The end to SPAM calls in South Africa is in site!

The end to SPAM calls in South Africa is in site!

South Africa is moving decisively to protect citizens from the relentless deluge of unwanted direct marketing calls and communications. The national opt-out registry is officially advancing, and the Department of Trade, Industry, and Competition (DTIC) confirms the project is in an advanced stage, ushering in a new era of digital privacy and compliance for all organizations.


The National Opt-Out Registry: A New Era of Consumer Control

The initiative, first championed by Trade and Industry Minister Parks Tau in December 2024 via proposed amendments to the Consumer Protection Act (CPA), is designed to give South Africans a powerful, simple tool to stop unsolicited marketing.

The acting commissioner at the National Consumer Commission (NCC), Hardin Ratshisusu, highlights the regulatory advantage: the registry will provide the NCC with full oversight of every direct marketer operating in South Africa.

StormWarning! has learned that the DTIC confirms the project is progressing smoothly. The system, accessible to consumers, is already operational in part:

  • Complaints Handling: This module was successfully rolled out in 2023.

  • Opt-Out Registry (OOR): This crucial module will become legally effective the moment the Minister officially promulgates the Amended Regulations.

In the interim, the system is fully accessible for profile creation. Consumers and Direct Marketers are encouraged to visit the NCC's website and use the "eService and OORs link" to set up their accounts.

The consumer registration process is designed for clarity and control:

  1. Select the "new consumer" option.

  2. Review and accept the NCC’s Terms and Conditions—the digital handshake for your privacy rights.

  3. Submit your South African ID or passport number, along with personal details, including your name, surname, gender, citizenship, and cell number.

  4. Note: The system requests additional details like maiden name, work address, and work telephone number, but these are optional.

The NCC states the goal clearly: to "make sure your address, email address, telephone and cell number are no longer available to organisations that want to make offers and send information that you do not want."

StormWarning! Compliance Alert: While the system is advanced, like any major digital platform, initial teething issues can occur. When tested, for example, some users encountered errors related to inputting a surname, despite the field not being visible. This underscores the need for robust compliance monitoring as the platform matures.


POPIA Amendments: The Consent Imperative

In a parallel and equally critical development, the South African Information Regulator published amendments to the Protection of Personal Information Act (POPIA) regulations in April 2025, introducing stringent new rules specifically targeting telemarketers. These regulations took effect immediately on 17 April 2025.

The most significant change is the shift to an "Opt-In" mentality for direct marketers:

  • Explicit Consent Required: Telemarketers (including those using automated calling machines) must now obtain telephonic consent when first contacting a data subject.

  • Proof is Mandatory: As detailed by our legal experts, these consent recordings must be maintained and made available to data subjects upon request. This aligns with the Regulator's Guidance Note on Direct Marketing.

  • New Customers & Consent: Organisations targeting individuals who are not existing customers must secure their consent before sending any direct marketing communications. This consent must be "convenient, free of charge, and reasonably accessible," allowing for channels like email, telephone, SMS, WhatsApp, or automated calling.

Opt-Out is Not Consent

Perhaps the most impactful regulatory clarification is the Information Regulator's explicit statement that “opt-out shall not constitute consent.”

Merely providing a mechanism to opt out is no longer sufficient to justify the communication in the first place.
Direct marketing players must obtain 
explicit, positive consent from data subjects—a definite "yes."

"Consent in this context requires a positive action.”

This mandates a fundamental shift in how organisations approach their marketing databases and communication strategies. Compliance is no longer about simply respecting a consumer's wish to stop; it's about proactively confirming their wish to start.

This convergence of the DTIC's National Opt-Out Registry and the Information Regulator's stricter POPIA consent requirements creates a powerful, two-pronged approach to safeguarding personal information and digital privacy in South Africa. Organisations must adapt quickly or face the full force of this enhanced regulatory environment.

 

Stay Ahead of the Curve

This notice was brought to you by StormWarning!

Is your organisation PoPiA compliant? Find out more about how StormWarning! can assist your organisation with automatic compliance!

TAKE ACTION NOW!

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.