The information provided on this blog and any articles is for general informational purposes only and does not constitute legal advice. The content is not intended to create, and receipt of it does not establish, an attorney–client relationship. You should not act upon any information contained in this blog without seeking professional counsel from a qualified legal advisor licensed in your jurisdiction. The authors and publishers of this blog disclaim any liability for actions taken or not taken based on the content herein.

KKA LEGAL LIFESTYLE BLOG

Law. Life. Clarity.

PoPIA and Direct Marketing: What Every South African Business Needs to Know


The Protection of Personal Information Act (PoPIA), fully enforced from 1 July 2021, has reshaped how organisations across South Africa handle data. While data collection and storage often dominate discussions around compliance, one of the most significant shifts is in direct marketing.

To help businesses understand the changes, Impression Signatures — a local provider of e-signatures — launched its PoPIA Campaign. In a discussion with Carrie Peter, Solution Owner at Impression Signatures, several crucial points about direct marketing compliance came to light.


What Counts as Direct Marketing?

Direct marketing is any direct or indirect engagement with a person for the purpose of:

  • Promoting or offering goods/services, or

  • Requesting a donation.

This applies to communications that are in-person, telephonic, via automatic calling machines, or online.


The Consent Requirement

According to Section 69 of PoPIA:

  • Direct marketing is prohibited unless direct consent has been obtained.

  • A data subject may be approached once for consent. If refused, the organisation may not ask again.

  • Businesses may only contact existing customers, and only to promote their own products or services.

  • Customers must always have the opportunity to object to marketing, free of charge.


Compliance Checklist for Direct Marketing

When engaging in direct marketing, businesses must:

  • Provide business details in every message (address and contact number).

  • Offer a clear opt-out option in all communications — without requiring a reason or charging a fee.

  • Keep customer databases up to date and remove anyone who has unsubscribed.

  • Avoid purchased databases — they can no longer be used.

  • Obtain consent before adding a person to a marketing directory and explain the directory’s purpose.


What About Existing Directories?

Section 70 of the Act allows data subjects who were included in a directory prior to PoPIA’s commencement to remain — but with strict conditions:

  • They must be notified of their inclusion and the directory’s purpose.

  • They must be given the option to opt out at any time.

  • If they refuse or request removal, they may not be approached again for the same directory.


Final Word

As Carrie Peter explains:

“The stipulations in PoPIA have made it exceedingly clear that the data subject — the organisation’s customer — must feel in control of the communication that is being received.”

PoPIA marks the end of mass marketing databases and ushers in an era where customer consent and control are central. For businesses, compliance isn’t just about avoiding penalties — it’s about building trust through transparent, respectful communication.