On This Page
Key takeaways
- POPIA requires prior, explicit opt-in consent for marketing to anyone outside an existing customer relationship.
- Bought or rented lists rarely carry valid consent for your specific business and create real complaint risk.
- Documented, timestamped consent records are your main defence if a complaint reaches the Information Regulator.
- Treat your privacy and consent pages as genuine content, not boilerplate, since this also supports trust and SEO.
Why POPIA Matters for Database Marketing
South African businesses have collected names, emails and phone numbers for marketing lists for years, often without a clear legal basis. The Protection of Personal Information Act changed that, and the Information Regulator has shown it will act on complaints. A marketing database built without proper consent is now a liability rather than an asset.
This matters most for small and medium businesses that rely on email newsletters, WhatsApp broadcasts or SMS promotions to drive repeat sales. One complaint from an annoyed customer can trigger an investigation into your entire database. Getting the basics right costs far less than fixing them after a complaint lands.

What POPIA Actually Says About Direct Marketing
Section 69 of POPIA deals directly with marketing by electronic communication. It requires prior consent before you send marketing emails, SMSes or WhatsApp messages to someone you have not sold to before. The law treats an existing customer relationship differently from a cold contact.
If someone bought from you already, you can market similar products to them without fresh consent, provided you gave them a clear chance to opt out at the time of collection. For anyone outside that relationship, you need explicit opt-in before the first message goes out. This single distinction trips up more South African businesses than any other part of the Act.
The Difference Between Opt-In and Opt-Out
Opt-in means a person actively ticks a box or signs up before you add them to a list. Opt-out means you add them first and let them leave later, a pattern POPIA restricts for new contacts. Many older databases in South Africa were built the opt-out way, through conference sign-up sheets or bought lists.
Switching a database culture from opt-out to opt-in takes discipline, but it is the only defensible position under the Act. Every new form, pop-up or paper sign-up sheet should ask for consent before the contact is added, not after.
Penalties and Enforcement by the Information Regulator
The Information Regulator can issue fines, enforcement notices and, in serious cases, criminal penalties for non-compliance. It has already pursued action over unsolicited marketing complaints, so this is not a theoretical risk. Writing trustworthy, people-first content about how you collect data is now part of avoiding that scrutiny.
Reputational damage from a public complaint often outweighs the fine itself for a small business. A customer who reports your SMS campaign to the Regulator will usually also post about it on social media first.
Building a Compliant Database From the Start
The cheapest way to stay compliant is to build the database correctly the first time. Retrofitting consent onto thousands of old contacts is slow, and some contacts are lost in the process. New collection points should be designed around consent from day one.

Consent at the Point of Collection
Every form, whether on your website, at a trade show or on a till slip, needs a clear consent statement next to the submit button. State what you will send, how often, and that the person can withdraw consent at any time. Avoid long legal paragraphs that nobody reads before ticking the box.
Pre-ticked checkboxes do not count as valid consent under POPIA. The box must start unticked, and the person must take the action themselves.
Website Forms and Lead Magnets
Lead magnets, such as a free guide or price list in exchange for an email address, are still subject to section 69 if you plan to market to that person afterwards. Separate the consent for the download from the consent for ongoing marketing emails. A lead generation form that bundles both into one tick box is harder to defend if challenged.
On mobile, where most South African visitors browse, a cramped consent checkbox is easy to misread or miss entirely. Test every form on a phone before it goes live, since a form that is technically compliant but practically unreadable still creates risk.
Buying or Renting Lists (and Why It's Risky)
Bought and rented marketing lists almost never come with POPIA-valid consent for your specific business. The person on that list consented to someone else contacting them, not to you. Using a purchased list for cold email or SMS campaigns is one of the fastest ways to attract a complaint.
If a list broker cannot show exactly when and how each contact consented to hear from your business by name, treat the list as non-compliant. Growing a list slowly through genuine opt-ins beats a large bought list that generates complaints instead of sales. Itβs less glamorous, but safer.
Cleaning Up an Existing Database
Most businesses trading before 2021 have a database built under looser rules. That does not mean starting over, but it does mean auditing what is there and dealing with the parts that will not hold up.
Auditing What You Already Hold
Pull your full contact list and sort it by source: online opt-in, trade show sign-up, business card, bought list, or unknown. Contacts with no record of how they joined your database are the highest risk group. Unknown-source contacts should be the first ones you re-permission or remove.
This audit also surfaces duplicate entries and outdated addresses that waste sending budget regardless of compliance. A smaller, accurate database usually performs better than a large, unverified one.
Re-permissioning Older Contacts
A single, honest email asking people to confirm their consent is the standard way to re-permission a list. Keep the ask short and explain what they will receive if they stay subscribed. Anyone who does not respond within a reasonable window should be removed rather than kept by default.
Re-permissioning campaigns typically shrink a list before they grow it, which can feel uncomfortable. A smaller list of people who actually opted in converts better than a larger one sitting on shaky consent.
Segmenting by Consent Status
Once the audit is done, tag every contact with their consent status and the date it was captured. This record becomes your proof of consent if a complaint ever reaches the Information Regulator. Most email platforms allow a custom field for this, so a separate system is not needed.
Segmenting also stops guesswork about who is safe to market to. New campaigns should pull only from the confirmed opt-in segment, never the full historical list.
Email and SMS Marketing Compliance in Practice
Compliance does not end once someone is on your list correctly. How you run ongoing campaigns matters just as much as how contacts got there.

Unsubscribe Mechanisms That Actually Work
Every marketing email and SMS needs a working unsubscribe link, and that request must be honoured within a reasonable time, not at your next quarterly clean-up. A broken unsubscribe link is one of the most common complaints the Information Regulator receives. Test the link yourself after every campaign send.
SMS and WhatsApp campaigns need the same standard, with a clear reply word like STOP that actually removes the person. Platforms that cannot support this reliably are not worth the convenience.
Record-Keeping as Proof of Consent
Keep a timestamped record of when and how each person opted in, whether that is a form submission log, a signed paper slip, or a confirmation email. Documented consent is what protects you if a contact later disputes receiving your marketing. Checking Search Console data for the landing page where a form lives can also show how often it was submitted, which supports your records.
Store this evidence somewhere separate from the marketing platform itself, in case you switch tools later. Losing proof of consent when migrating email providers is a common and avoidable mistake.
Third-Party Tools and Data Processor Agreements
If you use an email platform, CRM or SMS gateway to send campaigns, that provider is a data processor under POPIA and needs a written data processor agreement covering how it handles your contacts' information. Most reputable platforms already offer a standard version of this agreement. Confirm it is signed before you load a single contact into the system.
This applies even to free or low-cost tools, since the size of the provider does not change your obligations as the business collecting the data. Check where the provider stores data too, since cross-border storage adds another layer of POPIA requirements.
Turning Compliance Into a Trust Advantage
Compliance is often treated as a cost, but a visibly careful approach to customer data is also a selling point. South African consumers have grown more aware of how their information gets used.
Transparency as a Differentiator
A short, plain-language privacy notice on your contact and checkout pages signals that you take data seriously, at a time when many competitors still bury this in dense legal text. Plain language builds more trust than a long policy nobody reads. This is a small, low-cost way to stand out in a crowded inbox.
Mention your consent practices directly in onboarding emails rather than hiding them in a footer link. Customers who understand why they are receiving a message are less likely to complain about it.
Linking Compliance to Content and SEO
A dedicated privacy and data page, written clearly rather than copied from a template, also supports content marketing goals by giving the site genuine, specific pages instead of boilerplate. Search engines reward mobile-friendly, clearly structured pages, and a privacy page is no exception. Treat it as real content, not a legal afterthought buried in the footer.
Businesses rethinking their database strategy around POPIA often end up reviewing their wider content marketing strategy at the same time, since both depend on knowing exactly who you are talking to. If you are unsure who holds and controls customer data across different marketing tools, it is worth reading about data ownership in agency relationships generally.
Frequently asked questions
Do I need consent to email existing customers in South Africa?
No, if you already have a sale-based relationship with the customer, POPIA allows direct marketing of similar products without fresh consent, provided you gave them the chance to opt out when you first collected their details. You still need a working unsubscribe option on every message. This exception does not apply to contacts who have never bought from you.
Is WhatsApp marketing covered by POPIA?
Yes, WhatsApp broadcasts and groups used for marketing fall under the same section 69 rules as email and SMS. You need prior consent for anyone outside an existing customer relationship, and a clear way for recipients to opt out. Treat WhatsApp lists with the same care as an email database.
Can I still use a database I bought years ago?
Only if you can show that each contact gave valid, specific consent to receive marketing from your business, which most bought lists cannot prove. Without that evidence, using the list for cold outreach puts you at risk of a complaint to the Information Regulator. Re-permissioning the list or discarding it is usually the safer route.
What counts as proof of consent under POPIA?
A timestamped record showing when, where and how a person opted in, such as a form submission log, a signed physical form, or a confirmation email reply. Screenshots or exports from your email platform's sign-up history are usually enough. Keep this record separate from the platform itself in case you switch providers.
How much does non-compliance actually cost a small business?
The exact penalty depends on the Information Regulator's findings and can include fines, enforcement notices or, in serious cases, criminal liability, but there is no fixed Rand figure that applies to every case. The bigger practical cost for most small businesses is reputational, since complaints often become public before the Regulator even responds. Fixing a list after a complaint also takes far longer than building it correctly from the start.