South Africa's email marketing law is not one rule but three overlapping Acts, each with a different regulator, a different penalty scale, and a different job to do — and as of 2026, all three apply simultaneously to every commercial message your business sends. Website and digital compliance in South Africa spans the same framework: POPIA governs consent and data use, the Consumer Protection Act governs recipients' blocking rights, and the Electronic Communications and Transactions Act set the original disclosure floor. If your email programme was built before April 2026, there is a new mandatory layer you may not have added yet.
The practical problem is that most SA operators know they need an unsubscribe link, assume that covers them, and stop there. The POPIA operator regime and the 2026 Consumer Protection Act amendments created obligations that go well beyond a footer opt-out — including a national opt-out registry that overrides consent you already collected. This post maps all three laws to the scenarios that actually arise in practice, so you can tell at a glance whether a given segment is legally mailable.
Quick Answer
South Africa's email marketing law draws from three Acts: POPIA section 69 (the primary law for electronic direct marketing), CPA section 11 (individual opt-out rights, plus an NCC national registry as of April 2026), and ECTA (disclosure obligations). For a cold prospect, you may send one consent-request message only — no direct marketing content until they agree. For existing customers, you may email without fresh consent if three specific POPIA conditions are all met, but you must still check the NCC registry at least monthly and honour any block immediately. Non-compliance carries administrative fines under both POPIA and the CPA — covered in detail in the penalties section below.
Jump to a section
Not sure your opt-in forms capture consent the way POPIA requires?
Share your current sign-up flow and we will check it against the Section 69 requirements and the 2026 CPA registration obligations — no obligation.
Get a free compliance checkWhat South Africa's email marketing law requires from every sender
South African email law rests on three statutory pillars that work in parallel — satisfying one does not excuse non-compliance with the others. Understanding the direct marketing law South Africa operates under is the starting point for building a compliant email programme, because each Act carries its own regulator, its own enforcement mechanism, and its own penalty scale.
| Act | Primary obligation for email senders | Regulator |
|---|---|---|
| POPIA s69 | Section 69 restricts the lawful basis for direct electronic marketing specifically to consent or the existing-customer exception under s69(3). POPIA s11 lists six lawful bases for general data processing, but s69 is the controlling provision for email campaigns: those six bases do not expand what you may rely on when sending commercial messages electronically. One-approach rule for cold prospects; every message must identify the sender and include an opt-out mechanism. | Information Regulator |
| CPA s11 + 2026 Regulations | Recipients can pre-emptively block all electronic marketing via national NCC registry; marketers must register annually with NCC, cleanse databases monthly; all commercial messages must show full identity and address | National Consumer Commission (NCC) |
| ECTA (residual) | Section 45 (the original spam provision) was repealed when POPIA commenced on 1 July 2021; ECTA s43 disclosure obligations and s44 seven-day cooling-off for online purchases still apply | Courts (civil enforcement) |
The practical effect: POPIA s69 is your primary authority on whether you may send a commercial message at all. The CPA adds a national blocking layer that can remove permission you already have. ECTA fills in the disclosure floor and governs what happens after a purchase triggered by your email.
How POPIA section 69 governs direct electronic communications
POPIA section 69 is the operative law for electronic direct marketing in South Africa — it replaced ECTA section 45 when POPIA commenced on 1 July 2021, shifting the channel from an opt-out model to an opt-in model.
Section 69(1) of POPIA states that processing personal information for the purpose of direct marketing by means of any form of electronic communication — including email, SMS, fax and automatic calling machines — is prohibited unless the data subject has given consent, or the data subject is an existing customer and the conditions in section 69(3) are met. Both bases have distinct requirements, and only one needs to apply for any given send, but neither is automatic.
The one-approach rule (POPIA s69(2))
If a prospect has not previously refused direct marketing, you may approach them once to request consent. That single approach must identify your organisation and provide a way to opt out of further contact. If they decline, or if they have previously refused, you cannot approach them again. The approach can request consent — it cannot contain direct marketing content itself.
The December 2024 guidance note issued by South Africa's Information Regulator confirmed that where consent is the basis relied on for POPIA email marketing, it must be informed, voluntary and specific — a pre-ticked box or a bundled-in terms clause does not qualify. It also confirmed that telephone calls are treated as electronic communications under this framework, bringing cold calling under the same opt-in standard.
For non-electronic direct marketing (physical mail), businesses may rely on legitimate interests through a three-stage assessment examining purpose, necessity and balance. Electronic channels have no equivalent — consent or the existing-customer exception are the only lawful bases for email campaigns under s69.
Key point: POPIA s69 is opt-in, not opt-out
Before POPIA, SA email marketing operated under ECTA section 45's opt-out model — you could send, and recipients could unsubscribe. POPIA reversed this: you need a lawful basis (consent or existing-customer exception) before the first send. An unsubscribe link satisfies the message-level obligation but does not create the initial sending right.
The existing-customer exception: three conditions that must all be met
Section 69(3) of POPIA permits email campaigns to existing customers without fresh consent, but only when all three conditions below are satisfied simultaneously. One gap disqualifies the exception and requires you to obtain consent before sending.
| Condition | What it means in practice | Common mistake |
|---|---|---|
| Contact details obtained in the context of a sale or service | The email address came from an actual transaction — not a competition, a giveaway, or a third-party list | Using emails collected via a lead magnet or list rental as if they were "customers" |
| Marketing is for your own similar products or services | If you sold running shoes, you can promote other running gear — not affiliate offers, partner products or unrelated categories | Including third-party promotions or cross-sell categories with no similarity to the original purchase |
| Opt-out offered at collection AND in every subsequent message | The customer must have been given a free, clear way to object when you first took their details, and every campaign must carry the same mechanism | Collecting the address at checkout without an opt-out option, or sending emails without an unsubscribe link |
The existing-customer exception does not stretch to re-engagement of lapsed buyers, marketing from related companies sharing a database, or campaigns to leads who never converted. In all those situations you need explicit POPIA consent before sending.
The CPA opt-out registry and what it demands from senders
The 2026 Consumer Protection Act Amendment Regulations introduced a national opt-out registry administered by the National Consumer Commission that adds a second, independent obligation on top of POPIA — and it is the layer most SA email operators have not yet integrated.
The regulations took effect on 15 April 2026. Registration for direct marketers and consumers opened in July 2026. The NCC describes the registry as a fundamental shift in how unsolicited electronic communications are governed. The framework operates as follows:
- Marketer registration: all direct marketers must register with the NCC and renew annually. Non-registration is itself a violation of the 2026 Regulations.
- Consumer pre-emptive blocks: any consumer may register a pre-emptive block on the NCC registry, which prohibits you from sending them electronic marketing communications from any business — not just yours.
- Monthly database cleansing: marketers must remove from their databases all contacts who have registered a pre-emptive block, on at least a monthly cycle.
- Mandatory message identity: all electronic commercial messages must include the marketer's name, electronic address, physical address and contact number. This is a separate requirement from the POPIA s69(4) sender-identification obligation — both must be satisfied.
Critical interaction: treat a pre-emptive NCC block as a hard stop
If a consumer who previously opted in to your emails later registers a pre-emptive block on the NCC registry, the safest position — and the one legal counsel consistently recommends — is to treat that block as superseding the earlier consent. The 2026 Regulations do not yet provide a practical mechanism for the one potential exception (a subsequent prescribed-form opt-in obtained demonstrably after the block was registered, which remains legally unsettled). Both the POPIA objection right and the NCC registry block independently terminate your sending permission — satisfying one does not excuse non-compliance with the other.
The CPA's five-business-day cooling-off period also applies specifically to purchases resulting from direct marketing approaches (offers you initiate proactively). Where a purchase results from a standard online transaction rather than a direct marketing approach, ECTA section 44 provides a seven-day cooling-off period instead — these are different rights with different triggers, and they are not interchangeable.
Mandatory disclosures in every commercial message
A legally compliant SA marketing email must contain specific information drawn from both POPIA s69(4) and the 2026 CPA Regulations. Neither set alone is sufficient; together they define the minimum content of every outbound commercial message.
| Required element | Authority | Notes |
|---|---|---|
| Identity of the sender (or the party on whose behalf the email is sent) | POPIA s69(4)(a) | Trading name and legal entity name where different |
| Contact address or details allowing recipient to request cessation | POPIA s69(4)(b) | An accessible, working email address or unsubscribe mechanism |
| Electronic address of the direct marketer | CPA 2026 Regulations | A business reply address — a no-reply address does not satisfy this |
| Physical address of the direct marketer | CPA 2026 Regulations | Registered business address |
| Contact number of the direct marketer | CPA 2026 Regulations | A number at which the marketer can actually be reached |
The email marketing regulations South Africa imposes through the CPA 2026 Regulations are practical requirements, not aspirational standards — they apply to every outbound campaign regardless of platform. Most reputable email platforms — Klaviyo, Omnisend and Mailchimp among them — include fields for physical address and sender identity in their footer templates.
Leaving those fields blank, or populating them with a no-reply address, does not satisfy the CPA 2026 requirement for a functioning contact address. Check every template you are currently using against this table. You can read more about the disclosure requirements SA online stores actually need, many of which carry across to email footers.
Three-scenario decision table for SA email senders
The most useful output of the three-law framework is a practical decision tool. South Africa's email marketing law applies differently depending on the recipient's relationship with your business and their NCC registry status: given a specific segment in your database, can you legally send a marketing email to it, and what must that email contain? The table below maps the three scenarios that cover most SA email marketing situations.
| Scenario | POPIA s69 status | CPA 2026 check | Permitted action |
|---|---|---|---|
| Cold prospect — no prior transaction, no consent on file | One approach permitted to request consent only (s69(2)); no marketing content in that message; must disclose identity and opt-out | Check NCC registry before approach; cannot approach if registered pre-emptive block | One consent-request message with mandatory disclosures. Nothing else until explicit consent received. |
| Existing customer — all three s69(3) conditions met; not on NCC registry | Existing-customer exception applies; no separate consent required for similar-product campaigns | Must cleanse against NCC registry at least monthly; honour individual CPA opt-out requests immediately | Regular campaigns for similar products; every email must include all mandatory disclosures and a free opt-out |
| Existing customer or consented subscriber who has registered a pre-emptive NCC block | Treat the block as terminating sending permission; a post-block prescribed-form opt-in may be the one potential exception, but this is legally unsettled and the Regulations provide no clear mechanism for it | Marketing to this contact is prohibited until the pre-emptive block is removed by the consumer | Remove from all electronic marketing databases. Transactional and service emails (not promotional) are not affected. |
This table reflects the interaction as set out in the 2026 CPA Regulations and the Information Regulator's December 2024 guidance note. Legal interpretation of how exactly prior consent and a post-block prescribed-form opt-in interact is still developing — the safest position is to treat any NCC block as a hard stop on electronic direct marketing.
Need to check whether your list qualifies as legally mailable?
Tell us how your contacts were collected and we will map them against the three scenarios above — so you know exactly which segments you can send to before your next campaign goes out.
Get a list auditPenalties for non-compliance: what the regulators can impose
Both regulators have moved from issuing guidance to issuing fines, and the enforcement posture is escalating. The structure of penalties differs between POPIA and the CPA.
Under POPIA: the Information Regulator follows an escalating sequence — investigation, enforcement notice, and then an administrative fine if the notice is ignored. The maximum administrative fine is R10 million. Persistent non-compliance with an enforcement notice can result in criminal prosecution carrying imprisonment of up to 10 years, a fine, or both.
In 2024–25, FT Rams Consulting received an R100,000 administrative fine for sending persistent marketing emails without consent and continuing after opt-out requests — the first direct marketing fine under POPIA, now being recovered through court. As of August 2026, the Regulator has issued six administrative fines and has two direct marketing matters in court proceedings.
Under the CPA 2026 Regulations: the NCC can impose an administrative penalty of up to R1 million or 10% of the direct marketer's annual turnover, whichever is the greater. Failure to comply with an NCC compliance notice carries a further potential penalty of up to 12 months' imprisonment.
The enforcement pattern to understand
Under POPIA, the road to a fine runs through ignoring the Regulator — an enforcement notice comes first, and a fine follows only if the notice is disregarded. Under the CPA 2026 Regulations, the administrative penalty can follow directly from the violation. Both regulators are active, and the FT Rams Consulting case shows that volume and persistence of non-compliant email is enough to trigger formal action.
Why South African Businesses Choose Growth Pulse Media
Dirk van Greuning built and scaled a large South African ecommerce business before founding Growth Pulse Media. Running campaigns at that scale meant learning POPIA's direct marketing provisions not as a compliance exercise but as a practical constraint that determines whether your list is actually sendable — and what happens to deliverability when you get it wrong.
GPM works with a deliberately limited number of clients and executes all work in-house. Registered Shopify Partner and Omnisend Certified Partner. When we build email programmes, the lawful basis — whether consent under s69(1) or the existing-customer exception under s69(3) — is determined at the point of collection, not in the email platform. The opt-in form on your website is where that basis is either captured correctly or lost entirely. A form that does not meet the requirements for whichever basis you are relying on cannot be fixed by email-platform settings later.
For businesses whose existing sites were built before the 2026 CPA Regulations took effect, we review the consent capture flow, sender identity disclosures, and opt-out mechanics against the three-law framework. You can also read more about the POPIA rules for cold email specifically if your outreach programme includes prospecting to contacts who have not opted in.
Who This Is NOT For
Ready to build an email programme that is legally sound from the opt-in form outward?
Send us your current setup — forms, templates and platform — and we will run it against the s69 requirements, the 2026 CPA Regulations, and the mandatory disclosure checklist. No obligation, and we will get back to you within 24 hours.
Request a free reviewFrequently Asked Questions
Can I email my existing customers without POPIA consent?
You may email existing customers without separate POPIA consent only when all three conditions in section 69(3) are met: their contact details came from an actual transaction with your business; you are promoting your own similar products or services; and you offered a free opt-out both when you collected their details and in every subsequent message. If any of those three conditions is not satisfied, you need explicit consent before sending. You must also check the NCC opt-out registry monthly and remove anyone who has registered a pre-emptive block — even a customer who previously agreed to receive your emails.
What is the one-approach rule under POPIA section 69?
Section 69(2) allows you to contact a cold prospect once to request consent for direct marketing, provided they have not previously refused. That single approach must identify your organisation, provide an opt-out option, and must not contain direct marketing content — it is a consent request, not a campaign. If the prospect declines or does not respond, you cannot contact them again for marketing purposes. This rule applies to email, SMS, phone calls and any other electronic channel.
Do POPIA and the CPA apply at the same time to email marketing?
Yes, both apply simultaneously and independently. Where they overlap and create different standards, the stricter standard applies — which for electronic direct marketing means POPIA's opt-in requirement governs the sending right, while the CPA's 2026 NCC registry adds an obligation to cleanse databases monthly and to register annually with the NCC. Complying with one framework does not excuse non-compliance with the other, and the email law South Africa imposes through both Acts must be satisfied in full for every campaign.
What must every SA marketing email include by law?
Under POPIA s69(4) and the 2026 CPA Regulations, every commercial email must include: the identity of the sender (trading name and legal entity where different); a functioning reply address or mechanism through which recipients can request that marketing stop; a physical business address; and a contact telephone number. A no-reply sender address does not satisfy the CPA requirement for a functioning contact address. The unsubscribe link satisfies the opt-out mechanism requirement but does not substitute for the physical address or phone number.
What happens if I ignore an Information Regulator enforcement notice?
If you fail to comply with an enforcement notice issued by South Africa's Information Regulator, the consequence escalates from administrative fine to potential criminal prosecution. The maximum administrative fine under POPIA is R10 million. Persistent non-compliance can result in criminal liability carrying imprisonment of up to 10 years or a fine or both. The FT Rams Consulting case — a documented R100,000 fine for persistent unsolicited emails — shows that the Regulator is prepared to pursue court recovery where administrative fines are not paid.
Build an email list that is legally yours to send to
Growth Pulse Media designs opt-in flows that establish the correct lawful basis at the point of collection — whether that is consent under POPIA s69(1) or the conditions for the existing-customer exception under s69(3) — include the mandatory CPA disclosures in every template, and connect to the opt-out mechanisms the law requires. As a registered Shopify Partner and Omnisend Certified Partner, we implement this across the platforms SA operators actually use — and we execute in-house, not through a sub-contractor chain. No obligation — we will get back to you within 24 hours.
Talk to us about your email setup

