Compliance · POPIA

POPIA and AI: What South African Small Businesses Need to Know

You've started using ChatGPT or Claude in your business. Maybe you pasted a customer list in to sort it. Maybe you typed a client's details into a chatbot to draft a quote. And somewhere at the back of your mind, a question you can't quite answer: am I actually allowed to do this?

It's a fair question, and almost nobody is answering it for small business owners. Most POPIA content is written for companies with legal departments. Most AI guidance is written for the United States, where POPIA doesn't exist. Here's the plain-English version for a South African small business.

This article is general information, not legal advice. For guidance on your specific situation, speak to a qualified attorney.

First, the thing most people get wrong

There's a widespread assumption that AI is unregulated in South Africa — that because there's no AI Act, there are no rules. That's not correct.

South Africa does not have a standalone AI law, and it's not getting one imminently. A Draft National Artificial Intelligence Policy was published for public comment on 10 April 2026 — then withdrawn roughly two weeks later, after it emerged the document contained fictitious academic citations, most likely generated by AI itself. The policy timeline has since stretched well beyond 2026.

But a missing AI Act does not mean a legal vacuum. POPIA already governs how AI systems handle personal information — including automated decision-making, profiling, and sending data across borders. If your AI use touches anyone's personal information, POPIA applies to you right now, today, whether or not a dedicated AI law ever arrives.

What actually counts as "personal information"

This is where most small business owners trip up, because POPIA's definition is broader than people expect. It covers information relating to an identifiable person — a customer, a supplier, an employee, a child in your care.

In practice, for a typical small business, that includes:

  • Names, ID numbers, addresses, phone numbers, email addresses
  • Banking and payment details
  • Health information — directly relevant if you run a creche, a salon doing chemical treatments, or a beauty business recording client allergies
  • Information about children, which POPIA treats with additional care
  • Employment records for anyone you employ

It's worth being clear about the flip side too, because the fear is often bigger than the risk: a great deal of AI use touches no personal information at all. Asking Claude to help you think through your pricing, using Gemini to research what competitors are charging, generating a marketing image in ChatGPT, drafting a social media caption — none of that involves anyone's personal data. POPIA has nothing to say about it.

The rules kick in when real people's details are involved.

The issue nobody thinks about: your data leaves the country

Here's the one that catches people out.

When you paste something into ChatGPT or Claude, that information is processed on servers outside South Africa. POPIA has specific provisions governing the transfer of personal information across borders — and most small business owners have never considered that pasting a client list into a chatbot is, legally speaking, a cross-border data transfer.

This doesn't mean you can't use these tools. It means you should be deliberate about what you put into them.

Five practical rules that solve most of it

You don't need a compliance department. For a small business, most of the risk disappears with a handful of habits.

1. Anonymise before you paste.

If you want AI to help analyse your customer list, strip the names first. "Customer 1, Customer 2" works just as well for spotting patterns as real names do. The AI doesn't need to know who they are to be useful.

2. Use initials, not full names.

Drafting a message to a specific client? Write "draft a payment reminder for a client who is 30 days late" — not "draft a payment reminder for Thabo Mokoena at 42 Church Street."

3. Never upload identity documents.

ID copies, passports, birth certificates, proof of address. There is almost no business task where uploading these to a chatbot is necessary, and it's the highest-risk thing you could do.

4. Be especially careful with children's and health data.

If you run an ECD centre or a health-adjacent service, this category deserves extra caution. Don't put children's names, medical details, or family circumstances into AI tools.

5. Know what the tool does with your input.

Some AI tools use what you type to train their models by default; some don't; many let you turn it off in settings. Check the setting on whichever tool you use, and turn training off if the option exists.

A separate warning: marketing messages

This one isn't about AI directly, but it catches small businesses constantly, and AI makes it easier to get wrong at scale.

Amended POPIA regulations that took effect on 17 April 2025 tightened the rules on direct marketing, requiring written consent before sending unsolicited electronic communications. Enforcement attention on electronic direct marketing has been increasing.

The practical implication: using AI to generate a marketing campaign is completely fine. Using it to blast that campaign to a list of people who never agreed to hear from you is where the risk sits — and that risk exists whether a human or an AI wrote the message.

Why this matters more than it used to

South Africa's Information Regulator has been actively focused on data breaches. Reported security compromises between April and September 2025 numbered 1,607 — around a 60% increase on the previous year. A mandatory reporting tool went live in April 2025 to streamline how breaches get reported.

The direction of travel is clear: more attention, more reporting, more enforcement. Small businesses that build good habits now are simply better positioned than those who deal with it after something goes wrong.

What this means for a township or small business specifically

There's an honest point worth making here. Compliance conversations in South Africa are usually pitched at businesses that can afford a compliance officer. That framing leaves out most of the country's actual businesses — and it creates a real problem, because fear of getting it wrong stops people from adopting tools that would genuinely help them.

The realistic position for a small business is this: you are not expected to build a corporate data governance framework. You are expected to be careful with other people's information. For most small businesses, the five habits above cover the overwhelming majority of the practical risk.

Being cautious about what you paste into a chatbot costs you nothing. Avoiding AI entirely because you're unsure about the rules costs you a great deal. If you're still weighing the broader compliance picture, our guide on township business registration is a good companion read, and the free business diagnostic will tell you where compliance sits relative to the other gaps in your business.

How kasiAIhub handles this

Compliance runs through the kasiAIhub programme rather than sitting in a separate module. In Session 1, entrepreneurs build a compliance checklist specific to their business type using Claude — and part of that work is understanding what information their business actually holds, and how to use AI tools safely with it.

The approach throughout is the same as this article: practical habits over paperwork, and confidence over fear. You should finish the Entrepreneur AI Journey using AI more, not less — just deliberately.

See how compliance is covered in Session 1 →

Frequently asked questions

Is it illegal to use ChatGPT or Claude in a South African business?

No. There is no law prohibiting the use of AI tools in South Africa. POPIA governs how you handle personal information when using them — which is a rules-for-use question, not a ban.

Does POPIA apply to my small business, or only to big companies?

POPIA applies broadly to organisations processing personal information, not only to large companies. The practical obligations scale with what you actually do, but the law is not limited to businesses of a certain size.

Can I paste my customer list into an AI tool?

It's safer to anonymise it first — remove names and identifying details, then paste. You'll get the same analytical benefit without transferring identifiable personal information to servers outside South Africa.

Is South Africa getting an AI law?

Not immediately. The Draft National AI Policy was published in April 2026 and withdrawn shortly afterwards, and the timeline has extended beyond 2026. The current expectation is that existing laws like POPIA will be strengthened to address AI, rather than a standalone AI Act being introduced.

What happens if I get this wrong?

POPIA provides for enforcement action by the Information Regulator. Rather than focusing on worst-case penalties, the practical takeaway is that most small business risk is addressed by basic caution about what personal information you share with AI tools. If you're concerned about your specific situation, speak to a qualified attorney.

Sources

Michalsons commentary on South African AI policy and POPIA (April 2026); DLA Piper analysis of the withdrawal of South Africa's Draft AI Policy (May 2026); Werksmans Attorneys, South Africa's Data, AI and Cybersecurity Outlook 2026; HRSpot guidance on POPIA-aligned workplace AI policy (2026).

This article provides general information only and does not constitute legal advice.