HomeBlogCan You Cold Email in South Africa? POPIA Section 69 Explained

Can You Cold Email in South Africa? POPIA Section 69 Explained

Section 69 is stricter than most marketers realise, and the rules differ for existing customers. What you may send, to whom, and how consent must be recorded.

The answer is "once, in writing, in a prescribed form"

Most articles on this question say South Africa is opt-in, so cold email is illegal, full stop. That is not quite what section 69 says, and the difference matters if you sell business to business.

Section 69 prohibits direct marketing by electronic communication unless the recipient has consented, or is an existing customer. But section 69(2) then allows you to approach a person whose consent you need, and who has not previously refused, once, in order to ask for that consent.

So a single, properly formed request for permission is contemplated by the Act. What is prohibited is marketing to someone who has not agreed, and coming back a second time after silence or a refusal.

The catch: it has to be Form 4

That one approach is not a free hand to write whatever you like. Section 69(2) requires the request to be made in the prescribed manner and form, which is Form 4 of the POPIA Regulations, headed "Application for the consent of a data subject for the processing of personal information for the purpose of direct marketing".

The Information Regulator has indicated that your request need not look exactly like Form 4, but it must substantially comply with it. In practice that means the approach must identify who you are, say what personal information you hold and where you got it, state what you want to send, and give the person a clear way to consent or refuse.

That is a long way from a templated sales email, and it is why most cold outreach in South Africa is unlawful in form even when the sender believes they are allowed one approach.

Two consequences worth being blunt about:

  • Buying or renting a list does not work. You cannot obtain consent by purchasing it from someone else, and you will usually be unable to say lawfully where the details came from.
  • Scraping is worse. Harvesting addresses from LinkedIn or company websites gives you neither consent nor a defensible collection story, and a scraped list is normally used for repeated campaigns rather than a single Form 4 approach.

The existing customer exception

The genuinely useful exception is section 69(3), for people who have already bought from you. You may market to an existing customer without prior opt-in, but only if all of the following hold:

  • You obtained their details in the context of a sale of a product or service to them.
  • You are marketing your own similar products or services, not a partner's, and not something unrelated to what they bought.
  • You gave them a reasonable opportunity to object, free of charge and without unnecessary formality, when you collected the details.
  • You give them that same opportunity in every message you send.

Each condition does real work. A customer who bought accounting software has not agreed to hear about your travel business. And "reasonable opportunity to object, free of charge" means an unsubscribe link that works, not a request to phone your office during business hours.

Cold calling is a different statute

Live telephone calls are commonly lumped in with email and SMS. They should not be.

Section 69 regulates direct marketing by electronic communication, which POPIA defines as a text, voice, sound or image message sent over an electronic communications network and stored in the network or the recipient's device until collected. An automated call, a voicemail drop, an SMS, a WhatsApp message or an email is stored. A live conversation with a human being is not, so it falls outside section 69's opt-in regime.

That does not make cold calling unregulated. It moves it to the Consumer Protection Act, which gives consumers the right to demand that direct marketing stop and provides for a registry on which people can pre-emptively block approaches. POPIA still applies to the personal information you hold about the person you are calling, including how you obtained their number and what you record afterwards.

The practical position: a live call is on an opt-out footing, an electronic message is on an opt-in footing, and mixing the two up is how businesses end up sending an SMS follow-up that is unlawful even though the call was not.

WhatsApp is covered too

Everything above applies unchanged to WhatsApp, which is comfortably an electronic communication. The channel adds problems email does not have, starting with the fact that adding someone to a group discloses their number to every other member. See WhatsApp Business and POPIA.

Unsubscribes are not a courtesy

Every electronic marketing message must carry a working, easy way to opt out, and an objection must be acted on. Under section 11(3) a data subject may object to processing, and once they have, continuing to market to them is processing without a ground.

Practically:

  • Make the unsubscribe one click. A link that requires logging in fails "without unnecessary formality".
  • Process it promptly and across every list, not only the one they clicked from.
  • Keep a suppression list, so a later import does not resurrect someone who opted out. This is the most common way businesses breach after they thought they had fixed the problem.
  • Record when and how consent was obtained. If challenged, the burden of showing consent sits with you, and "they are on the list" is not evidence.

What good practice looks like

  • Build the list yourself, with an unticked opt-in box and a clear description of what you will send.
  • Keep proof: timestamp, source, and the wording shown at the time.
  • Separate transactional messages from marketing. An invoice or a delivery notification is not direct marketing and does not need consent, but do not smuggle promotions into it.
  • If you approach a non-customer, do it once, substantially in Form 4, and do not follow up if there is no reply. Silence is not consent.
  • Segment existing customers so the "own similar products" condition actually holds.
  • Say what you do in your privacy notice, including how someone objects.

The Information Regulator has published guidance on direct marketing, and it has shown more appetite for this area than most, because unwanted marketing is the thing ordinary people actually complain about. See how to manage user consent under POPIA for recording and withdrawal, and POPIA fines and penalties for how enforcement actually escalates.

POPIA Ready generates a privacy policy that sets out your marketing practices and how people object, along with six other documents, free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at August 2026, not legal advice. Direct marketing sits across POPIA and the Consumer Protection Act, and a campaign at scale deserves a professional opinion.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Your WhatsApp Messages Are Records You Must Keep for Five Years

Read article →

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →