ESP and your ad platform, which is a data orchestration problem.

The layer no checklist mentions: the NCC opt-out registry

Every generic POPIA checklist currently ranking predates this, and it is the most time-sensitive item on your desk.

Amendments to the Consumer Protection Act regulations establishing a national opt-out registry, run by the National Consumer Commission, were gazetted on 15 April 2026. Direct marketers must register with it, and must remove consumers who have opted out from their lists before marketing to them. Non-compliance may attract an administrative penalty of up to R1 million or 10 percent of annual turnover, whichever is greater. The commission said registration of direct marketers and consumers would commence in July 2026, and its announcement refers to registration, renewal and cleansing fees without stating the amounts or the renewal period.

Practitioner reporting puts the 2026 registration fee at R2 574, a cleansing fee of 12 cents per record, a registration window running from 1 July to 30 September 2026, and full compliance expected from 1 October 2026 with databases cleansed monthly. Those figures and dates come from that reporting rather than from the commission's own announcement, so confirm the tariff and the deadline with the NCC before you plan around them.

The consumer-facing opt-out registry portal also restates the restricted contact hours: no direct marketing on Sundays and public holidays, on Saturdays before 09h00 or after 13h00, or on any other day between 20h00 and 08h00 the following day.

This sits on top of POPIA, not instead of it. The Guidance Note states that even where a person has not registered a pre-emptive block, you must still comply with section 69, because the absence of a block is not consent. Whether a valid earlier POPIA consent survives a later block is unresolved, so honour the block.

Does POPIA apply to B2B and to one-person businesses?

Yes, and this is where South African marketers who learned their habits from GDPR content go wrong.

POPIA defines personal information as information relating to an identifiable, living, natural person and, where it is applicable, an identifiable, existing juristic person. A named individual at a company is personal information regardless of whether the address ends in a company domain, and a sole proprietor is a natural person, full stop. The qualifier "where it is applicable", attached to juristic persons, has not been judicially interpreted, so company-level protection is arguable. The individual-level point is not.

One entity-level obligation does land on small businesses: the head of a private body is automatically the Information Officer by virtue of their position, and registration with the Information Regulator is compulsory and a prerequisite to taking up the duties, through the regulator's eServices portal.

What enforcement has actually looked like

In February 2024 the Information Regulator issued an enforcement notice against FT Rams Consulting for contravening sections 69(1) and (2) by sending persistent marketing emails without first obtaining consent. Three details matter operationally. Although the recipient could opt out, the regulator said this did not remedy the situation. The first message should have been the consent request, on the prescribed form, whose use the regulator described at the time as compulsory, before the 2025 amendment opened the alternatives above. And the company was ordered to compile a database of people who withheld or did not give consent, submit that database design to the regulator, and demonstrate compliance within 90 days.

An unsubscribe link is not a cure. A suppression database is an ordered remedy.

Section 109(2)(c) caps an administrative fine imposed by infringement notice at R10 million, and failing to comply with an enforcement notice is a separate criminal offence for which section 107(a) provides a fine or imprisonment not exceeding 10 years, or both. The enforcement notices register shows a regulator that has been willing to act, though its other notices concern other subject matter.

A POPIA compliance checklist for the next two weeks

Ordered by risk, not effort.

  1. Segment your list by provenance. Where each segment came from and what the person was told. Anything you cannot answer goes to quarantine.
  2. Separate customers from non-customers. Two legal positions under section 69, so two audiences in your platform.
  3. Fix the objection route. One click, free, no login wall, honoured on every channel including WhatsApp and SMS.
  4. Build the suppression database and make it authoritative. Every send checks it, and a re-import never overwrites it.
  5. Rewrite your lead forms to section 18. Purpose stated, consent unticked and separate from the enquiry, privacy notice linked.
  6. Log consent properly. Timestamp, wording, source, channel. Assume you will have to produce it.
  7. Get signed data processing terms with your ESP, CRM, ad platforms and any offshore contractor.
  8. Confirm your Information Officer is registered with the Information Regulator.
  9. Register with the NCC. Registration was due to open in July 2026, so confirm the current deadline with the commission and build registry cleansing into your send process.

Most of this is a few days in your automation platform and an afternoon with your forms. It does not get done because it sits between marketing, legal and IT, and nobody owns it. If you want a second pair of eyes on where your list came from and what your stack is doing with it, talk to us about your list.

Ready to Get Started?

Let's discuss how we can help transform your business with AI and digital strategies.