
The Information Regulator of South Africa has recently issued its inaugural enforcement notice as a consequence of a direct marketing complaint. This notice was directed towards FT Rams Consulting, an educational institution, following the Information Regulator's determination that the organization had violated various provisions of the Protection of Personal Information Act (POPIA).
The impetus for this action was the Regulator's decision to incorporate a clause regarding marketing through telephone communication into Section 69 of POPIA. The enforcement notice stemmed from a complaint lodged by an affected individual, who had been inundated with numerous direct marketing messages. Despite repeated attempts to opt out and requests to be removed from the company's email distribution list, FT Rams Consulting conspicuously disregarded the data subject's pleas and persisted in sending marketing messages via email.
Upon investigation, the regulator ascertained that FT Rams Consulting impeded the protection of the data subject's personal information, thereby violating the stipulated conditions for legally processing such information. Furthermore, the organization was found to be in contravention of Section 69 of POPIA, which governs direct marketing through electronic communications.
Consequently, FT Rams Consulting has been directed to cease sending unsolicited direct marketing messages through any electronic communication means without the explicit consent of the data subject. The company is obligated to ensure that its initial communication with data subjects explicitly requests their consent, limiting such requests to a single instance per data subject.
The regulator has mandated that FT Rams Consulting furnish evidence of its compliance with these directives within a 90-day period. Failure to adhere to these instructions may result in severe penalties, including fines of up to R10 million or imprisonment for a maximum of ten years.
Pansy Tlakula, the Chair at the Information Regulator, emphasized a shift away from leniency regarding direct marketing through unsolicited electronic communications. Non-compliance by responsible parties, whether public or private entities, with Section 69 of POPIA is viewed as an infringement on the rights of data subjects.
The regulator's scrutiny revealed that FT Rams Consulting violated not only Section 69 but also various other sections of POPIA by directly marketing to the data subject without obtaining prior consent, persistently sending unsolicited direct marketing communications via email, and offering an "Opt Out" option but failing to cease communications upon the data subject's exercise of this choice.
Section 69 (1) of POPIA explicitly prohibits companies from engaging in direct marketing to customers through any electronic communication without securing prior consent. Additionally, Section 69 (2) stipulates that marketers are permitted to solicit consent from a data subject only once.
The regulator clarified that the initial communication from FT Rams Consulting to the data subject should have been a request for consent, as defined by POPIA as a voluntary, specific, and informed expression of will permitting the processing of personal information. The data subject, upon consenting, should have also indicated the preferred means of communication for receiving direct marketing messages.
FT Rams Consulting was found to have neglected to use the prescribed form to obtain written consent from the data subject. In a broader context, the Information Regulator has identified 14 other entities as potential offenders, intending to issue enforcement notices to them in due course.
Are your marketing and email campaigns PoPiA Compliant?..
...Best you contact StormWarning! today not only will we will do our very best to answer that question for you and your organisation, but we will diligently endeavor to assist your organisation become Privacy legislation compliant while adhering to the constraints of your budget.