30/09/2026
If you're using AI tools that touch customer data, POPIA applies. Full stop.
But here's the problem: most AI vendors (especially global ones) don't understand SA data protection law. And most SA companies using AI haven't thought through the POPIA implications.
Here's what you need to know:
1. Consent must be specific "we use AI to improve our services" is not valid consent under POPIA
2. Data minimisation applies your AI tool shouldn't ingest more data than it needs
3. Cross-border data transfer rules apply if your AI vendor processes data outside SA, you need safeguards
4. Automated decision-making has limits Section 71 gives individuals the right to challenge decisions made solely by AI
5. Your Information Officer must understand the AI tools in use ignorance is not a defence
This is exactly the intersection we work in at RAHN. Our AI tools are built for SA regulatory frameworks from day one not retrofitted after the fact.
Save this post. Share it with your legal team.
What POPIA + AI questions keep you up at night?