A Marketer May Ask You Once. Only Once.
A company that wants to market to you electronically, and has no relationship with you, is allowed to ask for your permission once.
Not once a quarter. Not once per campaign. Once. And if you have previously withheld consent, it may not ask at all.
That rule has been in force since July 2020, and almost nobody invokes it — which is part of why the calls keep coming. POPIA is generally discussed as a compliance burden for businesses. It is also a list of rights belonging to you, several of which are sharper than people expect: a right to be told the logic behind an automated decision built on your credit score, a right to have a disputed record annotated so nobody reads it without reading your objection too, and a right to sue for damages without proving the company was even careless.
Here is what the Act actually gives you, and how to use it.
Electronic marketing is opt-in, not opt-out
Start with the default position, because it is the opposite of how most people assume this works.
Processing your personal information for direct marketing by any form of electronic communication — the Act names automatic calling machines, fax machines, SMSs and email — is prohibited unless you have either given consent, or are a customer of that company.
So the burden does not sit with you to escape a list. It sits with the sender to have had permission before the first message. An SMS from a company you have never dealt with, sent without your consent, is not a nuisance you must now opt out of. It is prohibited processing.
An "automatic calling machine", for this purpose, is defined as a machine able to make automated calls without human intervention.
The one-approach rule
This is the provision worth memorising, because it converts a vague irritation into a specific breach.
A company may approach you to request your consent only once — and then only if you have not previously withheld that consent. The request must be made in the prescribed manner and form.
Read the two limbs together and the consequence is strict. If a company asks for permission and you say no, that is the end of it; it may not ask again. If it asks a second time having had no answer at all, it has exceeded what the section allows.
That is a considerably harder line than the "unsubscribe and hope" cycle most people are stuck in. The point of the section is that repeated permission-seeking is itself the harm.
The customer exception is narrower than companies think
The second route — you are already a customer — is where most legitimate marketing sits, and it comes with three conditions that all have to hold.
- The company must have obtained your contact details in the context of the sale of a product or service.
- The marketing must be of its own similar products or services.
- You must have been given a reasonable opportunity to object, free of charge and in a manner free of unnecessary formality — both at the time your information was collected, and on the occasion of each communication.
Each of those does work. "Its own similar products" excludes marketing a company's entirely unrelated line, and it excludes marketing somebody else's products to a list it built while selling you something. "In the context of the sale" excludes details harvested from an enquiry that never became a sale.
And "free of unnecessary formality" is the phrase to quote when opting out means calling a premium line, logging into an account you do not have, or replying to an address that does not accept replies. An objection mechanism that is deliberately awkward is not compliant with the section.
Every marketing message must identify who sent it
A short but useful requirement: any communication for the purpose of direct marketing must contain
- the identity of the sender, or of the person on whose behalf it was sent; and
- an address or other contact details to which you may send a request that the communications cease.
An unsigned SMS from a shortcode with no way to reply fails this on both limbs. It is also, in practice, the fastest thing to point at in a complaint, because it needs no argument about consent — it is either there or it is not.
Objecting, and what happens next
Alongside the electronic-marketing rules, you have a general right to object.
You may object at any time to the processing of your information for direct marketing other than the unsolicited electronic kind — the post, the phone call placed by a person, the doorstep. You may also object, in the prescribed manner and on reasonable grounds relating to your particular situation, to processing that rests on certain other legal bases, unless legislation provides for that processing.
And then comes the sentence that gives the right its teeth:
If a data subject has objected to the processing of personal information in terms of subsection (3), the responsible party may no longer process the personal information.
There is no balancing exercise in that sentence, no weighing of the company's commercial interest against yours. The objection is made; the processing stops.
Finding out what a company holds, free
Before you can correct anything, you need to know what is there — and the first step costs nothing.
Having provided adequate proof of identity, you have the right to ask a company to confirm, free of charge, whether it holds personal information about you.
You may then request the record itself, or a description of it — and this is the part people miss — including the identity of all third parties, or categories of third parties, who have or have had access to the information. That is how you find out where a list came from and who it has been passed to. It must be provided within a reasonable time, in a reasonable manner and format, and in a form that is generally understandable.
A fee may be prescribed for that second request. If one is charged, the company must give you a written estimate before providing the service, and may ask for a deposit. So a fee cannot appear as a surprise after the fact.
Access can be refused on the grounds set out in the Promotion of Access to Information Act, but only in part: where part of the information may or must be refused, every other part must still be disclosed. A blanket refusal covering an entire record is not what the section contemplates.
Correcting the record, and the note that must travel with it
You may request a company to correct or delete information about you that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully — or to destroy a record it is no longer authorised to keep.
Note "irrelevant" and "excessive" sitting in that list beside "inaccurate". The information does not have to be wrong for you to have grounds. It can simply be more than the company should be holding.
On receiving the request the company must, as soon as reasonably practicable, correct it, delete it, or give you credible evidence supporting the information as it stands. And where you cannot reach agreement, if you ask, it must take reasonable steps to attach an indication to the information, in such a manner that it will always be read with it, that a correction was requested and not made.
That is a genuinely useful outcome when a dispute deadlocks. You cannot always force a change, but you can ensure that nobody reads the record without also reading that you disputed it.
Two further duties follow. If the change affects decisions that have been or will be taken about you, the company must — where reasonably practicable — tell everyone it disclosed the information to. And it must notify you of the action it took either way.
This is the mechanism that sits behind a great deal of credit-record housekeeping, and it pairs with the sector-specific route in our guide to reading your credit report. If your credit score or credit report carries something inaccurate, out of date or excessive, POPIA gives you a general right of correction in addition to whatever the credit bureau's own process offers.
Decisions made by a machine
This section deserves far more attention than it gets on a continent of rapidly automating lenders.
You may not be subject to a decision that has legal consequences for you, or affects you to a substantial degree, where that decision is based solely on the automated processing of your information intended to build a profile of you — and the Act expressly lists credit worthiness among the things such a profile may cover, alongside performance at work, reliability, location, health, personal preferences and conduct.
There are carve-outs. The prohibition does not apply where the decision was taken in connection with concluding or performing a contract and either your request was met, or "appropriate measures" were taken to protect your legitimate interests. Nor does it apply where a law or code of conduct specifies appropriate measures.
But where a company relies on that "appropriate measures" route, the Act says what those measures must do. They must:
- give you an opportunity to make representations about the decision; and
- require the company to give you sufficient information about the underlying logic of the automated processing to enable you to make those representations.
In plain terms: if a machine declined you and the company's defence is that it protected your interests appropriately, then you are entitled to enough of the reasoning to argue back. "The system declined it" is not, by itself, the posture the section contemplates.
What it costs a company to get this wrong
Two routes matter to you, and one of them is unusual.
You may sue. A data subject — or the Regulator at your request — may institute a civil action for damages for breach, and the Act says this may be done whether or not there is intent or negligence on the part of the company. That is close to no-fault liability: you are not required to prove the company meant it, or was even careless.
The company has five defences: vis major, your consent, fault on your part, that compliance was not reasonably practicable in the circumstances, or that the Regulator granted an exemption.
A court may award an amount that is just and equitable, including compensation for patrimonial and non-patrimonial loss — financial and non-financial — as well as aggravated damages in its discretion, interest and costs.
Or you may complain to the Information Regulator, which is free and is the ordinary route. Where the Regulator issues an infringement notice, the administrative fine it specifies may not exceed R10 million. Separately, conviction for the offences in the Act carries imprisonment of up to ten years for the most serious, and up to twelve months for the rest.
What to actually do about the calls
A practical sequence, in the order that produces results:
- Reply once, in writing, and keep it. State that you object to the processing of your personal information for direct marketing and require it to cease. Email or an in-app message is fine; you want a record with a date on it.
- Ask where they got your details. Use the access right: confirmation is free, and you are entitled to know the third parties or categories of third parties who have had access to your information. This is what turns "who are these people" into an answer.
- Note what the message did not contain. If it did not identify the sender or give contact details for a cessation request, that is a discrete breach requiring no argument about consent.
- Count the approaches. If a company with no prior relationship has asked for consent more than once, or asked again after you declined, that is the one-approach rule.
- Escalate to the Information Regulator if it continues. Complaints are free, and the Regulator is the body with the infringement-notice power.
- Keep the paper. Dates, screenshots, message headers. Every remedy above turns on being able to show a sequence rather than describe an impression.
If you are on the other side of this — running a business that holds customer data — our guide to POPIA obligations for a small business sets out the duties rather than the rights. And where unsolicited contact is not marketing at all but an attempt to defraud you, what to do if you suspect fraud on your bank account is the more urgent read.
For everything else, start at our money guides.
Frequently asked questions
How many times may a company ask for my marketing consent? Once. A responsible party may approach a data subject whose consent is required, and who has not previously withheld consent, only once in order to request it.
Is direct marketing by SMS or email opt-in or opt-out in South Africa? Opt-in. Processing for direct marketing by electronic communication is prohibited unless you have consented, or you are a customer of that company and the narrower customer conditions are met.
A company I have bought from keeps emailing me. Is that allowed? It may be, but only if it got your details in the context of a sale, is marketing its own similar products or services, and gave you a reasonable opportunity to object free of charge and free of unnecessary formality both when it collected your details and on each communication.
What must a marketing message contain? The identity of the sender or the person on whose behalf it was sent, and an address or other contact details for a request that the communications cease.
What happens when I object? Where you have objected in terms of section 11(3), the responsible party may no longer process the personal information.
Can I find out what a company holds about me? Yes. Confirmation of whether it holds your information is free. You may then request the record or a description of it, including the identity of third parties or categories of third parties who have had access, at a prescribed fee if any — and you must be given a written fee estimate first.
Can I force a company to correct my information? You may request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained. Where no agreement is reached, you may require a note to be attached that will always be read with the information, recording that a correction was requested and not made.
Can a lender decline me purely by algorithm? Not where the decision has legal consequences or affects you to a substantial degree and is based solely on automated processing intended to profile you — creditworthiness is expressly named — unless a carve-out applies. Where the company relies on "appropriate measures", those measures must let you make representations and must give you sufficient information about the underlying logic to do so.
Do I have to prove the company was negligent to sue? No. The Act allows a civil action for damages whether or not there is intent or negligence, subject to the defences it lists.
What can it cost the company? An administrative fine specified in an infringement notice may not exceed R10 million, and the offences in the Act carry imprisonment of up to ten years for the most serious and up to twelve months for the others.