This is the question I get asked most by bookkeepers, PAs and anyone who handles other people's information, and it's usually asked quietly, after everyone else has left.

It deserves a proper answer, because the honest one is neither "it's fine" nor "don't risk it."

Necessary caveat

I'm not a lawyer and this isn't legal advice. It's a plain-language starting point. If you're in a regulated profession or handling sensitive information at scale, get advice from someone qualified and check your professional body's guidance.

What POPIA actually asks of you

The Protection of Personal Information Act governs how personal information about living people, and, unusually, about companies too, is handled in South Africa. The parts that matter for AI use come down to a few practical ideas:

  • You need a lawful reason to process someone's information
  • You should use the minimum necessary for the purpose
  • You must keep it secure, including when a third party handles it for you
  • People are entitled to know broadly how their information is used
  • Sending personal information outside South Africa comes with extra conditions

That last one matters here, because essentially every major AI tool processes your text on servers overseas.

The practical question

When you paste a client's information into ChatGPT, you are sending that information to a third party, usually outside South Africa, to process on your behalf. That isn't automatically wrong. You already do something similar with cloud accounting software, email and backups. The difference is that you probably signed something for those, and you almost certainly didn't for this.

A workable rule

Rather than trying to make a legal judgment every time, use this:

Could this text identifya specific person or business?

If yes, either strip it out or don't paste it. If no, you're on much safer ground.

Generally fine

  • Your own writing, with names removed
  • General questions: "how do I explain a provisional tax adjustment simply?"
  • Templates and standard letters with placeholders
  • Anything already public, legislation, published guidance, your own website
  • Your internal processes, as long as they don't name clients

Strip it first

  • Emails and letters, take out names, companies, account numbers, reference numbers
  • Meeting notes with people named
  • Anything with an ID number, tax number or address in it

Don't

  • Full bank statements, payroll files or tax returns as they are
  • ID documents, passports, medical information
  • Anything covered by a confidentiality agreement you'd struggle to reconcile with sending it offshore
  • Anyone's information where they'd be genuinely surprised to learn you'd done it

Stripping is easier than it sounds

The trick is that these tools don't need the real names to do the work. Replace and it still functions perfectly:

Instead of

"Draft a response to Mrs Pretorius at Kloof Engineering about her outstanding March invoice of R48,200."

Try

"Draft a response to a long-standing client about an outstanding invoice from five months ago, roughly R48,000. Warm but clear that payment is needed this week."

You get the same letter. You paste the names back in yourself. It takes about fifteen seconds and removes almost the entire problem.

Three settings worth changing today

  • Turn off training on your data. Most tools let you opt out of your conversations being used to improve the model. It's usually buried in settings under data controls. Do it once, for every tool you use.
  • Check whether your business account already covers this. Business and team tiers generally come with stronger commitments than consumer accounts, including not training on your content. If your employer pays for Copilot or Gemini, use that rather than a personal account.
  • Delete conversations you didn't need to keep. Simple hygiene, and it costs nothing.

If you're doing this at work

Two things worth raising, and it's better if you raise them than if someone asks later:

Ask whether there's a policy. Many South African businesses now have one, and a lot of employees don't know. If there isn't one, being the person who asks is a good look, not a risky one.

Suggest one if there isn't. It doesn't need to be elaborate. Which tools are approved, what may never be pasted in, and who to ask when unsure. One page is plenty.

The thing not to conclude

Some people read all this and decide it's safer to avoid AI entirely. I'd push back on that gently.

You already send client information to cloud accounting platforms, email providers and backup services hosted overseas. You manage that with sensible precautions rather than by refusing to use email. This is the same category of decision.

Strip the identifying details, turn off training, know what your employer's position is, and get on with the work.