South Africa's Information Regulator (InfoReg) has adopted a resolute stance against telemarketing, asserting that telephonic communication falls under the category of electronic communication. In response to this, the InfoReg has completed a comprehensive guidance note on direct marketing, which is now open for public consultation.
The primary objective of this note is to provide directives to the direct marketing sector, ensuring adherence to the provisions of the Protection of Personal Information Act (POPIA). Historically, telemarketing entities have exploited a loophole in the interpretation of electronic communication as defined by POPIA. The Act previously defined electronic communication as information stored in the network or on the recipient's device until collected. Advocate Pansy Tlakula, chairperson of the Information Regulator, highlighted this during the ITWeb Governance Risk and Compliance 2024 conference.
This interpretation allowed telemarketing companies to persist with unsolicited direct marketing calls, despite the existence of POPIA. To address this, the InfoReg has clarified that a telephone falls within the ambit of electronic communication, bringing telemarketing activities under Section 69 of POPIA. Advocate Tlakula emphasized the nuisance caused by these calls and the need to address the issue definitively.
Discussing recent milestones, Advocate Tlakula revealed that the Information Regulator is actively addressing the issue of unsolicited marketing emails and is finalizing its first complaint investigation in this regard.
While acknowledging potential legal challenges ahead, Advocate Tlakula stressed that the goal is not to force businesses to shut down. Drawing parallels with international practices, she suggested that direct marketing through a telephone can coexist with legal compliance. Companies need to seek consent from data subjects during the initial call, specifying the products to be marketed and the preferred communication method (email, SMS, or phone call).
Despite anticipating resistance from direct marketing companies, Advocate Tlakula emphasized the importance of building a consent-based database to distinguish between those willing to receive marketing messages and those who are not. Addressing concerns about data acquisition, she clarified the rules, emphasizing the necessity of obtaining information legally, either from public records or deliberate public disclosures.
Acknowledging the likelihood of legal battles, especially concerning the definition of a telephone as electronic communication, Advocate Tlakula emphasized the regulator's commitment to addressing direct marketing complaints that span various sectors, including members of Parliament within the portfolio committee. The recently finalized guidance note is a significant step toward establishing clarity on the classification of telephonic communication in the context of electronic communication within the regulatory framework.
Offences, Penalties and Administrative Fines
Sections 100 – 106 of the POPI Act deal with instances where parties would find themselves “guilty of an offense”. The most relevant of these are:
- Any person who hinders, obstructs or unlawfully influences the Regulator;
- A responsible party which fails to comply with an enforcement notice;
- Offences by witnesses, for example, lying under oath or failing to attend hearings;
- Unlawful Acts by responsible party in connection with account numbers;
- Unlawful Acts by third parties in connection with account number.
- Section 107 of the Act details which penalties apply to respective offenses.
For the more serious offences the maximum penalties are a R10 million fine or imprisonment for a period not exceeding 10 years or to both a fine and such imprisonment.
For the less serious offences, for example, hindering an official in the execution of a search and seizure warrant the maximum penalty would be a fine or imprisonment for a period not exceeding 12 months, or to both a fine and such imprisonment.
Failure to comply with the requirements of the POPI Act could have dire consequences.
This article must be read in conjunction with the POPI Act which can be downloaded from Act No. 4 of 2013 : Protection of Personal Information Act, 2013
Do you want to know if your organisation is compliant?..
...well contact StormWarning! today for a NIST CyberSecurity Audit and we will do our very best to answer that question for you and your organisation, rest assured, we will diligently endeavor to support your organization while adhering to the constraints of your budget.