Compliance

POPIA for marketers

POPIA, in force since July 2021, governs how South African marketers collect, store and use personal information. The practical takeaways are: only collect data you genuinely need, tell people why you are collecting it, secure it properly, and get the right permission before sending direct marketing. The regulator is the Information Regulator, which oversees how organisations handle data.

If you run campaigns in South Africa, POPIA is now part of the job. The good news is that most of it is common sense once you strip away the jargon: be honest about what you collect, keep it safe, and respect the choices people make. This guide turns the Act into plain marketing practice.

POPIA for marketers in South Africa explained

TL;DR: Quick Answer

POPIA shapes how South African marketers collect, store and use personal data. Learn consent, lawful basis and a practical compliance checklist.

POPIA FOR MARKETERS key takeaway, Juicy Designs

Please note: this article is general informational guidance for marketers, not legal advice. POPIA, the CPA and related rules can apply differently to each business, so confirm your own position with a qualified professional before you act.

What does POPIA actually ask marketers to do?

POPIA, the Protection of Personal Information Act, has been in force since July 2021. It sets out how organisations in South Africa may collect, store and use personal information. For marketers, the Act translates into a handful of habits rather than a wall of legal text. You should collect only the data you genuinely need, be open about why you are collecting it, keep it secure, use it for the purpose you stated, and give people a clear way to opt out or ask what you hold.

The regulator that oversees POPIA is the Information Regulator. Its role is to guide organisations and act where personal information is mishandled. Treating it as a partner rather than a threat is the right mindset: most enforcement attention follows complaints, and complaints usually follow sloppy data practice.

What counts as personal information in a marketing context?

It is easy to assume personal information means ID numbers and addresses. In practice it is much wider. Names, email addresses, mobile numbers, location data, online identifiers such as cookies and device IDs, and even opinions about a person all qualify. That means your email list, your customer database, your remarketing audiences and your analytics data can all hold personal information.

A few categories are treated as special and carry stricter conditions, including health, religion, political views and race. Most everyday marketing avoids these, but if a campaign touches them, slow down and get advice.

Consent is the part marketers ask about most. POPIA does not say you need fresh consent for everything. It recognises several lawful reasons to process data, including performing a contract, a legitimate interest, or the person's consent. For direct marketing by electronic means to people who are not already your customers, consent is generally the safe route. For existing customers, the Act allows marketing about similar products or services under certain conditions.

The practical rule of thumb is simple. Keep a record of how you obtained each contact, tell people what to expect, and make opting out effortless on every message. If you cannot explain where a contact came from, do not market to them.

What is a lawful basis and why does it matter?

A lawful basis is the legitimate reason you rely on to use someone's data. Naming it before a campaign keeps you honest and gives you a clear answer if anyone ever asks why you contacted them. For a newsletter, the basis is usually consent at sign up. For a service update to a paying client, it may be the contract between you. Writing this down in a short internal note per campaign takes minutes and saves headaches later.

A practical POPIA checklist for marketing teams

Use this as a working list rather than legal gospel. It captures the habits that keep most South African marketing teams on the right side of POPIA:

  • Publish a clear, readable privacy notice and link it from every form and your site footer.
  • Collect only the fields you actually use. Every extra field is extra risk.
  • Record how and when each contact gave you their details.
  • Add a working unsubscribe link to every marketing email and honour it quickly.
  • Secure your data: strong passwords, limited access, and care with exported lists.
  • Have a simple process for when someone asks what you hold or asks you to delete it.
  • Vet the tools and partners that touch your data, from email platforms to ad networks.

None of this should slow good marketing down. In fact, leaner lists and clearer consent tend to lift engagement, because the people who remain genuinely want to hear from you.

How does POPIA connect to the rest of your digital marketing?

POPIA does not sit in a corner on its own. It touches your cookie banner and privacy policy, your analytics and consent setup, and the wider advertising rules that govern South African campaigns. Getting these working together is the difference between compliance as a box tick and compliance as a quiet advantage.

If you would rather hand the heavy lifting to a team that builds compliant campaigns every day, our digital marketing service covers strategy, content and channels with data hygiene built in. From R6,000 per month, founder led since 2015 with a 4.9 star Google rating across 214 reviews, we help South African businesses grow without cutting corners.

POPIA for marketers: common questions

Does POPIA apply to small businesses in South Africa?

Yes. POPIA applies to almost every organisation that processes personal information in South Africa, regardless of size. A sole trader collecting email addresses for a newsletter is processing personal information just as much as a large retailer. The obligations scale with the volume and sensitivity of the data you hold, but the core duties to be transparent, collect only what you need and keep data secure apply broadly.

Do I always need consent to market to someone under POPIA?

Not always. POPIA allows direct marketing to existing customers about similar products or services under certain conditions, while electronic direct marketing to people who are not customers generally requires their consent. Because the detail depends on the channel and relationship, the safest approach is to keep clear records of how you obtained each contact and to make opting out easy on every message.

What counts as personal information under POPIA?

Personal information is broad. It includes names, email addresses, phone numbers, ID numbers, location data, online identifiers and even opinions about a person. Some categories such as health, religion and race are treated as special and carry stricter conditions. For marketers this means your CRM, email list, ad audiences and analytics data can all contain personal information.

Who enforces POPIA and what should marketers watch for?

The Information Regulator is the body responsible for POPIA in South Africa. Marketers should focus on practical hygiene: a clear privacy notice, a lawful reason for each use of data, secure storage, a simple way for people to opt out or request their data, and a record of consents. This is general guidance, so confirm your specific obligations with a professional.

How is POPIA different from GDPR?

POPIA and the European GDPR share the same spirit: transparency, purpose limitation and security. POPIA is South Africa's own law with its own regulator and terminology, so you should not assume a GDPR setup automatically satisfies POPIA. If you market to both South African and European audiences, treat them as related but separate compliance tasks.

Wynand van der Westhuizen

Creative Director & Co-founder, Juicy Designs, Pretoria

Wynand co-founded Juicy Designs in 2015 and leads creative direction and client strategy. A Meta Business Partner, he owns client relationships across automotive, entertainment, retail and professional services, and reviews published content for accuracy and brand fit.

  • Co-founder & Creative Director, Juicy Designs, established 2015
  • Meta Business Partner
  • 64+ South African clients, 4.9-star Google rating
  • Specialist in brand, creative & paid social
  • Reviewed and updated June 2026