In This Article
The short answer: sometimes, but not as a normal cold sales pitch
Can a South African SME email, SMS or WhatsApp a prospective customer who has never dealt with it? Usually, the business first needs the person’s consent. A narrow rule permits one approach to request that consent, provided the person has not previously withheld it. That first message should be a genuine consent request — not a promotional email with “reply yes” added at the bottom.
A separate exception may permit marketing to an existing customer, but only when every statutory condition is satisfied. It is not enough that the person once submitted an enquiry, downloaded a document or appears in the accounting system.
Adding an unsubscribe link does not retrospectively make an unlawful first sales message compliant. The Information Regulator’s amended Regulations expressly state that opt-out does not constitute the consent required for unsolicited electronic direct marketing.
This distinction applies across channels. Changing an email campaign into WhatsApp messages does not avoid POPIA. The Regulator’s Guidance Note on Direct Marketing treats email, SMS, telephone calls and other electronic methods as part of the section 69 framework.
What POPIA section 69 actually regulates
Section 69 deals with processing personal information for direct marketing through unsolicited electronic communication. POPIA defines direct marketing around approaching a data subject, in person or electronically, to promote or offer goods or services, or request a donation.
The starting position is prohibition: electronic direct marketing is not allowed unless the recipient has consented or qualifies as the responsible party’s customer under the limited section 69(3) exception.
This is important for business-to-business campaigns. POPIA’s concept of a data subject can include a juristic person, and a named work address such as thandi@example.co.za is personal information connected to an identifiable person. An address published on a website is not automatically permission to use it for an unsolicited sales campaign.
Section 69 is not the only consideration. A responsible party must still satisfy POPIA’s broader conditions, including accountability, purpose specification, data minimisation, openness, information quality, security and data-subject participation. Consent to marketing does not authorise unrelated profiling, indefinite retention or insecure sharing.
For the official wording and supporting forms, consult the Information Regulator’s POPIA forms page.
You get one approach to request consent
If a person is not a qualifying customer and has not previously withheld consent, section 69(2) allows the responsible party to approach that person once to request consent. “Once” should be managed across the organisation, not reset for every salesperson, campaign or communications platform.
The consent request must identify the responsible party, specify the goods or services to be marketed and identify the proposed communication method. Consent must be voluntary, specific and evidenced through a process substantially similar to Form 4. A pre-ticked box, silence, failure to unsubscribe or an imported “opt-out” status is not positive consent.
Do not include product prices, discounts, case studies, persuasive claims or a meeting-booking pitch in the request. Those elements can turn the supposed permission request into the direct marketing that permission was meant to precede. Keep the message neutral and wait for an affirmative response before sending promotional content.
If the person says no, does not respond or has previously withheld consent, do not send another request. Retain the minimum information necessary on a suppression list so another staff member or future data import does not contact them again.
When the existing-customer exception applies
Consent is not always required where the recipient is genuinely your customer, but section 69(3) sets cumulative conditions. First, you must have obtained the contact details in the context of selling that customer a product or service. Buying their details elsewhere or collecting them during an unrelated competition does not satisfy this condition.
Second, you may market only your own similar products or services. A web-hosting customer might reasonably receive information about a related hosting upgrade. That does not automatically justify messages about an unrelated partner’s insurance product. Nor does the exception generally authorise selling or passing the customer’s details to another marketer.
Third, the customer must have received a reasonable, free and uncomplicated opportunity to object when the details were collected. If they did not object then, every subsequent marketing communication must provide that opportunity again.
All three requirements matter. A previous enquiry is not necessarily a sale. A person who abandoned a quotation form is not automatically an existing customer. Likewise, a five-year-old transaction does not excuse irrelevant or unexpected messaging; purpose, retention and reasonable expectations still need consideration.
Document why each audience qualifies instead of applying an “existing customer” label to the whole CRM.
Every marketing message needs a clear sender and way to stop it
Section 69(4) requires every direct-marketing communication to contain details of the sender’s identity, or the identity of the person on whose behalf it was sent, plus an address or other contact details through which the recipient can request that the messages cease.
For email, use an accurate sender name, a functioning reply address and a prominent unsubscribe facility. For SMS, provide a practical free method to object; do not force the recipient to phone a premium-rate number. For WhatsApp, identify the business in the first message and make instructions such as “Reply STOP” effective.
Process objections across channels. If someone unsubscribes by email, consider whether their objection covers the campaign or marketing relationship generally before moving them to SMS. Channel-hopping to bypass an objection is a poor compliance practice and a fast way to damage trust.
An unsubscribe should not require an account password, a lengthy form or unnecessary identity documents. Remove the person promptly from active marketing and retain their suppression status. Transactional notices that are genuinely necessary to deliver an existing service may continue, but they should not be padded with promotional content.

What changed under the amended POPIA Regulations in 2025
The amended POPIA Regulations came into effect on 17 April 2025. They did not create a general licence for cold outreach. They clarified accessible methods for consent requests and objections and strengthened operational expectations.
Under amended Regulation 6, written consent may be obtained using a process substantially similar to Form 4 in an expedient, free and reasonably accessible manner, including email, telephone, SMS, WhatsApp, fax or an automated calling machine. A telephone or automated consent request must be electronically recorded, and the recording or a transcription must be supplied free of charge if the data subject requests it.
The amended text expressly says that opt-out does not constitute section 69(2) consent. Therefore, “You are subscribed unless you click here” is not a valid foundation for marketing to a non-customer.
The amendments also make accessible objections important: Form 1 or a substantially similar mechanism may be made available through methods including email, SMS or WhatsApp. Telephonic objections must be recorded and made available upon request.
Businesses should read the Information Regulator’s amended Regulations rather than relying on an old consent template.
Why bought, borrowed and scraped lists are high risk
A supplier’s claim that a database is “POPIA compliant” is not proof that your business may market to everyone on it. Ask where each detail came from, what the person was told, which organisation they consented to hear from, which products and channels were specified, when consent was given and whether it has been withdrawn.
Generic consent to receive “offers from selected partners” may not establish specific permission for your identified business and campaign. The seller cannot turn publicly visible contact details into consent merely by compiling them. Scraping email addresses from websites or LinkedIn presents the same underlying problem: availability is not permission.
Nor can a bought list usually fit the existing-customer exception. Those people bought from someone else, not from you, and you did not obtain their contact details in the context of your own sale.
Before importing any third-party data, perform and document due diligence, review the contract and obtain legal advice where appropriate. If valid, provable permission for your responsible party is absent, do not send marketing. Building a first-party list through transparent forms, useful resources, events and customer relationships takes longer but produces better trust and cleaner campaign data.
A practical POPIA direct-marketing decision tree
Use this sequence before adding any person to an email, SMS or WhatsApp campaign:
- Is the message direct marketing? If it promotes goods or services or requests a donation, continue. A necessary service notice may follow a different basis, but keep it genuinely transactional.
- Is the channel electronic? Email, SMS, WhatsApp, automated calls and, in the Regulator’s view, telephone and certain direct messages fall within the electronic framework.
- Do you have specific, provable consent for this business, purpose and channel? If yes, check that it remains valid and no objection has been made.
- If not, is the person a qualifying existing customer? Confirm that you collected the details during your own sale, the campaign concerns your own similar offering, and free objection opportunities were provided at collection and in every message.
- If neither basis applies, have you previously requested consent? If no consent request has been made and the person has not withheld consent, send one neutral, compliant request only.
- If there is no affirmative response, stop. Do not send the sales campaign or repeat the request.
Finally, screen every send against your suppression list and ensure the message identifies the sender and provides a working objection mechanism.
A compliant consent-request example
The wording below is a practical starting point, not a substitute for reviewing Form 4 or obtaining legal advice:
Consent request from Example (Pty) Ltd
We would like your permission to send you occasional email updates about our website design and maintenance services. If you consent, please select “I give my consent” below. You may withdraw your consent at any time by using the unsubscribe link in our emails or contacting privacy@example.co.za.
[I give my consent] [I do not give my consent]
Responsible party: Example (Pty) Ltd, [physical or business address], [contact number], privacy@example.co.za. Proposed communication method: email.
This is a request for consent, not a promotional offer. If you do not respond, we will not send marketing messages or repeat this request.
Record the exact wording shown, recipient, date, channel and response. The consent action should not be preselected. Link to a clear privacy notice explaining collection, purposes, rights, retention and contact details. Dsignr Digital’s privacy policy illustrates the type of owned page businesses should maintain, although each organisation needs a notice matching its own processing.
Keep records and make compliance part of campaign operations
Compliance depends on evidence. Keep a consent register recording who consented, when, how, to which business, for which goods or services and through which channels. Preserve the wording and privacy notice version presented at the time. Separately maintain a suppression register for refusals, withdrawals and objections.
Track whether the one permitted consent request has already been used. Restrict imports, define retention periods and ensure agencies, sales teams and marketing platforms apply the same suppression data. Your organisation remains accountable when an operator sends campaigns on its behalf.
Before each campaign, document the audience, legal basis, source, offer, channel and unsubscribe test. Send a test message, verify sender details and confirm that replies and opt-outs reach people who can action them. Train staff not to export contacts into private spreadsheets or personal WhatsApp accounts.
A well-run permission programme is not merely a legal burden. It protects deliverability, improves engagement and avoids wasting budget on people who never wanted the message.
Dsignr Digital can help South African SMEs build permission-led lists, automated journeys and measurable campaigns through our email marketing services. To discuss a more sustainable approach than purchased lists and bulk outreach, book a call.
Disclaimer: This article is practical general guidance, not legal advice. POPIA compliance depends on the facts, and businesses should obtain qualified legal advice where necessary.
Frequently Asked Questions
Is cold email completely illegal in South Africa?
No, but unsolicited electronic direct marketing is prohibited unless consent or the qualifying existing-customer exception applies. A non-customer who has not previously withheld consent may be approached once through a compliant request for consent. That request should not double as a sales pitch.
Can I email a business address published on its website?
Publication does not automatically equal consent to direct marketing. POPIA can protect information relating to natural and juristic persons. Assess whether you have valid consent or another section 69 basis before using the address for a campaign.
Does an unsubscribe link make a cold email POPIA compliant?
No. An unsubscribe facility is required operationally, but it does not replace the consent needed before marketing to a non-customer. The amended Regulations explicitly state that opt-out does not constitute section 69(2) consent.
Can I send a follow-up if someone ignores my consent request?
The safer reading of the one-approach rule is no. Silence is not consent, and a follow-up would be another approach for permission. Record the non-response and exclude the person from marketing.
Can I market to someone who asked for a quotation?
You may process their details to answer the quotation request, but that does not necessarily make them a customer under section 69(3). If no sale occurred, obtain compliant marketing consent before adding them to unrelated newsletters or promotions.
Does the existing-customer exception last forever?
POPIA does not provide a simple universal expiry period for this exception. However, information must not be retained longer than authorised, products must remain similar, and processing must stay relevant and reasonable. Old, dormant records deserve careful review.
Can a customer unsubscribe from marketing but still receive invoices?
Yes. Necessary transactional messages such as invoices, security notices or service updates may continue where another lawful basis applies. Keep them focused on the transaction and do not disguise advertising as operational communication.
May we ask for consent over WhatsApp?
Yes. The amended Regulation 6 identifies WhatsApp as an accessible method for obtaining consent. The request should contain information substantially similar to Form 4, offer a genuine affirmative choice and be retained as evidence.
What records should an SME retain?
Keep the source of the details, consent wording and notice version, date, channel, affirmative response, permitted topics and any withdrawal or objection. Also record one-time consent requests and maintain a suppression list so refused contacts are not re-imported.
Are bought email lists ever safe to use?
Only where you can establish a valid lawful basis for every recipient and prove that any consent specifically covers your responsible party, purpose and channel. Generic supplier assurances are inadequate. In practice, many bought lists cannot meet that standard.
