Direct Marketing and Data Protection: New Obligations for South African Businesses

This article provides a practical overview of the rules now governing direct marketing in South Africa. It deals with the national opt-out registry established under the Consumer Protection Act 68 of 2008 (“CPA”) in 2026, the consent requirements in section 69 of the Protection of Personal Information Act 4 of 2013 (“POPIA”), and what businesses that market to customers and prospects must do to comply with both.

Background: Two Regimes, One Activity

Direct marketing in South Africa has long been governed by overlapping statutes, with the practical consequence that many businesses complied with one and overlooked the other. POPIA regulates the use of personal information for direct marketing. The CPA confers a right on consumers to pre-emptively block unwanted approaches. The Electronic Communications and Transactions Act 25 of 2002 imposes its own requirements on unsolicited electronic communications.

Two developments have brought this area into focus. First, the Information Regulator has moved decisively from guidance to enforcement. Second, the mechanism that gives practical effect to the CPA’s pre-emptive block, dormant since 2008, has finally been established.

The National Opt-Out Registry

The Consumer Protection Act Amendment Regulations, 2026 were published on 15 April 2026 and operationalise section 11(6) of the CPA by establishing a national opt-out registry administered by the National Consumer Commission. Registration by consumers, and by direct marketers, commenced in July 2026.

The registry places direct obligations on businesses that conduct direct marketing. In broad terms, a direct marketer must:

  • register with the National Consumer Commission through its eService portal, and renew that registration annually on payment of the prescribed fee;
  • cleanse its databases monthly against the registry, removing the data of persons who have registered a pre-emptive block;
  • refrain from directing any marketing communication to a consumer who has registered such a block;
  • ensure that every communication identifies the sender by name, electronic address, physical address and contact number; and
  • not disseminate communications from sources that cannot be identified.

The monthly cleansing obligation is the provision most likely to be missed. It is an ongoing operational requirement rather than a once-off compliance step, and it requires a business to hold its marketing data in a form that can actually be reconciled against the registry.

POPIA: Section 69 and Consent

Compliance with the registry does not discharge a business’s obligations under POPIA. Section 69 prohibits the processing of personal information for the purpose of direct marketing by means of any form of electronic communication unless the data subject has consented, or is an existing customer of the business.

Where consent is relied on, it may be requested only once, and only in the prescribed form. Where the existing customer exception is relied on, the contact details must have been obtained in the context of a sale, the marketing must relate to the business’s own similar products or services, and the customer must have been given a reasonable opportunity to object both when the details were collected and in each subsequent communication.

The Information Regulator has taken the view that telephone calls constitute electronic communications for the purposes of section 69, which materially narrows the scope for outbound telephone marketing to non-customers.

Where the CPA and POPIA both apply, section 3(1)(b)(i) of POPIA provides that the provision conferring the greater protection on the data subject prevails. Businesses should therefore comply with the stricter of the two requirements rather than selecting the more convenient one.

The Enforcement Environment

The Information Regulator has become considerably more active. At its media briefing on 31 August 2026, the Regulator reported having received more than 8 000 security compromise notifications since the enforcement provisions of POPIA commenced, with more than 1 220 received in the 2026 financial year alone and a projected 3 000 by year end.

The Regulator has issued enforcement notices against both public and private bodies, including a notice against the South African Bureau of Standards following a ransomware incident, which identified excessive processing, inadequate consent mechanisms and insufficient security safeguards, and required remedial action within 90 days.

The Regulator has also indicated that it is pursuing legislative amendments that would allow it to impose administrative fines directly, without the current intermediate steps. Businesses that have treated POPIA as a low-risk compliance area should reassess that view.

Practical Steps for Businesses

A business that markets to customers or prospects should:

  • determine whether it is a direct marketer for the purposes of the CPA regulations and, if so, register with the National Consumer Commission;
  • implement a monthly registry cleansing process, with an audit trail evidencing that it was performed;
  • segment its marketing database to distinguish existing customers from prospects, since the lawful basis for contacting each differs;
  • record the source, date and form of consent for every contact relied on as having consented;
  • include a clear and functional opt-out mechanism, and full sender identification, in every communication;
  • ensure that operator agreements with marketing agencies, CRM providers and mailing platforms impose equivalent obligations and address security;
  • appoint and register an Information Officer with the Regulator, and ensure the PAIA manual and POPIA policies are current; and
  • allocate ownership of this area to a senior person, rather than leaving it with whoever operates the mailing platform.

Conclusion

Direct marketing remains lawful in South Africa, but it is now meaningfully regulated on two fronts simultaneously. The opt-out registry converts a consumer right that existed on paper since 2008 into an operational obligation with monthly consequences, and POPIA continues to govern the consent on which most marketing databases depend.

For most businesses the practical work is not complicated: know your database, know the basis on which each contact is held, cleanse it regularly and be able to prove that you did. The businesses that struggle will be those whose marketing data has accumulated over years without any record of where it came from.

How O’Reilly Law Can Assist

Data protection and consumer law compliance is an area where the cost of remediation after a complaint substantially exceeds the cost of getting the framework right at the outset, and where the reputational consequences of an enforcement notice can exceed the legal ones.

O’Reilly Law advises businesses on POPIA and CPA compliance, including direct marketing frameworks, consent mechanisms, privacy notices, PAIA manuals, Information Officer registration, operator agreements and responses to data breaches and Regulator enquiries. We provide this work on a project basis or under an ongoing retainer, which many clients prefer given the pace of regulatory change.

Speak to a Data Protection and Commercial Law Specialist

If you market to customers or prospects and are unsure whether your practices comply, it is essential to obtain advice early.

📩 Email: info@oreillylaw.co.za

📞 Tel: +27 (0)82 929 7015

🌐 Web: www.oreillylaw.co.za

Our team advises businesses on data protection, direct marketing and consumer law compliance.