If your staff have a browser, there is a fair chance someone has already pasted a customer email, a CV or a list of account balances into a public AI chat tool to get it summarised or rewritten. They were trying to do their job faster. The question for the business is whether it can account for where that information went, and whether it has met its obligations under the Protection of Personal Information Act (POPIA) while doing so.
Start with what is already happening
Many businesses do not have an AI problem yet. They have a visibility problem. Before writing a policy, find out which tools people use, what they use them for, and what kind of information goes in.
Ask openly and make it safe to answer. A blanket ban announced on a Monday does not stop use. It moves it to personal phones and personal accounts, where you can see even less. You want an honest picture, because the rest of this article depends on it.
Who is responsible, and when a vendor becomes an operator
Under POPIA, the responsible party is the one that decides why and how personal information is processed. For your customer and staff records, that is your business. It stays your business when an employee, acting in the course of their work, pastes that information into a tool you never approved.
An operator is someone who processes personal information on your behalf, under a contract or mandate, without coming under your direct authority. An AI provider that processes your data under a business agreement, on your instructions, will usually sit in this role.
The trouble starts with free, consumer versions of AI tools that a staff member signed up for with a personal email address. There is no contract between your business and that provider. Personal information you are responsible for has gone to a third party on terms you never agreed to. And if those terms let the provider use what it receives for its own purposes, it is not acting purely on your behalf at all.
The contract and the safeguards: sections 19 to 21
The written operator contract
Section 20 says an operator may process personal information only with the knowledge or authorisation of the responsible party, and must treat it as confidential. Section 21 requires the responsible party to ensure, in a written contract, that the operator establishes and maintains the security measures described in section 19. It also requires the operator to tell the responsible party immediately if there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person.
In practice, that means using a business or enterprise version of a tool, under an agreement your business has accepted, and reading that agreement for:
- processing only on your instructions, and confidentiality;
- the security measures the provider commits to;
- notifying you of a security compromise;
- return or deletion of your data when the agreement ends;
- which subcontractors the provider uses to process your data.
A staff member clicking “I agree” on consumer terms is not the same thing.
Security safeguards
Section 19 requires the responsible party to secure the integrity and confidentiality of personal information by taking appropriate, reasonable technical and organisational measures. That includes identifying foreseeable risks, putting safeguards in place, checking they work and updating them as risks change.
For AI tools, the practical questions are ordinary ones:
- Are staff using company accounts, or personal ones?
- Is sign-in protected with multi-factor authentication?
- Can an administrator see who has access, and remove it?
- Who can see chat history, and can conversations be shared by link?
- How long is history kept, and can you shorten that?
- When someone leaves, does their chat history leave with them?
That last one catches people out. A personal account full of customer details walks out of the door with the employee.
Training, data location and section 72
Two questions matter most when you read a provider’s terms.
Does it train on your data? Check whether your inputs are used to train or improve the provider’s models, whether that is switched on by default, whether you can switch it off for the whole organisation, how long inputs are kept and whether people at the provider may review them. Terms often differ between the consumer and business versions of the same product, and they change. Record which terms you read and when.
Where is it processed? Many AI tools process data outside South Africa. Section 72 restricts transfers of personal information to a third party in a foreign country. Broadly, a transfer is allowed where the recipient is bound by a law, binding corporate rules or a binding agreement that gives an adequate level of protection substantially similar to POPIA’s, or where another listed condition applies, such as the data subject’s consent or the transfer being necessary to perform a contract with them. Find out where the provider processes your data, and whether its agreement commits it to that level of protection. Do not rely on consent you collected for something else.
If something leaks: section 22
Where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, section 22 requires the responsible party to notify the Information Regulator and, unless their identity cannot be established, the affected data subjects. Notification must happen as soon as reasonably possible after the compromise is discovered, in writing, with enough information for people to protect themselves.
If you find that personal information went somewhere it should not have:
- Stop the activity, and make it safe for the person involved to report it.
- Record what was shared, with which tool, from which account and when.
- Delete what you can and ask the provider about deletion.
- Assess whether it amounts to a security compromise, with advice if you need it.
- Notify where required, and fix the cause so it does not happen again.
A simple policy and a one-page checklist
The policy
You do not need a long document. You need something staff can remember. A three-level rule works for most SMEs:
- Green: any approved tool. Public information, and your own drafts that contain no personal information.
- Amber: approved business tool only. Internal business information, and customer or staff personal information where the task genuinely needs it. Only in the tool your business has a signed agreement for, with training on your data switched off.
- Red: not in a general AI tool. Special personal information such as health or biometric data, identity numbers, bank details, children’s information, and anything covered by a confidentiality obligation. Only in a system approved specifically for that purpose.
Add a named owner, a short list of approved tools, a way to ask for a new one, and a no-blame route for reporting a mistake. People report mistakes when reporting is safe. They hide them when it is not.
The checklist
- We know which AI tools staff use, and for what.
- We have chosen approved tools and use business accounts, not personal ones.
- We have a written agreement with each provider that meets sections 20 and 21.
- Sign-in is protected, access is controlled, and leavers lose access.
- We have checked whether each provider trains on our data, and switched it off where we can.
- We know where each provider processes our data, and how section 72 is met.
- Staff know the green, amber and red rules.
- There is a named owner and a no-blame way to report a mistake.
- We know what we would do, and who we would notify, under section 22.
- We re-check provider terms at least once a year.
If you would like to work through where AI fits in your own business, safely and with the right controls, talk to us about an AI Operations Audit.