POPIA, NDPR and outreach: a practical compliance checklist
Compliance28 July 20266 min read

POPIA, NDPR and outreach: a practical compliance checklist

A short checklist for revenue teams operating in South Africa, Nigeria and other African markets with data protection rules.

Data protection compliance is not a blocker to good sales; it is a quality filter. If you can explain the lawful basis for every contact, keep an audit trail, and honour opt-outs, you are already ahead of most competitors. This checklist is a practical starting point.

Before you start a campaign

  • Confirm the lawful basis for processing (legitimate interest for B2B is common, but document your reasoning).
  • Identify which markets are in scope: South Africa (POPIA), Nigeria (NDPR), Kenya (DPA 2019), Ghana (Data Protection Act 2012), etc.
  • Set up an opt-out and suppression list before any outbound message is sent.
  • Train your team on what qualifies as personal information and special personal information.

During outreach

  • Include an easy opt-out in every message.
  • Avoid sending sensitive personal data or health/financial details without a clear basis.
  • Keep records of consent, opt-outs and legitimate-interest assessments.
  • Do not purchase or scrape lists from unverified sources.

After a campaign

  • Handle data subject requests promptly — typically within 30 days.
  • Delete or anonymise data once the retention period is reached.
  • Review your suppression list and audit trail before re-targeting.
How Konexium helps

Konexium does not replace legal advice. It does provide workspace-level audit trails, DSR request tracking, suppression-list integration and evidence links so you can demonstrate accountability if asked.

Key takeaways
  • Document the lawful basis and keep an audit trail before contacting anyone.
  • Honour opt-outs and suppression lists across all channels.
  • Use tools that provide evidence links and DSR tracking, not just contact data.