The most common question we hear from financial planning practices and law firms is not "can AI do the work" but "are we allowed to put client information through it". The honest answer: yes, with the same discipline POPIA already demands of every other system that touches personal information. AI does not get an exemption, and it does not need one. Here is the map.
Who is who: responsible party and operator
Under POPIA, your firm is the responsible party: you decide why and how client information is processed. An AI provider processing that information on your instructions is an operator. Two duties follow. You may only use an operator who can secure the information properly, and you must have a written agreement obliging the operator to process only with your authorisation and to treat the information as confidential. If your AI tool's terms say your data may be used to train their models for other customers, that is processing beyond your authorisation; either switch it off contractually or do not use the tool for client data.
The conditions that do the work
- Purpose limitation and minimisation. Send the AI the slice of data the task needs, not the whole client file. A drafting agent needs the meeting notes and the relevant product data, not ten years of correspondence.
- Security safeguards (section 19). You must take reasonable technical and organisational measures: encryption in transit, access control, and knowing exactly which systems the data touches. This is where consumer chatbot accounts fail and properly configured business agreements pass.
- Cross-border transfers (section 72). Most serious AI providers process outside South Africa. That is permitted where the recipient is bound by an agreement providing substantially similar protection to POPIA, which is what a proper enterprise data processing agreement does. Check for it before you sign, not after.
- Special personal information. Health information (think medical aid and underwriting detail) and children's information carry stricter processing rules. If your workflows touch these, your AI workflows must respect the same limits.
- Notification and openness. Your privacy notice should reflect that client information is processed by service providers, including AI tooling, for the purposes clients already expect: producing their advice records, their reports, their matter documents.
The practical checklist
- Written operator agreement with the AI provider, covering confidentiality, security, and no training on your data.
- Confirm where processing happens and which section 72 ground covers it.
- Minimise: define per workflow exactly which fields and documents the AI receives.
- Access control: business accounts with named users, never shared consumer logins.
- Human review: a person signs off every output that reaches a client or a regulator.
- Records: log what was processed, when, and by which system, the same way you would for any operator.
How we handle it
Our managed agents are built on this model by default: each agent receives only the defined slice of data its workflow needs, processing runs under enterprise agreements with no training on client data, and every output crosses a professional's desk before it counts. The details are on our security page, and the FAIS side of the same question lives in our record of advice requirements guide.
POPIA is not the reason to avoid AI. It is the specification for using it properly, and practices that meet it get the efficiency while their competitors are still asking whether it is allowed.
Want the operator agreement, data-flow map and review workflow set up properly from day one? That is part of every build we do.
Book a free 15-minute call