Guide · Compliance

AI and POPIA for South African small businesses, without the jargon.

The moment you use AI for calls, messaging or chasing invoices, you’re handling personal information, so the Protection of Personal Information Act (POPIA) applies. The good news: for a typical small business the rules are sensible and manageable. Here’s what matters.

Does POPIA apply to AI?

Yes. POPIA governs how you handle personal information (names, numbers, addresses, job details) whether a human or an AI tool does the handling. It’s overseen by the Information Regulator (South Africa). Using AI doesn’t create a special exemption or a scary new burden; the same principles you already follow extend to the new tools.

Lawful basis and being upfront

You don’t need fresh consent for every single interaction. Most small-business AI use rests on a legitimate business interest or on carrying out a contract, for example replying to an enquiry or booking a job the customer asked for. What matters most is transparency: your privacy notice should explain, in plain terms, that AI helps handle enquiries, and customers should always be able to reach a human if they want one.

Where your data lives

This is the bit most people miss. Some AI tools route personal information overseas, which brings extra rules about cross-border transfers. Keep personal information in South Africa wherever you can, and treat any supplier who can’t clearly tell you where your data is stored with healthy suspicion.

If a supplier can’t explain, in one sentence, where your customers’ data lives, that’s your answer.

Customer data and AI training

Your customers’ information should be used to do your job, not to train a public model that anyone can use. With properly configured, business-grade tools that’s exactly how it works. Get a written Data Processing Agreement (DPA) confirming it, and practise data minimisation. Give the AI only what it needs to do the task.

A practical checklist

  • Update your privacy notice to mention that AI helps handle enquiries and admin.
  • Get a written DPA confirming where data is stored (South Africa preferred).
  • Check that customer data won’t be used to train public AI models.
  • Always offer a way to reach a human.
  • Apply data minimisation. Only collect and share what’s needed.
  • Be able to action a customer’s request to access or delete their information.
This is general guidance, not legal advice. For your specific situation, see the Information Regulator’s resources or speak to a data-protection adviser.

How we handle it: South African data residency wherever possible, business-grade tools that don’t train public models on your customers, and a written DPA on every retainer.