
POPIA, NDPR and outreach: a practical compliance checklist
A short checklist for revenue teams operating in South Africa, Nigeria and other African markets with data protection rules.
Data protection compliance is not a blocker to good sales; it is a quality filter. If you can explain the lawful basis for every contact, keep an audit trail, and honour opt-outs, you are already ahead of most competitors. This checklist is a practical starting point.
Before you start a campaign
- Confirm the lawful basis for processing (legitimate interest for B2B is common, but document your reasoning).
- Identify which markets are in scope: South Africa (POPIA), Nigeria (NDPR), Kenya (DPA 2019), Ghana (Data Protection Act 2012), etc.
- Set up an opt-out and suppression list before any outbound message is sent.
- Train your team on what qualifies as personal information and special personal information.
During outreach
- Include an easy opt-out in every message.
- Avoid sending sensitive personal data or health/financial details without a clear basis.
- Keep records of consent, opt-outs and legitimate-interest assessments.
- Do not purchase or scrape lists from unverified sources.
After a campaign
- Handle data subject requests promptly — typically within 30 days.
- Delete or anonymise data once the retention period is reached.
- Review your suppression list and audit trail before re-targeting.
Konexium does not replace legal advice. It does provide workspace-level audit trails, DSR request tracking, suppression-list integration and evidence links so you can demonstrate accountability if asked.
- Document the lawful basis and keep an audit trail before contacting anyone.
- Honour opt-outs and suppression lists across all channels.
- Use tools that provide evidence links and DSR tracking, not just contact data.


