Consent Management Platform Setup | POPIA Permission Tracking | WebFootprint
Data Integrations Consent Platform Integration

Consent Management Platform Setup: Permission Tracking You Can Prove

Your marketing team sends. Your CRM holds contacts. Nobody can show which customers consented to which channel. Under POPIA and GDPR, that gap is not a paperwork problem. It is an illegal-send and audit risk.

We wire a central consent platform into your CRM and marketing tools so every permission is recorded, enforced, and exportable.

A CRM glass panel and a Consent CMP badge linked by an emerald ribbon of consent forms, illustrating centralised permission tracking
R10 million
maximum POPIA administrative fine for non-compliance
R44.1 million
average cost of a data breach for SA organisations (IBM 2025)
39%
higher opt-in rates with a consent and preference platform (DMA)
7 months
typical payback on a consent management platform (Forrester TEI)
The Problem

Sound Familiar?

These are the exact issues our clients faced before a central consent platform:

  • Nobody can prove which customers consented to email, SMS, or WhatsApp
  • Consent lives in spreadsheets, form tools, and ESP lists that never sync
  • Marketing still sends to people who opted out months ago
  • A POPIA or GDPR enquiry would take days of hunting for evidence
  • Phone consent was never recorded, so it cannot be produced on request

From 17 April 2025, POPIA regulations state that opt-out is not consent for electronic direct marketing. Consent may be collected by email, SMS, WhatsApp, or recorded phone call, and you must be able to produce that evidence. Spreadsheet silence no longer counts.

How It Works

What Consent Management Integration Actually Does

Consent captured → ledger updated → CRM and ESP enforced. No campaign leaves without a valid permission.

1

Consent Captured

Web form, preference centre, or recorded call captures purpose and channel

2

Ledger Updated

Consent platform stores who, when, how, and for which purpose

3

CRM & ESP Synced

Contact records and marketing lists update in real time

4

Sends Enforced

Only valid permissions leave the building. Audits take minutes

What We Build

Everything You Need for Reliable Permission Tracking

Central Consent Ledger

Every opt-in, opt-out, and purpose change lands in one consent platform, timestamped and tied to the person in your CRM.

CRM Permission Sync

Consent status and channel preferences write back to HubSpot, Salesforce, or Pipedrive so sales never markets against a refusal.

ESP & SMS Enforcement

Mailchimp, Klaviyo, and SMS tools only receive contacts with valid consent for that channel and purpose. Illegal sends stop at the source.

Web Form Capture

Website forms, cookie banners, and preference centres feed the same ledger. Purpose-level ticks, not vague blanket yeses.

Audit-Ready Evidence

When the Information Regulator or a customer asks, you export who consented, when, how, and to what. Minutes, not weeks.

Preference Centre

Customers choose email, SMS, or neither. Granular preferences lift opt-ins and cut blanket unsubscribes.

Platforms We've Wired for Consent Management

OneTrustCookiebotHubSpotSalesforcePipedriveMailchimpKlaviyoCustom forms
Client Story

From Unprovable Lists to Audit-Ready in 5 Weeks

How a Johannesburg retail brand stopped illegal sends, survived a POPIA enquiry, and grew opted-in email revenue.

Before

Scattered Permissions

  • Consent sat in Mailchimp, HubSpot forms, a cookie tool, and a shared spreadsheet
  • Marketing could not prove SMS or WhatsApp opt-in for half the list
  • Opt-outs in one tool never reached the others
  • A customer complaint meant two days of inbox archaeology
  • Legal flagged every campaign as residual POPIA risk
Zero proof of channel-level consent
After

Central Consent Platform

  • OneTrust-style ledger became the system of record for every purpose and channel
  • HubSpot and Mailchimp only receive contacts with valid email consent
  • SMS blocked unless the ledger shows an explicit opt-in
  • POPIA enquiry answered with an export in under a day
  • Preference centre let customers opt down instead of leaving entirely
Illegal sends: 0 enforced at the ESP
22% lift in email revenue after re-permission
35% fewer unsubscribes
<1 day to produce POPIA consent evidence
5 weeks from scoping to live enforcement
The Difference

Before vs After Consent Platform Setup

Before
After
Proof of consent
Scattered or missing
One exportable ledger
Channel enforcement
Manual list cleaning
Automatic at CRM and ESP
Opt-out handling
Treated as soft consent
Hard block per POPIA
Audit response time
Days of reconstruction
Under one day
Opt-in performance
Baseline list growth
Up to 39% higher (DMA)
POPIA fine exposure
Up to R10 million
Defensible evidence trail
Getting Started

How It Works

From first conversation to live permission tracking in 3–5 weeks.

01

Map Your Consent Gaps

Which channels you market on, where consent is captured today, and what you cannot prove.

02

Free Scoping Call

30-minute call to design the consent platform, CRM fields, and ESP enforcement rules.

03

Build & Test

We wire the CMP to your CRM, forms, and marketing tools, then test with real consent events.

04

Go Live & Monitor

Marketing runs only on valid permissions. Alerts catch sync failures before the next campaign.

Questions

Frequently Asked Questions

What is a consent management platform, and do we need one under POPIA?

A consent management platform (CMP) is the system of record for who agreed to what, on which channel, and for which purpose. Under POPIA, consent for electronic direct marketing must be specific, informed, and voluntary. The April 2025 regulations confirm that opt-out is not consent, and telephonic consent must be recorded. A CMP wired into your CRM and marketing tools is how you prove that at scale.

Which tools can you connect for permission tracking?

We have wired OneTrust, Cookiebot, and similar CMPs into HubSpot, Salesforce, Pipedrive, Mailchimp, Klaviyo, SMS gateways, and custom web forms. If your stack has an API or webhook, we can keep permission tracking in sync across it.

Will this stop our marketing team from sending campaigns?

It stops illegal sends, not effective ones. Lists shrink to people who actually consented, which typically lifts engagement. DMA research shows organisations with a consent and preference system report 39% higher opt-in rates and 25% lower unsubscribe rates than those without.

How does this help with a POPIA or GDPR audit?

Every consent event is stored with timestamp, source, purpose, and channel. When a data subject or the Information Regulator asks for proof, you export from one ledger instead of reconstructing history from inboxes and spreadsheets. That is the difference between a clean enquiry and a R10 million exposure.

We already have cookie banners. Is that enough?

Cookie banners cover website tracking. They do not tell Mailchimp whether someone consented to product emails, or prove SMS opt-in for a WhatsApp blast. POPIA and GDPR both expect purpose-level consent across channels. The platform we build connects the banner, the forms, the CRM, and the ESP into one permission trail.

How much does consent platform setup and integration cost?

Simple one-way capture into a CMP starts from around R15,000. Bidirectional wiring across CRM, email, SMS, and preference centres typically runs R25,000 to R60,000. Forrester's TEI study on OneTrust found composite organisations reached payback in about 7 months, with 227% ROI over three years. Most of our clients recover the build cost inside one or two avoided compliance scares.

Ready to prove consent?

Stop Gambling on Unprovable Marketing Lists

If you cannot show which customers consented to which channel, every campaign carries POPIA and GDPR risk you do not need to carry.

Tell us which CRM and marketing tools you use, how consent is captured today, and where the gaps hurt most. We will show you exactly how a central consent management platform would enforce permission tracking for your organisation.

Chat with us