The cold email rules South Africa POPIA establishes are stricter than most marketers expect — and the gap between knowing them and following them is exactly where real enforcement risk sits. POPIA's Section 69 creates a clear framework for email marketing in South Africa: unsolicited promotional emails are prohibited unless the recipient has explicitly consented or qualifies as an existing customer under specific conditions. Get either of those wrong and you are in breach, as the first POPIA direct marketing enforcement notice — issued against FT Rams Consulting in February 2024 — made plain.
This guide covers what Section 69 actually says, the one-contact consent request rule that trips up most cold emailers, when the existing customer exception applies, why legitimate interest is not a valid basis for electronic direct marketing in South Africa, and what changed with the December 2024 Guidance Note and April 2025 regulation amendments. If you also want to understand broader POPIA email compliance for opted-in lists, that guide covers the full compliance picture beyond cold outreach.
Quick Answer
Under cold email rules South Africa POPIA mandates, sending unsolicited promotional emails requires either explicit prior consent from the recipient or an existing customer relationship that meets the three conditions in Section 69(3). Legitimate interest is not a valid lawful basis for electronic direct marketing. First-time outreach to non-customers must take the form of a consent request — not a sales email — and if that request is refused, the contact is permanently closed. Violations carry administrative fines of up to R10 million.
In This Guide
Not Sure Whether Your Current Email List Is POPIA-Compliant?
Send us your list acquisition process and we will identify where your consent records may fall short before the Information Regulator does.
Request a Free List AuditWhat POPIA Section 69 Says About Cold Email in South Africa
Section 69 of the Protection of Personal Information Act is the operative provision for electronic direct marketing in South Africa. It applies to any marketing communication sent via email, SMS, WhatsApp, automated calls, or fax — in other words, any channel where the message is electronically stored and received by a specific individual or organisation.
The rule has a default prohibition with two narrow exceptions:
| Scenario | Permitted? | Condition |
|---|---|---|
| Unsolicited email to a non-customer (no consent) | No | Prohibited outright |
| First contact to request consent | Yes (once only) | Must follow prescribed consent request format |
| Email to an existing customer | Yes (conditional) | Three conditions under s69(3) must all be met |
| Email after consent was refused or revoked | No | No further contact permitted |
The distinction between electronic and non-electronic channels matters. Direct marketing by post or in-person does not fall under Section 69 — it operates under Section 11's legitimate interest framework, where the opt-out right is unconditional but prior consent is not required. Cold email does not enjoy that flexibility.
Key Takeaway
Section 69 creates an opt-in regime for all electronic direct marketing in South Africa. There is no category of "permissible unsolicited email" beyond the consent request and the existing customer exception. The rules apply to B2B outreach just as they do to consumer emails — POPIA explicitly protects juristic persons (companies) as data subjects.
The One-Contact Consent Request Rule and Form 4
POPIA permits a responsible party to make one approach to a non-customer to request consent for direct marketing by electronic means. That first contact must be a consent request — not a sales pitch, not a newsletter, not a "just checking in" email that happens to mention a product. The Information Regulator's enforcement notice against FT Rams Consulting turned specifically on this point: the first message the company sent should have been a consent request, not an unsolicited promotional email about courses.
The consent request must follow the format prescribed in Form 4 of the POPIA Regulations, or (following the April 2025 amendments) a form substantially similar to it. Form 4 requires the organisation to:
- Identify the goods or services it intends to market
- Specify the electronic communication channel it will use
- Give the data subject a clear, positive way to say yes
Not this: Sending a promotional email with a line at the bottom saying "Reply STOP to opt out." Providing an opt-out option is not the same as obtaining consent — the April 2025 amendments expressly state that "an opt-out shall not constitute consent." Consent requires a positive, affirmative action by the data subject.
This: A dedicated outreach email that introduces who you are, names the specific service or product category you want to tell them about, states how often you intend to be in touch, and asks them to reply or click to confirm they are happy to receive those communications. No marketing content in the same message.
Once that consent request is refused — explicitly or by silence that you treat as refusal — the contact is permanently closed for electronic direct marketing. There is no "try again in six months" provision.
When You Can Email Without Prior Consent: The Section 69(3) Exception
POPIA's existing customer exception allows electronic direct marketing without separate consent if three conditions are met simultaneously. Satisfy all three and you are compliant; miss any one of them and you need consent like any other contact.
The Three Section 69(3) Conditions
- Contact details were obtained in the context of a sale. The address must have come to you because this person or company bought something from you — not from a scraped list, a purchased database, or a trade show badge scan that did not involve a transaction.
- You are marketing your own similar products or services. The marketing must relate to the responsible party's own comparable offerings. Passing the list to a partner, or pivoting to market a completely unrelated product line, falls outside the exception.
- An opt-out opportunity was provided at collection and is included in every subsequent communication. The customer must have had the chance to object when you first collected their details, and each marketing message must include a usable opt-out mechanism.
The practical limitation here is significant. A business that sold accounting software to a company may legitimately email that company about a new accounting module. It may not use the same details to market a new HR product unless it can argue that is "similar" — and a conservative reading of the Act says it is not.
Once your legal basis is confirmed — either through documented consent or a qualifying customer relationship — the B2B cold email subject line guide for South Africa covers how to write openers that earn the open without triggering spam filters.
Does Legitimate Interest Apply to Cold Email Under POPIA?
No. Legitimate interest cannot be used as the lawful basis for electronic direct marketing under POPIA, and this is one of the most common misconceptions that B2B marketers carry over from GDPR thinking.
Section 11 of POPIA lists several lawful bases for processing personal information, including legitimate interests under Section 11(1)(f). However, Section 69 is the specific provision that governs direct marketing by electronic means — and it does not provide legitimate interest as an available basis. The December 2024 Guidance Note from the Information Regulator reinforces this: electronic communications require consent as the default, with the existing customer exception as the only alternative. Legitimate interest is specifically applicable to non-electronic direct marketing such as postal mail and in-person outreach.
This means the GDPR-era B2B argument — "we have a legitimate business interest in contacting companies that might benefit from our services" — does not justify a cold email in South Africa. The lawful basis you need is consent, obtained in advance, via the prescribed format.
Key Takeaway
If you are cold emailing South African businesses and relying on legitimate interest as your legal justification, you are relying on a basis that does not exist for electronic direct marketing under POPIA. The only options are prior consent or the existing customer exception — there is no third path.
What Every Cold Marketing Email Must Include
Section 69 specifies two mandatory elements for every direct marketing communication sent by electronic means, regardless of whether it is a consent request or a communication to an existing customer:
- Sender identity: The message must clearly identify the sender, or the person on whose behalf the communication is sent. Sending from a generic domain, a first-name-only alias, or an address that does not resolve to an identifiable organisation is non-compliant.
- Opt-out mechanism: The message must include valid contact details through which the recipient can request that no further communications be sent. This must be genuine and actionable — a dead email address or a link to a form that generates no response is not sufficient.
Following the April 2025 amendments, businesses must be prepared to accept opt-out requests through multiple channels. The amended regulations require that objections be accepted free of charge via hand delivery, fax, post, email, SMS, WhatsApp, or any other expedient method the data subject chooses. An opt-out submitted via WhatsApp reply must be honoured with the same urgency as one sent by email.
The Act does not prescribe a specific window for processing opt-outs; the operative standard is as soon as reasonably practicable. In practice, treat any opt-out as requiring a same-day suppression list update — particularly in automated sequences where the next send may be scheduled hours away.
Maintaining a suppression list — a record of everyone who has objected or refused consent — is not optional. If someone opts out and receives another email from you three months later because you failed to update your list, that is a standalone breach.
Running B2B Campaigns and Unsure About Your Legal Exposure?
Tell us how you currently acquire B2B contacts and what your opt-out process looks like — we will map the POPIA exposure points and show you what to change.
Get a Compliance ReviewThe 2024 Enforcement Action and 2025 Regulation Changes
For several years after POPIA's commencement, the concern among direct marketers was theoretical — the Information Regulator had issued no enforcement notices specifically for direct marketing violations. That changed on 27 February 2024, when the Regulator issued its first direct marketing enforcement notice against FT Rams Consulting.
The case involved unsolicited promotional emails about courses and webinars sent without consent, combined with repeated failures to honour the recipient's opt-out requests. The Regulator found that FT Rams Consulting's first communication should have been a consent request, not a marketing email.
Sending without consent and ignoring opt-outs are themselves the offences under POPIA; the enforcement notice is the Regulator's formal demand to stop. Non-compliance with a notice escalates enforcement, but the maximum administrative fine of up to R10 million and criminal penalties of up to 10 years' imprisonment apply to the underlying breach — not only to ignoring the notice.
The Information Regulator followed the enforcement notice by publishing a formal Guidance Note on Direct Marketing in December 2024 — the first time the Regulator provided structured operational guidance on Section 69 compliance. The Guidance Note is advisory rather than law; POPIA itself prevails in the event of any conflict. But it clarifies the Regulator's interpretation on contested points, including the one-contact rule and the treatment of telephone calls.
In April 2025, the POPIA Regulations were formally amended. The key changes relevant to cold email:
- Consent requests no longer need to use Form 4 precisely; a form "substantially similar" to Form 4 is acceptable, provided it is free of charge and reasonably accessible
- The principle that "an opt-out shall not constitute consent" was codified explicitly in the Regulations
- Data subjects can now submit objections to processing through an expanded set of channels including WhatsApp and SMS
The combined effect is a regulatory environment that has shifted from theoretical risk to active monitoring. The first-party data strategy most SA businesses need starts with getting consent architecture right before launching outbound campaigns.
Cold Email Rules South Africa POPIA: Practical Compliance Checklist
POPIA cold email compliance requires confirming eight items before every send: list categorisation, timestamped consent records, a consent-request-only first contact, positive-action consent, sender identification, a functional opt-out mechanism, a live suppression list, and a permanent block on any contact who has refused. Each maps directly to a legal obligation under Section 69 or the April 2025 amended Regulations.
| Check | What to Confirm | Legal Basis |
|---|---|---|
| List categorisation | Every contact is classified as either (a) consented, (b) existing customer qualifying under s69(3), or (c) un-emailable | Section 69(1)–(3) |
| Consent records | You have a timestamped record of when and how each consented contact gave permission | Section 69(2) |
| First contact format | First email to any non-customer is a consent request only, using Form 4 or a substantially similar format | Section 69(2), Regulation 6 |
| No opt-out-as-consent | Consent is obtained via a positive action — not by pre-ticking boxes or treating silence as agreement | April 2025 Amendments |
| Sender identification | Every email clearly identifies the sending organisation and contact details | Section 69(4) |
| Opt-out mechanism | Every email includes a functional opt-out method; objections via any channel (email, WhatsApp, SMS) are actioned promptly | Section 69(3)(c), April 2025 Amendments |
| Suppression list | All refusals and opt-outs are recorded and applied before every campaign send | Section 69, s11(3)(a) |
| No recontact after refusal | Any contact who refused consent is permanently excluded from future cold outreach | Section 69(2) |
For B2B teams currently using email automation for B2B lead nurturing, the compliance checkpoint is whether the automation sequences are being triggered by confirmed consent or an existing customer relationship — not by a scraped LinkedIn list or a purchased database. Cold email deliverability in South Africa also depends on sender reputation, which collapses when a campaign generates spam complaints from non-consented recipients.
Why South African Businesses Choose Growth Pulse Media for POPIA-Compliant Email Marketing
The email marketing service we run at Growth Pulse Media is built around platforms that enforce consent architecture by design — Klaviyo and Omnisend both require double opt-in flows, suppression list management, and POPIA-compatible consent tagging. We do not manage email lists where the acquisition method cannot be documented.
Dirk built and scaled a South African ecommerce business before founding GPM, which means the compliance questions are not abstract for us — we have had to structure our own lists under POPIA, navigate the existing customer exception for cross-sell campaigns, and build consent flows that survive regulator scrutiny. We take a limited number of email marketing clients and provide senior-level attention to every campaign, which means your consent architecture gets reviewed before anything goes out, not after a complaint is filed.
The cold email rules South Africa POPIA enforces are the baseline every acquisition strategy must be built around — the guide to building an email list in South Africa covers compliant list growth methods from the ground up.
Who Cold Email Under POPIA Is Not Right For
Sales teams using cold email as a volume prospecting channel. If your outreach model depends on sending hundreds of introductory emails per week to contacts from LinkedIn, scraped databases, or purchased lists, POPIA's one-contact consent request rule and prohibition on post-refusal contact will constrain that volume significantly. Cold email still has a role in B2B prospecting, but it needs to be restructured around a consent-first sequence rather than a mass-blast model.
Businesses planning to run the same campaign to opted-in and non-opted-in contacts. The compliance requirements for these two groups are fundamentally different. Non-customers need a consent request email first. Mixing consented and non-consented contacts in the same campaign flow is a compliance failure regardless of the content quality.
Organisations relying on GDPR-style legitimate interest arguments. If your legal team or agency has modelled your SA email outreach on GDPR's legitimate interest basis — without checking whether POPIA's Section 69 applies — the compliance gap is real. The frameworks are different, and POPIA is unambiguous: legitimate interest does not justify cold email to South African data subjects.
Any business that wants to continue emailing contacts who have already opted out. Once a data subject refuses consent or exercises their opt-out right, that decision is permanent for cold outreach. There is no POPIA provision allowing a cooling-off period or a second attempt. If you are looking for a way to continue contact with lapsed prospects, the answer is inbound strategy and retargeting — not re-queuing them for cold email.
Ready to Build an Email Programme That Does Not Create Legal Exposure?
Share your current email strategy and we will assess where your consent and list management architecture needs to change to hold up under POPIA.
Book a Strategy AssessmentFrequently Asked Questions
Can I cold email businesses in South Africa under POPIA?
You can send one initial email to request consent — but it must be a consent request only, not a marketing email. POPIA Section 69 applies to B2B outreach in exactly the same way it applies to consumer outreach, because POPIA explicitly protects juristic persons (companies) as data subjects. If the business does not respond or declines consent, you cannot follow up with further cold email contact.
What is the existing customer exception under Section 69(3)?
You may send direct marketing emails to an existing customer — without obtaining separate consent first — if three conditions are met simultaneously: you obtained their contact details in the context of a sale, you are marketing your own similar products or services, and you provided an opt-out opportunity when you collected their details and include one in every subsequent communication. All three conditions must be satisfied; meeting only two of them does not qualify.
Can I send one introductory cold email to ask for permission?
Yes — Section 69(2) allows a single contact with a non-customer for the purpose of requesting consent. That first email must follow the format prescribed in Form 4 of the POPIA Regulations (or a substantially similar form after the April 2025 amendments), naming the goods or services you want to market and specifying the communication channel. If consent is refused, that contact is permanently closed for electronic direct marketing.
What happens if I ignore a POPIA opt-out request?
Ignoring an opt-out request is a standalone breach of POPIA. The Information Regulator can issue an enforcement notice requiring immediate compliance. If the notice is ignored, the responsible party faces an administrative fine of up to R10 million, criminal liability carrying up to 10 years' imprisonment, or both. The 2024 enforcement action against FT Rams Consulting was triggered in part by exactly this failure — the company continued sending marketing emails after the data subject had made multiple opt-out requests.
Does legitimate interest allow cold email in South Africa?
No. Legitimate interest is not a valid lawful basis for electronic direct marketing under POPIA. Section 11(1)(f) lists legitimate interests as a basis for processing personal information generally, but Section 69 governs electronic direct marketing specifically — and it restricts the available options to consent or the existing customer exception. Legitimate interest applies only to non-electronic direct marketing, such as postal mail or in-person outreach.
Run POPIA-Compliant Email Campaigns With GPM
We manage email marketing on Klaviyo and Omnisend for South African businesses that need campaigns which perform and comply — consent architecture built in, suppression lists maintained, and every sequence reviewed before it goes live. No obligation — we'll get back to you within 24 hours.
Talk to the Team

