Database marketing popia compliance rests on a principle most South African operators discover the hard way: buying a contacts list does not give you permission to email, SMS or call the people on it. Under POPIA's B2B lead generation regulatory framework, consent is personal and non-transferable — whatever a data vendor obtained for their own marketing purposes cannot be assigned to yours. The practical consequence is that the bought-database blast, once a routine acquisition tactic, is now a live enforcement risk under two separate pieces of legislation.
Two compliance layers now apply simultaneously. POPIA section 69 governs the channel — how, and on what basis, you may approach someone electronically. The 2026 CPA Amendment Regulations govern the process — requiring every direct marketer to register with the National Consumer Commission and cleanse their database monthly against a national opt-out registry. Understanding how those layers interact matters whether you run your own outbound team or work with a B2B prospecting partner who builds lists on your behalf.
This post explains what each law requires, how the Information Regulator's December 2024 Guidance Note on Direct Marketing clarified the rules, and what a compliant database marketing operation actually looks like in South Africa.
Quick Answer
Database marketing popia rules prohibit electronic direct marketing (email, SMS, automated calls) to a purchased list unless you have obtained fresh, specific consent from each person on it. A list vendor's consent does not transfer to your marketing. You may send one unsolicited consent-request message (POPIA s69(2)) before a prospect has refused, but nothing further until consent is given. The existing-customer exception (s69(3)) applies only to your own customers, on your own similar products, with opt-out offered at every touch. Non-electronic outreach (postal, in-person) runs on legitimate interests under s11, not consent. From July 2026, the CPA also requires all direct marketers to register with the NCC and cleanse databases monthly.
On This Page
What "database marketing" means under POPIA
The POPIA rules for bought marketing lists
The existing-customer soft opt-in
The CPA opt-out registry: the second compliance layer
Does POPIA treat B2B databases differently?
Not sure whether your current outreach list is POPIA-compliant?
Share your database acquisition approach with us and we will map it against the POPIA direct marketing rules and the CPA registry requirements so you know exactly where the risk sits.
Get a Compliance ReviewWhat "Database Marketing" Means Under POPIA
Database marketing is the practice of using structured contact records — names, email addresses, phone numbers, job titles — to send targeted commercial messages at scale. The database may be self-built (opt-in forms, gated content, event registrations), purchased from a list vendor, or assembled through outreach tools that scrape publicly available information. POPIA does not use the phrase "database marketing" as a term of art, but it governs every step of the practice: how data may be collected, on what basis it may be processed, and how it may be used for direct marketing.
The Act's eight conditions for lawful processing — accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation — apply to any database of personal information, regardless of whether you compiled it yourself or bought it ready-made. The source of the data does not change the compliance obligation; it changes how easy that obligation is to meet. Database marketing popia compliance therefore begins at the moment data is collected, not at the moment a campaign is sent.
What counts as personal information? Under POPIA, a business email address in the form firstname.lastname@company.co.za qualifies as personal information because it is identifiable to a natural person. A generic address such as info@company.co.za is more likely to be outside POPIA's scope, though this turns on whether the address identifies a specific individual in context. The Act protects information about natural persons, not juristic persons (companies) — which is why the B2B question is more nuanced than a flat yes-or-no answer.
What Are the Database Marketing POPIA Rules for Bought Lists?
POPIA section 69 prohibits unsolicited electronic direct marketing unless one of two conditions applies: the recipient has given prior consent, or the responsible party qualifies for the existing-customer exception under s69(3). A purchased list satisfies neither condition — and this distinction is what makes bought-database marketing legally problematic for electronic channels.
Consent under POPIA is specific and non-transferable. When a person subscribes to a vendor's newsletter or agrees to receive information from a data broker, that consent was given to that vendor for that vendor's purposes. It cannot be reassigned to your business. Consent under POPIA is specific and non-transferable. When a person subscribes to a vendor's newsletter or agrees to receive information from a data broker, that consent was given to that vendor for that vendor's purposes. It cannot be reassigned to your business. The Information Regulator's December 2024 Guidance Note on Direct Marketing confirmed that for electronic channels, the only permissible bases are consent and the existing-customer exception — the table below shows how this plays out across the scenarios most SA operators encounter.
The table below shows how POPIA allocates lawful basis by scenario for electronic channels. Note that postal mail and in-person outreach sit outside section 69 entirely and are governed by separate s11 conditions. For electronic channels, the column that changes with real constraints is the third one — and for bought lists, it is empty.
| Scenario | Channel | Lawful basis available | What the law allows |
|---|---|---|---|
| Own contacts who gave clear consent at opt-in | Email, SMS, calls | Consent — s69(1) | Market within the scope of what they consented to; honour opt-outs |
| Existing customers (you sold them something) | Email, SMS, calls | Soft opt-in — s69(3) | Own similar products only; opt-out offered at collection and in every message |
| Purchased third-party list — new prospects | Email, SMS, calls | None without fresh consent | One consent-request message (s69(2)); nothing further until consent is received |
| Self-built B2B list (LinkedIn, events, referrals) | Email, SMS, calls | Consent required | Explicit consent needed before electronic direct marketing begins |
One qualified exception exists for purchased lists: section 69(2) permits a single unsolicited communication whose sole purpose is to request consent — not a sales pitch that also asks for consent. If the prospect declines or does not respond with consent, no further electronic communications may be sent. That one-shot window is narrow and should not be treated as a loophole; the Regulator's enforcement posture has hardened since its first direct marketing enforcement notice in March 2024.
Bad practice: A Johannesburg distributor purchases a 10,000-contact database of procurement managers from a list vendor. The vendor's terms say contacts "opted in to receive commercial communications." The distributor treats this as consent and sends a monthly promotional email campaign. Under POPIA, the vendor's opt-in did not transfer. Every email sent without fresh, specific consent from each individual is a breach of s69.
The Existing-Customer Soft Opt-In: When It Applies
The existing-customer exception under POPIA s69(3) lets you market electronically to your own customers without separate consent — but only when three conditions are met simultaneously. Miss any one and the exception falls away.
First, you must have obtained the contact details in the context of a sale of a product or service to that customer. Details collected through a competition, a gated download, or a loyalty programme do not qualify unless they were collected as part of a completed transaction.
Second, you may only market your own similar products or services — not a partner's offers, not unrelated products, not a new business line that is substantially different from what the customer bought. Third, you must have given the customer a reasonable opportunity to object at the time you collected their details, and you must repeat that opportunity in every marketing message you send. POPIA section 69 marketing obligations for the existing-customer route are as strict as those for any consent-based send — the difference is that the threshold to communicate is lower, not that the conduct rules are lighter.
Good practice: A Cape Town software company sells a project management tool to a client. The client's operations manager gave their email address during the purchase process and was offered an opt-out at that point. The company now sends the operations manager emails about a new reporting add-on for the same platform. The message clearly identifies the sender and includes an unsubscribe link. All three s69(3) conditions are met.
Key rule: The existing-customer exception is for your own customers, on your own similar products, with opt-out at every touch. It does not apply to contacts acquired by any means other than a direct transaction with your business — and it never applies to a bought list.
The CPA Opt-Out Registry: The Second Compliance Layer
POPIA is not the only law governing marketing databases in South Africa. The Consumer Protection Act Amendment Regulations, which took effect on 15 April 2026, added a second compliance layer that operates alongside POPIA's consent requirements rather than replacing them.
The regulations establish a national opt-out registry administered by the National Consumer Commission (NCC). Every direct marketer — not just large enterprises — must register before conducting direct marketing. Registration is not optional; marketing to consumers without registration is itself a CPA contravention. The registration fee started at R2,574 for 2026, with annual renewal at R1,930.50. Consumer and marketer registration on the registry began in July 2026, with implementation phased by the NCC. For any direct marketing database South Africa businesses run, specific operational steps are still being rolled out; check the NCC's direct communications for current requirements rather than relying on secondhand commentary.
Once registered, marketers must cleanse their databases monthly — removing every consumer who has registered a pre-emptive block. The regulations define "cleansing" as removing opted-out consumers from a marketer's database before each campaign cycle. For a purchased list, this means the list must be checked against the NCC registry before any use, and then monthly thereafter. A pre-compiled list purchased once and used repeatedly without cleansing will accumulate blocked contacts over time.
CPA penalty: Failure to comply with the 2026 CPA Amendment Regulations can attract an administrative penalty of up to R1 million or 10% of the direct marketer's annual turnover, whichever is greater. POPIA's own maximum criminal penalty for failing to comply with an enforcement notice is R10 million and/or imprisonment of up to 10 years under sections 107 and 109 of the Act. These penalties run in parallel — a single marketing campaign to a non-compliant list can trigger consequences under both pieces of legislation.
Does POPIA Treat B2B Databases Differently?
B2B marketers frequently assume POPIA does not apply to business email addresses, or that a separate B2B exemption makes cold outreach to professional contacts permissible. The honest answer is that South African law does not clearly settle this question, and assuming a blanket exemption carries real risk.
POPIA protects personal information relating to natural persons. A business email address in the format firstname.lastname@company.co.za identifies a natural person and falls within the Act's scope. A generic company address such as info@company.co.za is less likely to qualify, but the distinction depends on context. The Information Regulator's December 2024 Guidance Note on Direct Marketing is silent on whether business email addresses attract different treatment — and silence is not an exemption. The safer position, consistent with how most practitioners read the Act, is to treat professional email addresses as personal information and apply the s69 rules accordingly.
This matters for POPIA-compliant lead generation because most B2B databases are built from professional email addresses. If those addresses belong to identifiable individuals, the consent requirement for electronic marketing applies. The fact that the contact is a procurement director rather than a consumer does not change the channel rule — database marketing popia obligations follow the nature of the information, not the commercial context of the relationship.
On B2B exemptions: The Information Regulator's December 2024 guidance does not establish a B2B exemption for electronic direct marketing. Until the Regulator issues a contrary position, treat personalised business email addresses as personal information governed by s69.
Building a compliant B2B pipeline from scratch?
Tell us your target sector and deal size, and we will map a lead generation architecture that works within the POPIA direct marketing framework — no consent gymnastics, no enforcement risk.
Discuss Your PipelineHow to Build a Compliant B2B Marketing Database
A compliant database marketing operation builds consent in from the first touch rather than trying to retrofit it onto a bought list. Getting bought database POPIA compliance right means building the architecture before the campaign, not after a breach. The practical steps below apply to most South African B2B contexts.
Collect consent at the point of contact. Every channel where you collect a business email address — a website form, an event registration, a webinar signup, a gated report download — is an opportunity to obtain specific, documented consent for electronic marketing. Consent must be freely given, specific, informed and unambiguous. A pre-ticked checkbox does not meet that standard.
Record what was consented to. POPIA's accountability principle requires you to be able to demonstrate consent, not merely assert it. Log the date, channel, and scope of each opt-in. Your CRM or email platform's built-in consent timestamps serve this function if the system is configured to capture them.
Include sender identification and opt-out in every message. POPIA s69(4) requires that every electronic marketing message identifies the sender and provides a functional opt-out address or mechanism. This applies to both consent-based sends and the existing-customer exception — it is not optional in either scenario.
Honour opt-outs immediately and permanently. A data subject who opts out of electronic marketing must not receive further electronic messages. Build your suppression list as a non-deletable record, not as a temporary filter that can be overridden by a fresh data import.
Segment by consent scope. If contacts opted in for a specific purpose (e.g., product updates), they have not consented to promotional offers on an unrelated product line. Consent is specific — do not treat it as a general licence. A first-party data strategy built around consent segmentation is both legally sound and commercially more sustainable than blasting a unified list whose permission basis is uncertain.
Register with the NCC and cleanse monthly. From July 2026, registration with the NCC is a baseline requirement for any direct marketing activity. Build the monthly registry cleanse into your campaign workflow before each send cycle.
For cold outreach, use the s69(2) window deliberately. If you want to reach a prospect you have not previously sold to, the law permits one unsolicited communication requesting consent. That message must be clearly positioned as a consent request, not a sales pitch. If the prospect does not grant consent, your electronic channel to them is closed. For B2B cold outreach at scale, cold email POPIA rules work alongside a channel mix that includes LinkedIn, events, and referrals — all of which can generate consensual opt-ins without requiring the single-shot gamble.
Why South African Businesses Choose Growth Pulse Media
Growth Pulse Media's founder, Dirk van Greuning, built and scaled a large South African ecommerce business before founding the agency — which means the compliance questions that abstract themselves in legal guides are the same ones Dirk navigated operationally: how do you build a pipeline that fills the funnel without exposing the business to regulatory risk?
The answer GPM uses for its own clients is a consent-first architecture: organic content, gated assets and direct outreach that builds opt-in lists rather than buying reach. All work is executed in-house, not outsourced to junior staff or offshore teams who do not know the SA regulatory environment. GPM carries a limited client load specifically to maintain senior attention on each account — which, on a compliance-sensitive engagement, means the person reviewing your outreach strategy is the same person who built ours.
If your current B2B lead generation approach relies on purchased lists or inherited databases without documented consent, the B2B lead generation services GPM offers are designed to replace that exposure with a first-party pipeline that compounds over time rather than depreciating with each regulatory tightening. The platforms we work with — LinkedIn, email, Google Ads — all offer mechanisms for building consent-based audiences that do not require buying third-party data.
Who This Is NOT For
Not for: businesses that want a plug-and-play purchased list. If your acquisition strategy requires buying a database and emailing it immediately, this post has given you the legal context — but GPM's approach builds consent-based pipelines from the ground up. Those take longer to fill and cost more upfront. If immediate volume from a purchased list is the brief, we are not the right fit.
Not for: businesses that have already built a clean, consent-documented CRM. If your database was collected with clear opt-ins, your email platform stores consent timestamps, and your suppression list is current — you are already operating correctly. The value here is in the setup, not the maintenance; if the infrastructure is right, you need execution support more than compliance advice.
Not for: operators who expect a confirmed B2B exemption. If your business model depends on cold electronic outreach to business email addresses and you are counting on a legal carve-out that definitively excludes B2B contacts from POPIA's reach, that exemption does not currently exist in the Act or the Regulator's guidance. Taking that position is a business decision, but it is not one GPM can recommend or build around.
Not for: very early-stage businesses with no existing customer base. The existing-customer exception under s69(3) requires an existing transactional relationship. If your business is pre-revenue, you have no existing customers to market to under that exception, and all electronic outreach requires fresh consent. The pipeline-building work is still the right approach — but the timeline to a compliant, functioning database is longer and needs realistic expectations on both sides.
Ready to audit your current lead database for compliance gaps?
Share your current list-building process and we will run a structured POPIA audit against the Information Regulator's December 2024 guidance on direct marketing and the 2026 CPA registry requirements.
Request a Database AuditFrequently Asked Questions
Is it legal to buy a marketing database in South Africa under POPIA?
Buying a database is not itself illegal — but using it for electronic direct marketing without fresh, specific consent from each contact is a breach of POPIA section 69. The vendor's consent does not transfer to your marketing. You may send one unsolicited consent-request message (s69(2)) before a prospect has refused; after that, electronic outreach requires consent. Non-electronic outreach to a purchased list — postal mail, in-person — can run on legitimate interests under s11, provided a right to object is offered.
What is the existing-customer exception under POPIA section 69(3)?
Section 69(3) allows electronic marketing to existing customers without separate consent, but only when all three conditions apply: the contact details were obtained during a sale, you are marketing only your own similar products or services, and you offered an opt-out at the time of collection and in every subsequent message. This exception applies exclusively to your own customers — not to purchased lists, not to event contacts, and not to contacts from a business you acquired.
Does POPIA apply to B2B email addresses?
POPIA protects personal information relating to natural persons, and a business email address that identifies a specific individual — firstname.lastname@company.co.za — qualifies under that definition. The Information Regulator's December 2024 Guidance Note does not establish a B2B exemption for electronic direct marketing, and silence is not an exemption. The safest position is to treat personalised business email addresses as personal information and apply the section 69 consent rules accordingly; generic addresses like info@company.co.za are less clearly in scope but depend on context.
What is the CPA opt-out registry and does it apply to B2B marketers?
The 2026 CPA Amendment Regulations require all direct marketers — including B2B operators — to register with the National Consumer Commission (NCC) and to cleanse their databases monthly against a national opt-out registry. The regulations took effect on 15 April 2026, with the registry operational from July 2026. Implementation is phased; confirm current obligations directly with the NCC. Any contact on the registry cannot be marketed to electronically, regardless of whether you hold consent.
What is the penalty for sending marketing emails to a purchased list under POPIA?
Breaching POPIA's direct marketing rules can result in an enforcement notice from the Information Regulator. Failure to comply with an enforcement notice carries criminal penalties of up to R10 million and/or imprisonment of up to 10 years under sections 107 and 109 of the Act. Non-compliance with the 2026 CPA Amendment Regulations carries a separate administrative penalty of up to R1 million or 10% of annual turnover, whichever is greater. These penalties apply independently and can run simultaneously.
Build a B2B Pipeline That Compounds — Without the Compliance Risk
Growth Pulse Media designs consent-first lead generation architectures for South African B2B businesses — LinkedIn, content, email and paid channels working together to build an owned database that is both commercially scalable and fully POPIA-compliant. Senior-level execution, in-house, with a limited client load so your pipeline gets the attention it needs. No obligation — we will get back to you within 24 hours.
Talk to Us About Your Pipeline

