Legal News

Johannesburg High Court: POPIA Compliance Essential for AI Customer Interactions

South Africa·Briefly Analysis⏱️ 3 min read

Summary

  • Organisations using AI to interact with customers must ensure they can reconstruct how these interactions were created, reviewed, approved, distributed, and acted upon.
  • Failure to do so may expose them to non-compliance with POPIA.
  • The stakes are high, as a single inaccurate answer or inability to reconstruct an interaction can lead to severe consequences.

What's at Stake

Organisations using AI to interact with customers must ensure they can reconstruct how these interactions were created, reviewed, approved, distributed and acted upon. Failure to do so may expose them to non-compliance with POPIA.

Organisations using AI to interact with customers must ensure they can reconstruct how these interactions were created, reviewed, approved, distributed and acted upon. Failure to do so may expose them to non-compliance with POPIA. This is not just about capturing every messaging channel, but also about understanding the entire decision chain behind AI-generated customer communications. The stakes are high, as a single inaccurate answer or inability to reconstruct an interaction can lead to severe consequences.

The Fragmentation Problem

As organisations increasingly rely on multiple AI models and agents across various channels, fragmentation becomes a significant challenge. A customer interaction might begin in email, be summarised in Microsoft Copilot, rewritten in Claude Enterprise, approved in Microsoft Teams, completed on a call, and governed one piece at a time. Each new model becomes another integration, another policy set, and another evidentiary gap. This makes it difficult to capture the entire decision chain behind AI-generated customer communications.

Regulatory Landscape

The Protection of Personal Information Act (POPIA) in South Africa requires organisations to ensure that personal information is handled and processed in accordance with the law. Section 72 of POPIA allows personal information to leave South Africa only where an applicable basis exists, such as adequate protection in law or consent. However, when AI is involved, residency becomes harder to pin down due to multiple data movements triggered by a single interaction. Organisations must be able to reconstruct how AI-generated customer communications were created, reviewed, approved, distributed, and acted upon to ensure compliance with POPIA.

Practical Implications

Organisations using AI to interact with customers must implement robust governance and capture mechanisms to ensure that all interactions are recorded and reconstructed. This includes capturing records from various AI models and agents, as well as logs and metadata from sub-processors. Smarsh currently captures records from ChatGPT Enterprise, Microsoft Copilot, and Claude Enterprise, but the available content varies by platform and API.

Practical Implications

Organisations using AI to interact with customers must ensure they can reconstruct how these interactions were created, reviewed, approved, distributed and acted upon, as failure to do so may expose them to non-compliance with POPIA.

Source

Source: Original reporting via Smarsh

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Wansom is AI and can make mistakes.