POPI Act and Direct Marketing - Opting in and Opting out

POPI Act and Direct Marketing - Opting in and Opting out

POPI Act and Direct Marketing - Opting in and Opting out

The Protection of Personal Information Act 4 of 2013 (POPIA) defines direct marketing as approaching a data subject (which could be either an organisation or an individual) in person, per electronic communication or by mail, for the purpose of promoting or advertising goods or services to the data subject or asking them to donate.

Electronic communication covers a wide variety of methods, including text, voice, sound and images, any of which are transmitted over an electronic network. In other words, this covers all the popular methods used today and probably even some with which we are not yet familiar.

When it comes to direct marketing, consumers are protected under POPIA and the Consumer Protection Act 68 of 2008 (CPA). Thus, for companies to comply with both these acts and to act lawfully when it comes to direct marketing, could sometimes be a daunting task.

For ease of understanding and interpretation, we created a series of articles about Direct Marketing to assist you in understanding these compliance elements better. We have already discussed Navigating Direct Marketing in the business environment and also the POPI Act and electronic direct marketing.

In this article, we will look in depth at ‘Opting in’ and ‘Opting out’ in terms of POPIA.

What is the difference between 'opting in' and 'opting out'?

‘Opting in’ means that the individual receiving direct marketing wishes to continue to be a recipient of the company’s direct marketing. ‘Opting out’, on the other hand, means that the individual receiving direct marketing does not wish to receive any direct marketing from that company; hence, marketing to that individual should be suspended with immediate effect.

Initial direct marketing and opting in

Where the client is not an existing customer, section 69 of POPIA provides that a data subject must consent before electronic direct marketing can take place. The supplier cannot market to that consumer unless the consumer’s consent was obtained. Now, how do you get consent if you are not allowed to contact the client? The marketer may contact the consumer ONCE to get their consent (OPTING IN) and be given a reasonable opportunity to object (OPTING OUT), free of charge and in a manner free of unnecessary formality. If the consumer has already opted out, either with the supplier directly or with the registry, the direct marketer may not even contact that consumer once to obtain consent to be marketed to. If the client does not respond to the initial contact made, the direct marketer will have to assume that the consumer has opted out until it is confirmed that this is not the case, instead of assuming that they have opted in.

Where the consumer is an existing customer who has not expressly consented already or a customer who gave their personal information to the supplier in the context of a sale for the purpose of direct marketing, POPIA and CPA will apply as both provide that the direct marketer may market to a consumer unless that consumer has opted out (free of charge). If you do direct marketing through cold calling, learn more about it here: POPI Act and Electronic Direct Marketing – YES cold calls are allowed!

What is ‘Opting out’?

Section 11(3)(b) of POPIA makes it clear that a data subject may object to any form of direct marketing, not necessarily just by electronic means. Section 11(4) states that once the data subject (which may be an organisation or juristic entity) has objected, the Responsible Party may no longer process their personal information for direct marketing , whilst by implication, processing may continue for other specific purposes, following section 13 which requires that “personal information must be collected for a specific, explicitly defined and lawful purpose”; this refers to the purpose for which it was collected in the first place. A client or potential customer can only opt out of direct marketing and not out of transactional communication, which refers to the continuous exchange of information where both the sender and receiver are involved in the process and take turns to communicate messages.

There are two main ways in which opt-out options are offered to the consumer:

  • Pre-emptive opt-out – a consumer can untick/uncheck a pre-selected checkbox or otherwise undo a confirmation indicating their refusal to data processing.
  • Consent withdrawal – where users are provided with a clear option to withdraw their permission or change their preferences concerning the treatment of their personal data.

Hence the Marketer should allow for a clear opting-out option within their marketing material or first initial contact communication sent to the client.

In conclusion

We are in the early days of understanding the full implications of the impact of POPIA on direct marketing activities by whatever means. Organisations that take action now to review their policies and adapt their procedures will give themselves a competitive advantage by being better prepared to anticipate how to address the rights of their future and current customers, and demonstrate both legal compliance and good governance, all of which will enhance their reputation in the marketplace. Compliance will further prevent hefty fines for transgressing POPIA and CPA legislation.

SERR Synergy assists businesses in ensuring that Personal Information is processed according to legislation, while simultaneously serving the needs your business may have in respect of such data. We provide a full range of Information Compliance service offerings by compiling Assessment and Due Diligence Reports, drafting the required Privacy Policies, updating your agreements to deal with data considerations, advising on internal data-handling requirements or understanding exactly what data privacy role you fulfil.

About the Author: Gisela van der Merwe completed her B.Ed degree at the University of Pretoria. She joined the SERR team as an Information Compliance Advisor and specialises in POPIA, PAIA and CPA compliance.

Sources:

  • Consumer Protection Act 68 of 2008
  • Electronic Communications and Transactions Act 25 of 2002
  • Protection of Personal Information Act 4 of 2013

Newsletter Inner

Get Instant Access to This Download

Enter your details below, and we'll email the pdf straight to your inbox.

Upload requirements

You May Also Like

 
A checklist when preparing for POPI and Data Laws
The Protection of Personal Information Act (POPI) may not yet be effective, but businesses need to make compliance a top priority for 2017.  Irrespective of whether POPI has been fully implemented, businesses are required to exercise a duty of care in respect of the person
 
Promotion of Access to Information Act - handling requests and reporting for public and private bodies
Discussing the Process for Handling PAIA Requests and PAIA Reporting Requirements to the Information Regulator for Public and Private Bodies.
 
Service Messaging – not to be confused with Direct Marketing
As highlighted by the previous articles in our Direct Marketing series, the Protection of Personal Information Act 4 of 2013 (POPIA) imposes stringent requirements on businesses in order to lawfully conduct direct marketing to data subjects.