POPIA and AI: Can Staff Paste Client Data Into ChatGPT?
POPIA and AI: Can Staff Paste Client Data Into ChatGPT? Employees are increasingly using ChatGPT, Microsoft Copilot, Claude and other generative-AI tools to summarise documents, draft correspondence and analyse information. The productivity benefits can be substantial. The risk appears when staff paste client records, identity documents, contracts, financial information or confidential company data into an […]
POPIA and AI: Can Staff Paste Client Data Into ChatGPT?
Employees are increasingly using ChatGPT, Microsoft Copilot, Claude and other generative-AI tools to summarise documents, draft correspondence and analyse information.
The productivity benefits can be substantial. The risk appears when staff paste client records, identity documents, contracts, financial information or confidential company data into an AI service without understanding where that information goes.
Under South Africa’s Protection of Personal Information Act, a business remains responsible for personal information under its control. Using a convenient AI tool does not remove that responsibility.
What information should concern businesses?
Potentially sensitive prompts may contain:
- Customer names and identity numbers
- Contact and address information
- Medical or insurance information
- Banking and payment details
- Employee disciplinary records
- Contracts and legal correspondence
- Passwords or security configurations
- Confidential pricing and proposals
- Proprietary source code
- Information received under a non-disclosure agreement
Even when a task seems harmless, the surrounding document may contain far more information than the employee intended to share.
Is using AI automatically a POPIA violation?
No. AI use is not automatically unlawful, and the answer depends on the service, configuration, contract, purpose and information involved.
However, the business should establish whether it has a lawful basis for processing the data, whether the use is compatible with the original purpose, whether adequate security safeguards exist and whether information may be processed outside South Africa.
The organisation must also consider contractual confidentiality—not only POPIA. A client agreement may prohibit disclosure to an unapproved third party even if the information does not meet a narrow definition of personal information.
Consumer and enterprise AI are not identical
AI products may offer different privacy and data-handling terms depending on the plan being used.
An enterprise service configured through an approved company tenant may provide stronger controls than an employee’s personal free account. Features can include administrative management, access controls, contractual protections and limitations on using business data for model training.
That does not mean every enterprise AI prompt is automatically safe. The business must still control access, minimise information and configure the service correctly.
Adopt a simple staff rule
Until a tool has been formally approved, employees should not paste personal, confidential or client-identifiable information into it.
Where AI assistance is appropriate, staff can often remove or replace sensitive information. For example:
- Replace names with “Client A”
- Remove identity and account numbers
- Exclude signatures and contact details
- Summarise the relevant facts instead of uploading the full file
- Use fictional figures when testing a calculation
- Paste only the paragraph needed for editing
Redaction should be performed before information reaches the AI tool.
What should an AI policy include?
A practical workplace AI policy should define:
- Approved tools and accounts
- Prohibited information
- When redaction is required
- Who may upload documents
- Human review requirements
- Rules for generated legal, financial or technical advice
- Retention and record-keeping
- Incident reporting
- Approval for new AI services
Staff also need short, realistic training. A policy hidden in a folder will not change daily behaviour.
Use AI deliberately
RandTech IT helps South African businesses assess AI tools, secure Microsoft 365 environments and develop practical usage policies that balance productivity with privacy.
Generative AI can be enormously useful, but convenience should not bypass client confidentiality. Before pasting business information into an AI prompt, employees should ask: is this tool approved, is this data necessary, and can the request be completed without identifying the person?
For formal compliance decisions, businesses should also obtain advice from a qualified privacy or legal professional.
Reference: South African Information Regulator


