September 5, 2026. Most guides to South African spam law still describe an opt-out regime under Section 45 of the Electronic Communications and Transactions Act: include an unsubscribe, disclose where you got the address, and you are fine. That section was repealed with effect from June 30, 2021, when the Protection of Personal Information Act took full effect and its Schedule struck Section 45 out. South Africa has been a pure opt-in jurisdiction for five years, and it is one of the few in the world where the data protection statute protects companies as well as people. The Information Regulator's first direct marketing enforcement case, against a training firm, treated a sender's habit of guessing five different email domains for one contact as evidence of unlawful collection, and said the unsubscribe link cured nothing.
The rule: Section 69 of POPIA
The Protection of Personal Information Act 4 of 2013 defines personal information as information about an identifiable, living, natural person and, where applicable, an identifiable, existing juristic person. A company's contact data is protected. Electronic communication is defined widely, and the Regulator's Guidance Note on Direct Marketing treats email, SMS, push notifications, direct messages on Instagram or LinkedIn and telephone calls as within Section 69.
- The default is prohibition. Section 69(1): processing for direct marketing by any form of electronic communication, including email, is prohibited unless the data subject has consented or is an existing customer.
- You may approach a person once, and only to ask. Section 69(2)(a) allows a responsible party to approach a data subject who has not previously withheld consent only once, in order to request that consent. The Guidance Note says the first message must be a communication requesting consent, not a pitch. The burden of proving consent is on the sender under Section 11(2)(a).
- The request has a prescribed form. Regulation 6 of the 2018 POPIA Regulations requires the request to be made on Form 4, which names the sender, the goods or services to be marketed and the data subject's chosen channel, with a signed give or withhold choice. The April 2025 amendment to the Regulations allows a form substantially similar to Form 4, or any expedient, free and reasonably accessible manner, including email, telephone, SMS or WhatsApp. Regulation 6.4 adds the line the whole regime turns on: opt-out shall not constitute consent.
- The customer exception has three cumulative conditions. Section 69(3): details obtained in the context of a sale, marketing only of the responsible party's own similar products or services, and a free, formality-free opportunity to object both at collection and on the occasion of each communication. The Guidance Note's example: funeral cover is not similar to clothing.
- Every message must carry identity and a stop address. Section 69(4): the identity of the sender or the person on whose behalf it is sent, and an address or other contact details to which a request to cease may be sent.
- Objections end processing. The data subject may object at any time under Sections 5 and 11, after which the sender may no longer process. The Guidance Note requires a suppression database of everyone who withheld consent or objected.
- Lists are further processing. Section 12 requires collection directly from the data subject unless an exception applies; purchased or rented lists must satisfy the further-processing and notification rules in Sections 15 and 18.
Territorial reach
Section 3(1)(b) applies POPIA to a responsible party domiciled in South Africa, or not domiciled there but making use of automated or non-automated means in the Republic. Whether sending email from abroad to a South African inbox counts as making use of means in the Republic has not been ruled on by the Regulator or a court. No enforcement notice on the Regulator's index from 2023 to 2026 targets a foreign sender. A business abroad should not treat that silence as permission; it is an open question, not a safe harbour.
Penalties and the enforcement route
A Section 69 breach is interference with personal information rather than a criminal offence in itself. The teeth are procedural. The Regulator issues an enforcement notice; failing to comply with it is the offence, punishable by a fine or imprisonment of up to 10 years, or both, under Section 107. Alternatively the Regulator can issue an infringement notice with an administrative fine of up to R10 million under Section 109, with 30 days to pay, arrange instalments or elect a trial; an unpaid fine becomes a civil judgment. Section 99 lets a data subject, or the Regulator on request, sue for damages whether or not there was intent or negligence.
What the Regulator has actually done
The first direct marketing enforcement notice was issued on February 21, 2024 against FT Rams Consulting, a training company that had sent persistent emails about courses and webinars without consent. The Regulator found breaches of Section 69(1) and (2), missing cease details under 69(4)(b), indirect collection under Section 12 and no notification under Section 18. Two findings matter for outbound teams. The Regulator held that an unsubscribe link did not remedy the non-compliance, because the regime is opt-in. And it noted that the sender had used five possible email domains to reach the complainant, which may point to the fact that it did not obtain the details directly from him. Guessed permutations, the standard output of an email-finder, were read as evidence of unlawful collection. The notice ordered twelve steps within 90 days, including the use of Form 4 and a suppression database. According to the Regulator's November 2025 briefing, FT Rams did not comply, an infringement notice of R100,000 was issued, it went unpaid, and the Regulator started court proceedings to recover it.
The pipeline is filling. At its August 2026 briefing the Regulator said it received more than 3,800 complaints in the past year, about 10 percent concerning direct marketing, and referred two Section 69 matters, involving OUTsurance and MTN, to its Enforcement Committee. In April 2026 it stated, on the launch of a national opt-out registry under consumer protection regulations, that registration status is irrelevant to POPIA and that by merely opting out a data subject cannot be regarded as having given consent.
What it means for operators
South Africa is an opt-in market with an unusually formal front door. The lawful sequence is one message that asks for consent in a Form 4-equivalent manner, then marketing only to those who said yes, then a suppression database that is honoured for everyone else. A classic three-step cold sequence is two steps too long, and the unsubscribe link at the bottom is not a defence.
The FT Rams reasoning is the piece to internalise. Email-finding tools that try firstname@, f.lastname@ and the rest across several domains leave a trail that the Regulator has already read as proof that the address was not collected from the person. If you use lead generation tooling for South African contacts, the enrichment method is now part of your compliance exposure, not just your bounce rate.
The customer exception is narrower than most CRMs assume: the sale must be the sender's own, the product similar, and the objection route present at collection and in every message. And because POPIA protects juristic persons, the fact that the recipient is a company does not take the message outside the Act.
Checklist for South African outreach
- One consent request, in a Form 4-equivalent shape, naming you, what you will market and the channel.
- Market only to a yes. Silence and a missing unsubscribe click are not consent; Regulation 6.4 says so.
- Identity and a cease address in every message, per Section 69(4).
- Build the suppression database the Guidance Note requires, before the first send.
- Audit how each address was obtained. Guessed permutations are evidence against you.
- Treat foreign-sender reach as unresolved, not as an exemption.
South Africa's regime is closer to the UAE than to Australia, where inferred consent from a published business address still exists. For teams that want the market anyway, the workable model is consent capture through content, events and partnerships, with the outreach itself run through our cold email service so that the single-approach rule and the suppression database are enforced by the system rather than by memory.
Frequently Asked Questions
Not without consent. Section 69(1) of POPIA prohibits direct marketing by electronic communication, including email, unless the data subject has consented or is an existing customer of the sender. You may approach a person once, and only to request consent in a prescribed manner. The old opt-out regime under Section 45 of the ECT Act was repealed with effect from June 30, 2021.
Yes. POPIA defines personal information to include information about an identifiable, existing juristic person, so a company's contact details are protected and Section 69 applies to B2B email. The Regulator's Guidance Note also treats direct messages on LinkedIn and Instagram, SMS and telephone calls as electronic communications within the section.
The prescribed form for requesting a data subject's consent to direct marketing under Regulation 6 of the 2018 POPIA Regulations. It names the sender, the goods or services to be marketed and the channel, with a signed give or withhold choice. Since the April 2025 amendment, consent may be obtained on a substantially similar form or in any expedient, free and accessible manner, including email, SMS or WhatsApp. Regulation 6.4 states that opt-out shall not constitute consent.
A breach is interference with personal information, enforced through an enforcement notice. Failing to comply with that notice is an offence carrying a fine or up to 10 years' imprisonment under Section 107. The Regulator may instead issue an infringement notice with an administrative fine of up to R10 million under Section 109, and data subjects may claim damages under Section 99 without proving intent or negligence.
Yes. Its first direct marketing enforcement notice, against FT Rams Consulting on February 21, 2024, found unsolicited course emails breached Section 69, held that an unsubscribe link did not cure the breach, and read the sender's use of five guessed email domains as evidence of unlawful collection. After non-compliance a R100,000 infringement notice followed, and the Regulator has gone to court to recover it. Two further Section 69 matters, involving OUTsurance and MTN, were referred to the Enforcement Committee in 2026.
It applies to a responsible party not domiciled in South Africa that makes use of automated or non-automated means in the Republic, under Section 3(1)(b). Whether sending email from abroad meets that test has not been decided by the Regulator or a court, and no enforcement notice against a foreign sender exists on the Regulator's index. Treat it as an open question rather than an exemption.