AI & Data9 September 20268 min read

AI and POPIA, in Plain Language — Part 2 of 6

POPIA does not say your data must stay in South Africa

The single most repeated belief about POPIA and AI is not what the Act says. Section 72 sets conditions for sending personal information abroad — five of them — rather than forbidding it. Being wrong in the cautious direction still costs you.

#POPIA#AI & Data#AI Governance#Leadership

If you have been in any South African meeting about AI in the last two years, you will have heard the sentence: "We can't use that — POPIA says our data has to stay in the country."

It is said with confidence, usually by someone careful and well-intentioned. It is not what the Act says.

This matters in both directions. Organisations have stopped projects that were permitted, and others have gone ahead on a vague sense that "we have a contract, it's fine" without checking which condition they were relying on. Both are avoidable by reading what is actually written.

What people believe POPIA says, and what it saysCOMMONLY BELIEVEDWHAT THE ACT ACTUALLY DOES“Personal information maynever leave South Africa”It may, through any one offive lawful routes“We need consent forevery transfer”Consent is one route of five,and rarely the practical one“A local data centremakes us compliant”Location is one control.It is not the whole obligation“POPIA bans AI”POPIA does not mention AI.It governs personal information
Every belief on the left is held sincerely and repeated confidently, usually by people trying to be careful. Being wrong in the cautious direction still has a cost: it stops work that was permitted, and it spends goodwill that a genuinely hard case will need later.

What the Act actually does

The relevant part is section 72 of the Protection of Personal Information Act. It deals with what the Act calls transborder flows — sending personal information about a person to a third party in a foreign country.

Section 72 does not say you may not do this. It says you may not do this unless one of five things is true.

Five lawful ways personal information may leave South AfricaIN PLAIN WORDSHOW OFTENA binding agreementThe receiver is held to protection like ours, by law or contractthe usual oneConsentThe person agreed to this specific transferrarely practicalTo perform a contractNeeded to do what the person asked you to dosometimesA contract for themA deal made in the person’s interest with someone elseoccasionallyClear benefitIt helps them, and asking first is not reasonably practicalnarrowAlmost every cloud and AI contract you already have runs on the first row.
Section 72 of POPIA lists these five. Note what the list does not contain: a rule that personal information may never leave. The Act sets conditions for sending it, not a prohibition on sending it. This is an explainer, not legal advice — your legal and privacy people make the call.

Read that as five doors. You need to be going through one of them. You do not need to go through all five, and you do not need to justify why you are not using the other four.

The binding agreement route. The recipient is subject to a law, binding corporate rules, or a binding agreement that provides an adequate level of protection — upholding principles substantially similar to POPIA's own conditions, and including a provision governing any onward transfer.

Consent. The person agreed to the transfer.

Necessary for a contract with them. The transfer is necessary to perform a contract between the person and you, or to take steps at their request before entering one.

A contract in their interest. The transfer is for the conclusion or performance of a contract, concluded in the person's interest, between you and a third party.

Clear benefit, consent impractical. The transfer is for their benefit, getting consent is not reasonably practicable, and they would be likely to give it if asked.

The route almost everyone is actually using

Here is the practically important point, and it is the one that changes decisions.

The first door — a binding agreement providing adequate protection — is how essentially every mainstream cloud and AI contract already works. The major providers publish data processing terms designed precisely to carry this weight, in South Africa and in the many other jurisdictions with similar rules.

So when someone says "we can't send this abroad", the accurate response is usually not yes we can, don't worry. It is: which door are we going through, and where is it written down?

That question has a real answer. It lives in your contract with the provider, in the data processing addendum, and in whatever your privacy officer signed. If nobody can point to it, that is a genuine gap — but it is a paperwork gap, not a prohibition.

Two cautions on the other doors, because they get misused.

Consent is weaker than it looks. It has to be specific and freely given, and it can be withdrawn. Building a public service on the assumption that every citizen will consent to overseas processing — and that none will change their mind — is a fragile design. Consent is one route of five, and rarely the practical one for a service at scale.

"Necessary for the contract" means necessary. It covers what you must do to deliver what the person asked for. It is not a general-purpose justification for any processing that happens to be convenient.

Where the real constraints come from

If POPIA is not the blanket prohibition, why do so many South African organisations genuinely face hard localisation requirements?

Because the constraint usually comes from somewhere else, layered on top.

Government data policy. South Africa's National Data and Cloud Policy, published in May 2024, requires that government data concerning the protection and preservation of national security and sovereignty be stored only on infrastructure inside the country. It is directed principally at government departments, state-owned entities and critical information infrastructure — and it reaches private companies that supply services to government or process government data.

Sector regulators. Financial services and telecommunications carry additional restrictions of their own. Separately, the South African Revenue Service requires prior written approval before employee tax information is stored outside the country.

Special categories of data. Some information starts from a prohibition rather than a permission. That is the subject of the next article.

Your own policy. Plenty of boards have simply decided that citizen or customer data does not leave, whether or not the law compels it. That is a legitimate decision. It is just important that everyone knows it is a policy choice rather than a legal necessity, because policy choices can be revisited with evidence and legal necessities cannot.

Notice that all four of those are checkable. Someone in your organisation can find out, in a week, which of them apply to you. The reason it feels unknowable is that the question is usually asked as "what does POPIA say about AI?" — which is too broad to answer — rather than "which of these four applies to this specific data?"

What POPIA says about AI

Nothing, directly. POPIA does not mention artificial intelligence. It governs the processing of personal information, and an AI service processing personal information is simply processing.

South Africa does not currently have AI-specific legislation. Cabinet approved the publication of a draft National AI Policy in April 2026, and the direction of travel is a sector-specific, multi-regulator model — AI governance embedded in existing supervisory frameworks rather than a single new AI regulator — with POPIA remaining the cornerstone for anything involving personal information.

The practical implication for you today: there is no separate AI compliance regime to satisfy. If you have understood your obligations for personal information, you have understood most of your obligations for AI. That should be reassuring, and for most organisations it is the opposite of what they assume.

What to take from this article

POPIA sets conditions, not a prohibition. Five lawful routes exist for sending personal information abroad.

Almost everyone is using the first route. A binding agreement with adequate protection. The useful question is where yours is written down.

The hard constraints usually come from elsewhere — government data policy, sector regulators, special data categories, or your own board.

Being wrong cautiously is still being wrong. Stopping permitted work has a cost: it delays value, and it spends credibility you will need when a genuinely hard case arrives.

Plain-language explainer, not legal advice, and I am not a lawyer. Section 72, section 26 and the policies mentioned here have real detail behind them. Your legal and privacy people make the determination — this article is meant to help you brief them properly.

How CloudNala can help

We do not give legal opinions. What we do is produce the thing your legal people need in order to give one: an accurate, written description of exactly what data moves, where it goes, who holds it and for how long. Most POPIA questions about AI stall not because the law is unclear but because nobody has written down what the system actually does.


Work with CloudNala

CloudNala helps organisations move from technology ambition to practical execution across cloud, AI, data, platform engineering and digital services.

Whether you are exploring AI, modernising your cloud environment, building a public-sector digital service, or turning an idea into a working MVP, we can help you shape the roadmap and deliver the next step.

Book an AI Readiness Workshop or write to us at consult@cloudnala.co.za