Context Design Co
§ Notes / Essay

Your customers' information, someone else's servers

Staff are already pasting business information into free AI tools — not out of malice, out of deadline. Here is what POPIA makes of that, and what the private alternative looks like.

Published: 13 August 2026 · Context Design Co · ~1,100 words

§1 — Tuesday, 16:40, a reminder letter

Someone in your accounts department has a stack of overdue statements and a letter to write. The free AI tool writes beautifully, so they paste in the customer's statement — name, account number, amounts owed, the lot — and ask for a firm-but-friendly reminder. It works. The letter is good. Everyone moves on.

No one was careless on purpose. But a customer's personal and financial information just left your business for servers you don't control, in a country you couldn't name, under terms nobody in the building has read. If your customer asked you tomorrow where their information is held, the honest answer would now be: we're not entirely sure.

This is the quietest data problem in South African business right now — not a breach, not a hack, just a thousand helpful pastes a day.

§2 — What POPIA makes of that paste

The Protection of Personal Information Act doesn't mention AI tools, and it doesn't have to. Its rules are about personal information, wherever it goes. In plain terms, three of them matter here:

None of this makes AI illegal to use. It makes unaccounted-for AI use a liability — one that sits with the owner, not with the staff member who was just trying to get the letters out.

§3 — Why "just ban it" fails

The reflex answer is a memo: no AI tools on company data. We've watched how that plays out. The productivity gain is real, so people keep using it — quietly, on personal phones, where the business has even less visibility than before. The memo doesn't remove the risk; it removes your ability to see it.

The other reflex — buying the enterprise version of a cloud AI tool — is better, but it still means your business's information lives in someone else's system, under someone else's retention rules, with your leverage limited to the contract you signed.

§4 — The private alternative

There is a third option: give the business its own AI. A private system your company owns, running on your hardware, that has read what you already have — files, emails, history — and answers in plain English. The personal information in it stays exactly where POPIA expects you to be guarding it: with you.

The difference in one sentence: instead of your data visiting the AI, the AI lives where your data already is.

What that looks like in practice:

§5 — Honest limits

Private does not mean automatically compliant, and anyone who tells you otherwise is selling too hard. You still need the basics POPIA asks of every business: a reason for holding the information you hold, sensible retention, access limited to the people who need it, and someone accountable for all of it.

What a private system changes is that the answers to those questions become knowable. Where is the customer's information? On that machine, in that room. Who can see it? These accounts. When did the AI last touch it? It's on the record. We hold ourselves to the same standard we sell: our founder serves as the deputy information officer of our own operating company, and the compliance discipline we recommend is the one we run.

§6 — Where to start

Not with a policy document. Start by finding out what an AI system that knows your business would actually do for it — twenty minutes of plain questions, free, no data handed over. From there, prove it on one workflow before you spend real money. Costs are public on the pricing page, and the straight answers to the usual questions — including "is our data safe?" — are on the FAQ.