POPIA Consent Management System: Lawful Marketing You Can Prove
If your team emails or SMSes people without a living record of consent, you are one complaint away from an Information Regulator enforcement notice and lasting brand damage. Data protection SA rules under section 69 demand opt-in for electronic direct marketing, and April 2025 regulations made clear that an opt-out link is not consent.
We build the central marketing consent management ledger that stops unlawful sends and proves you are audit-ready.

Sound Familiar?
These are the exact issues our clients faced before a living consent system:
- Marketing consent lives in the ESP, SMS gateway, and a spreadsheet, and none of them agree
- Someone replies STOP on SMS but still gets the Friday email blast
- You cannot prove purpose, channel, and timestamp when the Information Regulator asks
- Sales imports bought or event lists into the CRM without a lawful section 69 basis
- Suppressions are cleaned monthly, so unlawful sends happen every week in between
The Information Regulator’s leniency on unsolicited electronic marketing is over. February 2024 brought the first section 69 enforcement notice. December 2024 Guidance Note and April 2025 regulation amendments (including “opt-out shall not constitute consent”) raised the bar for every SA marketing team still relying on silence or an unsubscribe link as proof.
What POPIA Consent Management Actually Does
Permission captured → ledger updated → channels suppressed or cleared → every send is defensible.
Consent Captured
Form, checkout, or Form 4-style ask records purpose, channel, and timestamp
Ledger Updated
CRM marketing flags, ESP audiences, and SMS allow-lists update from one source of truth
STOP Honoured Everywhere
SMS STOP, email unsubscribe, or CRM objection suppresses all marketing channels
Audit-Ready Sends
Campaigns only go to proven consent; evidence packs are exportable on demand
Everything You Need for Marketing Consent Management
Central Consent Ledger
Every permission records purpose, channel, timestamp, source wording, and status. One ledger is the system of record for email, SMS, and CRM marketing flags.
CRM + ESP + SMS Sync
HubSpot, Salesforce, Pipedrive, Mailchimp, Klaviyo, ActiveCampaign, and SA SMS gateways stay aligned. A change in one place updates the others before the next send.
STOP and Opt-Out Honouring
Reply STOP, unsubscribe links, and CRM objections suppress that person across every channel within minutes, not at the next monthly cleanup.
Section 69 Send Guards
Campaigns only leave when consent or a valid soft opt-in is proven for that channel. One-ask consent requests and Form 4-style captures are logged, not guessed.
Audit-Ready Evidence Packs
Export who consented, when, for what purpose, and how they withdrew. Your Information Officer answers Regulator queries with records, not screenshots.
List Value Recovery
Clean suppressions and proven opt-ins recover deliverability and stop burning domains. Mature programmes typically keep 10–25% of contacts suppressed for a reason.
Platforms We've Wired into Consent Ledgers
From 4-Day STOP Lag to Under 5 Minutes
How a mid-size Johannesburg retailer stopped cross-channel unlawful sends and recovered a clean, auditable marketing list.
Scattered Permissions
- ESP held email unsubscribes; SMS STOP sat in a gateway CSV; CRM flags were months out of date
- Average 4 business days before an SMS opt-out reached the email list
- No purpose or timestamp stored, so Information Officer could not prove section 69 consent
- Bought event lists mixed with customers, creating soft-opt-in confusion
- Spam complaints drifting toward the 0.1% danger zone on promotional campaigns
Living Consent Ledger
- One ledger records purpose, channel, timestamp, and status for every contact
- STOP, unsubscribe, and CRM objection suppress email and SMS within minutes
- Campaign send guards block anyone without proven POPIA consent for that channel
- Unproven historical records quarantined; only recovered opt-ins re-enter marketing
- Information Officer exports evidence packs in minutes for audit queries
Before vs After Consent Management
How It Works
From first conversation to live consent ledger in 2–4 weeks.
Map Your Consent Mess
Where permissions live today, which channels send marketing, and where STOP requests currently die.
Free Scoping Call
30-minute call with your marketing or ops lead to design the ledger, sync points, and send guards.
Build & Parallel Test
We wire CRM, ESP, and SMS, backfill proven consent, quarantine unproven records, and test STOP paths end to end.
Go Live & Monitor
Unlawful sends stop. Alerts catch sync failures. Your Information Officer gets an evidence pack they can defend.
Frequently Asked Questions
What is a POPIA consent management system?
It is a living ledger of marketing permissions: purpose, channel, timestamp, source, and current status, synced to your CRM, email platform, and SMS tools. It is not a one-off migration cleanup. It decides, in real time, who you may lawfully email or SMS under section 69.
How does this differ from a POPIA data migration?
Migration work moves and cleans records at cutover. Consent management runs every day after: recording new opt-ins, honouring STOP across channels, blocking unlawful campaigns, and proving audit readiness when the Information Regulator asks. You need both at different moments.
What are the penalties for unlawful direct marketing under POPIA?
Failing to comply with an Information Regulator enforcement notice is an offence that can attract a fine of up to R10 million, imprisonment for up to ten years, or both. In February 2024 the Regulator issued its first direct-marketing enforcement notice (FT Rams Consulting). December 2024 Guidance Note and April 2025 regulation amendments tightened consent and closed the “opt-out equals consent” loophole.
How fast should STOP and unsubscribe requests be honoured?
Mailbox providers expect spam complaint rates below 0.1% (hard ceiling 0.3%). Daily batch suppressions are no longer enough when a STOP arrives on SMS and tomorrow’s email still goes out. We sync opt-outs across CRM, ESP, and SMS within minutes so one channel’s refusal stops every channel.
Which platforms can you connect?
We have built consent ledgers across HubSpot, Salesforce, Pipedrive, Zoho CRM, Mailchimp, Klaviyo, ActiveCampaign, and South African SMS gateways. If your tool has an API or webhook, we can include it in the sync.
How much does a POPIA consent management build cost?
A focused one-way suppression sync starts from around R15,000. A full bidirectional consent ledger with CRM, ESP, and SMS send guards typically ranges from R25,000 to R60,000. Against R10 million fine exposure and the brand cost of a public enforcement notice, most marketing teams see payback inside the first avoided complaint cycle.
Stop Gambling With Unlawful Marketing Sends
If your POPIA consent, data protection SA posture, and marketing consent management still live in three tools that do not talk to each other, you are carrying fine risk and brand damage you do not need to carry.
Tell us which CRM, email platform, and SMS gateway you use, and where STOP requests currently land. We will show you how a central ledger would work for your stack, and what it costs in Rand against R10 million exposure.