Announcing Khanya: The new CRM built specifically for South African service businesses. Read our story
Home/Blog/Compliance & Legal
Compliance & Legal

Understanding POPIA: A Practical Guide for Modern Sales Outreach Teams

Viwe MhlabaFounder
8 min read·2026-05-12

In February 2024, South Africa's Information Regulator fined a company called FT Rams Consulting R100,000. Not for a data breach. Not for hacking anyone. For sending marketing emails to people who hadn't consented to receive them, and then ignoring the opt-outs when people asked to be removed.

If your sales team is running cold email campaigns, cold-calling scraped lists, or buying contact databases from a broker, that fine should get your attention. POPIA isn't a policy document your legal team files away. It's an active piece of legislation, and the Regulator has started enforcing it.

This is a practical guide to what POPIA actually requires before your team picks up the phone or hits send, without the legal jargon.

Why This Suddenly Matters

POPIA was signed into law in 2013, but the compliance deadline only kicked in on 1 July 2021. For a few years after that, enforcement was quiet. Most sales teams kept doing what they'd always done: buy a list, load it into an email tool, blast it out, hope for a 2% reply rate.

That quiet period is over. In December 2024, the Information Regulator published a formal Guidance Note on direct marketing, spelling out exactly how Section 69 of POPIA applies to emails, SMSs, and phone calls. The FT Rams Consulting fine wasn't a one-off warning shot, it was the first of what the Regulator has said will be more consistent enforcement.

Here's the part that catches most sales teams off guard: the Regulator has confirmed that phone calls count as electronic communication under POPIA. Cold-calling isn't exempt just because it's not an email. If your outbound sales process still runs on "call first, ask forgiveness later," that process now carries real financial risk.

The Two Regimes: Electronic vs. Non-Electronic

POPIA doesn't treat all outreach the same way. It splits direct marketing into two lanes, and the rules are very different depending on which one you're in.

Non-electronic marketing covers things like postal mail, hand-delivered flyers, and face-to-face approaches. This can generally rely on "legitimate interest" rather than upfront consent, as long as you give people a clear, free way to opt out, and you can justify why the outreach was necessary in the first place.

Electronic marketing covers email, SMS, automated calls, and (as of the December 2024 guidance) live phone calls too. This is opt-in by default. You need consent before you contact someone, not an opt-out link after the fact.

There's one exception worth knowing: the existing-customer exception under Section 69(3). If someone already bought a product or service from you, you obtained their contact details in that process, and you're marketing your own similar products or services to them, you can continue that relationship without fresh consent, provided you gave them a clear opt-out at the time and every time you contact them.

That exception does not cover a list of businesses you found on Google Maps, a database you bought from a broker, or contacts scraped from LinkedIn. Those are cold leads, and cold electronic outreach to them needs consent first.

The "One Call to Ask" Rule

This is the part that trips up most South African sales teams, because it doesn't exist in the American sales playbooks most of us learned from.

Under Section 69, if someone isn't already your customer, you're allowed to approach them once to ask for consent to market to them electronically. That's it. One approach, and it has to be a request for consent, not a sales pitch dressed up as one. The Regulator's Guidance Note is explicit on this: the first communication has to actually ask for permission, not smuggle a product pitch in alongside it.

If they say yes, you can proceed. If they say no, or they simply don't respond, the Regulator's position is that silence is not consent. You treat non-response as an opt-out and you don't contact them again electronically.

This is the opposite of the "spray and pray, keep following up until someone replies" approach that a lot of cold email tooling is built around. Under POPIA, that follow-up sequence is only lawful once you've actually got a yes.

Where Global Sales Tools Get This Wrong

Most sales engagement platforms, and most sales training, comes out of the US or UK. They're built around CAN-SPAM or GDPR, and neither maps cleanly onto POPIA.

CAN-SPAM in the US is largely opt-out: you can email someone until they tell you to stop. Import that mindset into a South African sales process and you're now running an unlawful campaign, because POPIA requires the opt-in to come first.

GDPR is closer to POPIA in spirit, but the two aren't identical. POPIA's Section 69 guidance around phone calls, the "one call to ask" limit, and the specific Form 4 consent format are South African-specific requirements that a GDPR-compliant process doesn't automatically satisfy.

The practical effect: if your sales stack, your scripts, or your outreach cadence were copied from an international sales blog, there's a good chance part of that process needs to be rebuilt for a South African audience.

What This Actually Looks Like in Practice

None of this means cold outreach is dead in South Africa. It means the sequence changes.

1. Source leads from public business information, not bought consumer lists. A business's name, phone number, and public listing (like a Google Maps entry) sits in a different category than a personal contact bought from a data broker with no clear origin. It's still your job to handle what happens next lawfully, but starting from public business data is a materially safer foundation than an unverifiable bought list.

2. Treat your first message as a consent request, not a pitch. One outbound email or call, clearly identifying who you are and what you're asking permission to send, before any actual sales content goes out.

3. Build in a real opt-out, every time. Every marketing communication needs to clearly identify the sender and give an easy way to stop future contact. Section 69(4) requires this on every message, not just the first one.

4. Keep a do-not-contact list, and actually use it. If someone opts out or doesn't respond to your one consent request, they go on a list your whole team can see, and nobody re-adds them to a campaign six months later because a new rep didn't know.

5. Treat existing customers differently from cold leads. If someone's already bought from you, you can keep marketing similar products to them without asking again, as long as you gave them an opt-out when you collected their details and you keep giving them one.

This is where a CRM earns its keep. If your leads, your consent status, and your opt-out list all live in one pipeline instead of scattered across a spreadsheet, a mail tool, and a rep's personal notes, you can actually enforce this process instead of hoping everyone remembers it. Khanya's Lead Engine sources businesses from public Google Maps listings rather than scraped personal databases, which gives your team a cleaner starting point than a bought list. What you do with that lead from there, the consent request, the opt-out, the do-not-contact list, is still on your process, and it's worth building deliberately rather than assuming your CRM handles it for you.

A Necessary Disclaimer

We're a CRM company, not a law firm. This guide reflects our understanding of the Information Regulator's December 2024 Guidance Note and Section 69 of POPIA, written to help sales teams think about their process, not to serve as a compliance certificate. If your outreach volume is meaningful or your risk exposure is real, get a South African attorney to review your actual process, your consent forms, and your data sourcing. The Regulator's guidance note itself is advisory; POPIA and its Regulations are what ultimately govern, and there's ongoing legal debate (particularly around telemarketing) that a lawyer will be better placed to help you navigate than a blog post.

The Takeaway

POPIA isn't a reason to stop doing outbound sales in South Africa. It's a reason to do it deliberately: source from clean data, ask before you pitch, honour the opt-out, and keep a record of who said no. The sales teams that build that discipline in now won't be the ones explaining themselves to the Information Regulator later.

Build a high-performing South African sales engine.

Discover active local businesses with our built-in Lead Engine, manage your deals seamlessly, and dispatch compliant ZAR tax invoices. No credit card required.