On 7 October 2026 South Africa's National Consumer Commission (NCC) launched a National Opt-Out Registry, unveiled in Pretoria by Trade, Industry and Competition Minister Parks Tau. The NCC's Hardin Ratshisusu described it as a free, government-administered mechanism to stop unwanted direct marketing. The tool is sensible, proportionate and overdue. But it is a consumer-protection instrument being asked to answer what is partly a security problem, and the two should not be confused.
What the registry actually does
The registry gives practical force to Section 11 of the Consumer Protection Act, which lets consumers block unwanted direct marketing. According to the government's launch statement, Tau gazetted the Consumer Protection Act Amendment Regulations, 2026 to empower the NCC to run it. It covers calls, SMSes and emails.
The obligations fall on marketers. Per SAnews, direct marketers must register and renew annually, and must cleanse their lists against the registry monthly before any campaign. Marketer registration opened on 15 September 2026 and runs to December 2026. A free list-cleansing phase follows from December 2026 to April 2027. Registered consumers can then pre-emptively block marketers from May 2027. Once a block is registered, marketers must remove that person even where consent was given earlier. Engineering News adds that every communication must be traceable to the marketer's name, address and contact number.
Sources agree on when blocking starts. April 2027 is when the list-cleansing phase ends and full enforcement begins, while consumer blocking opens in May 2027, after the April cleansing window closes. The launch statement also gives no fine amounts. It says only that a marketer who fails to register after the registration period "may constitute a contravention" of Section 11 read with the 2026 Regulations.
The strongest case for the registry
The case for acting is strong. Truecaller's 2026 South Africa Spam Report, as reported by EWN, counted 17.47 billion spam calls in January to June 2026, up about 25% on the same period of 2025. It also counted 3.71 billion spam SMSes, up almost 59%. The right to privacy is constitutional, and an individual cannot reasonably police thousands of inbound contacts one number at a time. A central register that shifts the burden onto the marketer is the textbook remedy. It is also the model many jurisdictions have used for telemarketing.
The design also gets several things right. It is a registry, not a ban. Tau stressed that "this is not a ban on direct marketing," and noted that the industry supports jobs, including in call centres. It gives marketers a free five-month runway to clean their lists before enforcement bites. It places compliance cost on firms that profit from contact, not on consumers. For a pro-innovation publication that matters: legitimate businesses get clear, predictable rules.
Where the design runs out
The limit is that the registry governs people who are willing to follow rules. Ratshisusu noted, per EWN, that under POPIA every direct marketer still needs a data subject's consent even if that person is not on the registry. So the registry layers an opt-out on top of an existing consent regime. It does not create a new class of enforcement against anonymous callers.
Criminal traffic is a different animal. SAnews reports that nearly 30% of calls from unknown numbers are classified as spam or fraudulent, and that scam and marketing networks use number spoofing and artificial intelligence to reach consumers. A fraudster running a bank-impersonation campaign from spoofed numbers will not register with the NCC, will not cleanse a list, and will not be deterred by a Section 11 contravention. For them the registry is simply irrelevant. A consumer who blocks marketers in May 2027 may feel protected while the calls that cost them money continue.
This gap is a risk in its own right. If the public reads "spam registry" as "spam solved," trust in the system erodes when the scam calls keep coming. Regulators should say plainly what the registry covers and what it does not.
What would close the gap
The answer is not to stretch consumer law further. It is to pair the registry with measures aimed at the actual attack surface:
- Caller-identity authentication. Operator-level measures that verify or flag spoofed numbers address the technique fraudsters rely on. Telecom regulation, not consumer regulation, is the right lever, and ICASA is the natural home.
- Operator and platform cooperation. Networks and handset or app-level filtering can act on traffic patterns without reading content, which keeps speech and privacy intact.
- Evidence on outcomes. Publish registry uptake, complaint volumes and the share of complaints that involve registered versus unregistered senders, so policy can be judged on results.
- Proportionate penalties. The regulations as described leave sanctions unspecified. Clear, graduated consequences for repeat registered offenders will matter more than headline numbers.
None of this requires heavy-handed rules on lawful communication. Targeted authentication and telecom-level controls impose cost on bad actors, not on the open internet or on legitimate small businesses reaching customers.
The verdict
The NCC has built a proportionate, consent-centred tool, and the phased rollout is a mark of good regulatory practice. Judged as consumer protection, it deserves support. Judged as an answer to the 17.47 billion spam calls in the Truecaller data, it is incomplete, because a meaningful share of that traffic is fraud that no marketing list will ever capture. The credibility of the programme will depend on whether South Africa treats the registry as the first step in a wider anti-fraud approach or as the whole response.