CAI Systems · Compliance 7 October 2026

Is your AI chatbot POPIA compliant? Five questions to ask your supplier

A chatbot isn't compliant or non-compliant on its own — you are the responsible party. Five questions that separate a supplier who has thought about it from one with a badge on a sales page.

Can a chatbot be POPIA compliant?

Not by itself. POPIA regulates how an organisation processes personal information, so compliance is a property of your whole arrangement — what the bot collects, why, where it goes, who can reach it — not a feature a supplier can switch on.

This matters because of how the duty is allocated. Under the Protection of Personal Information Act, the business whose customers are talking to the bot is the responsible party. A supplier who builds and runs it is an operator, processing on your behalf. If the arrangement leaks, the Regulator's first conversation is with you.

So "is this chatbot POPIA compliant?" is the wrong question to put to a vendor. The useful one is: what have you done that I can check, and what will I have to explain if it goes wrong?

What does section 19 actually require?

Appropriate, reasonable technical and organisational measures to prevent loss of, damage to, or unauthorised access to personal information. The Act deliberately doesn't list the measures, because what is appropriate for a dentist differs from a bank.

Section 19 asks you to identify reasonably foreseeable risks, establish safeguards against them, verify the safeguards are implemented, and keep them updated. Four verbs, no checklist.

That vagueness is the point and it is also the loophole. A supplier can say "POPIA compliant" on a sales page without ever naming a safeguard. The Act gives you no definition to hold them to — but it does give you a test. If you cannot describe the measures, you have not verified them, and section 19 asked you to.

Five questions to ask before you sign

Ask what the bot collects, where it is stored, what it is allowed to say, how the supplier holds access to your systems, and what happens to that access when the relationship ends. The fourth is where most suppliers have never been asked anything.

1. What does it collect, and does it need to?

Minimality is a POPIA principle: collect what is adequate and relevant, not everything available. A chatbot that logs full conversations is collecting personal information whether it meant to or not — people type their names, their phone numbers, sometimes their ID numbers, into a text box without being asked.

Ask what is retained, for how long, and whether a customer can have it deleted. A supplier who has never considered deletion has not built for this.

2. Where does the data live, and does it leave South Africa?

Section 72 restricts transferring personal information outside the Republic unless certain conditions are met — most commonly, that the destination has comparable protection. The EU, under GDPR, generally qualifies. Many hosting defaults put your database in Ireland or Virginia without anyone deciding to.

This is usually fine. It is not fine to be unable to say where the data is. Ask for the region, in writing.

3. What is the bot allowed to say?

Less a POPIA question than a liability one, but it belongs on the list. A bot that can quote a price it invented, promise a delivery date, or accept a complaint has made representations your business must honour. Ask where the boundary is and how it is enforced — in a prompt, or in code the model cannot argue with.

4. Where do you keep the keys to my systems?

This is the one that gets blank looks.

To build anything useful, a supplier needs access: to your website, your WhatsApp number, your analytics, sometimes your database. That access is usually a long string called an API key, which does not expire and grants whatever it was issued for.

Ask where those keys live. The honest answers range widely:

AnswerWhat it means for you
"In our password manager, access-controlled"Reasonable. Ask who on their team can read it.
"In the project's environment variables"Normal and defensible, if the hosting account is locked down.
"It's in our shared drive / a WhatsApp message / a spreadsheet"A reportable breach waiting to happen, on your watch.
"There isn't one"Worth understanding — see below.

That last answer is newly possible. Since mid-2026 the major AI platforms support workload identity federation, where a server proves which deployment it is rather than presenting a stored secret, and receives permission that expires in minutes. There is no key to store, lose, or hand back.

It is not available everywhere — the hosting platform has to support it, and most shared cPanel hosting does not. So "there isn't one" is a good answer, not the only acceptable one. What you are testing is whether the supplier has thought about it at all.

5. What happens to that access when we stop working together?

Ask it before you start, because afterwards it is awkward. A supplier should be able to describe revocation in one sentence: which credentials exist, who revokes them, and how you confirm it happened.

"We'll delete our copy" is not revocation. A key that has been copied cannot be un-copied; it can only be replaced. If the supplier cannot tell you how to rotate the keys they hold, you are relying on their goodwill indefinitely.

Why this one matters more than the compliance badge

Because section 22 puts the notification duty on you. If a supplier's leaked key exposes your customers' information, you must notify the Information Regulator and every affected person — not the supplier who leaked it.

Section 22 requires notification as soon as reasonably possible after discovering a compromise, to the Information Regulator and to the data subjects themselves, in writing. The notice must describe the possible consequences and what you are doing about it.

Read that as a business owner rather than a lawyer. A credential your supplier pasted into the wrong window becomes a letter you write to your own customers. That is the risk you are actually managing when you ask question four, and it is why a badge on a sales page is not an answer.

Common questions

Does using an overseas AI model break POPIA?
No. Sending text to a model abroad is a cross-border transfer under section 72, which is permitted when the recipient is subject to comparable protection, or the data subject consents, or it is necessary to perform a contract with them. What matters is that you can describe the arrangement and that it is in your operator agreement.

Do I need a written contract with my chatbot supplier?
Yes. Section 21 requires a written agreement with any operator processing personal information on your behalf, obliging them to maintain the security measures in section 19. A verbal arrangement with a developer does not satisfy it.

Is a chatbot that collects no personal information exempt?
In principle, but it is harder than it sounds. People volunteer personal information into free-text boxes unprompted. If conversations are stored at all, assume personal information is in them and plan for retention and deletion.

What is an API key, in plain terms?
A long password that a program uses instead of a person logging in. It usually does not expire and cannot be limited to one task, which is why where it is kept matters so much.

Who is the Information Officer for a small business?
By default, the head of the organisation — the owner, CEO or equivalent — unless someone else is formally designated. Registration with the Information Regulator is required. For a one-person business, that is you.

Running these five questions past your own setup.

CAI Systems builds automation and AI agents for South African businesses, on the client's own accounts, with the access handed over and documented. If you want a straight answer about what your current arrangement exposes, ask the assistant on this page or have us test it.

Test my response time See what it costs

Ask us about your own setup

Not sure what your current supplier can reach?

Most businesses cannot name the credentials their suppliers hold, which is the part POPIA section 19 asks you to have verified.

The assistant on this page answers from our real price list and will put a written quotation together. It fetches a person the moment there is actually something to decide.

Sources

One email, when there is something worth sending.

Research notes on AI visibility, automation and cash flow for South African businesses. No schedule, no filler.

What should we send you?

We only use this to send what you ticked. See Legal & POPIA.