The framework
South Africa regulates personal data through the Protection of Personal Information Act (POPIA), dating from 2013 and supervised by the Information Regulator.
For advertisers the consent posture matters most, and South Africa sits in the opt-in bloc, where tracking and outreach need permission up front.
Key instruments
Protection of Personal Information Act (POPIA)
POPIA has been fully in force since July 2021, and the Information Regulator has used it, with enforcement notices against major institutions, a standing fight over direct marketing interpretation, and guidance confirming that unsolicited electronic marketing needs consent. Consumer Protection Act regulations gazetted in April 2026 add a second layer, requiring every direct marketer to register with the National Consumer Commission's opt-out registry before contacting anyone and to scrub lists monthly; the Regulator stresses that an opt-out registration never counts as consent. South Africa is opt-in for email and SMS marketing in practice.
Marketing and advertising
Eight processing conditions with justification grounds including legitimate interests, but section 69 makes electronic direct marketing opt-in, with a narrow existing-customer exception. Since April 2026, direct marketers must also register with the National Consumer Commission's opt-out registry and clean their lists against it monthly. Most channel decisions here follow from that consent rule.
Cross-border transfers
Adequate-law destinations, binding rules, consent or contract necessity.
Enforcement and penalties
Fines up to ZAR 10M and criminal penalties; enforcement notices are the workhorse.