On 2 October 2026, the Acting Commissioner of the National Consumer Commission (“the Commission”) published draft Guidelines for Compliance with the Opt-Out Registry Regulations (“the Guidelines”) in terms of the Consumer Protection Act, No. 68 of 2008 (“the CPA”). Interested parties have been invited to submit written comments within 15 days of the date of publication.
The Guidelines do more than simply restate what the CPA and the Consumer Protection Regulations, 2011 (as amended) (“Regulations”) already require; they provide operational detail, clarify the scope of application of compliance obligations, and in at least one respect appear to take a position that is arguably stricter than the Regulations themselves. The Guidelines therefore deserve careful attention.
Legal foundation for the Guidelines
The regime is rooted in section 11 of the CPA, which establishes the consumer’s right to privacy in the context of direct marketing, including the right to refuse, require discontinuation of, or pre-emptively block any approach or communication that is primarily for the purpose of direct marketing, whether that means promoting or offering goods or services, or soliciting a donation.
To give that right practical effect, section 11 also empowers the Commission to establish and maintain a registry in which any person may register a pre-emptive block, either generally or for specific purposes, against any communication that is primarily for the purpose of direct marketing (“the Opt-Out Registry”), and places a corresponding duty on anyone authorising or conducting direct marketing not to contact a consumer who has registered a relevant block.
The Regulations, having been recently amended in 2026 to further operationalise the Opt-Out Registry, introduce requirements for direct marketer registration and renewal, monthly database cleansing, prescribed fees and rules on identification and compliance. The Guidelines in turn give operational content to those Regulations and, although not formally binding, must be taken into account by the Commission, the National Consumer Tribunal (“Tribunal”) and the courts when interpreting or applying the CPA.
Scope of application
The Guidelines apply to every person or business that engages in direct marketing, irrespective of the industry in which they operate. The list of businesses expressly caught is deliberately broad, including suppliers, retailers, insurers, financial institutions, telemarketing companies, call centres, marketing agencies, estate agencies, vehicle dealerships and digital marketers, as well as any other person promoting goods or services directly to consumers.
Robocalls, automated calls and other forms of automated dialling also fall within the scope of direct marketing where they are used to promote or offer goods or services.
As is clear from the above, the reach of the Guidelines is not limited to the traditional direct marketer operating a call centre; it extends equally to a bank that contacts customers about new lending products, a bond originator promoting mortgage solutions, an estate agent marketing new listings, an online retailer or food delivery platform that pushes promotional notifications or discount offers to its user base, an insurer that contacts policyholders about additional cover, or any other business that communicates with consumers for a promotional purpose, regardless of the channel used.
The fact that a business also operates an inbound or omnichannel model (i.e., where consumers initiate contact to browse, order or enquire) does not bring it outside the regime; the obligations are triggered by outbound promotional communications, not by the business model as a whole.
Importantly, compliance obligations apply even when marketing is conducted by a third party on behalf of a direct marketer, and a direct marketer remains responsible for compliance even when another person conducts marketing on its behalf. Businesses using call centres or marketing agencies should accordingly ensure that their service agreements clearly allocate compliance responsibility, and that their providers are themselves registered and conducting monthly cleansing in accordance with the Regulations.
It should also be noted that compliance with a third-party opt-out registry (such as that administered by the Direct Marketing Association of Southern Africa (“DMASA”), which operates on a voluntary basis within the marketing industry) does not satisfy the obligations imposed on direct marketers by the CPA and the Regulations. There is also no indication in the CPA, the Regulations or the Guidelines that pre-emptive blocks registered on any registry other than the Commission’s Opt-Out Registry will be carried over. Consumers who have registered with DMASA (or any similar body) and who wish to exercise their relevant statutory rights in respect of the Opt-Out Registry must presumably register afresh with the Commission’s Opt-Out Registry; and direct marketers cannot rely on any existing DMASA cleansing processes as a substitute for the monthly cleansing obligation under Regulation 4(7)(i).
The compliance process
Every direct marketer must register with the Opt-Out Registry before conducting any direct marketing. Once registered, a direct marketer must submit its intended marketing database to the Registry; that is, the full list of consumers it intends to contact must be submitted during the month in which it intends to conduct such direct marketing.
The Registry system automatically cross-checks the submitted list against the Opt-Out Registry, and identifies those consumers who have registered a relevant pre-emptive block. The direct marketer is responsible for payment of a cleansing fee of 12 cents per consumer identified as having registered a relevant block. After payment of the cleansing fee, the marketer will receive a cleansed list reflecting all consumers who have registered pre-emptive blocks, which consumers must then be removed from the marketing list before commencing any direct marketing. The cleansed list remains valid for 30 days from the date of issue.
Beyond registration and cleansing, every direct marketing communication must clearly identify the marketer’s name, contact details, email address, physical address where applicable, and any other information necessary to identify the sender.
Types of pre-emptive blocks
Understanding the different categories of pre-emptive blocks is important in practice, because a direct marketer’s obligations vary depending on the scope of the block a consumer has registered, and misreading that scope creates compliance risk.
A general pre-emptive block is a registration by which a consumer indicates that they do not wish to receive any direct marketing, and it must be respected by direct marketers irrespective of sector, category of goods or services, or marketing channel. A consumer may also register a specific pre-emptive block limited to a particular purpose, category, marketing channel, marketer or sector; a direct marketer may not treat such a block as having a broader or narrower application than the scope selected by the consumer. A sector-specific pre-emptive block applies only to direct marketers operating within the sector or category identified by the consumer, and must not be interpreted as a general block unless the consumer has registered one.
Distinguishing ordinary business communications
The Opt-Out Registry is directed at communications that are primarily for the purpose of direct marketing; ordinary business engagements that are not primarily promotional in nature are not prohibited.
Ordinary business communications may include, for example, responding to a consumer’s enquiry, confirming or administering an existing order or transaction, arranging delivery or an appointment, dealing with accounts or payments, providing customer support or after-sales service, handling complaints, returns or warranty matters, and any other communication reasonably necessary to complete or give effect to an existing business engagement.
The Guidelines caution, however, that if an otherwise routine business communication is used as a vehicle to promote, advertise or offer additional goods or services, the promotional component may constitute direct marketing and would need to comply in full with the CPA, the Regulations and applicable privacy legislation. By way of example, a call made to resolve an account or transaction-specific query may be entirely permissible; an unsolicited sales pitch introduced during that same call may constitute direct marketing.
Provisions potentially warranting closer attention
Three aspects of the Guidelines appear to raise questions that the CPA and Regulations do not fully resolve, and which have direct implications for how businesses structure their marketing operations.
The definition of “direct marketing”
The Guidelines define “direct marketing” as direct communication with consumers for the purpose of promoting or offering goods or services through telephone calls, SMSs, emails, messaging applications, online platforms or any other form of electronic communication. This definition is narrower than the definition contained in the CPA, which expressly includes requests for donations of any kind for any reason.
Although Annexure B to the Guidelines (which reflects the Commission’s responses to various frequently asked questions) later acknowledges that the CPA’s definition of direct marketing encompasses donation solicitations, that element is omitted from the operative definition in the Guidelines themselves. A non-profit organisation (“NPO”) is not automatically excluded from the regime merely because it operates on a non-profit basis; the determining factor is whether its communications constitute “direct marketing” under the CPA, and an NPO that solicits donations from individuals or from juristic persons with an annual turnover exceeding ZAR 2 million may be regarded as a direct marketer for that purpose.
Businesses and organisations that solicit donations (whether directly or through affiliated fundraising structures) should note that the Guidelines, in their current form, do not resolve this question with certainty, and the comment period may present an opportunity to seek greater clarity on the point.
Consent and registered pre-emptive blocks
The Guidelines state that historical or existing consent is invalid once a consumer registers a pre-emptive block, and that fresh consent does not override a pre-emptive block unless the consumer has removed the block. The Commission has communicated that a marketer should not assume that previous or fresh consent automatically permits marketing contrary to a registered block.
This position has significant practical implications for marketers who hold consent obtained from consumers who have subsequently registered a pre-emptive block. Under the Guidelines, historical or existing consent is invalid once a consumer registers a pre-emptive block. A marketer who continues to rely on it therefore exposes itself to regulatory risk regardless of when that consent was obtained.
Indeed, Regulation 4(7)(i) of the Regulations (inserted by the 2026 amendments) expressly requires a direct marketer to remove from its database all data of persons who have registered a relevant pre-emptive block by cleansing such data monthly with the Commission. A marketer must accordingly submit its list of consumer databases each month it intends to conduct direct marketing, and the cleansed list that results is valid for thirty days only, meaning the marketer has current visibility of every registered block before each and every marketing cycle. It cannot credibly claim ignorance of a registered block at the point of contact.
The difficulty is that this approach appears to sit in tension with Regulation 4(3)(g), which carves out an exception for existing clients. Under Regulation 4(3)(g), a direct marketer need not assume that a comprehensive pre-emptive block has been registered by a consumer where the direct marketer has proof that the existing client has, after commencement of the Regulations, expressly consented to receiving direct marketing from that direct marketer.
On one reading, Regulation 4(3)(g) creates a substantive exception: post-commencement consent from a qualifying existing client displaces the block, permitting the marketer to continue marketing to that consumer notwithstanding the registration. On another reading (and the one the Guidelines appear to favour), the provision operates more narrowly, relieving the marketer only of the obligation to assume that a comprehensive block exists, rather than permitting it to market to a consumer who has actually registered one.
The monthly cleansing obligation in Regulation 4(7)(i) increases this tension considerably. Because the marketer receives a list of blocked consumers before each marketing cycle, and Regulation 4(7)(h) already independently prohibits a direct marketer from directly marketing any goods or services to any consumer who has registered a relevant pre-emptive block, any reliance on the Regulation 4(3)(g) consent exception, in the face of a confirmed registered block, would amount to a deliberate choice rather than an inadvertent one.
The Guidelines adopt the narrower reading, providing that fresh consent does not override a pre-emptive block unless the consumer has removed such pre-emptive block. However, the Guidelines do not engage directly with Regulation 4(3)(g) or explain how the various provisions are to be reconciled. This may be a potential gap that the comment period offers a genuine opportunity to address.
Importantly, any business that has built its customer marketing strategy around obtaining fresh consent from existing clients (e.g., through loyalty programmes, opt-in campaigns or similar mechanisms) may find that strategy insufficient where those clients have registered a pre-emptive block with the Opt-Out Registry.
The content of the “cleansed list” and the interface with the Protection of Personal Information Act, No. 4 of 2013 (“POPIA”)
The CPA and POPIA regulate different but related aspects of direct marketing and the protection of consumers’ personal information; the Guidelines confirm that compliance with one does not discharge obligations under the other, and the Commission has engaged with the Information Regulator on the relationship between the two frameworks, with the position being that they are capable of operating together. Marketers must satisfy both regimes independently before initiating any direct marketing communication.
One aspect of the regime that sits squarely at the interface of the two frameworks, and which the Guidelines do not presently address with sufficient clarity, is the nature of the information that the Registry returns to a direct marketer following the cleansing process. The Guidelines contemplate that, after payment of the prescribed cleansing fee, a marketer will receive a “cleansed list” reflecting consumers who have registered relevant pre-emptive blocks. However, Regulation 4(3)(f) expressly provides that the administrator of the Registry may only confirm whether or not a pre-emptive block has been registered by a consumer, and may not provide any detail to the direct marketer in respect of any identifier provided by the consumer to the Registry.
It is not presently clear whether, or in what form, the “cleansed list” output is consistent with that restriction. For example, it is unclear whether the Registry returns a marked version of the marketer’s submitted list, a separate list of flagged entries, or simply a binary confirmation per record. This ambiguity has direct implications for, amongst other things, how marketers structure their database systems and adhere to their obligations under POPIA. The comment period presents an opportunity to press for greater operational clarity on this point.
Consequences of non-compliance
The consequences of non-compliance with the opt-out framework are meaningful.
The Guidelines note that non-compliance with section 11 read with the amended Regulations may result in a complaint being lodged with the Commission, an investigation, and the issue of a compliance notice or a referral application to the Tribunal for the imposition of administrative penalties. Given that the monthly cleansing process gives the Commission a contemporaneous record of every marketer’s activity, the evidentiary burden in any enforcement action is likely to be relatively low.
The Guidelines add that, in more serious cases, contraveners may face criminal prosecution, with convicted persons liable to a fine or imprisonment for a period not exceeding 12 months under the CPA.
Importantly, the Guidelines provide that compliance obligations extend not only to the direct marketer itself but also to any agency, call centre, franchise or branch, and the direct marketer remains responsible for the conduct of those third parties regardless. It would therefore appear that both the principal marketer and the third-party face potential exposure, meaning that outsourcing marketing activities reduces neither party’s liability.
Next steps
The publication of the Guidelines for public comment is an early opportunity for all businesses engaged in direct marketing to engage with the Commission’s compliance framework. The comment period enables stakeholders to seek to influence the final form of the regime, particularly where the Guidelines as currently drafted leave meaningful uncertainty.
Key contacts
Nick Altini
Partner, Johannesburg
Natasha Rachwal
Senior Associate, Johannesburg
Ntandokazi Shazi
Associate (Designate), Johannesburg
Disclaimer
The articles published on this website, current at the dates of publication set out above, are for reference purposes only. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action.