SMS Marketing Compliance in South Africa: POPIA Explained
The Protection of Personal Information Act (POPIA) is South Africa's data protection law, and a phone number is personal information under it just as much as an ID number or an email address. Any business sending marketing SMS to South African numbers is processing personal information, and POPIA sets out real obligations around how that's allowed to happen. This isn't a full legal guide - talk to a lawyer for advice specific to your business - but here's the practical shape of it for SMS marketing specifically.
Consent comes first
POPIA requires a lawful basis for processing personal information, and for direct marketing by SMS, that basis is generally consent, or an existing customer relationship for similar products (section 69's soft opt-in). In practice: don't buy a list of numbers from a third party and start texting it. Build your list from people who gave you their number - a signup form, a purchase, a booking - and, ideally, keep a record of when and how consent was given.
Every marketing message needs an opt-out
POPIA requires that direct marketing communications give the recipient a way to opt out, and that a request to stop is honoured. In an SMS this is usually a simple instruction - "Reply STOP to opt out" - but the mechanism has to actually work: if someone replies STOP, they need to stop receiving messages, not just be logged as a complaint to deal with later. Ignoring opt-out requests is one of the more common ways businesses get into trouble, and it's also one of the easiest things to fix with the right platform.
Data minimisation and security
POPIA expects you to hold only the personal information you actually need, and to keep it secure. For a contact list, that usually means: don't collect fields you have no use for, restrict who on your team can export the full list, and use a platform that encrypts data at rest rather than an unprotected spreadsheet emailed around the office. If you're importing contacts from an external database, check that the connection itself is secure and that access is limited to people who need it.
Why messages sometimes get blocked before they send
SimpliSend runs every outgoing message through an automated content check aimed at hate speech, abuse, and similarly harmful content before it's sent - a POPIA-aligned safeguard against the platform being used to send genuinely harmful messages at scale, not a filter on ordinary marketing copy. A flagged message is queued for review rather than sent silently, and a high-severity flag blocks the send outright. Legitimate campaigns essentially never trip this; it exists for the edge case where they might.
A short practical checklist
- Only message numbers that consented or are existing customers for a similar offer
- Include a working opt-out instruction in marketing messages
- Act on opt-out requests immediately, not at the end of the campaign
- Keep contact data limited to what you actually use, and access-controlled
- Don't buy or scrape phone number lists from third parties
None of this is about slowing a campaign down - it's about not building a marketing channel on a foundation that a single complaint or audit can knock over. Getting consent and opt-out right at the start is far less work than untangling it after the fact.
More on Fundamentals
Transactional SMS vs Marketing SMS: Know the Difference
Not every SMS your business sends is "marketing." The distinction between transactional and marketing messages affects consent rules and how a list should be built.
SMS Open Rates vs Email: The Real Numbers
You've probably seen the claim that SMS gets a 98% open rate. Here's what that figure actually means, and how to think about it for your own campaigns.
Two-Way SMS: Why Reply Handling Matters for Customer Engagement
A text a customer can reply to is a different tool than a text they can only read. Here's what changes when SMS becomes two-way.
Ready to send your own campaign?
Create a free SimpliSend account and send your first message today.
Register for free