AI Guide by Zaiq

AI for SA business

POPIA-compliant AI tools for South African business

You can have the speed of AI without handing your customers’ personal information to a black box. The difference is almost entirely the tool you choose and how you set it up. There is no such thing as a “POPIA-certified” AI, so compliance is something you assemble, not something you buy off a badge. Here is what a defensible setup actually looks like, and the realistic options for a South African business.

What “POPIA-compliant” actually means for an AI tool

POPIA never names a tool as approved. Compliance comes from the contract and the controls around the tool, so demand all of the following before personal information goes anywhere near it.

What to demandWhy it matters under POPIA
A signed DPA, with the vendor as your operators19: an operator may process only on your instructions and must keep the data secure. The DPA is what binds them.
No training on your inputsStops your customers’ data being absorbed into a model you cannot control or delete from.
Configurable retention and deletionYou decide how long data is kept and can have it removed, which the security and minimality duties expect.
Access controls19 reasonable security: only the right people and systems should reach the data.
A defensible cross-border basiss72: a US or offshore vendor is a transborder flow, lawful only with adequate-protection terms (usually via the DPA), consent, or contractual necessity.
A processing record you keepAccountability: be able to show what the tool touches, why, and on what basis.

Free vs Enterprise: the difference that matters

The gap between the free tab and the paid tier is not features, it is what happens to your data. Consumer tiers are built for individuals and may use what you type to improve the model by default. Business tiers are built for organisations bound by laws like POPIA, so they switch that off and put a contract behind it.

The realistic options for a SA business

You do not have to pick one tool for everything. Match the tier to the sensitivity of the work.

OptionBest forThe POPIA catch
Consumer tools, personal data stripped outDrafting, brainstorming, general questions with no real personal informationDiscipline-dependent: one pasted ID number breaks it. De-identify so it cannot be re-identified (s6); reversible pseudonymisation does not count.
ChatGPT Team / Enterprise or the API, training off, DPA in placeDay-to-day work that touches customer dataYou must actually sign the DPA and confirm training is off and retention is set. Verify the plan’s current terms.
Microsoft Copilot or Google Gemini business tiersBusinesses already on Microsoft 365 or Google WorkspaceUse the business or enterprise tier with its DPA, not the free version. Terms vary by tier and change.
Private or locally-hosted open modelsThe most sensitive work: health, financial, legal, large personal datasetsMore setup and cost, but the data never leaves your control, which sidesteps the s72 transborder question entirely.

Tiers, plan names and terms change often. Treat the table as the shape of the decision, not a frozen spec, and verify the current terms of whatever you actually buy.

What to check before you sign up

Before you put any customer data into a new tool, do a short vendor vet. It takes minutes and saves a lot.

  1. Read the data terms. Find what the vendor does with your inputs, in their own words, not a summary.
  2. Confirm no training. Make sure the plan does not learn from your data by default, and that it stays off.
  3. Get the DPA. Without it, the vendor is not your operator under POPIA and you carry the risk alone.
  4. Check retention. Know how long data is kept and whether you can shorten that or delete on demand.
  5. Check sub-processors and location. See who else touches the data and where it sits, so your s72 basis holds.

Where Zaiq fits

We are an AI engineering studio in South Africa, and building the compliant setup is part of the job, not a bolt-on. We pick the right tier for the work, get the DPA in place, keep personal information out of public tools, stand up private deployments for the sensitive cases, and leave you with a clean processing record you can show. We have built this where the data could not sit in a public tool: a wholesaler’s entire operating system keeps sensitive client and pricing data inside private, controlled software, never pasted into a consumer AI. Safe is a build decision, not a disclaimer. Bring us the use case at zaiq.ai/work and we will tell you straight what a POPIA-safe setup looks like for it.

This is general guidance, not legal advice. For a high-risk or consequential processing decision, confirm with a POPIA practitioner.

Questions people ask

What makes an AI tool POPIA-compliant?

There is no POPIA certification, so it is the setup, not the logo. A defensible one has a signed data processing agreement making the vendor your operator (s19), a commitment not to train on your inputs, configurable retention and deletion, access control, a lawful cross-border basis under section 72, and a record of what the tool processes. Get those and the tool is on solid ground.

Is free ChatGPT or ChatGPT Enterprise better for POPIA?

Enterprise, for any work touching personal information. As of 2026, consumer ChatGPT may train on your conversations by default unless you turn it off, while ChatGPT Team, Enterprise and the API do not train on business data by default and offer a DPA with limited, configurable retention. Verify the current terms of the specific plan, as they change.

What is a Data Processing Addendum (DPA) and do I need one?

A DPA is the contract that makes the vendor your operator under POPIA and sets out security, retention, sub-processors and transfer safeguards (s19, s72). If a tool processes any personal information on your behalf, especially across borders, you need one. Without a DPA the vendor is not bound as your operator and you carry the exposure as the responsible party.

Are Microsoft Copilot and Gemini for Business POPIA-compliant?

Their business and enterprise tiers are built for this. As of 2026, Microsoft Copilot and Google Gemini offer business tiers with a DPA and commitments not to train on enterprise data. The exact terms vary by tier and change, so do not assume the free version behaves the same. Confirm the DPA, training stance and retention for the specific plan you buy.

Do I have to keep AI data inside South Africa?

No. POPIA does not require data to stay in the country. Section 72 lets personal information leave South Africa if the recipient is bound by substantially similar protection, the data subject consents, or it is necessary for a contract with or for them. A US AI vendor processing your data is a transborder flow, and a DPA with adequate-protection terms is how you meet section 72.

Can a small business afford a POPIA-compliant AI setup?

Yes. The cheapest defensible route costs nothing extra: use consumer tools but strip personal information out before you ask. Beyond that, paid Team or API tiers with a DPA and training off are within reach of most businesses, and you only need private deployments for genuinely sensitive work. Compliance is mostly discipline plus the right tier, not a big spend.