The recent amendments to the regulations under the Consumer Protection Act (CPA) introduce a formal, operational framework governing direct marketing activities in South Africa. These amendments are specifically aimed at persons or entities engaged in direct marketing and do not apply indiscriminately across all industries or regulated sectors.
The Information Regulator has welcomed the amendments which provide added protection to consumers against unsolicited direct marketing but has also noted that compliance with the Protection of Personal Information Act (POPIA) is still mandatory.
At the centre of the amendments to the CPA regulations is the establishment of a National Consumer Commission (NCC)-administered Opt-Out Registry. This system enables consumers to proactively block unwanted direct marketing communications, either from individual marketers or across the industry as a whole. The introduction of this mechanism gives practical effect to existing consumer rights under section 11 of the CPA, read together with the amended Regulations, by creating a structured and enforceable process for restricting unsolicited marketing.
The amendments impose a number of clear obligations on direct marketers. These include the requirement to register with the Opt-Out Registry before engaging in direct marketing, to renew such registration annually, and to comply with prescribed administrative requirements, including the payment of applicable registration, renewal and database cleansing fees. Direct marketers are also required to ensure that their marketing databases are regularly aligned with the registry by removing the details of consumers who have exercised their right to opt out. This cleansing process must be undertaken on a recurring basis to ensure ongoing compliance.
In addition to database management requirements, the Regulations introduce enhanced transparency obligations. Direct marketers must ensure that recipients of electronic communications can clearly identify the origin of the marketing communication, including the name and contact details of the sender. The use of anonymous or untraceable communication channels is prohibited. Furthermore, direct marketers are expressly prohibited from contacting any consumer who has registered a pre-emptive block on the Opt-Out Registry.
Non-compliance with these requirements constitutes a contravention of the CPA and may result in significant administrative penalties, including a fine of up to R1 million or 10% of annual turnover, whichever is greater.
A critical consideration in applying these amendments is the scope of the CPA in relation to other regulatory frameworks. Financial services, particularly advice and intermediary services, are primarily governed by sector-specific legislation such as the Financial Advisory and Intermediary Services Act (FAIS), as well as broader financial sector laws. These activities are generally excluded from the CPA to the extent that they are regulated under those frameworks.
However, the position becomes more nuanced when considering direct marketing activities. Where an organisation engages in marketing conduct, particularly at a stage prior to the provision of regulated financial services, the activity itself may fall within the ambit of the CPA, regardless of the nature of the entity performing it. This necessitates an activity-based assessment, rather than a blanket assumption based on sector or licensing status.
The CPA amendments must therefore be understood as operating alongside other regulatory instruments. POPIA governs the lawful processing of personal information used in direct marketing, requiring that such processing is based on valid consent or another recognised lawful basis. The CPA, in turn, regulates the circumstances under which marketing may be conducted from a consumer protection perspective, including whether a consumer has exercised the right to block such communication. FAIS continues to apply to the rendering of financial services through direct marketing, ensuring that advice and intermediary services are provided in a manner that is fair, appropriate and consistent with conduct standards.
These frameworks do not replace one another, but instead apply concurrently, each addressing a distinct aspect of the interaction between businesses and consumers. As regulatory focus continues to shift toward outcomes-based and conduct-driven supervision, the alignment between these frameworks becomes increasingly important.
From a practical perspective, organisations engaged in direct marketing should ensure that their systems and processes can support compliance across all applicable requirements. This includes maintaining accurate and up-to-date marketing databases, implementing effective consent management mechanisms, and ensuring that governance structures support ongoing monitoring and regulatory responsiveness.
The amendments to the CPA Regulations therefore do not represent a wholesale extension of consumer protection laws into all sectors but rather reinforce the importance of responsible and transparent direct marketing practices within a clearly defined regulatory framework.
