Tech & Legal Updates
Short, executive level legal and commercial updates for founders and leaders of scaling technology businesses.
POPIA Compliance Foundations for AI and Data-Driven Products
POPIA compliance remains foundational for AI and data-driven products. The Protection of Personal Information Act 4 of 2013 mandates lawful processing, purpose limitation, security safeguards, and regulated cross-border transfers. As POPIA gives effect to section 14 of the Constitution, privacy is a rights-based compliance obligation. Scaling technology businesses must embed these requirements into data architecture, consent design, and international hosting arrangements to reduce enforcement exposure.
Why a rights-based framing changes the analysis
Compliance regimes built on a constitutional right behave differently from those built purely on statute. Obligations tend to be interpreted purposively rather than narrowly, which means a technically defensible reading that defeats the purpose of the protection is a weaker position than it looks. For a business deploying AI on personal information, that has a specific consequence: purpose limitation is the constraint most likely to bind, and it is the one most often overlooked at the architecture stage.
Training a model on data collected for a different purpose is the clearest example. It is rarely a deliberate decision. It is usually a downstream use of a data set that was lawfully collected for something else.
What to check
- Whether personal information used to train or fine-tune a model was collected for that purpose, or repurposed.
- Whether consent language covers the AI use specifically, or covers processing in terms broad enough to be arguable.
- Where model training, inference and hosting physically occur, and whether the transfer position was ever assessed.
- Whether a data subject could be given a meaningful account of how an automated decision about them was reached.
Where this lands in the contract
Operator agreements are where this typically fails. Standard terms address security and breach notification well, and address purpose limitation for AI use barely at all. Where a vendor processes personal information through an AI system, the agreement should state whether that data may be used for model training, whether outputs derived from it may be retained after termination, and what happens to a model that has already learned from it.
