What Is GDPR?

GDPR stands for the General Data Protection Regulation, a European Union regulation that came into full effect on 25 May 2018. It is one of the most comprehensive and widely influential data protection laws in the world. GDPR establishes strict rules around the collection, storage, processing, and use of personal data belonging to EU residents. Personal data under GDPR is defined broadly and includes name, email address, IP address, location data, and any other information that can identify a person, directly or indirectly.

For email marketers, GDPR's most significant requirement is consent. Before sending a commercial email to an EU resident, you must have obtained clear, specific, and freely given consent from that individual to receive marketing communications from you. Pre-ticked boxes, bundled consent with terms and conditions, and implied consent are not valid under GDPR. The subscriber must take a positive, unambiguous action to opt in. This is the opt-in model, which stands in direct contrast to the opt-out approach permitted under CAN-SPAM in the United States.

GDPR also grants individuals extensive rights over their personal data. These include the right to access the data you hold about them, the right to correct inaccurate data, the right to have their data deleted (the "right to be forgotten"), and the right to withdraw marketing consent at any time without penalty. Your systems must be capable of fulfilling these requests promptly. GDPR non-compliance penalties are substantial, reaching up to 4% of global annual turnover or 20 million euros, whichever is greater. Even smaller fines issued to medium-sized businesses by EU supervisory authorities have run into hundreds of thousands of euros.

GDPR In Practice

A South African travel agency based in Cape Town operates a website that attracts visitors from across Europe. Their sign-up form offers a newsletter to all visitors. Under GDPR, the form must have a separate, unticked checkbox specifically for marketing emails, accompanied by a clear description of what the subscriber is consenting to receive. The checkbox cannot be pre-ticked, and it cannot be bundled with acceptance of general terms and conditions. The agency must also maintain records proving when and how each EU subscriber gave consent, and must be able to honour deletion requests within one month.

South African businesses dealing with European clients or operating SaaS products used by EU customers will find significant overlap between GDPR and South Africa's Protection of Personal Information Act (POPIA), which came into full effect in 2021. Both laws share core principles: lawfulness of processing, consent for direct marketing, data minimisation, purpose limitation, and data subject rights. Building your email marketing processes to satisfy GDPR's higher standard will generally also satisfy POPIA's requirements for South African subscribers, reducing the operational complexity of managing two separate compliance frameworks. The practical foundation is the same: only send marketing emails to people who have explicitly said they want to receive them, keep clear records of consent, and make unsubscribing effortless at all times.

What GDPR is

GDPR (the General Data Protection Regulation) is a comprehensive European Union data-protection and privacy law, in force since 2018, that governs how organisations collect, use, store and protect the personal data of individuals in the EU (and European Economic Area), granting individuals significant rights over their data and imposing substantial obligations on organisations that handle it. GDPR is one of the world's most influential privacy laws, setting a high standard for data protection, and it applies not only to organisations based in the EU but, importantly, to organisations anywhere that process the personal data of individuals in the EU (for example, by offering goods or services to, or monitoring, people in the EU), which gives it extraterritorial reach beyond Europe. GDPR establishes principles for lawful, fair and transparent data processing, requires a lawful basis for processing personal data (such as consent or legitimate interests), grants individuals rights (including to access, correct, delete and port their data, and to object to certain processing), requires appropriate security and, in cases, breach notification, and imposes accountability obligations, backed by potentially significant fines for non-compliance. For marketing, GDPR notably affects how personal data is collected and used, requiring, in many cases, clear consent for things like marketing communications and certain tracking, transparency about data use, and respect for individuals' rights and choices. Understanding GDPR matters because it is a major, far-reaching privacy law with global influence and extraterritorial scope, so any organisation, including outside Europe, that handles the personal data of individuals in the EU may be subject to it, and its high standards have shaped privacy practice worldwide, meaning that knowing what GDPR is, and whether and how it applies, is important for businesses handling personal data, particularly those with any European audience or data.

GDPR, POPIA and South African businesses

For a South African business, two questions about GDPR are whether it applies and how it relates to South Africa's own privacy law, POPIA, and understanding both helps a business handle personal data compliantly for its audiences. On whether GDPR applies: GDPR can apply to a South African business if it processes the personal data of individuals in the EU, for example, by offering goods or services to people in the EU, or monitoring their behaviour, because GDPR has extraterritorial reach based on whose data is processed, not only where the organisation is based, so a South African business with EU customers, an EU audience, or that otherwise handles EU individuals' personal data may be subject to GDPR for that data, and would need to comply with its requirements for those individuals. A purely domestic South African business with no EU audience or data generally would not be subject to GDPR, but any genuine European dimension can bring it into scope. On the relationship to POPIA: South Africa has its own comprehensive data-protection law, the Protection of Personal Information Act (POPIA), which governs the processing of personal information in South Africa and shares many principles and aims with GDPR (lawful, transparent processing, a basis for processing, individual rights, security, accountability), so the two are broadly similar in spirit and both impose privacy obligations, though they differ in specifics, jurisdiction and some requirements. A South African business is subject to POPIA for its handling of personal information, and may additionally be subject to GDPR where it handles EU individuals' data. The practical implication is that a South African business should comply with POPIA (its own applicable law) as a baseline, and, if it has an EU audience or handles EU personal data, also meet GDPR's requirements for that data, in practice, because the two share principles, sound privacy practice, lawful, transparent, consent-respecting handling of personal data, secure storage, honouring individual rights, and clear privacy information, tends to support compliance with both, while attention to the specific requirements of each is needed where they apply. For a South African business, the guidance is to understand and comply with POPIA for its data handling, to determine whether it has any EU dimension that brings GDPR into scope and comply with GDPR for that data if so, and generally to adopt good, privacy-respecting data practices that align with both laws' shared principles, since strong privacy practice not only meets legal obligations but builds trust. Understanding GDPR and its relationship to POPIA thus helps a South African business handle personal data lawfully for both its domestic and any European audiences, which is increasingly important as privacy regulation and expectations grow.

FAQ

Does GDPR apply to South African businesses?

Yes, GDPR applies to any business, regardless of where it is based, that processes personal data of individuals located in the European Union. A South African company with EU customers, subscribers, or website visitors from EU countries must comply with GDPR requirements including lawful processing grounds, data subject rights, and explicit consent for marketing emails.

How does GDPR differ from South Africa's POPIA?

GDPR and POPIA share the same core principles around consent, data minimisation, purpose limitation, and data subject rights. POPIA is South Africa's equivalent privacy law, which came into full effect in 2021. Both require lawful grounds for processing personal data and explicit opt-in consent for direct marketing. GDPR applies to EU residents, POPIA to South African residents, and businesses dealing with both must satisfy both frameworks.

Want a team that knows these metrics cold?

Founder-led digital marketing for South African businesses since 2015. 4.9-star rated, 64+ clients, no long-term contracts.