Insights · 27 September 2026

AI agents and POPIA: using AI on customer data in South Africa without breaking the rules

You can use AI agents on customer data in South Africa. The agent has to stay inside the purpose the data was collected for, a person has to make any decision that seriously affects a customer, and the data has to stay in the country or leave on one of the grounds in section 72. Add a written contract with every AI vendor and a breach plan, and you have covered most of what POPIA asks of an agent.

What POPIA asks of any processing, agents included

Section 4(1) of POPIA sets eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation. An AI agent is one more way of processing personal information. All eight apply to it, exactly as they apply to a clerk with a spreadsheet.

Two of them bite first. Section 15 says further processing must be compatible with the purpose the data was collected for. A dealer's phone number collected to deliver an order is not automatically free for an agent that scores dealers for a sales push. Section 19 asks for reasonable technical and organisational measures against loss and unlawful access. An agent with read access to the whole customer database is exactly the kind of foreseeable risk section 19(2) tells you to identify.

Section 71: the agent recommends, a person decides

Section 71(1) says a person may not be subject to a decision with legal consequences, or one that affects them to a substantial degree, based solely on automated processing that profiles them. The Act names the profiles: performance at work, creditworthiness, reliability, location, health, personal preferences and conduct.

In a distribution business that list covers the agents people most want to build. An agent that cuts a dealer's credit limit, blocks an account for late payment or ranks field staff for a bonus is making that kind of decision if nobody reviews it.

Section 71(2) allows exceptions tied to a contract, or to a law or code of conduct that protects the person. Where you rely on the contract route, section 71(3) says the person must be able to make representations and must get enough of the underlying logic to do so. The simpler design is the one we build anyway. The agent flags the dealer and shows its evidence. A named person makes the call and records why.

Section 72: where the model runs

Section 72 stops a responsible party in South Africa sending personal information to a third party in a foreign country unless one of five grounds applies. The ones most businesses lean on are a recipient bound by a law, binding corporate rules or a binding agreement with protection substantially similar to POPIA's, the person's consent, or a transfer that a contract with the person needs.

Treat an agent that sends customer records to a model hosted in another country as a section 72 transfer until your legal adviser tells you otherwise. Special personal information and children's information go further. Under section 57(1)(d), sending them to a country without adequate protection needs the Information Regulator's prior authorisation.

The cleaner answer is to keep the processing at home. For a South African deployment we offer AWS Cape Town, Azure South Africa or your own premises, and we design so the model can be swapped without rebuilding the system around it. Which option you get is written into the engagement, not left to a settings page.

Your AI vendor is an operator, and a breach starts a clock

An AI provider that processes customer data for you is an operator under POPIA. Section 20 says it may process only with your knowledge or authorisation and must keep the information confidential. Section 21 says you need a written contract that makes it maintain the section 19 safeguards, and it must tell you immediately if it believes someone unauthorised has reached the data.

Section 22 then puts the duty on you. Where there are reasonable grounds to believe personal information was accessed or acquired by an unauthorised person, you notify the Information Regulator and the affected people as soon as reasonably possible. The notice to people is in writing. It describes the possible consequences, what you have done or will do, what they should do, and who the intruder is if you know.

The Information Regulator is the independent body section 39 sets up, accountable to the National Assembly. It can serve enforcement notices under section 95, and infringement notices with administrative fines of up to R10 million under section 109. Its own guide takes breach reports through its eServices portal, and only an organisation with registered information officers can file one. Register before you need to.

A checklist before an agent touches customer data

Run it with your information officer and your legal adviser before the agent sees a real record.

  1. Name the purpose. Write down what the agent is for, and check it against the purpose the data was collected for under sections 13 and 15.
  2. Limit what it reads. Give the agent the fields its one job needs, not the whole customer table.
  3. Keep a person on the decision. Any output that changes credit, access, pay or price goes to a named person who can see the evidence.
  4. Say where the data goes. List every place the agent sends data and, for each one outside South Africa, the section 72 ground you rely on.
  5. Sign the operator contract. Every model or tool provider gets a written contract covering section 19 safeguards and immediate notice of a breach.
  6. Check consent before any message. Section 69 allows marketing by SMS, email or other electronic means only with consent, or to an existing customer who could object when the details were collected and on every message since.
  7. Rehearse the breach. Register your information officer on the Regulator's portal and draft a section 22 notice before you need one.

How we would set it up

We start with one process and the number it should move. The agents on it flag and draft, and a person approves every move that touches money. Every agent is named, scoped to one job and switchable per business.

NeauraPrivPro is the consent register behind our own products. It checks a message against consent before it goes out, sends a withdrawal to every connected system, routes access and erasure requests against a deadline, and keeps an append-only record a regulator can read line by line. It was built for India's DPDP Act. For POPIA we would configure its request deadlines, notices and breach record with your legal adviser. It is a register and a workflow, not legal advice, and it reaches only the systems connected to it.

Sources

THE PROMISE

We stay until the ROI you were promised is the ROI you get.

Most projects fail after go-live, not before it: the software works and nobody uses it. So we do not stop at delivery. We advise, build, implement, operate, and only then transfer, with change management and adoption run as hard as the code.

ADVISE→BUILD→IMPLEMENT→OPERATE→TRANSFER
THE FORCE

A force of AI agents, on one framework that fits any business.

Named, scoped, switchable agents that read, reconcile, forecast, flag and draft, taking the work off your people’s desks and putting revenue back on your books. A person approves every move that touches money.

See the framework →

Read next: NeauraPrivPro · AI and agentic systems · Identity, security and privacy · South Africa · All insights