WhatsApp is where South African patients actually are. It is also where practices get nervous, because POPIA arrived, everyone got a compliance email from someone selling compliance, and the practical question never got a clear answer: can I message my patients or not?
The answer is yes, mostly, and the confusion comes from one distinction that POPIA itself makes very clearly — and that almost nobody quotes.
This is not legal advice. It is a plain-language summary of published sources, written by someone who builds WhatsApp messaging for practices, not a lawyer. Check your own policy with an attorney before relying on it.
The distinction everything hangs on
POPIA's rules about consent for electronic messages live in section 69, and section 69 governs one thing: direct marketing.
So the question is not "does POPIA cover WhatsApp". It is "is this message direct marketing". POPIA answers that in its own definitions, in section 1:
"direct marketing" means to approach a data subject, either in person or by mail or electronic communication, for the direct or indirect purpose of — (a) promoting or offering to supply, in the ordinary course of business, any goods or services to the data subject; or (b) requesting the data subject to make a donation of any kind for any reason.
Read that against an appointment reminder. "Hi Sarah, this is a reminder of your appointment tomorrow at 9am. Reply MOVE if you need to reschedule."
It promotes nothing. It offers to supply nothing. It requests no donation. It is not direct marketing, and section 69's consent machinery does not apply to it.
That single paragraph resolves most of what practices worry about. Reminders, confirmations, "your results are ready", "the doctor is running twenty minutes late", "here is your intake form" — none of these are direct marketing. They are you delivering the service the patient asked you for.
What POPIA still requires, because "not direct marketing" is not the same as "unregulated": you need a lawful basis for holding the number in the first place (you have one — they gave it to you to book an appointment), you may only use it for the purpose it was given for, and you must keep it secure. Purpose limitation is the one to watch, and it is exactly what the next section is about.
Where the line actually gets crossed
Here is the same message, one sentence longer:
*"Hi Sarah, this is a reminder of your appointment tomorrow at 9am. Reply MOVE if you need to reschedule. PS — 20% off all facials this month, book now!"*
That message is now direct marketing. It promotes a service in the ordinary course of business, and adding it to an operational message does not launder it. The whole message is caught.
This is the mistake practices actually make. Not "we WhatsApped a patient" — that is fine. It is "we bolted a promotion onto a reminder because we had their attention", which converts a message that needed no consent into one that does.
What section 69 requires when you do market
If you genuinely want to promote something, POPIA gives you three doors and they are narrow.
1. Consent. The default. The patient has agreed to receive marketing from you.
2. The existing-customer exemption, section 69(3). You may market to an existing customer without separate consent, but all three conditions must hold:
- you obtained their contact details in the context of the sale of a product or service;
- you are marketing your own similar products or services; and
- they were given a reasonable opportunity to object, free of charge and without unnecessary formality, both when you collected the details and in every communication since.
Most practices satisfy the first two and fail the third, because nobody put an opt-out in the messages. That third condition is not a one-off at signup — it is an ongoing obligation on each message.
3. Ask once, section 69(2). You may approach someone a single time to request consent, and it must be requested in the prescribed manner and form — Form 4 of the POPIA Regulations. Once. If they decline or ignore it, you may not ask again.
And whichever door you use, section 69(4) requires every marketing message to carry the identity of the sender and an address or contact details for asking the messages to stop.
What the Information Regulator added in 2025
The Information Regulator published a Guidance Note on Direct Marketing on 25 June 2025, and two points from it are worth knowing.
Telephone calls count as electronic communications. The Regulator's position is that a marketing phone call needs opt-in consent, or must satisfy the existing-customer exemption, in the same way an SMS does. That is a broader reading than many businesses assumed, and it is a position some lawyers expect to be challenged — but it is the regulator's stated view, and you would be arguing against it rather than relying on silence.
You must keep records of who withheld consent. Not just a list of who opted in — a record of who said no, so you can prove you did not ask twice.
Non-electronic marketing — in person, or by post — sits under a different framework where legitimate interests can be relied on, subject to a purpose, necessity and balancing assessment. Which is a curious outcome: a letter is easier to justify than a WhatsApp.
The second rulebook nobody reads
Here is the part that catches out businesses who did their POPIA homework properly.
WhatsApp has its own rules, and they are stricter than the law. Meta's Business Messaging Policy is a contract between you and them, entirely separate from South African legislation. Under it:
- Any business-initiated message requires an opt-in. Not just marketing — any message you start. The single exception is replying inside the 24-hour window after a customer messages you first.
- Outside that 24-hour window you must use a pre-approved message template. You cannot free-type. Templates are submitted to Meta and can be reviewed, paused or rejected at any time.
So an appointment reminder that POPIA does not treat as direct marketing still needs a WhatsApp opt-in and an approved template, because Meta says so. You can be perfectly compliant with POPIA and still have your templates rejected or your number restricted.
The penalty structures are different too, and the WhatsApp one bites faster. The Information Regulator works through enforcement notices. Meta simply stops your messages.
What to actually do
- Separate your message types. Operational on one side, promotional on the other, and never merge them to save a send.
- Collect a WhatsApp opt-in at booking regardless of POPIA. Meta requires it, it takes one line on your booking form, and it removes the whole question.
- Put an opt-out in every marketing message. Section 69(4) requires it, and 69(3) makes it a condition of the existing-customer exemption.
- Keep a record of refusals, not just consents.
- Get your templates approved before you need them. Approval is not instant, and you do not want to discover that the evening before a clinic day.
- Do not use Form 4 casually. It is a single shot per person. Spending it on a poorly-timed ask wastes it permanently.
None of this makes WhatsApp risky. It makes it a channel with two rulebooks instead of one, and the operational messages — the reminders that actually reduce your no-shows — are the least regulated thing you can send. The caution most practices apply is aimed at the wrong messages.
Sources: Protection of Personal Information Act 4 of 2013, section 1 definitions and section 69; Information Regulator, Guidance Note on Direct Marketing, 25 June 2025 (summarised by DLA Piper); WhatsApp Business Messaging Policy and Meta's opt-in documentation. Guidance and platform policy both change — confirm the current position before relying on this.