How to Manage User Consent Under POPIA (A Practical Guide)
Consent must be voluntary, specific and informed, and you must be able to prove you have it. How to collect it, record it, and handle a withdrawal properly.
Consent is not the foundation of POPIA
Most POPIA advice treats consent as the centre of the Act. It is not. Section 11 gives six lawful grounds and consent is only the first of them. Processing is equally lawful where it is necessary to conclude or perform a contract, to comply with a legal obligation, to protect a legitimate interest of the data subject, for a public law duty, or for the legitimate interests of the responsible party.
This matters practically, because consent is the weakest ground you can choose. It has to be freely given, it can be withdrawn at any moment, and you carry the burden of proving you have it. The other five do not evaporate when someone changes their mind.
So the first question is not "how do I get consent?" It is "do I actually need it here?" Usually the answer is no.
When you genuinely do need consent
Consent is required, or is realistically the only available route, in a handful of situations:
- Special personal information. Section 26 prohibits processing information about race, health, religion, political persuasion, trade union membership, sex life, criminal behaviour and biometrics. Consent under section 27 is often the practical way out, though each category also has its own authorisation section.
- Children's information. Section 34 prohibits it by default. Section 35 provides exceptions, the usual one being consent from a competent person, meaning a parent or guardian.
- Electronic direct marketing to non-customers. Section 69 requires consent, obtained through a single approach in the prescribed form. See is cold emailing legal in South Africa.
- Non-essential cookies and tracking. Analytics and advertising are not necessary to deliver your site, so they need agreement rather than assumption.
- Some cross-border transfers under section 72, where no other basis is available.
Outside these, reaching for consent when you have a better ground makes your position weaker, not stronger.
What makes consent valid
POPIA defines consent as a voluntary, specific and informed expression of will. Each word carries weight:
- Voluntary. Real choice, with no penalty for declining. Making access to your service conditional on accepting marketing is not voluntary. Neither, usually, is consent from an employee to their employer, which is why workplace consent is such shaky ground. See is fingerprint clocking legal in South Africa.
- Specific. Tied to a defined purpose. One tick covering "marketing, analytics and sharing with partners" is not specific. Separate the purposes and let people agree to some and not others.
- Informed. They understood what they were agreeing to, in plain language, before they agreed.
Pre-ticked boxes fail all three. So does consent bundled into a terms acceptance, and so does a cookie banner where the only visible button is "Accept".
You carry the burden of proof
Section 11(2)(a) puts the burden of proving consent on the responsible party. If challenged, "they are on the list" is not evidence. Record, at minimum:
- Date and time
- What they were shown, including the exact wording and the version of your notice in force at the time
- The specific purposes agreed to
- The method and source, whether a web form, a signed document or an in-person sign-up
Storing the wording matters more than people expect. Proving someone ticked a box is easy. Proving what the box said two years ago, after four redesigns, is where most businesses come unstuck.
Withdrawal, and what it does and does not undo
Section 11(2)(b) lets a person withdraw consent at any time. Two limits are worth knowing, because they are more forgiving than most summaries suggest.
Withdrawal does not retrospectively make your earlier processing unlawful. And it does not affect processing you are doing on one of the other five grounds. If you are keeping an invoice because tax law requires it, a withdrawal of marketing consent does not oblige you to delete the invoice.
What it does require is a working mechanism and a fallback. If your only ground was consent and it is withdrawn, you must stop. So before relying on consent, ask what you will do when someone says no, and whether you have an alternative that keeps the service working.
Objection is a different right
Withdrawing consent and objecting to processing are often confused. Section 11(3) gives a data subject the right to object, on reasonable grounds relating to their situation, to processing carried out on the grounds of legitimate interest, protecting their own interest, or a public law duty. There is also a right to object to direct marketing.
The practical difference: withdrawal applies where you relied on consent, objection applies where you did not. A business that only built an unsubscribe link has handled half of it. Requests to object arrive as ordinary emails, so your team needs to recognise one. See how to respond to a POPIA access request, which covers the neighbouring rights.
Cookies are their own problem
Agreeing to your privacy policy is not consent to tracking. Non-essential cookies need their own mechanism, and the mechanism has to actually work: nothing non-essential may fire before the choice is made, refusing must be as easy as accepting, and the choice must be changeable later. A banner that sets analytics cookies on page load and then asks permission is recording a decision it already ignored. See is your cookie banner POPIA compliant.
A short checklist
- For each thing you do with personal information, have you identified which of the six grounds applies?
- Where you are relying on consent, is another ground actually available and stronger?
- Are your consents unbundled, so people can agree to some purposes and not others?
- Are all boxes unticked by default?
- Do you store the wording shown at the time, not just the fact of a tick?
- Is there a working withdrawal route, and a fallback for when it is used?
- Can your team tell an objection from an unsubscribe?
- Does your cookie banner block non-essential scripts until a choice is made?
POPIA Ready generates a privacy policy that sets out your lawful grounds and how people withdraw or object, along with six other documents, free to preview. The free checklist will show you what else is missing.
General guidance on South African law as at August 2026, not legal advice. Which lawful ground applies depends on what you are doing and why, and a difficult case deserves a professional opinion.
Get Compliant Today
Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.
Generate Documents - Free to Preview