POPIA Consent Tracking System: Prove Who Authorised What
Your Information Officer cannot prove when customers consented, how they consented, or for what purpose. Spreadsheet consent logs and buried email threads fail POPIA evidence standards the moment the Information Regulator asks for records.
We build the consent tracking system that closes that gap with CRM write-back.
Sound Familiar?
These are the exact issues our clients faced before consent tracking:
- Consent lives in spreadsheets, buried email threads, and CRM notes that never match
- You cannot show when, how, and for what purpose a customer authorised processing
- A DSAR or Regulator query takes days of reconstructing who authorised what
- Telephonic and Form 4 consent is not recorded, so section 11 proof fails under inspection
- CRM contacts have marketing flags with no linked consent record, purpose, or timestamp
Amended POPIA Regulations took effect on 17 April 2025. Telephonic and automated-calling-machine consent must be electronically recorded and made available on request. Opt-out no longer counts as consent for direct marketing. The Information Regulator has already fined unlawful marketing (FT Rams, R100,000) and ignored enforcement notices (up to R5 million). Spreadsheet logs will not survive the next inspection.
What Consent Tracking Actually Does
Capture → purpose-bound record → CRM write-back → inspection-ready pack. No human reconstructing evidence from inboxes.
Consent Captured
Web form, email, SMS, WhatsApp, or recorded call lands as a discrete event
Evidence Pack Built
Purpose, channel, timestamp, source wording, and authorising party stored immutably
CRM Contact Updated
Status, purpose codes, and evidence ID write back to the contact record
Audit Export Ready
Information Officer answers Regulator or DSAR queries with records, not screenshots
Everything You Need for Audit-Ready Consent Tracking
Purpose-Bound Consent Records
Every grant stores purpose, channel, timestamp, source wording, and who captured it. POPIA consent tracking becomes evidence, not a tick box.
CRM Contact Write-Back
Consent status, purpose codes, and evidence IDs write back to HubSpot, Salesforce, Pipedrive, or Zoho contact records so sales never guesses permission.
Inspection Evidence Packs
One export answers the Information Regulator: who authorised what, when, how, and for which processing purpose, with channel and source attached.
Channel Capture Logging
Web forms, email, SMS, WhatsApp, and recorded telephonic consent (including Form 4-style captures) land as immutable events with audio or transcript links where required.
Authorisation Trail
Track which staff member, system, or operator recorded consent, plus versioned notice text at the moment of capture, so data permission disputes have a clear chain.
DSAR-Ready Lookups
Search a contact and pull every consent event in seconds. Your Information Officer stops rebuilding evidence from inboxes when a complaint arrives.
Systems We've Connected for Consent Tracking
From 14 Hours to 12 Minutes per Evidence Pack
How a 45-person professional services firm stopped reconstructing consent from spreadsheets and answered Information Regulator queries the same day.
The Spreadsheet Process
- Information Officer hunted email threads, shared drives, and CRM notes for each complaint
- Average 14 hours to assemble purpose, channel, and timestamp for one data subject
- CRM marketing flags had no linked consent record or source wording
- Telephonic consent existed only as staff memory, never as a producible recording
- Two Regulator queries in one quarter delayed other compliance work for three weeks
The Tracking System
- Every consent event stores purpose, channel, timestamp, and authorising party
- Evidence pack exports in about 12 minutes from a contact search
- HubSpot contacts show purpose codes and evidence IDs without leaving the CRM
- Call recordings and Form 4-style captures link into the same record
- Information Officer answers Regulator and DSAR queries the same day
Before vs After Consent Tracking
How It Works
From first conversation to live consent tracking in 2–4 weeks.
Map Your Evidence Gaps
Where consent sits today, which purposes you process for, and what you cannot prove under inspection.
Free Scoping Call
30-minute call with your CEO, ops lead, or Information Officer to design the tracking model and CRM write-back.
Build & Parallel Test
We wire capture channels, backfill proven records, quarantine unproven flags, and test evidence pack exports end to end.
Go Live & Monitor
Spreadsheet hunting stops. Alerts catch failed writes. Your Information Officer gets packs they can defend.
Frequently Asked Questions
What is a POPIA consent tracking system?
It is an audit-ready record of every consent event: purpose, channel, timestamp, source wording, and who authorised processing. Records link to CRM contacts so you can prove data permission under section 11, not reconstruct it from spreadsheets when the Information Regulator asks.
How is this different from marketing consent management?
Marketing consent management focuses on living ledgers, STOP/opt-out honouring, and campaign send guards. Consent tracking focuses on evidence packs: who authorised what, for which purpose, when, and how, with CRM write-back for Information Officer inspections and DSAR responses. Many businesses need both.
What does POPIA require for consent evidence?
Section 11 places the onus on the responsible party to prove consent was obtained. Consent must be voluntary, specific, and informed, linked to a discrete processing purpose. Amended regulations effective 17 April 2025 require telephonic and automated-calling-machine consent requests to be electronically recorded and made available to the data subject on request, free of charge. Opt-out is not consent for direct marketing.
What are the penalties if we cannot prove consent?
Administrative fines under POPIA can reach R10 million. The Information Regulator has already issued fines from R100,000 (FT Rams Consulting, unlawful direct marketing) up to R5 million where enforcement notices were ignored. Separately, section 99 allows civil claims by data subjects. Weak consent tracking raises both regulatory and civil exposure.
Which systems can you connect?
We have built consent tracking with HubSpot, Salesforce, Pipedrive, Zoho CRM, Monday.com, custom CRMs, web forms, and call-recording stores. If your capture channel or CRM has an API or webhook, we can include it.
How much does a POPIA consent tracking build cost?
A focused CRM write-back of purpose and timestamp fields starts from around R15,000. A full consent tracking system with multi-channel capture, evidence pack exports, and authorisation trails typically ranges from R25,000 to R60,000. Against R10 million fine exposure and roughly R22,900 average cost per manual DSAR (Gartner, converted at current Rand rates), most Information Officers see payback inside the first avoided reconstruction cycle.
Stop Rebuilding Consent Evidence from Spreadsheets
If your team cannot show when, how, and for what purpose processing was authorised, you are carrying POPIA risk a tracking system already solves.
Tell us where consent lives today, which CRM you use, and what the Information Officer struggles to prove. We will show you exactly how purpose-bound consent tracking and CRM write-back would work for your business.