POPIA applies to your AI the moment it collects a name, a number or an email address — and it applies to you, not to your supplier. The Protection of Personal Information Act does not mention artificial intelligence anywhere, which is exactly why it catches people out: there is no separate AI rule to look up. The ordinary conditions apply, and a chatbot is simply a new place where you process personal information.
Does POPIA apply to AI chatbots?
Yes, whenever the system touches personal information. A bot that answers "what are your hours" and nothing else is not processing personal information. A bot that asks for a name and a phone number so somebody can call back is, and from that moment every condition in the Act applies to what you do with it.
The important part is who carries it. You are the responsible party. Your supplier is an operator acting on your instructions, and outsourcing the build does not outsource the accountability. Your Information Officer — by default the head of the business, and registrable with the Information Regulator — remains answerable for what the bot collected.
What are the eight POPIA conditions, briefly?
- Accountability. Somebody in your business is responsible. Named, not implied.
- Processing limitation. Collect it lawfully, minimally, and with a justification — usually consent or legitimate interest.
- Purpose specification. Collect it for a stated reason, not because it might be useful later.
- Further processing limitation. Do not quietly reuse it for something else.
- Information quality. Keep it accurate and current.
- Openness. Tell people you are collecting it and why.
- Security safeguards. Protect it, and report a breach.
- Data subject participation. People can ask what you hold and require you to delete it.
Where does AI break POPIA in practice?
Rarely through anything exotic. Almost always through one of these five.
- Collecting more than the purpose needs. A bot that asks for an ID number to book a haircut has failed the processing limitation before anybody looks at the technology.
- Consent that is not really consent. A privacy policy linked in the footer is not consent for a chat window to capture a phone number. Say what you are collecting, in the chat, at the moment you collect it.
- Transcripts nobody thought about. Conversation logs are personal information. They need a retention period, and somebody has to know where they live and how to delete one.
- Training on customer data by default. Find out whether your supplier or their model provider uses your conversations to train on. It is a contract term, and it is not always off.
- No deletion path. A customer exercising their right to be forgotten is a routine request. If nobody can answer it in a day, the system is not compliant regardless of what the brochure says.
What does compliant AI deployment actually look like?
Six practical things, none of them expensive if they are decided before launch rather than after.
- The bot says what it collects and why, in the conversation, before it collects it.
- It asks for the minimum — usually a name and one contact detail.
- Transcripts have a stated retention period and somebody who can delete one.
- Your privacy policy actually mentions the chatbot, by name.
- Your operator agreement with the supplier says what they may and may not do with the data.
- Your Information Officer knows the system exists. This one is skipped more often than any of the others.
Which POPIA condition does each AI mistake break?
| What the deployment does | Condition it breaks | The fix |
|---|---|---|
| Collects a symptom description to book an appointment | Minimality | Ask for a name, a number and a time. Nothing else |
| Says nothing about what it is collecting | Openness | One plain line before the first message |
| Emails a list you bought or scraped | Section 69, direct marketing | There is no fix. Do not send it |
| Keeps conversations indefinitely | Retention | Set a period, and be able to delete on request |
| Pools customer data with other businesses' | Security safeguards | Data in the client's own account, separated |
| Invents an answer about a person's record | Information quality | Ground it, and let it refuse |
| Sends data to a processor with no agreement | Operator obligations | A written operator agreement, before you switch on |
The Act itself is short enough to read and is published by the Department of Justice: Protection of Personal Information Act 4 of 2013. The Information Regulator is the body that enforces it and publishes guidance notes. Neither is behind a paywall, and both are better sources than any vendor page — including this one.
What about cross-border data flow?
This is the detail most businesses miss, and it is the one that separates suppliers. Section 72 restricts sending personal information outside South Africa unless the recipient is subject to comparable protection, or the person consented, or it is necessary for the contract.
Almost every AI system sends text to a model hosted abroad. That is not automatically a breach — the exceptions are real and commonly relied on — but it is a decision you are making, and you should know you are making it. Ask any supplier three questions: where conversation data is stored, which model provider processes it, and what their retention terms are. A supplier who cannot answer those in one sentence each has not thought about it.
Who is liable if the AI gets it wrong?
You are, to the customer. That is uncomfortable and it is worth stating plainly, because it changes what you should ask for. It is why a bot must be grounded in your own content rather than answering from general knowledge, why it should refuse rather than guess, and why the handover to a person has to work. A confidently wrong answer about a price or a policy is your answer, in law and in the customer's mind.
Is there good news here?
Quite a lot of it. A well-built AI system is usually more POPIA-defensible than the process it replaces, because everything is written down. A structured chat log with a retention policy is easier to audit, search and delete than a WhatsApp thread on a staff member's personal phone, a notebook at reception, or a spreadsheet emailed between three people. Most South African small businesses are not moving from compliant to risky — they are moving from undocumented to documented.
POPIA does not have an AI chapter, and that is the point. A chatbot is a new place where you process personal information, and the ordinary rules were always going to apply to it.
What should I do before switching one on?
Write down four things: what the bot will collect, why, how long you keep it, and who deletes it on request. If you can answer those, you are ahead of most deployments. Everything DoubleDown AI builds is POPIA-aligned by design and the data stays in your own account — the privacy policy and the data rights page set out exactly what that means in practice.
This is a plain-English summary, not legal advice. If your business handles health, financial or children's data, take proper advice before deploying anything.
Where we do this
The same build runs for businesses in Kimberley, Mahikeng and Gqeberha, and the city pages set out what changes locally — the languages, the trading hours and the sectors that dominate. Everything is deployed and supported remotely from Vanderbijlpark.
