Artificial intelligence has raised a new question for businesses: Does existing data protection law already cover AI?
In South Africa, the answer is broadly yes — but with important limitations.
The country's primary data-protection law, the Protection of Personal Information Act (POPIA), covers several areas directly relevant to AI, including consent, automated decision-making, data quality, accountability, security and cross-border processing. However, POPIA was not written specifically for AI, and the GSMA research identifies significant uncertainty around how some of its provisions apply to emerging AI systems.
What does POPIA mean for AI?
POPIA provides the core legal framework for how personal information is collected, processed, stored and shared in South Africa.
For AI systems, this becomes relevant because many applications depend on personal information — whether customer records, behavioural data, financial information, health information or conversational data.
POPIA addresses restrictions around automated decision-making that has legal or significant effects, while also establishing requirements around accountability and security measures. It also regulates certain cross-border transfers of personal information.
The challenge is that the legislation predates many of the practical questions created by modern AI.
There is currently no AI-specific guidance clearly explaining how POPIA should apply across different AI use cases, and no sector-specific codes of conduct for high-risk applications such as credit scoring and healthcare support.
What about automated decision-making?
Automated decision-making is particularly important where an AI system can materially affect an individual.
Examples can include credit decisions, health triage or other decisions where a person may experience a significant consequence without direct human intervention.
The GSMA research found that the four case studies examined all involved automated decisions with material consequences. Yet POPIA's requirement for sufficient information about the underlying logic of automated decisions has no published interpretation for these specific contexts.
This creates an interpretive challenge.
The legal principle exists, but businesses may still need clearer guidance on what compliance looks like in practice for different AI applications.
The cross-border cloud compliance gap
For many SMEs, data governance does not stop at the country's borders.
Businesses increasingly use cloud infrastructure and software platforms provided by international companies. The GSMA survey found that 34% of surveyed SMEs used hybrid infrastructure and 32% used third-party cloud storage. Combined, this means two-thirds used at least some third-party or cloud-based storage.
Under POPIA, cross-border transfers of personal information require appropriate safeguards, including an adequacy determination or a data transfer agreement in the circumstances described by the report.
Yet the research indicates that many SMEs using international cloud infrastructure are unlikely to have fully documented these arrangements.
For businesses, the lesson is straightforward: using an international cloud provider does not remove local data-protection obligations.
How does POPIA compare with other approaches?
South Africa is not alone in trying to make existing data-protection systems work in an AI-enabled economy.
Different jurisdictions have approached the SME challenge in different ways.
European Union: The EU AI Act explicitly recognises SMEs and provides mechanisms including regulatory sandboxes, simplified technical documentation and proportionate conformity fees. Its risk-based approach is particularly relevant to high-impact applications such as credit scoring and clinical decision support.
India: India's Digital Personal Data Protection Act provides phased compliance timelines of up to 18 months and includes provisions intended to reduce fixed compliance costs for startups in certain circumstances.
Kenya: Kenya's Data Protection Act uses a penalty structure capped at 1% of annual turnover, while draft guidance includes sector-specific approaches for areas such as digital finance and telecommunications. The report highlights this as an example of how proportionality can be built into regulatory enforcement and guidance.
United Kingdom: The UK has taken a more coordinated approach, with the Information Commissioner's Office providing guidance for SMEs and the Digital Regulation Cooperation Forum coordinating across regulators. This can reduce conflicting guidance when AI systems fall across multiple regulatory areas.
What makes privacy law workable for SMEs?
The comparison points to a common principle: proportionality.
A small business and a large corporation may have the same basic responsibility to protect personal information, but they do not have the same resources to meet complex governance requirements.
The GSMA research therefore highlights the importance of regulatory approaches that account for organisational size, maturity and risk.
South Africa's experience demonstrates that having a comprehensive data-protection framework is an important foundation. But businesses also need practical guidance that translates broad legal requirements into operational expectations.
Frequently Asked Questions
Does general data-protection law cover AI?
It can cover many aspects of AI, particularly where AI involves personal information. However, general laws may not answer every AI-specific governance question.
What does POPIA require around AI?
POPIA provides requirements relevant to consent, automated decision-making, data quality, accountability, security and cross-border processing.
Does using an international cloud provider create compliance obligations?
Yes. The GSMA research highlights cross-border data processing as an important consideration for SMEs using international infrastructure.
How does POPIA compare with other data privacy laws?
Different jurisdictions address SME and AI governance challenges differently. The EU uses risk-based AI regulation and SME mechanisms; India uses phased compliance; Kenya uses turnover-linked penalties and sector guidance; and the UK emphasises coordinated regulatory guidance.
What can businesses learn from South Africa?
A strong general data-protection framework is an important starting point, but AI adoption also requires clear interpretation, practical guidance and proportionate compliance mechanisms.
Conclusion
POPIA provides South Africa with a substantial foundation for governing personal information in an AI-enabled economy. But the experience of SMEs shows that legislation alone cannot resolve every question created by AI.
As businesses increasingly rely on automated decisions, international cloud infrastructure and data-driven systems, the challenge is translating existing legal principles into practical AI governance.
The wider lesson is relevant well beyond South Africa: effective AI data privacy laws need to be not only comprehensive, but usable and proportionate for the businesses expected to follow them.
Based on research by Tanvi Deshpande and Emma Leering, GSMA Mobile for Development, with contributions from Robin Miller and Alim Ladha , Axum , GSMA Intelligence and research conducted by Axum and the Global Center on AI Governance, published in Scaling AI for SMEs: Insights Into South Africa’s AI Data Governance Environment (2026).




