POPIA Checklist: Before You Share Data with an AI Tool

A POPIA checklist for AI tools: 12 questions to answer before you upload customer or staff data to ChatGPT or any AI app, from minimisation to transfers.

· 4 min read · Summarix team

Before you share data containing personal information with an AI tool, check that you have a lawful purpose, that you are sharing only what the task needs, that the provider will keep it secure under a written agreement, and that any transfer outside South Africa meets POPIA’s conditions. The easiest way to reduce risk is to remove or mask personal information first. The checklist below turns that into twelve practical questions.

This is general information about POPIA, not legal advice. For guidance on your circumstances, consult a legal professional or the Information Regulator.

Why AI tools need a POPIA check

When you upload a spreadsheet or paste customer emails into an AI app, the provider processes that data on your behalf. Under POPIA, you remain the responsible party, and the provider is an operator. You are accountable for making sure it is handled lawfully, even when it is on someone else’s servers. Staff often do this informally, which is why a simple, written check helps.

Part A: Purpose and minimisation

  1. Do I know exactly what I want the AI to do? Write it in one sentence, for example ‘summarise March sales by region’.
  2. Does the task need personal information at all? Most summaries, trend analysis and reporting do not.
  3. Have I removed columns I don’t need? Names, emails, phone numbers, ID numbers, addresses, dates of birth and bank details are the usual suspects.
  4. Have I checked free-text fields? Notes, comments and transcripts often hide personal details.
  5. Is any special personal information involved? Health, religion, race, biometrics or criminal records need far stricter handling; keep them out unless you have a clear lawful basis and advice.

Part B: The provider

  1. Is this a business account or a personal one? Business terms usually give you more control than consumer accounts. Use the account type your organisation has approved.
  2. What do the terms say about using my data? Read whether your inputs may be retained or used to improve the provider’s models, and whether you can opt out.
  3. Is there a written agreement covering security? POPIA expects a written contract with an operator requiring it to maintain appropriate security measures.
  4. Where is data processed? If outside South Africa, POPIA’s cross-border transfer conditions apply, such as the recipient being subject to adequate protection, or consent, or the transfer being necessary for a contract.

Part C: Access and aftercare

  1. Who can see the results? Check sharing settings, workspace members and roles.
  2. Is sign-in protected? Two-factor authentication should be on for any tool holding business data.
  3. Can I delete the data and outputs when I’m done? Know how, and do it.

Worked example: preparing a customer file

Say you want an AI tool to find which customer segments bought more in the last quarter. Your export has 8,000 rows with name, email, cellphone number, ID number, suburb, date of birth, order date and order value. Before uploading:

  1. Delete name, email, cellphone and ID number; replace them with a customer number from your system.
  2. Convert date of birth to an age band, then delete the original column.
  3. Replace suburb with province or city if that is detailed enough for the question.
  4. Keep order date and order value, which carry the actual answer.

The resulting file still answers the business question, but it would reveal very little about any individual if it leaked.

A quick decision table

SituationSuggested approach
Aggregated sales or finance figures, no customer detailsGenerally low risk; still use an approved business tool
Customer list needed only for counts or segmentsReplace names and contact details with IDs or remove them first
Support tickets or call transcriptsRedact names, numbers and addresses; prefer tools that mask automatically
HR data, health or other special informationDon’t upload without legal advice and a clear lawful basis
You are unsureAsk your Information Officer before uploading

Tools that build the checklist in

Manual masking works but is easy to forget. Some tools do part of it for you. Summarix, for example, removes sensitive columns (emails, phone numbers, ID numbers, card and bank numbers, addresses, dates of birth, passwords) and scans free text for items like SA ID and card numbers before any AI call. The AI sees a statistical profile and a masked sample of at most 15 rows, not the whole file; the numbers are computed by Summarix’s own code. Workspaces support Owner/Admin/Editor/Viewer roles, an audit log, optional two-factor sign-in, and data export and account deletion from settings.

Whatever tool you use, the checklist still applies: automatic masking reduces risk, but you are still responsible for deciding what to upload and why. For a broader framework, see POPIA-compliant data analytics, and for a comparison of general chatbots with purpose-built tools, see ChatGPT vs an AI reporting tool.

Analyse your data with personal information masked before the AI sees it.

Free plan: 5 AI reports a month, no card needed.

Make it a team rule

Print the twelve questions, agree which AI tools staff may use, and add a one-line rule to your policies: ‘No personal information goes into an AI tool unless the task needs it and the tool is approved.’ Review it once a year, or whenever you adopt a new tool.

Frequently asked questions

Can I use ChatGPT with customer data under POPIA?

Only with care. The provider acts as an operator, so you need suitable terms and security, and cross-border transfer conditions apply. The safest approach is to remove or mask personal information before uploading.

Is an AI provider an operator under POPIA?

Generally, yes, when it processes personal information on your behalf. You remain the responsible party and must ensure a written agreement covers security.

What personal information should I remove before using AI?

Names, email addresses, phone numbers, ID and passport numbers, physical addresses, dates of birth, and bank or card details, plus anything similar hidden in free-text fields.

Does masking data make it exempt from POPIA?

Not necessarily. Data that can reasonably be re-identified is still personal information, but masking greatly reduces the risk if something goes wrong.

Keep reading