Legal updates and opinions
News / News
Blocking growth? Why the NCC’s Draft Opt-Out Registry Guidelines need revisiting | You were only given 15 days to comment – what are you doing?
by Ahmore Burger-Smidt, Director and Head of Regulatory, and Boitumelo Khwene, Candidate Attorney
No one defends the spam caller. According to the National Consumer Commission (“NCC”), South Africans received 17.47 billion spam calls between January and June 2026, a 25.2% increase in the same period during 2025. It therefore comes as no surprise that consumers are frustrated by spam calls from unwanted callers. Nonetheless, it is equally important that a regulatory response must be measured against the harm it targets and the harm it causes. Judged that way, the NCC’s draft Guidelines for Compliance with the Opt-Out Registry Regulations (“the draft Guidelines”) are materially flawed.
Gazetted on 2 October 2026, the draft Guidelines provided interested parties with 15 days to provide their comments for the NCC’s consideration. One could argue that this is insufficient time for interested parties to consider the implication of the guidelines on their businesses and to provide meaningful input. From a simple reading, one finds that these guidelines punish compliant marketers, overlap awkwardly with existing privacy laws, and create new privacy risks of their own with many unanswered questions lingering in the air.
Commercial paralysis
The draft Guidelines require every direct marketer to register before doing any direct marketing, and to renew that registration every year. The net is cast very wide. It covers retailers, insurers, financial institutions, estate agencies, vehicle dealerships and digital marketers, in every industry.
The most disruptive rule concerns consent. The draft Guidelines state that historical or existing consent becomes invalid once a consumer registers a pre-emptive block, and that fresh consent does not override that block unless the consumer first removes it. Practically speaking, this implies that a customer who actively asks a bank or insurer about a new product may not be contacted until that customer has gone back to a state registry and changed their registration. That does not protect consumer choice, but rather overrides it. This could cause a strain on existing customer relationships and how businesses engage with their customers, ultimately creating a barrier to commercial activity between businesses and their customers. Businesses whose growth depends on relationships with existing customers lose their most legitimate marketing channel. Thus, what seems to be a plausible move from the NCC may inadvertently have negative consequences on business, in particular, small and medium sized businesses who rely heavily on direct marketing to gain more customers and generate sales.
A disproportionate burden
The compliance cycle is relentless. Each month, a direct marketer must submit a list of consumers which it intends to contact, pay 12 cents for every name that matches a block, and remove those names. The cleansed list is valid for only 30 days only. For the time being, The NCC has offered free cleansing only from January 2027 to April 2027.
However, for a small business running regular campaigns, this means a recurring cost, an administrative routine to maintain, and the risk of acting on an expired list. The draft Guidelines also “encourages” direct marketers to appoint compliance officers, run training and conduct audits, resulting in businesses accruing more operational expenses. The penalties include administrative fine (either R1 million or 10% of a direct marketer’s annual gross turnover preceding financial year, whichever is great) and, in serious cases, criminal prosecution with imprisonment of up to 12 months.
More uncertainty looms considering that the draft Guidelines set out that they are not binding on the Commission, the National Consumer Tribunal or the Courts, but that anyone applying the Act must take them into account. Businesses are therefore expected to follow rules that the Regulator itself need not necessarily follow nor give much consideration to, creating further legal precariousness and a compliance conundrum. But one has to assume that the Commission would follow the protocol detailed in these Draft Guidelines!
The privacy paradox
The most troubling feature of the draft Guidelines is its approach to data privacy. To protect privacy, it requires direct marketers to upload their customer databases onto a state-run platform every month. POPIA defines an “information matching programme” as the comparison of documents that contain personal information about ten or more data subjects. A national registry that matches millions of records every month fits that description exactly.
Concentrating that much data in one place creates an obvious target for cyberattacks and opens the door for data breaches. It would seem that the NCC has not given much consideration to this issue in light of the fact that the draft Guidelines makes no mention of security safeguards, retention periods, limits on secondary use or what happens after a breach. The Constitutional Court in AmaBhungane Centre for Investigative Journalism NPC and Another v Minister of Justice and Correctional Services and Others struck down legislation in part because it failed to prescribe procedures for how data was to be examined, shared, stored and destroyed. State-held consumer data deserves the same attention. In preparing these draft Guidelines, the NCC somehow overlooked this crucial bit.
Legal and constitutional tensions
The NCC and Information Regulator (“IR“) will seemingly be addressing this issue on a bilateral basis. What does this mean? In essence, the Consumer Protection Act will not operate on its own in curbing unwanted spam calls. Section 69 of POPIA already prohibits electronic direct marketing unless the person has consented or is an existing customer. The IR has said that POPIA compliance remains mandatory whether or not a consumer is on the registry. Direct marketers therefore face two regimes with different consent rules.
POPIA defines consent as a “voluntary, specific and informed expression of will”. The draft Guidelines’ position is that fresh consent cannot override a block contradicts that definition. Section 3(2) of POPIA provides that POPIA applies to the exclusion of other legislation regulating personal information that is materially inconsistent with it. That potentially gives businesses a real argument that the draft Guidelines goes beyond what the law permits.
Importantly, the draft Guidelines present a broader constitutional concern. Section 22 of the Constitution allows the practice of a trade to be regulated, but that regulation must be rational. Courts have set a high bar for striking down economic regulation and will not do so simply because better options exist. Even so, a rule that ignores a consumer’s express, current consent is hard to connect rationally to the stated aim of protecting consumers from unwanted direct marketing.
Lessons from abroad
National do-not-call registries elsewhere, such as those in the United States and the United Kingdom, have shown a consistent pattern. Legitimate businesses comply, while offshore and fraudulent callers ignore the registry altogether. These schemes have generally worked best when they recognise existing-customer relationships and consumer consent, and when enforcement agencies target bad actors rather than imposing a uniform administrative burden on everyone. Our regulators should therefore take note: the scammers generating billions of calls will not register, cleanse lists or pay 12 cents a name nor will the registry inhibit them from calling customers.
A call to action
Time for comment is now. Considering the impact of the Draft Guidelines on marketing activities, requires evaluating the impact thereof on various business units within an organisation. This should be critically evaluated for practicality, failing which business might just be sterilised in terms of marketing activities.
At a minimum, consideration should be given to:
- Recognition of express, current consent and genuine customer relationships, in line with POPIA;
- replace monthly database uploads with a privacy-preserving model in which marketers download suppression lists, supported by published security standards;
- proportionate rules and fees for SMEs; and
- allowing a robust consultation period well beyond 15 days.
Protecting consumers and allowing legitimate commerce are not opposing goals. It would seem as if the current draft Guidelines treats them as such, and both businesses and consumers will pay the price.
What is the saying again about the baby and the bathwater….
Click here to view the draft regulations.
Latest News
Misuse of the business rescue process – failure before it begins
by Dr. Eric Levenstein, Director and Head of Insolvency & Business Rescue and Amy Mackechnie, Senior Associate Business rescue was introduced [...]
Constitutional Court clarifies rights of innocent contractors under invalid state contracts
by Sarah Moerane, Director and Kuhle Joja, Associate In Minister of Defence and Military Veterans v Zeal Health Innovations (Pty) [...]
Untangling the mischief of section 43 of the Electronic Communications Act: A missed opportunity in the Amendment Bill
by Corlett Manaka, Director and Head of Disputes, Akhona Bilatyi, Director and Koketso Rapoo, Senior Associate On 12 March 2026, [...]
A charge by any other name would smell as sweet
by Bradley Workman-Davies, Director The Labour Appeal Court's judgment in Machi v Chep SA (Pty) Ltd and Others serves as [...]
When a misdirected email becomes a data breach: The Information Regulator issues an enforcement notice on internal and accidental security compromises
by Armand Swart, Director, Hlonelwa Lutuli, Associate and Isabella Keeves, Candidate Attorney On 22 May 2026, South Africa’s Information Regulator [...]
Renting out your home? The Consumer Protection Act does not apply to you says Supreme Court of Appeal
by Armand Swart, Director In the judgment of Els v Venter and Another (449/2024) [2025] ZASCA 163 (27 October 2025), [...]
