AI for SA business
Is it legal to use AI for SARS and tax data in South Africa?
The appeal is obvious: AI is genuinely good at summarising messy financials, reconciling figures and drafting the boring parts of a return. The catch is just as real. Tax data is some of the most sensitive information you hold, and a return is a dossier of personal detail. Here is the plain version of what the law allows and how to do it safely.
The three laws that apply
Tax data does not sit under one rule. It sits under three at once, and you have to satisfy all of them.
| Law | What it covers | Why it matters for AI |
|---|---|---|
| POPIA (Act 4 of 2013) | The personal information inside the return: ID number, income, banking, often special personal information | Typing a return into an AI tool is processing personal information, so the Act’s duties apply in full |
| Tax Administration Act (2011) | Taxpayer secrecy on SARS officials regarding taxpayer information (Chapter 6) | SARS is bound by secrecy on its side; for you, the day-to-day duties are POPIA plus confidentiality |
| Professional confidentiality | Tax practitioners registered with a Recognised Controlling Body and with SARS owe clients confidentiality | A data leak is both a POPIA matter and a professional-conduct matter |
Why pasting a tax return into ChatGPT is risky
A tax return is full of personal information: ID number, income, banking details, often special personal information. Three things go wrong when it lands in a public chatbot.
- It is personal information under POPIA. Processing it means the Act’s duties apply, including security under section 19.
- It is a cross-border transfer. A US-based AI service processes the data outside South Africa, which is a transborder flow under section 72, allowed only with adequate-protection terms, consent, or contractual necessity.
- The tool may retain or train on it. Consumer tools can store inputs and use them to improve the model, putting the data somewhere you cannot control.
What SARS actually says (and doesn’t)
It is worth being honest here, because there is a lot of confident nonsense online. There is no public SARS rule that “permits” putting client tax data into public AI tools, and no public SARS ruling or guidance note that specifically bans it either. SARS is itself bound by taxpayer secrecy under the Tax Administration Act, on its own handling of taxpayer information.
So do not look for a SARS policy to lean on, in either direction. Your obligations come from POPIA and from the professional confidentiality you owe your clients, and those apply regardless of what any tool’s marketing says. Treat the absence of a SARS rule as a reason to be careful, not a green light.
The compliant way to use AI on financial data
You can use AI on financial work and stay defensible. The pattern is consistent.
- De-identify first. Under POPIA, data de-identified so it cannot be re-identified falls outside the Act. Strip the name, ID number and account numbers before you ask. Note that reversible masking does not count: if it can be undone, it is still personal information.
- Or use an Enterprise or API tool with a data processing agreement. Where you need the real data, use a deployment that offers a DPA, limited retention, and training switched off, rather than the consumer app.
- Keep a processing record. POPIA’s accountability duty means you should be able to show what AI touches, why, and under what terms.
- Keep a human reviewing the output. AI drafts; a person checks. This protects accuracy and keeps you accountable for the result.
For accountants and tax practitioners specifically
For a registered practitioner, confidentiality is not a nice-to-have, it is a professional obligation that runs through your Recognised Controlling Body and your SARS registration. That raises the stakes: a leak of client data is a POPIA matter and a professional-conduct matter at the same time, and POPIA enforcement can reach fines while the Information Regulator can issue enforcement notices.
Practical guardrails for a practice:
- A written rule that identifiable client data never goes into a public AI tool. Make it explicit so a junior does not “just ask ChatGPT”.
- A de-identification habit for anything you do run through AI, with masking that cannot be reversed.
- One sanctioned tool with a data processing agreement, rather than whatever each person happens to use.
- A short processing record so you can show a client, or the Regulator, what you do and why.
- Human review on every output that informs a client’s filing or position.
Where Zaiq fits
We are an AI engineering studio in South Africa, and we build AI workflows for financial and tax work with the data handled safely: private or Enterprise deployments rather than the consumer app, de-identification built into the pipeline, a data processing agreement in place, a clean record of what the system touches, and a human in the loop on the output. We do not sell AI for its own sake; we solve the problem and AI is how, safely. If you want the speed on your books and returns without the confidentiality risk, bring us the problem at zaiq.ai/work and we will tell you straight what safe looks like for your practice.
This is general guidance, not legal or tax advice. For a specific compliance decision, confirm with a POPIA practitioner or your Recognised Controlling Body.
Related guides
Questions people ask
Can a tax practitioner use ChatGPT with client data?
Not the public consumer version with identifiable client data. A practitioner owes professional confidentiality to clients and is bound by POPIA, and a leak is both a POPIA matter and a professional-conduct matter. De-identify the data first, or use an Enterprise or API tool with a data processing agreement and training switched off. When in doubt, do not paste the return.
Does SARS allow using AI tools for tax data?
There is no public SARS rule that permits, or specifically bans, putting client tax data into AI tools. SARS itself is bound by taxpayer secrecy under the Tax Administration Act. For a business or practitioner, the duties that bite day-to-day are POPIA and professional confidentiality, and those apply regardless of which tool you use.
Is sending tax data to ChatGPT a cross-border transfer?
Usually yes. A US-based AI service processes your data outside South Africa, which is a transborder flow under POPIA section 72. That is only allowed with adequate-protection terms, the person's consent, or where it is necessary for the contract. A consumer chatbot with no such terms does not satisfy section 72 for a client's personal information.
What law covers tax and financial data in South Africa?
Three layers. POPIA (Act 4 of 2013) governs the personal information inside a return. The Tax Administration Act of 2011 imposes taxpayer secrecy on SARS officials. And tax practitioners owe clients professional confidentiality through their Recognised Controlling Body and SARS registration. Tax data sits under all three at once.
How can accountants use AI safely?
De-identify first so the data cannot be re-identified, which under POPIA takes it outside the Act. Where you need real data, use an Enterprise or API tool with a data processing agreement and training switched off, keep a record of what you process and why, secure it with reasonable measures under section 19, and keep a human reviewing the output.
What are the risks of using AI for bookkeeping?
A client's books hold personal and financial information, so pasting them into a public AI tool can breach POPIA, count as a cross-border transfer under section 72, and may be retained or used to train the model. POPIA enforcement can reach fines and the Regulator can issue enforcement notices, and for a practitioner it is also a professional-conduct exposure.
Does using AI break taxpayer confidentiality?
It can. The Tax Administration Act binds SARS to secrecy; your own duties are POPIA plus the professional confidentiality you owe clients. Feeding identifiable tax data into a tool that retains or trains on it can breach that confidentiality. De-identifying the data, or using a private tool with a data processing agreement, keeps the duty intact.