POPIA marketing compliance in South Africa is not a single rule — it is three overlapping legal frameworks that govern different channels in different ways, and the most common mistake SA businesses make is reaching for "consent" as the default answer when it is often the wrong one. This post covers website compliance under SA law from a marketer's perspective: what POPIA's six lawful processing grounds mean for your campaigns, how section 69 governs electronic direct marketing, and what the 2026 Consumer Protection Act opt-out registry adds on top.

The Information Regulator issued its first formal Guidance Note on direct marketing in December 2024 and shifted to proactive compliance assessments in 2026. If your business runs email campaigns, SMS flows, cold outreach, or lead-gen forms, this is what you need to know before your next send.

Quick Answer

South African popia marketing compliance requires satisfying three frameworks simultaneously: POPIA section 11 (the lawful ground for processing personal information), POPIA section 69 (which requires consent or the existing-customer exception for electronic channels — email, SMS, and telephone), and the 2026 CPA Amendment Regulations (which added a National Consumer Commission opt-out registry that all direct marketers must register on and cleanse against monthly). Non-compliance exposes you to administrative fines up to R10 million under POPIA and up to R1 million or 10% of annual turnover, whichever is greater, under the CPA.

Is your current marketing stack POPIA-ready?

Send us your channel list and we'll show you where your consent flows and data-processing grounds need attention.

Get a Free Compliance Review

POPIA Marketing Compliance Involves Three Overlapping Frameworks

South African direct marketing operates under three concurrent legal frameworks — POPIA section 11 (the lawful ground for processing personal information), POPIA section 69 (the rule for electronic channels), and the 2026 CPA Amendment Regulations (the National Consumer Commission opt-out registry) — which all apply simultaneously and cannot substitute for one another. Understanding which layer addresses what is the starting point for building a defensible marketing operation.

FrameworkWhat It GovernsAdministered By
POPIA Section 11The lawful ground for processing personal information at allInformation Regulator
POPIA Section 69Unsolicited electronic direct marketing specifically (email, SMS, telephone)Information Regulator
2026 CPA Amendment RegulationsNational opt-out registry, marketer registration, monthly database cleansingNational Consumer Commission

These are not alternatives — satisfying the CPA opt-out registry does not remove your POPIA obligations. You must satisfy all three.

What Does POPIA Section 11 Actually Say About Processing for Marketing?

Section 11 of POPIA lists six lawful grounds for processing personal information — consent is only one of them, and for most everyday marketing processing it is often the wrong choice. The six grounds are: consent, contract, legal obligation, the data subject's vital interests, public law duty, and legitimate interests of the responsible party or a third party.

The Six Lawful Grounds (POPIA Section 11)

  1. Consent — voluntary, specific, informed agreement from the data subject
  2. Contract — processing necessary to conclude or perform a contract with the data subject
  3. Legal obligation — processing required by law
  4. Vital interests — processing to protect the data subject's life or health
  5. Public law duty — processing by a public body for a statutory function
  6. Legitimate interests — processing necessary for the responsible party's or a third party's legitimate interests, where not overridden by the data subject's rights

For marketing purposes, section 11 determines how you can collect and hold customer data in the first place. A retailer who collects a customer's email during checkout can justify that collection under contract — the email is needed to send the order confirmation. A B2B company prospecting from a business directory can potentially rely on legitimate interests for collecting contact details.

Neither of those requires consent under section 11 — but section 69 then adds a separate requirement before you can send that person a marketing message via electronic channels. Meeting all popia marketing requirements means understanding both sections. Confusing section 11 and section 69 is the root of most POPIA marketing compliance 2026 failures.

Key Point

Consent under POPIA is not a master key. It is one of six lawful grounds for processing, and for electronic direct marketing it works alongside — not instead of — the section 69 rule. Many businesses overcollect consent, creating legal fragility: if a data subject withdraws consent, you lose the processing ground entirely, whereas a contract or legitimate-interests ground is more durable.

How POPIA Section 69 Governs Electronic Direct Marketing

Section 69 of POPIA is the specific rule that controls unsolicited POPIA direct marketing South Africa businesses run via electronic channels — and it operates separately from section 11's general processing grounds. The section 69 POPIA electronic marketing rule is straightforward: under section 69(1), a responsible party may not send direct marketing to a data subject by electronic means unless one of two conditions is met: the data subject has given consent, or the existing-customer exception under section 69(3) applies.

The Existing-Customer Exception (Section 69(3))

The existing-customer exception allows you to market to current customers without prior consent, but three conditions must all be met:

  • You obtained the contact details in the context of a prior transaction (a sale or service engagement)
  • You are marketing only similar products or services to those in the original transaction
  • You offered a reasonable, free, and easy opportunity to opt out — at the point of collection and in every subsequent marketing message

The exception covers the same product or service category. An online clothing retailer can email a customer who bought a dress to promote another dress collection. Promoting a financial product to that same customer falls outside the exception and requires fresh consent.

The One-Contact Limit for Consent Requests (Section 69(2))

When building a consent-request flow for cold prospects, section 69(2) imposes a hard operational cap: a responsible party may approach a data subject only once to request consent for electronic direct marketing. If the data subject does not respond or declines, no further contact to request consent is permitted. This means a multi-touch "permission sequence" — sending two or three consent-request emails to a cold list — is non-compliant under POPIA from the second message. The one-approach rule applies per data subject, and there is no provision for follow-up nudges.

Key Point

Under section 69(2), you get one attempt to ask a cold prospect for consent to receive your marketing. If they do not respond or decline, the conversation ends there. Any consent-request automation that sends a second or third message to non-responders violates this rule from the second send.

What Counts as "Electronic Communication"?

The Information Regulator's December 2024 Guidance Note on direct marketing took a position that has significant implications for sales teams: telephone calls are classified as electronic communications under section 69. This means cold-calling a prospect who has not given prior consent is, on the Regulator's view, non-compliant. Werksmans Attorneys noted at the time that this position may face legal challenge — it contrasts with the Consumer Protection Act's historical approach — but it represents the Regulator's current enforcement stance and should be treated as such until clarified by a court or revised guidance.

Non-Compliant

Buying a marketing list and loading it into your email platform to run a prospecting campaign to contacts who have never interacted with your business — no prior consent, no existing-customer relationship. This fails section 69(1) regardless of how good your unsubscribe link is.

Compliant

Emailing customers who purchased from your store in the last 12 months to promote a new product in the same category — provided they were given an opt-out opportunity at purchase and every subsequent email includes a clear, working unsubscribe mechanism. This is the section 69(3) existing-customer exception in action.

Message Requirements Under Section 69(4)

Every direct marketing communication — compliant or otherwise — must clearly identify the sender (or the party on whose behalf the message is sent) and provide contact details that allow the recipient to request cessation of future messages. Missing sender identification is a standalone compliance failure even if your consent basis is solid.

Unsure whether your email flows and SMS sequences pass section 69?

Tell us what channels you run and we'll give you a straightforward assessment of where your consent structure holds up and where it needs work.

Book a Channel Assessment

The 2026 CPA Amendment Regulations: The Opt-Out Registry

The Consumer Protection Act Amendment Regulations came into effect on 15 April 2026, adding a third compliance obligation on top of POPIA that every business running direct marketing campaigns in South Africa must satisfy. The regulations establish a National Consumer Commission (NCC)-administered opt-out registry — a centralised database where consumers register a pre-emptive block against all direct marketing.

Three operational obligations apply to every direct marketer from 15 April 2026:

CPA 2026 Registry: What Marketers Must Do

  1. Register on the NCC opt-out registry and renew annually (consumer and marketer-side registration commenced July 2026)
  2. Cleanse monthly — remove from your marketing database every person who has registered a pre-emptive block
  3. Do not contact any consumer for marketing purposes unless your organisation is registered on the registry

The most operationally significant change: a consumer's prior opt-in consent does not override a later pre-emptive block registration. If someone consented to your email list two years ago but has since registered a block on the NCC registry, you must remove them from your database at the next monthly cleanse — their earlier consent is overridden.

The penalty for CPA non-compliance is up to R1 million or 10% of annual turnover, whichever is greater. This is separate from POPIA's R10 million administrative fine — a single marketing campaign breach could attract both.

Key Point

The 2026 CPA opt-out registry is not an alternative to POPIA — it is an additional requirement. SA marketers must comply with both. The NCC administers the CPA registry; the Information Regulator handles POPIA. Registering on the NCC opt-out registry does not mean your POPIA consent flows are in order.

Per-Channel Decision Table: Which Rule Applies?

Email, SMS, telephone, postal, social-platform ads, and WhatsApp each trigger different combinations of POPIA section 11 lawful-basis requirements, section 69 electronic-marketing restrictions, and 2026 CPA opt-out registry obligations — the table below maps the specific rule to each channel so you can assess your own stack without reading three Acts in full.

ChannelLawful Basis (s11)Section 69 RuleCPA Registry?Verdict
Email to existing customersContract or Legitimate Interestss69(3) existing-customer exception — similar products onlyYes — cleanse monthlyCompliant if similar product category and opt-out offered
Email to cold prospectsLegitimate Interests (for holding data)s69(1) — prior consent required firstYes — cleanse monthlyConsent required before first send
SMS to opted-in subscribersConsent or Contracts69(1)(a) — consent obtainedYes — cleanse monthlyCompliant if consent recorded and opt-out included
Cold telephone outreachLegitimate InterestsIR Guidance Note: treated as electronic — consent requiredYes — cleanse monthlyHigh risk without prior consent under current IR position
Postal / printed mailLegitimate InterestsNot electronic — s69 does not applyYes — cleanse monthlyLegitimate interests assessment + opt-out offered
Social media ads (Meta, LinkedIn)Legitimate InterestsNot direct electronic communication to data subject — s69 does not apply in the same wayNot directly applicableLower risk — but privacy policy and data handling still apply
Competition / prize promotionContract (entry terms)Separate consent needed to add entrants to marketing listYes — if marketing afterEntry ≠ marketing consent — separate opt-in required
WhatsApp Business API campaignsContract or ConsentElectronic — s69 applies: consent or existing-customer exceptionYes — cleanse monthlyWhatsApp's own opt-in requirements and POPIA apply simultaneously

Social media advertising sits in a different category because you are not directly sending a message to a named data subject — you are targeting an audience segment via the platform. The platform's own data policies apply to the targeting inputs you provide (custom audiences, lookalikes). Your POPIA obligation in that context is to ensure any customer list you upload was lawfully collected and that your privacy policy discloses the use. The SA email marketing law guide covers the email and SMS channel in further detail.

Website Obligations Under POPIA for Marketers

A POPIA-compliant website is a prerequisite for any lawful digital marketing programme in South Africa — because your site is where most data collection originates. Three website requirements are non-negotiable for any business running marketing campaigns.

Privacy Policy

Every SA website that collects personal information must publish a privacy policy. For marketers, this means disclosing: the identity and contact details of your business as responsible party; the name and contact details of your appointed Information Officer; exactly what personal information you collect (names, email addresses, IP addresses, browsing behaviour via cookies); and the purpose for which each type of data is used. "We use your data to improve your experience" does not satisfy the specificity requirement.

Cookie Consent

POPIA follows an opt-in consent model for cookies. Non-essential cookies — analytics, advertising trackers, retargeting pixels, Meta Pixel, Google Tag Manager triggers — may not be loaded before the user actively accepts them. A website that fires Google Analytics or a Meta Pixel on page load before consent is collected is non-compliant, regardless of how well-worded the privacy policy is.

This has a direct commercial impact: if your website's cookie consent mechanism is not correctly implemented, your retargeting audiences may be built on non-consented data, and any custom audience you upload to Meta or Google from that data carries the same risk. See our guide to website compliance in South Africa for the full technical checklist.

Form Disclosure

Every lead-generation form, contact form, newsletter signup, and competition entry form must include a clear statement of purpose — what you will do with the information submitted. Collecting an email address "to send you our newsletter" and then adding the contact to a cold-outreach sequence for a different product is a purpose-limitation failure under POPIA section 13.

Key Point

Your website is where POPIA marketing compliance starts, not ends. Cookie consent banners, privacy policies, and form disclosures are not legal formalities — they are the mechanism by which you establish a lawful basis for every downstream campaign. Getting the website right makes the rest of the stack defensible.

POPIA Penalties and the Enforcement Shift in 2026

POPIA's penalty structure operates as a ladder rather than a trap. The Information Regulator issues an enforcement notice first; the fine follows only if the business fails to comply with that notice. Every administrative fine to date has followed non-compliance with an enforcement notice — routine compliance mistakes do not attract immediate fines. The maximum administrative fine is R10 million.

Criminal liability under section 107 is reserved for specific conduct: obstructing the Regulator, certain account-number breaches, and — critically — failing to comply with an enforcement notice. The maximum is up to 10 years' imprisonment for these specified offences. The "10-year fine for sending an email" framing circulated in 2021 has no basis in how the Act actually works.

What changed in 2026 is the enforcement posture. The Information Regulator is no longer waiting for complaints — it is running its own proactive compliance assessments, with particular attention on financial services, insurance, health, retail, telecommunications, and the public sector. The most significant fine to date was R5 million, imposed on the Department of Basic Education after it published the 2024 matric results in newspapers — a large-scale data breach. Data breach notifications rose more than 40% year-on-year in the 2024–2025 reporting period.

Beyond administrative fines, section 99 of POPIA allows data subjects to sue for damages whether or not there is intent or negligence — a strict-liability exposure that can exceed the administrative fine for large-scale breaches.

For practical risk management: the businesses most exposed right now are those running email lists built from purchased databases with no documented consent, and those whose websites still fire tracking pixels on load. Both are visible to a proactive regulator.

Want a practical audit before the Regulator visits?

We review your marketing channels, consent flows, and website data practices against current POPIA requirements — and show you what to fix first.

Request a POPIA Marketing Audit

Why South African Businesses Work With Growth Pulse Media on Compliance-Ready Campaigns

Running web design and marketing from the same operator position means we build consent collection into the technical stack from the start — cookie consent banners, form purpose disclosures, and privacy policies are part of the site build, not an afterthought added after a legal review. The same team that sets up your Google Tag Manager or Meta Pixel also ensures it fires after consent, not before.

Our experience running and scaling South African ecommerce operations means we understand what compliance looks like in practice — not in a policy document. Managing opt-out lists, handling unsubscribe requests within the required timeframe, maintaining internal do-not-contact registries, and building POPIA operator agreements with third-party processors are operational tasks we handle as standard, not extras.

All work is executed in-house by a small senior team with a limited client load — which means your channel audit is done by the person who actually understands the regulations, not forwarded to a junior account manager.

Who This Approach Is NOT For

Businesses that want a one-size checkbox

If you are looking for a "we got POPIA sorted" badge without actually reviewing your channel stack, consent flows, and website data practices — that is not an approach we take. POPIA compliance is channel-specific and changes as your marketing mix changes.

Businesses that rely on purchased prospect lists

If your outbound email or SMS programme runs on purchased lists with no documented consent from the contacts on them, the compliance gap is fundamental — not a tweak. Fixing this requires rebuilding your list-acquisition model, not a better unsubscribe link.

Businesses that treat the CPA registry as optional

The 2026 CPA Amendment Regulations are in effect. Treating registration on the NCC opt-out registry as something to "look into later" creates direct regulatory exposure from the date your next campaign runs. Monthly cleansing is an operational requirement, not a discretionary good practice.

Businesses expecting consent to solve everything

Defaulting to consent for all processing — including processing that more naturally fits contract or legitimate interests — creates fragility. If a large share of your customer base exercises their POPIA right to withdraw consent, you lose the processing ground for their data. Build on the right ground for each channel from the start.

Frequently Asked Questions

Does POPIA require opt-in consent for all marketing?

No — consent is one of six lawful processing grounds under section 11, and for many forms of data handling it is not the right ground. For electronic direct marketing specifically (email, SMS, and — on the Information Regulator's current position — telephone), section 69 requires either prior consent or the existing-customer exception. Non-electronic marketing such as postal mail can rely on legitimate interests with an opt-out mechanism. Check our competition rules guide for how consent requirements apply to prize promotions.

What is the existing-customer exception under POPIA?

Section 69(3) allows a business to send electronic marketing to an existing customer without prior consent, provided three conditions are met: contact details were collected during a prior transaction, the marketing promotes similar products or services, and the customer was given a free and easy opportunity to opt out both at the time of collection and in each subsequent message. The exception is limited to similar products — marketing a different product category to an existing customer requires fresh consent.

What does the 2026 CPA opt-out registry require of marketers?

The Consumer Protection Act Amendment Regulations (effective 15 April 2026) require every direct marketer to register on the National Consumer Commission's opt-out registry, renew that registration annually, and cleanse their marketing database against the registry on a monthly basis. A consumer's prior consent does not override their pre-emptive block registration — once someone registers a block, they must be removed from your database at the next cleanse regardless of any earlier opt-in. Penalties for non-compliance are up to R1 million or 10% of annual turnover, whichever is greater.

Can I still run cold email outreach under POPIA?

Cold email to consumers (B2C) without prior consent is barred by section 69. For B2B outreach, the position is more nuanced — processing a business contact's work email may rely on legitimate interests under section 11, but section 69's rule still applies to the send itself. The Information Regulator's Guidance Note does not carve out a blanket B2B exemption, so documented consent is the lowest-risk approach for unsolicited electronic outreach. See the POPIA cold email rules post for a full breakdown.

What does POPIA require from my website?

At minimum: a privacy policy that discloses what personal information you collect, why, and how it is used; a cookie consent mechanism that loads non-essential cookies (analytics, advertising pixels) only after the user actively accepts them; and a purpose statement on every form that collects personal information. These are prerequisites for any lawful digital marketing programme — because your website is where most data collection originates. See the SA ecommerce disclaimers guide for the document layer.

What are the POPIA penalties for marketing non-compliance?

The Information Regulator may issue an enforcement notice requiring corrective action, followed by an administrative fine of up to R10 million for non-compliance with that notice. Section 107 creates criminal liability of up to 10 years' imprisonment for specific conduct, including failing to comply with an enforcement notice. Separately, section 99 allows data subjects to sue for damages on a strict-liability basis — no proof of intent or negligence required. The CPA opt-out registry adds a further penalty of up to R1 million or 10% of annual turnover, whichever is greater, for its own requirements.

Build a Marketing Stack That Passes the Regulator's Check

Growth Pulse Media designs and runs compliance-ready digital marketing for South African businesses — cookie consent integrated at build time, consent flows mapped to the right legal grounds, and campaigns structured around POPIA section 69 from the first send. No obligation — we'll get back to you within 24 hours.

Get in Touch
Dirk van Greuning — Founder, Growth Pulse Media
Dirk van Greuning Founder, Growth Pulse Media

Founder of Growth Pulse Media and a specialist in South African search dominance. Dirk translates his experience in scaling South African businesses into high-velocity digital strategies for B2B and retail leaders. He writes about SEO, lead generation, and paid media from an operator's perspective — prioritising pipeline value over impressions.

Connect on LinkedIn