Over 6 years, Nelium Systems, has specialized in helping businesses of all sizes establish, grow, and dominate their digital presence.

Gallery

Contact

+254 758 870 937 / 0710 520 510

Lotus Plaza, Chiromo Lane, Westlands, Nairobi

business@neliumsystems.com / hello@neliumsystems.com

Most South African marketing automation is quietly non-compliant

If your business sends marketing emails, runs SMS campaigns or retargets using customer data — and you haven’t specifically reviewed that against POPIA — there is a good chance you are exposed. The Protection of Personal Information Act has been fully enforceable since 1 July 2021, when its one-year grace period ended, and the Information Regulator has been actively enforcing it since. The era of “we had their email address, so we mailed them” is over.

This guide explains, in plain terms, what POPIA actually requires for marketing, where most automation setups go wrong, and how to configure your stack so growth and compliance stop fighting each other. It is practical guidance for marketers, not formal legal advice — for a binding interpretation of your specific situation, consult an attorney.

Why POPIA matters more than most SA businesses realise

Plenty of South African business owners treat POPIA as a box-ticking exercise or assume it only applies to banks and big corporates. It does not. POPIA applies to almost every organisation that processes the personal information of people in South Africa, and the consequences of getting it wrong are real. For serious contraventions the Act provides for administrative fines of up to R10 million, and in the most serious cases imprisonment of up to ten years. Beyond the legal penalty, there is the reputational damage of a public breach or an Information Regulator finding — something that erodes exactly the customer trust your marketing is trying to build. The good news is that compliant marketing is not harder to do well; it is simply done deliberately.

What POPIA actually requires for marketing

Opt-in is the standard, not the exception

Section 69 of POPIA prohibits direct marketing by electronic communication — email, SMS and automated calls — unless the recipient has consented. Consent must be voluntary, specific and informed. There is one narrow exception: you may market to an existing customer about your own similar products or services, provided you obtained their details in the context of a sale and gave them a reasonable opportunity to opt out, both then and in every message since. For everyone else, no opt-in means no marketing message.

Every message must identify you and offer an exit

Each unsolicited communication has to clearly identify the sender and provide an accessible way to opt out of future messages. Pre-ticked boxes and buried unsubscribe links don’t satisfy this.

The eight conditions still apply

POPIA’s eight conditions for lawful processing — accountability, processing limitation, purpose specification, further-processing limitation, information quality, openness, security safeguards and data-subject participation — govern how you hold and use marketing data, not just how you collect it.

Appoint and register an Information Officer

Under POPIA the head of every organisation is automatically its Information Officer, and that role must be registered with the Information Regulator before performing its duties. Larger organisations typically also designate deputy Information Officers. Registration is free through the Regulator’s portal, and skipping it is one of the most common — and most easily fixed — compliance gaps we see.

POPIA-Compliant Marketing Automation in South Africa (2026 Guide)

Most automation setups are quietly non-compliant. Yours doesn’t have to be.

What this means for your stack, practically

Email marketing

Every list needs documented, timestamped opt-in. Newsletter sign-ups, lead magnets and post-purchase sequences each need their own clear consent capture — and records you can produce if asked.

SMS and WhatsApp

The same opt-in standard applies to SMS and WhatsApp marketing. Regular audits of your direct-marketing practices are sensible, not paranoid.

Automation platforms

Mailchimp, HubSpot, Brevo and the rest don’t make you compliant — your consent collection and record-keeping do. Most South African businesses already have the technical capability switched off or misconfigured. The features you need — double opt-in, consent logging, suppression lists and a preference centre — usually already exist in your current tool; they simply have to be turned on and set up correctly, which is far cheaper than switching platforms.

Website forms and pop-ups

Cookie consent and form opt-ins must be genuinely optional, with no pre-ticked boxes and clear language about how data will be used. A contact form that quietly adds every enquiry to your newsletter list is a textbook POPIA problem.

A POPIA-ready automation checklist

Before you send your next campaign, work through the essentials.

How POPIA compares to GDPR, and what that means for your tools

If you have worked with European data rules, POPIA will feel familiar, but the two are not identical and the differences matter for marketers. Both require a lawful basis to process personal information, both grant data subjects rights to access and correction, and both demand reasonable security. POPIA, however, treats consent for electronic direct marketing more strictly than GDPR does in some respects: there is no broad “legitimate interest” route to cold-emailing strangers, and the existing-customer exception is narrow and specific. POPIA also protects the personal information of existing juristic persons (companies), which GDPR does not.

Practically, this affects the tools you choose. Many popular marketing platforms are built around GDPR assumptions and US defaults, so their out-of-the-box settings will not make you POPIA-compliant on their own. What keeps you compliant is how you configure consent capture, how you document it, and where the data is stored. A platform hosted entirely outside South Africa is not automatically off-limits, but it does trigger POPIA’s conditions on cross-border transfers, which you need a defensible basis for. We help clients map their stack against these requirements so they keep the tools they like while closing the gaps those tools leave open.

Turning compliance into a marketing advantage

It is tempting to see POPIA purely as a constraint, but the businesses that handle it well end up with better marketing, not just safer marketing. A list built entirely from people who genuinely opted in is smaller than a scraped or purchased one, but it converts far better, generates fewer spam complaints, and protects your sender reputation so more of your email actually lands in the inbox. Clear, honest consent language also signals respect, and respect builds the trust that turns first-time buyers into repeat customers.

There is a competitive angle too. Many of your South African competitors are still cutting corners, firing trackers without consent and mailing lists they never earned. When you get this right, you can say so: a visible, plain-language privacy commitment becomes a differentiator with the growing number of customers who care how their data is handled. Compliance done deliberately stops being a cost centre and starts being part of the brand. That is the mindset we bring to every automation setup we build, so the system that protects you also helps you grow.

Talk to us about compliant automation

We set up email, SMS and automation that grows your pipeline without creating regulatory risk. Let’s review your current stack.

POPIA vs other African data-protection regimes

A quick orientation if you operate across borders. This is a summary, not legal advice.

MarketLawMarketing consentLead regulator
South AfricaPOPIA (in force July 2021)Opt-in (s69); existing-customer exceptionInformation Regulator
NigeriaNDPA 2023Consent + immediate stop on objectionNDPC
KenyaData Protection Act 2019Consent-based; ODPC registrationODPC
How We Work

How we build compliant automation

Consent capture

Unticked opt-in checkboxes, plain-language purpose statements and timestamped records across email, SMS and WhatsApp.

Preference centres

Subscribers control what they receive, satisfying the ongoing opt-out requirement without you losing the whole relationship.

Sender identification and documentation

Every automated message identifies your business, and consent records are stored so they can be produced if the Information Regulator asks.

Questions & Answers

Frequently asked questions

Does POPIA apply to small businesses?

Yes. POPIA applies broadly to any organisation processing personal information in South Africa. The obligations — consent, purpose limitation, security, opt-out — apply regardless of size, even if enforcement attention tends to start with larger players.

My email platform is hosted overseas — does that matter?

It can. POPIA places conditions on transferring personal information outside South Africa unless adequate protection or consent exists. It is worth a specific review rather than assuming "everyone uses these tools, so it must be fine."

What are the penalties for getting POPIA wrong?

For serious contraventions POPIA provides for administrative fines of up to R10 million, and in the most severe cases imprisonment of up to ten years. The Information Regulator can also issue enforcement notices requiring you to change your practices. In reality the reputational cost of a public finding often outweighs the fine, which is why building compliance in from the start is the cheaper path.

Can I still do effective marketing under POPIA?

Absolutely. POPIA governs how you process data, not whether you can market at all. Compliant, consent-based marketing is entirely workable — and it tends to produce healthier, more engaged lists than scraped or bought data ever did.

What do I do with contacts I collected before I understood POPIA?

This is the most common question we get, and the honest answer is that you cannot simply keep marketing to a list whose consent you cannot demonstrate. The usual remedy is a re-permission campaign: a single, clearly worded message inviting those contacts to confirm they want to keep hearing from you, with everyone who does not respond removed from marketing. You lose some volume, but what remains is a clean, defensible list you can actually rely on.

How long do I need to keep consent records?

Keep evidence of consent for as long as you are relying on it to market to someone, and for a reasonable period afterwards in case you need to demonstrate compliance. In practice that means storing the timestamp, the source, and the exact wording the person agreed to. Good automation platforms capture this automatically once they are configured correctly, which is a large part of what we set up.

What's the first practical step?

Audit where your customer data currently lives, what consent (if any) was captured when it was collected, and which platforms store it where. That usually surfaces the biggest gaps quickly, and it tells us whether you need a light tidy-up or a more thorough rebuild of your consent and data flows.

Got a Project in Mind? Let’s Talk.

From strategy to execution, we help ambitious brands bring their ideas to life online. Let’s create something meaningful together — starting with a conversation.

Call to Action Illustration