POPIA Checklist for SA Call Centres: 2025 Rules Update

Call centre Compliance guide

The POPIA compliance checklist for South African call centres updated for the 2025 rules

The Information Regulator has stopped warming up: direct-marketing guidance landed in December 2024 and amended POPIA regulations took effect on 17 April 2025. Here is what a VoIP call centre must actually have in place.

R10mmaximum administrative fine
17 Apr 2025amended regulations in force
S69governs marketing calls
8checklist areas below

The short answer

What does POPIA require of a VoIP call centre in South Africa?

A call centre must process personal information lawfully and transparently: tell callers they are recorded and why, secure recordings and CRM data with role-based access, keep information only as long as a defined purpose exists, honour data-subject requests, and contract every cloud or VoIP vendor as an operator. Outbound marketing calls now require prior consent or an existing-customer relationship under section 69, with the call recorded as proof. Maximum administrative fines reach R10 million.

0
R-million maximum admin fine
0
the POPIA section on marketing calls
0
checklist areas to cover
0
days to stand up the basics
South African Call Centre Agents At Workstations With Headsets In A Modern Office
Every recorded call, CRM record and agent note is personal information under POPIA.

Why call centres carry more POPIA risk than most businesses

A VoIP call centre is a personal-information factory. Every shift produces recordings, metadata, CRM entries and agent notes, all of it regulated.

POPIA covers how personal information is collected, processed, stored and shared. In a call centre that reaches further than most operators realise: the voice recording itself, caller line identity, timestamps and call metadata, CRM records, ticketing history, quality-assurance scores tied to named agents, and any spreadsheet an agent exports. VoIP platforms make this worse in one specific way: they integrate everything, so data flows between the PBX, the CRM and reporting tools automatically, and a compliance gap in one system leaks into the others.

The stakes are real: administrative fines run up to R10 million, certain offences carry criminal liability, and the Information Regulator has moved from education to enforcement, with a publicly signalled focus on direct marketing.

What changed in 2024 and 2025

Two developments moved the goalposts for call centres specifically. If your compliance file predates them, it is out of date.

The direct-marketing guidance note (December 2024)

The Information Regulator’s guidance note on direct marketing, published on 3 December 2024, settled the argument the industry had been having for years: telephone calls count as electronic communication for section 69 purposes. Unsolicited marketing calls therefore require the recipient’s prior consent, unless you are contacting an existing customer about similar products or services under the narrow section 69(3) exception.

The amended POPIA regulations (17 April 2025)

Amended regulations took effect on 17 April 2025 and tightened the mechanics: consent for direct marketing is requested on the prescribed Form 4, telemarketers must convey the substance of that form on the call, and the consent call itself must be recorded and retained as proof. Objection and opt-out routes must work across channels, not just the one the marketer prefers.

!
The practical shift: “we bought an opted-in list” is no longer a defence. You need your own provable consent trail, on the prescribed form, with the recording to back it up.

The 8-point compliance checklist

Work through these in order. Each point names the thing an assessor or regulator will actually ask to see.

1. Lawful basis mapped per process

For every call type (sales, support, collections, surveys) write down the lawful basis: consent, contract performance, legal obligation or legitimate interest. If nobody can say why a process is lawful, it probably is not. Proof: a one-page processing register.

2. Recording notices that actually notify

Callers must know they are recorded and why, before the substantive conversation starts. Put the notice in the IVR greeting on inbound, and in the agent script on outbound. Proof: the greeting audio and the script version history.

3. Retention and deletion that runs on a schedule

Keep recordings and records only as long as a defined purpose or legal requirement exists, then delete them. Indefinite retention is the most common and most visible failure. Proof: a written retention schedule and evidence deletion actually executes on your VoIP platform.

4. Role-based access and audit logs

Recordings and CRM data restricted to named roles, playback and export logged, admin rights reviewed quarterly. A recording any agent can download is a breach waiting for a motive. Proof: the access matrix and a sample audit log.

5. Operator agreements with every vendor

Your VoIP provider, CCaaS platform, CRM and any BPO partner process personal information on your behalf: POPIA calls them operators, and section 21 requires a written agreement obliging them to secure it. Proof: signed operator clauses, plus a note on where each vendor stores data, since cross-border hosting triggers section 72 transfer conditions.

6. Data-subject requests handled on a clock

Callers can ask what you hold, demand correction or deletion, and object to processing. Route requests to a named owner, verify identity, respond within the timelines in your PAIA manual, and log every request. Proof: the request log, even if it is short.

7. Breach response ready before the breach

Section 22 requires notifying the Regulator and affected data subjects as soon as reasonably possible after a compromise. Have a one-page plan: who declares an incident, who drafts the notification, who talks to the platform vendor. Proof: the plan and one tabletop run-through.

8. An information officer who is registered and resourced

Your information officer must be registered with the Information Regulator, and actually empowered: they need sight of new campaigns, new vendors and new integrations before launch, not after. Proof: the registration and a standing agenda item.

Outbound marketing: the rules that bite in 2026

If your centre dials to sell, this is where enforcement attention is concentrated. The mechanics are now prescriptive.

Scenario What you need Proof required
Cold call to a prospect Prior consent (Form 4) Recorded consent call, retained
Existing customer, similar product S69(3) exception applies Customer relationship + opt-out honoured
Bought marketing list Consent you can prove yourself The list seller’s promise is not proof
Customer says stop Immediate opt-out, all channels Suppression list entry, timestamped

Recording is doing double duty here: the same platform capability that creates your compliance risk (storing voice data) is also your proof of consent. Get the recording governance right and the marketing compliance largely follows. For the recording-specific requirements in depth, see our POPIA call recording checklist.

A realistic 90-day programme

Nobody stands all of this up in a week. Sequence it so the highest-risk gaps close first.

Days 1 to 15: map and registerList every process that touches personal information, assign a lawful basis, confirm your information officer registration.
Days 16 to 30: fix the noticesRecording notice into every IVR greeting and outbound script. Cheapest fix, most visible gap.
Days 31 to 50: lock down accessRole-based access on recordings and CRM, export logging on, admin-rights review done.
Days 51 to 70: paper the vendorsOperator clauses with VoIP, CCaaS and CRM providers; note where each stores data for section 72.
Days 71 to 90: retention and responseRetention schedule configured to auto-delete, breach plan written and rehearsed, DSAR route tested end to end.

POPIA compliance in a call centre is not a policy document. It is a recording notice, an access matrix, a deletion schedule and a consent trail that all demonstrably run.

WhichVoIP editorial position

A Compliance Officer Reviewing A Data-Protection Policy Document At A Desk
The regulator expects working processes and proof, not a policy PDF nobody follows.

Our verdict

Call centres sit in the regulator’s highest-attention zone: they hold voice recordings at scale and many of them dial to sell, which is exactly where the December 2024 guidance and April 2025 regulations concentrated. The checklist above is achievable for an SME operation in a quarter, and most of it costs configuration time rather than money. The businesses that struggle are the ones treating POPIA as a legal project instead of an operational one.

Our recommendation: Close the visible gaps first: recording notices, access control and a written retention schedule. Then build the consent trail before your next outbound campaign, not after it.

Need a platform that makes compliance easier?

Modern SA contact-centre platforms handle recording notices, retention schedules and access control natively. Compare vetted providers.

Get free quotes
Call centre solutions guide

Frequently asked questions

Does POPIA apply to small call centres too?
Yes. POPIA applies to any business processing personal information in South Africa, regardless of size. A five-seat operation recording calls and holding customer records has the same core obligations as a 500-seat BPO; the scale of the measures differs, not the duty.
Do we have to tell callers the call is recorded?
Yes. Transparency is a POPIA condition: callers must be informed that the call is recorded and for what purpose, before the substantive conversation. An IVR notice on inbound and a scripted notice on outbound are the standard mechanisms.
Can we still make cold calls under POPIA?
Only with prior consent, or to existing customers about similar products under the section 69(3) exception. Since the Information Regulator’s December 2024 guidance confirmed phone calls are electronic communications, unsolicited cold calling to non-customers without consent is a compliance breach.
How long can we keep call recordings?
As long as a defined, documented purpose or legal requirement exists, and no longer. There is no single statutory number of years for all recordings; the obligation is a written retention schedule tied to purpose, with deletion that actually executes. Sector rules (such as FAIS for financial advice) can impose specific minimums.
Is our VoIP or cloud provider responsible for compliance, or are we?
You are the responsible party; your VoIP, CCaaS and CRM vendors are operators processing on your instructions. You need written operator agreements with them, and you remain accountable for what they do with your data, including where they host it.
What are the penalties for non-compliance?
Administrative fines of up to R10 million per infringement, plus criminal liability for certain offences, civil claims by data subjects, and enforcement notices that can halt processing operations. Reputational damage from a published finding often costs more than the fine.
What changed in the April 2025 POPIA regulations?
The amendments, effective 17 April 2025, tightened direct-marketing mechanics: consent requested on the prescribed Form 4, the substance of the form conveyed during telemarketing calls, the consent call recorded and retained as proof, and objection routes that work across channels.

Keep reading

POPIA call recording checklist
Call centre setup guide
Best call centre software
Call centre solutions in South Africa

Sources: POPIA (Act 4 of 2013); Information Regulator Guidance Note on Direct Marketing (3 Dec 2024); amended POPIA Regulations (in force 17 Apr 2025); PAIA. Verified 3 July 2026.


Now hiring Hire your AI receptionist