The moment you use AI for calls, messaging or chasing invoices, you’re handling personal information, so the Protection of Personal Information Act (POPIA) applies. The good news: for a typical small business the rules are sensible and manageable. Here’s what matters.
Yes. POPIA governs how you handle personal information (names, numbers, addresses, job details) whether a human or an AI tool does the handling. It’s overseen by the Information Regulator (South Africa). Using AI doesn’t create a special exemption or a scary new burden; the same principles you already follow extend to the new tools.
You don’t need fresh consent for every single interaction. Most small-business AI use rests on a legitimate business interest or on carrying out a contract, for example replying to an enquiry or booking a job the customer asked for. What matters most is transparency: your privacy notice should explain, in plain terms, that AI helps handle enquiries, and customers should always be able to reach a human if they want one.
This is the bit most people miss. Some AI tools route personal information overseas, which brings extra rules about cross-border transfers. Keep personal information in South Africa wherever you can, and treat any supplier who can’t clearly tell you where your data is stored with healthy suspicion.
Your customers’ information should be used to do your job, not to train a public model that anyone can use. With properly configured, business-grade tools that’s exactly how it works. Get a written Data Processing Agreement (DPA) confirming it, and practise data minimisation. Give the AI only what it needs to do the task.
How we handle it: South African data residency wherever possible, business-grade tools that don’t train public models on your customers, and a written DPA on every retainer.