The POPIA compliance checklist for South African call centres updated for the 2025 rules
The Information Regulator has stopped warming up: direct-marketing guidance landed in December 2024 and amended POPIA regulations took effect on 17 April 2025. Here is what a VoIP call centre must actually have in place.
What does POPIA require of a VoIP call centre in South Africa?
A call centre must process personal information lawfully and transparently: tell callers they are recorded and why, secure recordings and CRM data with role-based access, keep information only as long as a defined purpose exists, honour data-subject requests, and contract every cloud or VoIP vendor as an operator. Outbound marketing calls now require prior consent or an existing-customer relationship under section 69, with the call recorded as proof. Maximum administrative fines reach R10 million.
Why call centres carry more POPIA risk than most businesses
A VoIP call centre is a personal-information factory. Every shift produces recordings, metadata, CRM entries and agent notes, all of it regulated.
POPIA covers how personal information is collected, processed, stored and shared. In a call centre that reaches further than most operators realise: the voice recording itself, caller line identity, timestamps and call metadata, CRM records, ticketing history, quality-assurance scores tied to named agents, and any spreadsheet an agent exports. VoIP platforms make this worse in one specific way: they integrate everything, so data flows between the PBX, the CRM and reporting tools automatically, and a compliance gap in one system leaks into the others.
The stakes are real: administrative fines run up to R10 million, certain offences carry criminal liability, and the Information Regulator has moved from education to enforcement, with a publicly signalled focus on direct marketing.
What changed in 2024 and 2025
Two developments moved the goalposts for call centres specifically. If your compliance file predates them, it is out of date.
The direct-marketing guidance note (December 2024)
The Information Regulator’s guidance note on direct marketing, published on 3 December 2024, settled the argument the industry had been having for years: telephone calls count as electronic communication for section 69 purposes. Unsolicited marketing calls therefore require the recipient’s prior consent, unless you are contacting an existing customer about similar products or services under the narrow section 69(3) exception.
The amended POPIA regulations (17 April 2025)
Amended regulations took effect on 17 April 2025 and tightened the mechanics: consent for direct marketing is requested on the prescribed Form 4, telemarketers must convey the substance of that form on the call, and the consent call itself must be recorded and retained as proof. Objection and opt-out routes must work across channels, not just the one the marketer prefers.
The 8-point compliance checklist
Work through these in order. Each point names the thing an assessor or regulator will actually ask to see.
1. Lawful basis mapped per process
For every call type (sales, support, collections, surveys) write down the lawful basis: consent, contract performance, legal obligation or legitimate interest. If nobody can say why a process is lawful, it probably is not. Proof: a one-page processing register.
2. Recording notices that actually notify
Callers must know they are recorded and why, before the substantive conversation starts. Put the notice in the IVR greeting on inbound, and in the agent script on outbound. Proof: the greeting audio and the script version history.
3. Retention and deletion that runs on a schedule
Keep recordings and records only as long as a defined purpose or legal requirement exists, then delete them. Indefinite retention is the most common and most visible failure. Proof: a written retention schedule and evidence deletion actually executes on your VoIP platform.
4. Role-based access and audit logs
Recordings and CRM data restricted to named roles, playback and export logged, admin rights reviewed quarterly. A recording any agent can download is a breach waiting for a motive. Proof: the access matrix and a sample audit log.
5. Operator agreements with every vendor
Your VoIP provider, CCaaS platform, CRM and any BPO partner process personal information on your behalf: POPIA calls them operators, and section 21 requires a written agreement obliging them to secure it. Proof: signed operator clauses, plus a note on where each vendor stores data, since cross-border hosting triggers section 72 transfer conditions.
6. Data-subject requests handled on a clock
Callers can ask what you hold, demand correction or deletion, and object to processing. Route requests to a named owner, verify identity, respond within the timelines in your PAIA manual, and log every request. Proof: the request log, even if it is short.
7. Breach response ready before the breach
Section 22 requires notifying the Regulator and affected data subjects as soon as reasonably possible after a compromise. Have a one-page plan: who declares an incident, who drafts the notification, who talks to the platform vendor. Proof: the plan and one tabletop run-through.
8. An information officer who is registered and resourced
Your information officer must be registered with the Information Regulator, and actually empowered: they need sight of new campaigns, new vendors and new integrations before launch, not after. Proof: the registration and a standing agenda item.
Outbound marketing: the rules that bite in 2026
If your centre dials to sell, this is where enforcement attention is concentrated. The mechanics are now prescriptive.
| Scenario | What you need | Proof required |
|---|---|---|
| Cold call to a prospect | Prior consent (Form 4) | Recorded consent call, retained |
| Existing customer, similar product | S69(3) exception applies | Customer relationship + opt-out honoured |
| Bought marketing list | Consent you can prove yourself | The list seller’s promise is not proof |
| Customer says stop | Immediate opt-out, all channels | Suppression list entry, timestamped |
Recording is doing double duty here: the same platform capability that creates your compliance risk (storing voice data) is also your proof of consent. Get the recording governance right and the marketing compliance largely follows. For the recording-specific requirements in depth, see our POPIA call recording checklist.
A realistic 90-day programme
Nobody stands all of this up in a week. Sequence it so the highest-risk gaps close first.
POPIA compliance in a call centre is not a policy document. It is a recording notice, an access matrix, a deletion schedule and a consent trail that all demonstrably run.
WhichVoIP editorial position
Our verdict
Call centres sit in the regulator’s highest-attention zone: they hold voice recordings at scale and many of them dial to sell, which is exactly where the December 2024 guidance and April 2025 regulations concentrated. The checklist above is achievable for an SME operation in a quarter, and most of it costs configuration time rather than money. The businesses that struggle are the ones treating POPIA as a legal project instead of an operational one.
Need a platform that makes compliance easier?
Modern SA contact-centre platforms handle recording notices, retention schedules and access control natively. Compare vetted providers.
Frequently asked questions
Does POPIA apply to small call centres too?
Do we have to tell callers the call is recorded?
Can we still make cold calls under POPIA?
How long can we keep call recordings?
Is our VoIP or cloud provider responsible for compliance, or are we?
What are the penalties for non-compliance?
What changed in the April 2025 POPIA regulations?
Keep reading
Sources: POPIA (Act 4 of 2013); Information Regulator Guidance Note on Direct Marketing (3 Dec 2024); amended POPIA Regulations (in force 17 Apr 2025); PAIA. Verified 3 July 2026.