POPIA and AI, South Africa

Is an AI chatbot POPIA compliant? Software cannot be.

Compliance is a property of how a business handles personal information. It is not a feature you can buy, and no product can hold it on your behalf. Almost every AI vendor in this market claims it anyway, and almost none of them explains what the Act actually asks of you. So here is the explanation, question by question, including the one thing about cross-border data that most of the market has wrong.

This is not legal advice. It is a plain reading of what POPIA asks of a business that puts an AI assistant in front of its customers, written by the people who build them. Your own setup deserves a lawyer's eyes, and nothing below is a substitute for that.

A A business on WhatsApp
online, replies in seconds

Hang on. Where does this chat actually get stored, and is it POPIA compliant?19:42

Fair question. This conversation and your booking history are kept on this business's own server in Johannesburg. To write a reply, your message goes to the AI provider that generates it. The team here can read the chat so a person can step in. Nothing is sold on.19:42

The full privacy notice sets out what is kept, who receives it and how long for: the link is here.19:42

An illustration of the pattern. It says what the system does and points at the published notice. It never tells the customer the business is compliant, because that is not something software can know.

You are the responsible party, not your vendor Section 21 requires a written operator agreement No localisation rule in POPIA, section 72 permits transfer Financial information is not special personal information

The question people actually type

Is ChatGPT POPIA compliant for my business?

The short answer: that is a question about your use of it, not about the tool. Compliance describes how a business processes personal information, so it attaches to you, and no AI tool carries a badge that transfers to your business. The useful questions are about roles: who is responsible for the information, who is processing it on whose behalf, and what is in writing between them.

The badge does not exist

Nothing in POPIA certifies a product. The Act regulates processing, and the processing is yours: the moment your staff paste a customer's details into any AI tool, or you wire one into your customer chat, your business is processing personal information and the eight conditions below apply to you.

The roles are the real question

You are the responsible party for your customers' information whatever tool you use. A provider processing it on your behalf should be your operator, under a written agreement. Consumer AI tools are not built around that relationship, and most offer no operator agreement for what you type into them at all.

So read the terms, not the marketing

Whether it is ChatGPT, a platform agent or a local vendor, the checkable things are the same: what the terms take (licences over inputs, training use), where the processing happens, and whether you could still answer a customer's section 18 question honestly while using it.

None of that says do not use AI tools. It says the compliance question lands on your desk, not the vendor's, so buy from whoever makes your side of it easiest to carry. The operator section and the five questions below are the practical version.

The Act, in plain terms

POPIA regulates processing, not software.

The Act is about the processing of personal information: collecting it, storing it, using it, passing it on, deleting it. If your assistant takes a name, a phone number or a description of somebody's problem, that is processing and POPIA applies to the business doing it. It applies in exactly the same way whether a receptionist typed the reply or a model did. The technology is not the subject of the law, and asking whether a chatbot is compliant is asking the wrong question about the wrong thing.

There are eight conditions for lawful processing, and between them they are the core framework. The Act carries further duty areas beside them where they apply: special personal information, children's information, prior authorisation, direct marketing, automated decision-making and international transfers. Read the conditions as a checklist for your business, not for your software. The full text of the Act is published by the state and is more readable than its reputation: the Protection of Personal Information Act, 2013 on gov.za, supervised by the Information Regulator.

  • Accountability Somebody in the business is answerable for all of it. You cannot hand that to a supplier along with the work.
  • Processing limitation Collect only what you actually need, lawfully, with a proper ground for having it.
  • Purpose specification Know the specific reason before you collect, and do not keep the information once that reason is finished with.
  • Further processing limitation What somebody gave you to book an appointment does not become a marketing list on its own.
  • Information quality Take reasonable steps to keep what you hold complete and accurate.
  • Openness Tell people what you are doing with their information. Section 18 is the detail, and it has a section of its own below.
  • Security safeguards Protect what you hold, with security that suits how sensitive it is.
  • Data subject participation People may see what you hold about them, and ask for it to be corrected or deleted.

When applicable: direct marketing, section 69

Direct marketing by electronic communication, messages and email included, has its own rules: consent or the existing-customer conditions, and an opt-out with every message. An assistant that answers what customers ask is not doing direct marketing. One that sends promotional messages is, so if yours will, read section 69 before it does.

When applicable: automated decisions, section 71

A decision made solely by automated means, with a legal or similarly substantial effect on somebody, carries its own protections, including the right to have a person reconsider it. Answering questions and taking bookings is not that. Automated eligibility or credit-style scoring could be, so a system that decides rather than assists needs section 71 read first.

The distinction most readers have not met

You are the responsible party. Your vendor is the operator.

POPIA gives the two sides different names and different duties, and the difference decides who carries what. The business that decides why and how personal information is processed is the responsible party. If you are the one who bought the chatbot and pointed it at your customers, that is you. A supplier who processes that information on your behalf is an operator. That is your chatbot vendor, and usually your host and your CRM as well. The label follows the purpose: an operator processes for your purposes. A vendor that processes the same information for its own purposes, its own analytics or its own model training, is a responsible party for that processing, with duties of its own.

Section 21 requires it in writing

Section 21 requires a written contract between the responsible party and the operator, and the contract's job in the Act is to ensure the operator establishes and maintains the security measures section 19 sets. Not a handshake, not an invoice, not a paragraph on a pricing page. A document that exists and that you have read.

With your knowledge or authorisation

The Act itself requires anyone processing personal information on your behalf to do so only with your knowledge or authorisation, and to treat it as confidential: that is section 20, owed whether or not the contract repeats it. The scope of what an operator may do is still a thing you decide and a thing a good contract records.

And they must secure it

The operator must secure the information it holds, and section 21's contract is how the Act makes sure of it. The duty being theirs does not move the accountability condition off you: if it goes wrong, the person whose information it was comes to your business first.

This is the practical thing most businesses do not know they need. Plenty of South African companies have connected an AI assistant to their WhatsApp number this year with nothing in writing covering the processing at all. The gap in that arrangement is yours, not the vendor's, because accountability is the first condition and it sits with the responsible party. If you take one action off this page, ask your supplier for the operator agreement.

For the record, ours is not only a document in a drawer: every IndunAI instance's own published privacy notice names In House IT as the operator, processing on the client's behalf under a written agreement that limits what may be done with the information to running the service and nothing else. Your customers can read the arrangement on the notice that carries your business's name.

What you have to tell people

Section 18: they must be told who is collecting, and why.

When you collect somebody's personal information, section 18 requires reasonably practicable steps to make the data subject aware of it: what is being collected, who is collecting it, the purpose, and the other prescribed details, including recipients and cross-border transfers where applicable. The section carries its own exceptions: somebody already informed need not be retold when the same information is collected for the same purpose, and section 18(4) lists further exceptions.

For a chatbot that is not a footer link problem. The person is standing inside a chat window, so the chat is where the answer has to be reachable. In practice it comes to three things: the assistant can say what happens to the conversation, it can say who else receives it, and it can point at a published notice that carries the rest instead of improvising one.

The improvising is the part worth guarding against. An assistant asked a data question with nothing true to say will make something up that sounds reassuring, and a reassuring invention about somebody's personal information is worse than a link.

A A business on WhatsApp
online, replies in seconds

Who actually sees what I type in here?08:15

The business collects it to answer you and to make the booking. Your message goes to the AI provider that writes the replies, and the team here can read the chat. That is the whole list, and the privacy notice sets it out properly.08:15

Who is collecting, what for, and who else receives it. The heart of section 18's prescribed details, in the place the person is actually standing.

A defined and narrow list

Special personal information is narrower than people think.

POPIA defines a specific category and gives it extra protection under section 26: it is a closed list of religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour. Two things follow from that list which surprise almost everybody.

Financial information is not on it

An invoice, a payment reference, a card transaction, what somebody earns: none of that is special personal information under POPIA. It is ordinary personal information, which still has to be collected properly and protected properly. It simply does not sit in the category the Act singles out, and a supplier who calls your payment data "special category" is not describing POPIA.

Health information is

A clinic, an aesthetics practice, a physiotherapist, a dentist: the moment the assistant asks what is wrong, the business is handling special personal information, from the first message. Section 26 prohibits processing it unless a ground lifts the prohibition, and section 32 carries the health-specific provisions. That is not a reason not to run an assistant. It is a reason to have decided how you handle it before the assistant answers anybody, rather than after.

Clinics, one more check: prior authorisation, section 57(1)(d)

Prior authorisation from the Information Regulator can be required before special personal information such as health data, or children's information, is transferred to a foreign country that does not provide an adequate level of protection. A transfer arrangement that does provide substantially similar protection under section 72 is what keeps that from triggering. If your assistant sends patient messages offshore for replies, confirm with your own advisor that your transfer arrangement clears that bar.

In our own product this is not left to memory: an instance that declares a health sector publishes the special-personal-information section on its own privacy page, naming the ground it processes on. If health work is your day, AI for clinics covers where the line sits, and the live medical receptionist demo shows it holding.

The claim to be careful of

Does POPIA require my data to be hosted in South Africa?

The short answer: no. Section 72 permits the transfer of personal information outside the Republic on listed grounds: among them, that the recipient is subject to law, binding corporate rules or a binding agreement giving the information substantially similar protection; that the data subject consents; or that the transfer is necessary for the performance of a contract with the data subject. There is no data localisation requirement in the Act.

This is the correction worth the whole page. Several vendors in this market sell on a promise that your data never leaves South Africa, and imply that the law demands it. The law does not demand it. What local hosting actually buys is narrower and still worth having: for the data it covers, it removes the need for the section 72 analysis entirely. You only have to justify the legs that cross the border, so the fewer and better-named those legs are, the shorter your homework.

It matters because almost every capable AI model runs offshore. A South African business running an AI assistant is, in nearly every case, sending message content to a provider outside the country, whoever sold the assistant to them. A vendor who tells you otherwise is either not describing their own system accurately, or is running a model you should ask some careful questions about.

Our own position, stated the same way we state it everywhere: we do not claim your data never leaves South Africa. Client records are hosted in Johannesburg, on an isolated instance per client, and the one cross-border leg is named plainly: the AI provider that generates the replies processes the conversation text at inference time, outside the country. Naming that leg is section 18's work. Section 72 is a separate question, and the transfer has to satisfy one of its grounds on its own: ours relies on the binding-agreement ground, through the provider's data processing terms, and the client agreement is where that arrangement is recorded. The provider's commitment that content is not used to train their models is an additional safeguard, not by itself a section 72 ground. As with the rest of this page, how your own transfers meet section 72 is a question for your adviser. Named legs and a real ground are achievable. "Your data never leaves South Africa" is mostly not.

Saying this costs us an easy sales line, and that is rather the point of saying it.

We host in Johannesburg and we would love to write "your data never leaves South Africa" across the top of our own pages. We do not write it, because the model that composes the replies runs offshore, so it would not be true. A claim that flatters us and misleads you is worth less than a page you can check.

Keeping and deleting

How long may a chatbot keep the conversation?

The short answer: as long as the purpose needs and no longer. Section 14 is the retention condition: records of personal information must not be kept longer than is necessary for the purpose they were collected for, subject to the exceptions the law itself lists, and section 24 lets a person ask for the deletion of information that is inaccurate, excessive or no longer authorised to be kept.

Two honest complications. The retention period is a judgement about your business, not a number a vendor can pick for you: a plumber's quote thread and a clinic's patient chat do not age the same way. And other laws can require some records kept, tax law on invoices being the everyday example, so "delete everything" is not always the lawful answer either.

What a vendor can honestly offer is machinery that keeps your answer true, and here is ours, as built: a retention clock the owner switches on with their own periods, which previews what it would delete before it deletes anything; and an erasure control on every instance for the person who asks, which deletes their conversation, their customer record and their files together, requires a typed confirmation because it has no undo, and writes an erasure record that deliberately holds no personal data, so the business can show the request was honoured without re-creating the person in the log of their own deletion.

The other Act in the room

RICA, in brief.

The short answer: RICA governs the interception of communications generally, and the question people usually mean is about recording calls, which this assistant does not answer. RICA covers the interception and monitoring of communications in whatever form they take, voice, text or data, and the consent question it is best known for sits on call recording: whether and how a call may be recorded, and who must be told.

IndunAI does not answer voice calls at all, on purpose. It answers WhatsApp and website chat, in text, so there is no call to record and the call-recording question does not arise for the assistant. The chats themselves are stored as business records, and that is a POPIA matter the privacy notice covers, not an interception. If you do record calls elsewhere in your business, that is RICA's own territory and worth a real conversation with your adviser; we will not paraphrase it further because we do not operate there.

Five questions

What to ask before you sign anything.

None of these are trick questions, and none of them needs you to be technical. A vendor who has thought about POPIA answers all five without going quiet, and one who has not will start talking about certifications instead.

  • Where does the processing actually happen? Not where the company is registered. Where the records are stored, and where the model that writes the replies runs. Those are two different answers and you want both.
  • Is there a written operator agreement, and may I read it? Section 21 requires one. Ask for the document rather than a reassurance, and check that it says what they may do with the information and what they may not.
  • Is our data used to train models? Ask about the vendor and about whichever provider sits behind them, because the answer is often different for each, and only one of them is on your contract. Get it in writing.
  • What happens when we leave? Whether you can export everything, what gets deleted, how soon, and what licence over the content carries on after the agreement ends. That last one catches people out.
  • How is a deletion request handled? Somebody will eventually ask you to delete their record. Ask what actually happens, on your side and on theirs, how long it takes, and who tells you it is done.

The sharp one

Read what the licence says, not what the page says.

Of those five, the training question is the one that separates a considered vendor from a confident one. It is also the one where the answer usually lives in a terms document rather than in the conversation you are having, which is why it pays to go and read the terms.

Here is a current example, stated as fact and not as an attack on anybody. It is quoted because it is public, checkable, and about as clear a demonstration as exists of why the question is worth asking.

Meta's Business Agents and Platform Terms of Service state that by using Business Agents you grant Meta a perpetual, worldwide, non-exclusive, fully paid and royalty-free licence to use any Input for the purposes described in those terms, and that the licence survives termination of the terms by any party, for any reason.

The same terms state that where Business Agents hand chat control over to the company, the agent is muted in the conversation with the end user but may continue to observe the content being shared in the chat, and that this content is treated as Content under those terms.

Read the terms yourself · facebook.com/legal/3774714022740775

There is nothing hidden about any of that, and large platforms commonly take broad licences. The reason it belongs on this page is the shape of it: the answer was in a terms document, it outlives the end of the relationship, and a sales conversation would not have covered it unless somebody asked. Whatever you conclude about it for your own business, section 18 still does its work: who receives the information is among the prescribed details a person must generally be made aware of.

Who supervises it

The Information Regulator, and the numbers we will not quote.

POPIA's supervisory body is the Information Regulator. That is where a complaint about the way a business handled somebody's personal information goes.

You will see enforcement figures and fine amounts quoted in AI vendor marketing, usually in bold, usually next to a call to action. We are not repeating any of them here, because we have not verified them and in most cases neither has the person who put them on the slide. A page that scares you with a number it cannot source is not a page that has read the Act.

FAQ

Fair questions.

Is ChatGPT POPIA compliant for my business?

That is a question about your business, not about ChatGPT. The moment your staff paste a customer's details into any AI tool, or you wire one into your customer chat, your business is processing personal information and POPIA applies to you: you need a lawful ground, a section 18 answer for the person, and a section 21 operator agreement with whoever processes it on your behalf.

Consumer AI tools are not built around that relationship, and most give you no operator agreement at all. So the useful question is not whether the tool has a badge. It is whether your use of it can meet your duties, and whether the supplier will put what their system does in writing.

Is IndunAI POPIA compliant?

No software is, ours included, and we will not tell you otherwise to close a sale. Compliance describes how a business collects, uses, protects and explains personal information. A supplier can make that easier or harder for you, and can be a well-behaved operator or a careless one, but it cannot be compliant on your behalf.

What a supplier can honestly tell you is what their system does. That is what the closing note below sets out, and it is what you should ask any vendor for in place of the badge.

Does POPIA require my customers' data to stay in South Africa?

No. Section 72 expressly permits the transfer of personal information outside the Republic on listed grounds, including a binding agreement that gives the information substantially similar protection, the data subject's consent, and necessity for a contract with the data subject. There is no data localisation requirement in the Act.

This is worth knowing because it is sold the other way round quite often, and because almost every capable AI model runs offshore. The obligation is to handle the transfer properly and to tell people about it, not to prevent it.

What consent does a chatbot need under POPIA?

Usually none, for ordinary chat. Consent is one lawful ground in section 11, next to others such as carrying out actions for a contract the person themselves asked for. A customer messaging a business to book a plumber does not need a consent pop-up first.

What is generally required is section 18 openness: reasonably practicable steps so the person knows who is collecting the information, why, and the other prescribed details, including recipients and cross-border transfers where applicable, with the section's own exceptions, such as a person already informed not needing to be retold for the same information and purpose. Special personal information changes the answer: an assistant asking a patient what is wrong is processing health information, which POPIA prohibits unless a specific ground such as consent lifts the prohibition, so that ground gets decided before the assistant goes live.

Is our customers' financial information special personal information?

Not under POPIA. The special category is a defined list: religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour. Financial information is not on it.

It is still personal information, and everything else in the Act still applies to it. It simply does not carry the extra protection the special category does.

We run a clinic. Does that change things?

Yes, because health information is on that special list. If your assistant asks a patient what is wrong, the business is handling special personal information from the first message. That is a decision to make deliberately and before the assistant goes live, rather than something to discover afterwards.

Do I really need a contract with my chatbot vendor?

Section 21 requires a written contract between the responsible party and the operator, one that ensures the operator maintains the security measures the Act requires. The Act itself also requires anyone processing on your behalf to do so only with your knowledge or authorisation, and to keep the information confidential. If a vendor is processing your customers' personal information on your behalf, that is the arrangement being described.

Ask for the document. A vendor who has one will send it. A vendor who has not will offer you a compliance badge instead, and that answer is itself informative.

The assistant is the one talking to my customer. Who is responsible?

You are. The responsible party is the business that decides why and how the personal information is processed, and that is the business whose customers are typing. The Act does not treat a model as an actor with duties of its own, and no supplier can absorb the accountability condition for you.

Can my customers make me delete their information?

They can ask, and the Act backs the ask: section 24 lets a person request the deletion of information that is inaccurate, excessive or no longer authorised to be kept, and section 14 says records must not be kept longer than the purpose needs. Other laws can require some records kept, such as invoices for tax.

On IndunAI the request is answerable: every instance has an erasure control that deletes the person's conversation, customer record and files, and writes an erasure record that holds no personal data, so the business can show the request was honoured.

Does RICA apply to an AI chatbot?

RICA governs the interception of communications generally, in whatever form they take, and the consent question people know it for sits on call recording. IndunAI does not answer voice calls at all, on purpose: it answers WhatsApp and website chat in text, so there is no call to record.

The chats themselves are stored as business records, and that is a POPIA matter the privacy notice covers, not an interception.

How we handle these questions

A short note, and it makes no compliance claim about your business or about ours.

  • An isolated instance per client, with its own database. You are not a row in a shared table.
  • Records hosted in Johannesburg, on our own infrastructure.
  • Customer conversations are not used to train models.
  • Each instance publishes its own privacy notice, terms and PAIA manual in the client's name, not ours.

What we will not tell you is that any of that makes your business compliant. That depends on what you collect, why you collect it, what you tell people and what agreements you hold, and no supplier can know all of that about somebody else's business. What we can do is not be the reason you fall short.

The same five questions, answered for us

What we do with your customers' messages.

Asked of us, in the same order, so you can hold the answers next to anybody else's, including the ones quoted above.

Who is the operator

We are, under section 21, and we say so in writing: it is your instance, your business name on the privacy notice, and your customers' data, which the agreement limits to running the service for you and nothing else.

Where it is processed

Records live in Johannesburg, on an isolated instance per client. Replies are generated by an AI provider outside South Africa under terms that say content is not used for training. That is the one cross-border leg, named rather than hidden.

Is it used for training

No. The only licence our terms take over your conversations is to host and process them to provide the service. They stay yours, they are deleted on the retention schedule you set, and when you leave, the instance and its data are deleted, with an export offered first.

What happens on a request

A customer asking to see or delete their data raises an alert to you from the server on the same turn, whatever the assistant happens to say. Sections 23 and 24 on rails, not a model choosing well.

Who can read it

You, on your own dashboard, behind your own login. One isolated instance per business: no shared database, and no pooling of one client's conversations into another's.

And the exclusions

None. Meta's business agent excludes Finance, Government, Health, Alcohol, Gambling, over-the-counter drugs and matrimony outright. If you are in one of those, that is the whole decision.

That is the honest reason to use a small local vendor over a platform: not that the platform is badly run, but that its terms are written for a billion businesses and yours are written for you. IndunAI answers WhatsApp and your website, books into your real diary, takes deposits, invoices in Rand and asks for the review, at R1 450 a month with VAT included, on a server you can point at on a map.

Ask us the five questions.

Send them on WhatsApp or by email and you will get five straight answers, including the ones that are not flattering. If you are weighing up another vendor, ask them the same five and compare the answers rather than the pricing. If you would rather read first, how we build agents is the next page along.