NexBDM Blog
POPIA Direct Marketing: what section 69 requires before you send a WhatsApp or an email
By NexBDM Team · 2026-08-08
Key takeaways
- POPIA section 69 allows electronic direct marketing only with consent or to an existing customer, and you may ask a non-customer for that consent once. Here is what the Act, the gazetted Form 4 and the Information Regulator's Guidance Note actually require.
POPIA section 69 allows electronic direct marketing only with consent or to an existing customer, and you may ask a non-customer for that consent once. Here is what the Act, the gazetted Form 4 and the Information Regulator's Guidance Note actually require.
POPIA section 69 prohibits direct marketing by electronic communication unless the person has consented or is already your customer. WhatsApp, email and SMS all qualify, because POPIA defines electronic communication by how a message travels, not by which app carries it. A non-customer may be approached only once to ask for that consent.
That last sentence is the one that catches people. Most articles on this topic treat consent as a checkbox to add to a signup form. The Act treats it as a single, spendable attempt. If you send a badly built consent request to two thousand people, you have not started a campaign. You have used up your one lawful approach to two thousand people.
This guide works from the statute, the gazetted regulations and the Information Regulator's own guidance, and it flags the places where those three do not line up.
What counts as direct marketing under POPIA?
Section 1 of POPIA defines direct marketing as approaching a person, "either in person or by mail or electronic communication", for the direct or indirect purpose of promoting or offering to supply goods or services, or of requesting a donation.
Two things follow that owners routinely miss. Asking for a donation is direct marketing. And the "indirect purpose" wording means a message does not escape the definition by avoiding a sales pitch. A newsletter that exists to keep you front of mind is still an approach for an indirect commercial purpose.
Does section 69 apply to WhatsApp?
WhatsApp is not named in POPIA, not named in the regulations, and not named in the Guidance Note. It is still covered, and the reason is worth understanding because it is what makes the rule durable as channels change.
Section 1 of POPIA defines electronic communication as "any text, voice, sound or image message sent over an electronic communications network which is stored in the network or in the recipient's terminal equipment until it is collected by the recipient".
That definition describes a mechanism, not a product. A WhatsApp message is a text, voice, sound or image message, it travels over an electronic communications network, and it sits on the network or on the handset until the recipient opens it. It fits the definition on every limb. Section 69(1) then lists "automatic calling machines, facsimile machines, SMSs or e-mail", but it introduces that list with the word "including", so the list illustrates rather than limits.
The Information Regulator's Guidance Note reaches the same place from the other direction. Its own list of electronic direct marketing methods is expressly "not limited to" telephone, email, SMS, automatic calling machines and fax, and it adds push notifications, direct messaging on Instagram or LinkedIn, and the use of cookies.
So the honest answer to "is WhatsApp marketing legal in South Africa" is: yes, on exactly the same terms as email. There is no WhatsApp exception, and there is no WhatsApp penalty either.
The two lawful routes, and only two
Section 69(1) permits electronic direct marketing in two situations. Either the person "has given his, her or its consent to the processing", or the person "is, subject to subsection (3), a customer of the responsible party". There is no third route. Buying a list is not a route. Someone handing you a business card at an expo is not, by itself, either of these.
Route one: consent, and the once-only rule
Section 69(2)(a) allows you to approach a person to request consent only once, and only where that person "has not previously withheld such consent". Section 69(2)(b) requires the request to be made "in the prescribed manner and form".
The Guidance Note draws out the consequence plainly: the first communication you send to a non-customer must itself be the request for consent. You cannot market and ask for permission in the same message, because the marketing part of that message is the thing you do not yet have permission to send.
Read those together and the operational picture changes. Your consent request is not a campaign asset you can iterate on. There is no A/B test on the second send, because for that audience there is no second send.
Route two: existing customers, narrowly defined
Section 69(3) lets you market to a customer without separate consent, but attaches three conditions, all of which must hold:
- you obtained the contact details "in the context of the sale of a product or service";
- you are marketing "the responsible party's own similar products or services"; and
- the person was given a reasonable opportunity to object, free of charge and without unnecessary formality, both when the details were collected and on the occasion of each marketing message afterwards.
The Guidance Note supplies a useful worked example of "similar". For a clothing retailer, shoes and belts are similar products. Funeral insurance cover is not. The test is about what the customer bought, not about what you happen to sell.
The same passage disposes of a common assumption in one line: a customer who was never asked whether they consented "cannot be deemed to have given her consent", because consent is a voluntary, specific and informed expression of will. As the Guidance Note puts it, silence cannot mean consent.
What Form 4 actually asks for, and the box it is missing
The prescribed form is Form 4, set out in the Regulations Relating to the Protection of Personal Information, 2018, published in Government Gazette 42110 on 14 December 2018. It is titled an application for the consent of a data subject for the processing of personal information for the purpose of direct marketing in terms of section 69(2).
Reading the gazetted form itself, rather than a summary of it, turns up three things that matter.
It names the goods or services. Form 4 carries a "SPECIFY GOODS or SERVICES" field. Consent is not a general permission to contact someone. It is permission to market the things you wrote down.
It names the channel. Form 4 carries a "SPECIFY METHOD OF COMMUNICATION" field with options for fax, email, SMS, and "OTHERS", which must be specified. The Guidance Note is explicit that the responsible party "must adhere to the method chosen by the data subject". Consent to email is not consent to WhatsApp. WhatsApp is not a printed option on the form at all, so it has to be written into that "OTHERS" line, by name, to be the channel someone agreed to.
It has no way to say no. This is the discrepancy worth knowing about. The form as gazetted contains a single tick box: "Give my consent." There is no corresponding box to withhold consent. Yet section 69(2)(a)(ii) makes your right to approach someone depend on whether they "previously withheld" consent, which is a state you can only act on if you recorded it.
The Guidance Note patches the gap without saying it is patching anything. It advises that the form "can contain the words 'I give my consent' and 'I do not give my consent' at the end", so the person can choose one. Follow the guidance rather than the bare gazetted form here. A consent request that offers no way to refuse produces no record of refusal, and the record of refusal is what the once-only rule runs on.
Is a phone call an electronic communication?
This is the position in the Guidance Note most likely to surprise a South African business, and it is also the one to be most careful about repeating.
The Regulator takes the view that telephone calling is electronic communication, reasoning that telephone technology has become digital, that calls predominantly run over VoIP, which is packet-switched rather than the older analogue public-switched telephony, and that the voice data packets are stored on the network before being reassembled and relayed to the recipient's terminal equipment. That reasoning tracks the statutory definition word by word, which is presumably the point.
If that view holds, cold calling a stranger to sell to them requires prior consent, obtained on Form 4. The Guidance Note goes further on the mechanics: a responsible party using a telephone to obtain consent "must read out the contents of Form 4", and "the telephone call must be recorded".
Now the caveat, which most coverage of this document leaves out. The Guidance Note states its own status plainly: it "is advisory in nature", it does not limit the Regulator's enforcement of POPIA, and "the provisions of POPIA and the Regulations will prevail over the Guidance Note in the event of any inconsistency". It also says it does not constitute legal advice.
So the telephone position is the Regulator's stated interpretation, not settled law, and it has not been tested in court. It is nonetheless the view of the body that investigates complaints about you, which makes it the sensible thing to plan around even while it remains an interpretation.
Does the opt-out registry help?
No, and the Guidance Note addresses this directly because the assumption is so common.
Section 11 of the Consumer Protection Act 68 of 2008 provides for a registry where a person may register a pre-emptive block against direct marketing. The Guidance Note's conclusion is that a responsible party "cannot therefore contact a data subject for purposes of direct marketing simply because they have not registered a pre-emptive block".
Absence from a do-not-contact list is not presence on a consent list. The registry lets people opt out of being approached at all. It does not manufacture permission from the people who never used it.
What every marketing message must contain
Section 69(4) applies to every direct marketing communication, on both routes. Each one must contain the identity of the sender or of the person on whose behalf it was sent, and an address or other contact details to which the recipient can send a request that the communications stop.
The Electronic Communications and Transactions Act 25 of 2002 adds a second, older layer for unsolicited commercial communications. Section 45(1) requires the sender to give the consumer the option to cancel their subscription to the mailing list, and to identify, on request, the source from which the consumer's personal information was obtained. Section 45(2) adds a rule that quietly protects consumers from a whole category of trick: "No agreement is concluded where a consumer has failed to respond to an unsolicited communication." Silence is not acceptance.
Sections 45(3) and 45(4) make non-compliance, and sending to a person who has already said the communications are unwelcome, offences carrying the penalties prescribed in section 89(1) of that Act, which is a fine or imprisonment for a period not exceeding 12 months.
What actually happens if you get this wrong?
The widely repeated version is that POPIA carries a ten million rand fine for sending marketing without consent. That is not how the Act is built, and the accurate chain is more useful to plan around.
A breach of section 69 is not, by itself, a criminal offence. Section 73(b) of POPIA classifies non-compliance with section 69 as an "interference with the protection of the personal information" of that person. That opens the complaint route in section 74, an investigation, and potentially an enforcement notice under section 95.
The offence sits one step further along. Section 103(1) makes it an offence for a responsible party to fail to comply with an enforcement notice, and section 107(a) attaches to that a fine or imprisonment for a period not exceeding 10 years. Separately, section 109(2)(c) of POPIA provides that an infringement notice may specify an administrative fine not exceeding R10 million.
The practical reading: the serious consequences attach to ignoring the Regulator, not to a first mistake. A business that responds properly to a complaint is in a very different position from one that does not. That is worth knowing before panic drives a decision.
How this work stops being manual
Almost every obligation above is a record-keeping obligation wearing a marketing costume. That is what makes it automatable, and it is also why spreadsheets fail at it.
- Store consent as a record, not a flag. Section 11(2)(a) puts the burden of proving consent on you. A tick box with no date, no wording and no source proves nothing. Keep what was agreed to, when, through which channel, and the exact text shown at the time.
- Store the channel with the consent. Since the person chooses the method on Form 4, consent has to be held per channel. One "marketing opt-in" field cannot answer the question of whether you may send this person a WhatsApp.
- Store the goods or services. Consent is scoped to what you specified. A record that cannot answer "consent to what" cannot support a campaign for a different product line.
- Keep the suppression list as a first-class list. The Guidance Note requires a responsible party to compile and maintain a database of people who withheld consent and of people who objected. That list is more legally important than your mailing list, and it must survive every import, migration and tool change.
- Make the once-only rule enforceable by the system. A person who has been approached, or who has refused, must be mechanically unreachable by a future consent request. Humans reliably fail at this at list-import time. Software does not.
- Put the objection route in the template. Section 69(4) applies to every message, and section 69(3)(c) requires the chance to object on each occasion. Template-level, not campaign-level, is the only way that survives a busy month.
- Log the send. If a complaint arrives eight months later, the question is what was sent, to whom, on what basis. That is a query against your own records or it is nothing.
A customer record that holds consent alongside the contact is the difference between answering that question in a minute and reconstructing it from inboxes. If most of your conversations already happen on WhatsApp, the same logic applies to keeping those threads attached to the customer record rather than trapped on a phone.
What you should not automate
Some of this should stay slow and human.
- The decision to contact a cold list at all. The once-only rule means that decision is irreversible per person. It deserves a human sign-off, not a scheduled job.
- The wording of the consent request. You get one attempt. Write it, read it, have someone else read it.
- Judging whether a product is "similar". Shoes and belts against clothing is easy. Most real catalogues are not, and a rule engine will cheerfully approve the funeral cover case.
- Responding to a complaint from the Regulator. As above, that is where the real exposure lives.
- Any process not yet written down. Automating an undocumented process just makes the undocumented parts happen faster.
Where to start this week
- Separate your contacts into customers under section 69(3) and everyone else. The rules differ, so the lists must differ.
- For the customer list, confirm you can show an objection opportunity at collection, and that every template carries one.
- For everyone else, stop sending until you have a Form 4 style consent request, with a refusal option, that names your goods or services and lets the person choose the channel.
- Build the suppression list before the campaign, not after the first complaint.
- Check that your sender identity and cessation contact details appear on every message, per section 69(4).
If you want the wider obligations this sits inside, the POPIA compliance checklist covers the eight conditions and the Information Officer registration, and the business compliance checklist maps how this fits the rest of the annual calendar. If you are also putting AI tools near customer data, the AI policy template covers the internal rules that should exist first.
Frequently Asked Questions
Do I need consent to send marketing on WhatsApp in South Africa?
Yes, unless the person is your customer under section 69(3). POPIA defines electronic communication by how a message travels, not by the app, so WhatsApp sits under section 69 exactly as email and SMS do. There is no separate WhatsApp rule.
Can I ask someone for marketing consent more than once?
No. Section 69(2)(a) permits a responsible party to approach a person only once to request consent, and only if that person has not previously withheld it. A second request to the same person is not permitted, which makes the first one worth getting right.
Does consent to email cover WhatsApp too?
No. Form 4 requires the person to specify the method of communication, and the Guidance Note says the responsible party must adhere to the method chosen. Consent is held per channel, so email consent does not authorise WhatsApp messages.
Is cold calling allowed under POPIA?
The Information Regulator's view is that telephone calling is electronic communication, so consent is needed unless the person is an existing customer. That view sits in a Guidance Note that is advisory in nature, not in the Act itself, and it has not been tested in court.
What is the penalty for marketing without consent?
A section 69 breach is an interference under section 73, which triggers a complaint and possible enforcement notice. Ignoring an enforcement notice is the offence under section 103(1), carrying up to 10 years under section 107(a). An administrative fine may not exceed R10 million under section 109(2)(c).
Sources
- Protection of Personal Information Act 4 of 2013, Government Gazette 37067 of 26 November 2013. Sections 1 (definitions of direct marketing and electronic communication), 11(2)(a), 69, 73, 95, 103(1), 107 and 109(2)(c). Downloaded and parsed for this article.
- Regulations Relating to the Protection of Personal Information, 2018, Government Gazette 42110, Notice R.1383 of 14 December 2018, including Form 4. Downloaded and parsed for this article.
- Information Regulator, Guidance Note on Direct Marketing in terms of POPIA. Sections 7.1 to 7.3 on electronic communication, Form 4 and the customer exception, section 8 on the Consumer Protection Act pre-emptive block, and section 11 on the Guidance Note's advisory status.
- Electronic Communications and Transactions Act 25 of 2002, Government Gazette 23708 of 2 August 2002. Sections 45 and 89(1).
This article is general information about South African law, not legal advice. POPIA obligations depend on the facts of your business, and the Guidance Note discussed above is advisory rather than binding. Get advice on your specific situation before changing how you market.
If you want a clear view of where your own customer data actually lives and what it would take to market from it lawfully, that is the kind of thing the Autopsy is built to map. You can also start with a discovery call.