Marketing to minors in South Africa is governed by a layered framework of three pieces of legislation and an industry code — each with a different definition of "child," a different regulator, and a different set of obligations. This post maps exactly what applies at each age threshold so you can build a compliant approach rather than patch one together after a complaint. For the broader digital compliance picture, the website compliance guide for South African businesses covers the full regulatory landscape your site must satisfy.

The common mistake is treating this as a POPIA-only question. POPIA governs the data you collect; the Advertising Regulatory Board (ARB) controls what your creative can do; the Consumer Protection Act (CPA) classifies all minors as vulnerable consumers; and since April 2026, Meta's own platform mechanics enforce a version of these rules automatically — whether your account is set up to respect them or not. Miss any one layer and your exposure sits in whichever regulator owns that channel. The obligations around advertising to minors in South Africa are concurrent, not sequential: passing the POPIA data test does not clear you on the ARB creative standard, and vice versa.

Quick Answer

Marketing to minors in South Africa requires prior consent from a competent person (parent or guardian) before you collect any personal data from anyone under 18, under POPIA sections 34–35. Separately, the ARB Code of Advertising Practice prohibits exploiting the inexperience or credulity of children in any advertising, with stricter category-specific bans on gambling, vaping and alcohol creative targeting under-18s. Since April 2026, according to third-party reporting, Meta has removed interest-based, behavioural and retargeting options for users aged 13–17 globally — you can reach that audience by age, gender, country, and contextual placement based on current content only.

Not sure which compliance layer applies to your site?

Send us your current website and we will review the age-gating, consent flows and data collection points and show you specifically where the gaps are.

Get a Free Compliance Review

What counts as marketing to minors under South African law

South African law governs marketing to minors through at least three concurrent frameworks — POPIA, the CPA, and the ARB Code — each with a different definition of "child," a different age threshold, and a different regulator, so satisfying one does not discharge the others. POPIA defines a child as any natural person under the age of 18 who is not legally competent to take any action or decision for themselves without the assistance of a competent person. That is a higher threshold than the 13-year cutoff common in US-drafted privacy templates, and it means that any website handling South African users must treat all under-18s as a protected category, not just those under 13.

The ARB Code of Advertising Practice takes the same under-18 baseline for most of its restrictions, but adds a stricter under-12 rule for specific product categories (food advertising in particular). The ICASA Broadcasting Code defines "children" as persons below 16 years — but this definition applies specifically to broadcast television content, not to digital or direct channels. For digital advertising, the POPIA and ARB frameworks are the operative standards.

In practice, advertising to children in South Africa across digital channels triggers obligations across three axes simultaneously: what data you collect (POPIA), what your creative shows and implies (ARB), and whether your audience targeting is lawful (platform mechanics + ARB Appendix C on direct marketing). The sections below address each axis in turn.

Key Takeaway

POPIA's age threshold is 18 — not 13. Any SA website handling user data must treat all under-18s as a protected class requiring parental or guardian consent for data processing. US-style "under-13 only" privacy policies are not compliant with South African law.

POPIA's three-part compliance requirement for child data

Section 34 of POPIA states the general rule plainly: a responsible party may not process the personal information of a child. Section 35 then lists the exceptions — the most practical being prior consent of a competent person, defined as a parent or legal guardian under the Children's Act 38 of 2005. If your site collects any personal information (name, email, phone, location, device identifiers, behavioural data) from a user who may be under 18, and you cannot demonstrate that a section 35 exception applies, you are in breach.

For the vast majority of businesses, the workable path through section 35 involves three concrete steps. First, an age gate that genuinely asks users for their age — a self-declared birthdate is the accepted starting point, but SA legal guidance is clear that you must act on the answer rather than collect it and ignore it. Second, a competent-person consent flow that you can evidence: a documented email or in-app confirmation loop to the parent or guardian, recorded before the child account starts generating any data. Third, data minimisation for minor accounts — no behavioural advertising profiles, no unnecessary device identifiers, and collection limited strictly to what the feature requires.

For sites not specifically aimed at children but clearly attractive to them (gaming accessories, sports gear, youth fashion), the defensible position is to design the default data experience as if minors are present until age is established, with documented reasoning supporting the methodology. This is the guidance position from SA technology law practitioners and aligns with how the Information Regulator frames responsible party obligations. For more on how POPIA structures operator and responsible party obligations, the POPIA operator agreement guide for SA businesses covers the accountability chain in detail.

POPIA administrative fines can reach R10 million. In practice, fines imposed to date have ranged from R100,000 to R5 million — issued only after an enforcement notice was ignored. The first fine (R5 million, Department of Justice, July 2023) established that the Regulator acts; the WhatsApp enforcement notice of April 2025 confirmed that data-handling standards applied to European users must apply in South Africa too. Criminal liability (up to ten years' imprisonment) attaches only to specific offences such as obstructing the Regulator, not routine processing errors — but the civil claim for damages from an affected data subject runs separately from the administrative process and may carry greater practical financial exposure.

POPIA's direct electronic marketing provisions (section 69) require consent or the existing-customer exception for sending commercial messages. Under the 2026 CPA Amendment Regulations, businesses must also check the national direct marketing opt-out registry before sending — and compliance with the CPA's opt-out regime does not remove the obligation to comply with POPIA. Both frameworks apply. For the full picture on POPIA children personal information obligations as they interact with direct marketing, the SA email marketing law guide covers section 69 alongside the CPA and ECTA framework.

POPIA Penalty Ladder

Step 1: Complaint or investigation initiated
Step 2: Enforcement notice issued — corrective instruction, appealable to the High Court
Step 3: Administrative fine (R100,000–R10 million maximum) only if enforcement notice is ignored
Step 4: Criminal charges (up to 10 years) for obstruction or failure to comply with enforcement notices
Separate track: Data subject civil claim for damages — strict liability, no cap

ARB creative restrictions: what changes at each age

The ARB Code of Advertising Practice governs all advertising in South Africa — not just broadcast. Its general rule is that advertising aimed at, featuring, or likely to influence minors must not exploit the inexperience or credulity of children. Minors cannot be portrayed as sexually appealing or provocative, involved in sexual innuendo, or engaging in dangerous activities. These baseline rules apply across every medium and every product category.

Appendix C (Direct Marketing) of the ARB Code adds a specific consent layer for direct marketing to minors: marketers must obtain express consent from a minor for the collection and use of personal or contact information, and obtain express consent from the parent or guardian before disclosing a minor's contact information to any third party. Where a parent, guardian, or the minor themselves withdraws permission, the marketer must immediately delete all such information from its database. This is operationally more demanding than the POPIA consent requirement — it applies to the use of the data in direct marketing, not just to the initial collection.

On the creative side, the key age-based thresholds break down as follows:

Age ThresholdRuleCategorySource
Under 12TV commercials for products of questionable nutritional value may not feature celebrities, cartoon characters, puppets or computer animationsFood advertisingARB Code
Under 16Programming watershed — content not suitable for children may not broadcast before 21h00Broadcast TV (ICASA)ICASA Broadcasting Code
Under 18Gambling advertisements may not target minors or depict under-18s engaged in gamblingGamblingARB Gambling Code
Under 18Competitions linked to alcohol products cannot target under-18s; social media alcohol advertising requires age verificationAlcoholARB Code
Under 18Vaping products may not advertise to under-18s; ads may not feature anyone appearing under 25Vaping / e-cigarettesARB Code
Under 18Direct marketing contact data requires express parental/guardian consent before collection or sharingAll direct marketingARB Appendix C

The ARB's enforcement mechanism is a complaints-based system administered by an independent tribunal. Brands found in breach face corrective orders, required retractions and remediation campaigns — significant reputational and cost exposure for any business with meaningful SA brand value. Influencer campaigns fall under the same code: the ARB influencer disclosure rules cover what disclosures are required when a creator's audience includes minors.

Key Takeaway

The ARB's direct marketing appendix requires more than a POPIA consent tick-box. You need express parental consent before collecting OR sharing a minor's contact information — and you must delete it the moment permission is withdrawn. These are separate, concurrent obligations.

What Meta removes automatically from April 2026

Meta completed the global rollout of Teen Accounts across Instagram and Facebook in April 2026, extending changes that had previously launched in select English-speaking markets to every remaining region — including Africa. The implication for South African advertisers is that several targeting categories that may have been part of existing campaign setups no longer function for users aged 13–17, regardless of how the campaign is configured.

According to third-party reporting, the targeting methods now removed for this age group include interest-based targeting across all categories, behavioural targeting (purchase history, device usage patterns, travel behaviour), lookalike audiences built from teen users, custom audiences from website or app activity, customer list matching, engagement-based custom audiences, retargeting, and city-level or postal-code location targeting. What remains available, per the same reporting, is age, gender, and country or region — and contextual placement based on the content a teen is currently viewing.

Additionally, Meta's own advertising standards prohibit restricted-category ads — alcohol, financial products and weight-loss products and services — from being shown to users under 18. This operates at the platform level independently of your own targeting choices. If your ad is in a restricted category and a user is under 18, Meta's system suppresses the impression; there is no override available to the advertiser.

The practical implication: if you have been running campaigns with interest-based or lookalike targeting that included teen-age users, those targeting components no longer reach that audience. Checking your existing ad sets against these updated parameters is worth doing before the next campaign cycle rather than after a period of unexplained reach decline.

Running campaigns that may be reaching under-18s?

Share your current Meta or Google Ads account structure and we will walk through which settings may be non-compliant or redundant after the April 2026 platform changes.

Get a Campaign Compliance Check

Compliance decision table: law, age threshold, and what you need

When marketing to minors, compliance is most usefully understood as a grid: the law or regulator determines the obligation type, and the age threshold determines when it activates. A solid marketing to minors compliance framework addresses data collection, creative standards and platform targeting as separate but concurrent obligations. Managing digital marketing to minors across multiple legal frameworks is where most businesses find their current setup has gaps. The table below consolidates the principal obligations — use it as a checklist before launching any product, website or campaign that may reach users under 18.

Law / RegulatorAge TriggerWhat It GovernsWhat You Need
POPIA ss 34–35Under 18All personal data collectionAge gate + documented parental/guardian consent before any data is generated
POPIA s69 + 2026 CPA RegsUnder 18Direct electronic marketingConsent or existing-customer exception AND opt-out registry check
ARB Appendix CUnder 18Direct marketing data useExpress parental/guardian consent before collecting or sharing contact info; immediate deletion on withdrawal
ARB Code (general)Under 18All advertising creativeNo exploitation of inexperience or credulity; no sexualisation; no depiction in dangerous activities
ARB (gambling / vaping / alcohol)Under 18Category creative and targetingNo targeting of under-18s; gambling / vaping ads may not depict them; alcohol competitions excluded
ARB Code (food)Under 12TV commercials for nutritionally questionable productsNo celebrities, cartoon characters, puppets or computer animations in those formats
ICASA Broadcasting CodeUnder 16TV broadcast content (not digital advertising)Child-appropriate content before 21h00 watershed
Meta platform (April 2026)Ages 13–17Facebook and Instagram ad targetingAge, gender, country/region, and contextual placement available; all interest, behavioural and retargeting removed (per third-party reporting)
CPA ss 3, 29, 41Under 18All consumer-facing marketingNo misleading, deceptive or unfair practices; vulnerable-consumer classification applies

Two additional obligations are worth noting. First, under the Electronic Communications and Transactions Act, a contract with a minor carries limited enforceability — if your site collects payment from under-18s without parental consent, the transaction structure may be challengeable. Second, SA's government is advancing a proposal to restrict social media access for under-16s across major platforms; this is not yet enacted as at September 2026, but the direction of travel is relevant for businesses with significant under-16 audiences on Instagram, TikTok or YouTube.

For businesses that need to review whether their site's current disclaimer and policy infrastructure reflects these obligations accurately, the ecommerce disclaimers guide maps what a compliant policy layer looks like in practice. Competition mechanics that target younger audiences also carry their own compliance layer under SA law — the competitions and promotions rules guide covers what changes when the audience includes minors.

Does your current site collect data from anyone who could be under 18?

Tell us about your audience and we will audit your data capture points, consent flows and policy documents against the POPIA and ARB requirements set out above.

Book a Free Website Audit

Why South African businesses choose Growth Pulse Media

Dirk van Greuning built and scaled a South African ecommerce business before founding Growth Pulse Media — which means every compliance and data architecture decision we recommend comes from experience with the same regulatory framework our clients navigate, not from adapting a global template to an SA context.

Our web design work for South African businesses builds age-verification flows, structured consent capture and data-minimisation defaults into site architecture from day one. We implement these in WordPress and Shopify environments using a development process that keeps the compliance layer separate from the commercial layer — so updating a consent flow when the law changes does not require a full site rebuild. We work with a limited client load so that senior attention applies at every stage, from initial scoping through to launch review.

All work is executed in-house. We do not brief sub-contractors on sensitive compliance architecture, and we do not hand you a site without walking through the POPIA, ARB and CPA touchpoints relevant to your specific audience and product category. If your audience includes under-18s — or may include them based on your product — that conversation happens during brief, not as a discovery after launch.

Who this compliance framework is not for

Purely B2B operators with no consumer-facing digital touchpoints. If your business only markets to procurement teams and has no forms, accounts or content accessible to the general public, POPIA sections 34–35 and the ARB Appendix C requirements do not apply to your data flows. This post is not written for your context.

Businesses expecting a single cookie consent banner to satisfy child data obligations. A general-purpose "we use cookies" pop-up does not constitute parental consent under POPIA section 35, and it does not satisfy the ARB Appendix C requirement for express parental consent before collecting or sharing contact information. If your compliance is currently a consent banner, the data collection layer needs a rebuild, not a policy update.

Businesses that need a POPIA Information Officer appointment or regulatory filing service. Growth Pulse Media builds compliant digital infrastructure — website architecture, consent flows, data minimisation defaults, and policy documentation. Statutory Information Officer appointments and formal POPIA compliance submissions require a qualified legal practitioner. We are not that service.

Businesses wanting to run interest-based or behavioural campaigns specifically targeting teenagers on Meta. That targeting category was removed globally in April 2026. It does not exist in the platform regardless of who manages the account. The only parameters available when marketing to minors on Meta are age, gender, country, and contextual placement — if your strategy depended on interest-based or behavioural options beyond that, the strategy needs to change, not the setup.

Frequently asked questions

What is the legal age of a child under POPIA in South Africa?

Under POPIA, a child is defined as any natural person under the age of 18 who is not legally competent to take any action or decision for themselves without the assistance of a competent person. This is a higher threshold than the 13-year cutoff used in US privacy law (COPPA), so US-drafted privacy templates that treat under-13s as the protected class are not compliant with South African law. Any SA business collecting personal data from users must treat all under-18s as requiring parental or guardian consent under POPIA sections 34–35.

Does my website need parental consent before collecting personal data from under-18s?

Yes, in most cases. POPIA section 34 prohibits processing a child's personal information unless a section 35 exception applies — the most practical being prior consent from a parent or guardian (a "competent person" under the Children's Act). In practice this means an age gate that genuinely acts on the result, a documented parental consent flow recorded before any data is generated, and data minimisation so the child account holds only what the feature requires. POPIA does not prescribe a specific technical verification method, but the responsible party must demonstrate that the conditions for lawful processing have been met.

Can I target teenagers on Meta platforms in South Africa?

According to third-party reporting, Meta completed the global rollout of Teen Accounts in April 2026, removing interest-based targeting, behavioural targeting, lookalike audiences, custom audiences, retargeting, and city-level location targeting for users aged 13–17 globally. What remains available, per the same reporting, is age, gender, country or region, and contextual placement based on the content the teen is currently viewing. This change is platform-enforced globally — including South Africa — and is not configurable by the advertiser. Additionally, restricted-category ads (alcohol, financial products, weight-loss products) cannot be shown to under-18s regardless of targeting settings.

What does the ARB say about advertising food products to children?

The ARB Code of Advertising Practice restricts food advertising to children under 12 by prohibiting TV commercials for products of questionable nutritional value from featuring celebrities, cartoon characters, puppets or computer animations. This restriction is specific to television commercials — not digital advertising broadly — but the ARB's general rule that advertising must not exploit the inexperience or credulity of children applies across all media and all product categories. Businesses in food and beverage categories should review both the category-specific restriction and the general creative standard when developing child-directed or child-adjacent campaigns.

What are the POPIA penalties for processing children's data without consent?

The maximum administrative fine under POPIA is R10 million, though actual fines issued to date have ranged from R100,000 to R5 million. The enforcement process follows a ladder: a complaint or investigation leads first to an enforcement notice, and a fine is imposed only if the notice is ignored. In addition, data subjects can separately bring civil claims for damages under strict liability — a path that may carry greater financial exposure than the administrative fine for businesses with large user bases. Criminal liability (up to ten years' imprisonment) applies only to specific offences such as obstructing the Information Regulator, not to routine processing errors.

Build a site that handles under-18 audiences correctly from the start

Growth Pulse Media designs and builds South African websites with POPIA, ARB and CPA compliance built into the architecture — not bolted on after launch. We work with WordPress and Shopify, integrate with SA payment gateways including PayFast and Peach Payments, and manage consent flows that meet the parental authorisation standard required by sections 34–35. No obligation — we will get back to you within 24 hours.

Get a Free Consultation
Dirk van Greuning — Founder, Growth Pulse Media
Dirk van Greuning Founder, Growth Pulse Media

Founder of Growth Pulse Media and a specialist in South African search dominance. Dirk translates his experience in scaling South African businesses into high-velocity digital strategies for B2B and retail leaders. He writes about SEO, lead generation, and paid media from an operator's perspective — prioritising pipeline value over impressions.

Connect on LinkedIn