Skip to content
Monday, 7 September 2026Independent trade title · JohannesburgPublish with us
Media Marketing Advertising
Trade reporting for the South African communications industryAdvertise
Business

POPIA Marketing Rules in Practice: What South African Marketers Can and Cannot Do With Customer Data

Consent, legitimate interest, direct-marketing rules, data-subject requests and the operational habits that keep a marketing database lawful.

By the AdVantage Desk · 7 September 2026 · 5-minute read
POPIA Marketing Rules in Practice: What South African Marketers Can and Cannot Do With Customer Data
EFTA00002522 Cluttered server rack filled with colorful cables and networking equipment. Photo: Federal Bureau of Investigation · Public domain · Wikimedia Commons

Unsolicited marketing by email, SMS, phone or other electronic means is unlawful in South Africa, according to section 69(1) of the Protection of Personal Information Act (POPIA). The only way an organisation can lawfully conduct electronic direct marketing is with the data subject’s consent or if the data subject is an existing customer and the organisation can meet certain conditions.

The Information Regulator for South Africa has issued a Guidance Note on Direct Marketing[REF]4[/REF] that makes this opt-in regime concrete for marketers and CRMs. For any organisation managing a marketing database and planning out email or SMS campaigns, getting the consent flows and opt-out processes right is critical to avoid notice, fines, or worse.

POPIA’s Direct Marketing Cornerstone: Section 69

In essence, section 69 says that unsolicited electronic direct marketing to a data subject (for example via email, SMS, phone call, or WhatsApp) is prohibited unless you have that person’s consent or they are an existing customer that meets certain conditions.[REF]1,2,3,4[/REF]

POPIA’s definition of direct marketing is broad – it’s any form of communication to promote, offer or advertise a good or service (or encourage donation to a charity) which is targeted at a specific data subject using their personal information.

The upshot of this is that, if you’re building a marketing database or planning an email campaign, call list or SMS blitz under section 69, the law is clear: you must obtain the data subject’s consent, and if you can’t prove it, you can’t just keep dialling.[REF]1,2,3,4,11,12,13[/REF]

This isn’t a case of you might go to jail for marketing without proper consent – the Information Regulator has enforcement powers and has already taken action against organisations that flout the regime, as evidenced by a 2023 enforcement media statement.[REF]13[/REF]

Consent Under POPIA: Voluntary, Specific and Informed

Section 69(1)(a) of POPIA only permits consent for unsolicited electronic direct marketing, and that consent must be clear, positive, freely given, specific and informed.[REF]1,11,13[/REF]

Taking consent “at the time of collection” – in other words, when you collect a person’s information (such as on a trade-show lead form or entry to a prize draw) – is a good approach, but still has to meet the standard of voluntariness, specificity and information.[REF]1,11,13[/REF]

Section 69(2) then requires that, if you reject a consent request, you may only approach the data subject once to obtain their consent.[REF]2[/REF]

This has implications for how you must treat non-customers or newly acquired contacts. If you collect a person’s details for a prize draw, and they’ve not consented to direct marketing, you then have just one chance to ask for their consent to your future emails or calls – and you can’t just keep approaching them, hoping to get a positive answer. At every stage, you have a positive obligation to honour a decline of your request.[REF]2,11,13[/REF]

Existing Customers and the Narrow Exemption

While section 69(3) gives organisations that are marketing their own goods or services to their own customers limited extra room to contact them, the exemption is far from automatic.[REF]3,8,9,11,12[/REF]POPIA’s approach to these “existing customers” is noticeably more generous for postal direct marketing (under the “legitimate interest” model in section 11) than for electronic direct marketing. Operations can get more relaxed when following up with postal mail, in-person solicitation, or a call to a client. But once you want to move to email, SMS or any other electronic “unsolicited communication,” section 69’s consent rules bite.

If you’re marketing your similar goods or services to an existing customer, the data subject still has the right to opt out, so you must give them that opportunity free of charge and in an easy manner when you ordinarily collect their data (for example by offering a box to tick on an ecommerce checkout). You must also remind them that they can withdraw their consent to electronic marketing at any stage, and not just once or by the last email. [REF]3,4,5,6,8,11,12[/REF]

Electronic vs. Non-Electronic Direct Marketing

While section 69 only applies to electronic direct marketing, marketers have to switch gears when pursuing a target in person, in post, or without electronic contact, such as by a P2P call from a live telesales operator.[REF]4,9,10[/REF]

Section 11(3)(b) allows the processing of a person’s information for “the legitimate interest of the responsible party or third party”, so long as the data subject isn’t subjected to “unreasonable intrusion into their personal life, which includes, but is not limited to, lengthy surveillance, persistent telephone calls or the continual sending of correspondence.” The Guide explains the responsible party must also be able to identify each legitimate interest they rely on; it can never be assumed that a reputable company is acting in good faith.

Submitting to a legitimate business interest is a little different from consent, so marketers must map their different customer segments (prospects, existing customers, special groups and the like) and inbound/outbound channels correspondingly. It’s arguably trickier because of the legal uncertainty around what is and isn’t a “reasonable” communication, so keeping track of objections and unresponsiveness becomes still more important.[REF]4,5,8,9,10[/REF]

Habits that protect Marketing Databases

Under section 69, what’s necessary is an atomic, updated record of every individual’s consent, access to Form 4 during every first contact, a clean classification of customers and prospects, a clear “opt-out” on all messages, and a clear response system for any inquiries.[REF]6,7,11,12,13,14[/REF] During email campaigns, keep an eye on where your team is storing that consent, and keep it there so it can be easily reviewed and produced.

While an affidavit is not a common enterprise risk, breezy consent collection and unaudited Opt Out tables can generate one.

Note that you can script your calling operations to ensure that outbound calls are properly recorded, perhaps using a third-party broker’s Form 4, and that you can draft canned SMS or email send-outs to include the prescribed opt-out language.

The Regulator’s Enforcement Signals

The case highlighted how the regulator views common consent breaches. marketers must take care to ensure that any consent they seek is “voluntary, specific and informed,” and that a deliberate communication is always specified. Consent can’t just appear as an unstated option on a spreadsheet.

The media statement makes clear that organisations that collect contact details (for example at exhibitions or events) must obtain consent from the data subjects at that point. Only then, they may approach them once to ask for their permission to send direct marketing messages; once more for asking, a further attempt at voluntary consent does not apply. If a person rejects the marketing request, they must be taken off the mailing list.

Lower level breach redress may look like guidance from the regulator but what’s important is that POPIA settlements can get to where it hurts, quite literally, depending on the egregiousness of the breach.

The Information Regulator’s interpretation and enforcement, you see, is what gives the law its teeth. What’s practically important is that marketing teams who build consent tracking, customer/prospect separation, and reliable opt-out handling into their databases and campaigns are the ones who will stay on the right side of both the POPIA language and the regulator’s close reading of it – and their business deserves to flourish.[REF]4,11,13,14[/REF]

Sources consulted
Government of South Africa, Protection of Personal Information Act 4 of 2013 (official PDF hosted by National Treasury), 2013-11-26
Government of South Africa, Protection of Personal Information Act 4 of 2013 (official PDF), 2013-11-26
Government of South Africa, Protection of Personal Information Act 4 of 2013 (official PDF), 2013-11-26; Information Regulator, Guidance Note on Direct Marketing in terms of POPIA, 2021 (PDF)
Government of South Africa, Protection of Personal Information Act 4 of 2013, 2013-11-26; Information Regulator, “Media Statement: Enforcement Notice on Direct Marketing Complaint” (PDF), 2023-06-08
Information Regulator (South Africa), “Guidance Note on Direct Marketing in terms of POPIA” (PDF), published via Guidance Notes page, 2022-03-04
Information Regulator, “Guidance Note on Direct Marketing in terms of POPIA” (PDF), 2022-03-04; DLA Piper Africa, “Data Protection – Guidance Note on Direct Marketing,” 2025-06-25
DLA Piper Africa, “Data Protection – Guidance Note on Direct Marketing,” summarising Information Regulator guidance, 2025-06-25
Information Regulator, “Guidance Note on Direct Marketing in terms of POPIA” (PDF), 2022-03-04; Information Regulator, POPIA FAQ page, 2025

More in Business

The economics of the industry: adspend, ownership, regulation and compliance.Section index ›