AI for brokers

Before an AI tool touches your client book: the POPIA questions to put to a vendor

A demo tells you nothing about where client data goes. The POPIA operator, security and cross-border questions a South African brokerage should ask in writing.

Published on 9 min readFCB.ai
Contents
  1. You remain the responsible party, whoever runs the model
  2. The model call is usually a cross-border transfer
  3. Health information changes the answer
  4. Training on your book is a separate question
  5. Ten questions to send before you connect anything
  6. What ORIS looks like against that list
  7. Frequently asked questions

Every AI tool sold to brokerages demos the same way: a messy WhatsApp thread goes in, a tidy summary and a suggested reply come out. Nothing in that demo tells you where the client's personal information travelled to produce it, who else processed it on the way, or what the contract says happens if that party is breached. Those are the questions that decide whether the tool is a compliance asset or a notifiable incident waiting to happen.

The good news is that POPIA gives you a short, closed list of things to establish, and none of it requires a data-protection lawyer to start. This is what the Protection of Personal Information Act 4 of 2013 actually requires of a brokerage buying AI, and the questions to send a vendor before anything is connected to your book.

You remain the responsible party, whoever runs the model

Your brokerage decides why and how client personal information is processed, so you are the responsible party and you stay accountable. The AI vendor, and anyone the vendor uses, is an operator processing on your behalf. Three sections then apply directly.

Section 19 requires you to secure the integrity and confidentiality of personal information in your possession or under your control by taking appropriate, reasonable technical and organisational measures — identifying reasonably foreseeable internal and external risks, establishing safeguards against them, regularly verifying that those safeguards are effectively implemented, and continually updating them. It also tells you to have due regard to generally accepted information security practices that apply to your industry.

Section 20 requires an operator to process only with your knowledge or authorisation, and to treat what it learns as confidential.

Section 21 is the one that gets skipped. It says a responsible party must, in terms of a written contract, ensure that the operator establishes and maintains the section 19 security measures — and that the operator must notify you immediately where there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. Immediately, not within seventy-two hours. Your own duty under section 22 then runs to the Regulator and to affected data subjects as soon as reasonably possible after discovery.

A vendor whose only paperwork is an online terms-of-service page has not given you a section 21 contract. Ask for the data processing addendum by name.

The model call is usually a cross-border transfer

Most AI features in broker tooling call a model hosted outside South Africa. That is a transfer of personal information to a third party in a foreign country, and section 72 permits it only on one of five grounds.

Ground in section 72(1)What it means for a brokerage
(a) Law, binding corporate rules or binding agreement providing an adequate level of protectionThe durable answer. The agreement must uphold principles substantially similar to POPIA's conditions for lawful processing and contain provisions substantially similar to section 72 governing onward transfers
(b) The data subject consentsWorkable but brittle: consent must be voluntary, specific and informed, and it can be withdrawn, which leaves you re-papering a live system
(c) Necessary for performance of a contract with the data subject, or pre-contractual steps at their requestArguable for servicing an existing policy; much weaker for analytics, scoring or marketing uses layered on top
(d) Necessary for a contract concluded in the data subject's interest between you and a third partyNarrow; rarely the honest description of an AI subscription
(e) For the data subject's benefit where consent is not reasonably practicable and would likely be givenA fallback, not a plan

Ground (a) is where a serious vendor lands, and the second half of it is the part people miss: it is not enough that your vendor protects the data — the agreement has to control what happens when your vendor passes it on to its own model provider. Note also that the Information Regulator has not published a guidance note on section 72. Its published guidance notes cover direct marketing, special personal information, children's information and elections; a transborder note has been signalled but is not out. Until it is, you work from the text of the section, and any consultant telling you a particular country is approved is telling you something POPIA does not currently say.

Health information changes the answer

This is the point most brokerages miss entirely. Section 26 prohibits processing information concerning, among other things, a data subject's health, subject to the authorisations that follow. A broker book is full of it: underwriting answers on a life or funeral proposal, a medical scheme or gap cover application, the injury described in a claim thread, the reason a client is asking to increase their disability cover.

Section 57(1)(d) then says a responsible party must obtain prior authorisation from the Regulator before transferring special personal information — or the personal information of children — to a third party in a foreign country that does not provide an adequate level of protection as referred to in section 72. Section 58(2) says you may not carry out the notified processing until the Regulator has completed its investigation or told you a more detailed one will not be conducted; the Regulator has four weeks from the notification to say which.

The practical reading: if your AI vendor's arrangements clear section 72 through a proper binding agreement, you are in the ordinary lane. If they do not, and health information from your book is going offshore anyway, you are in the prior-authorisation lane and should not be live. That distinction is worth establishing before the pilot, not after.

Training on your book is a separate question

Client conversations were collected to service policies. Using them to train a model is further processing, and section 15 requires further processing to be compatible with the purpose of collection, weighed against the relationship between the two purposes, the nature of the information, the consequences for the data subject, how it was collected and the contractual position between the parties. Health information collected for underwriting, reused to improve a commercial model, is a hard case to argue.

So ask the question in contract language rather than sales language. Are inputs and outputs used to train or improve your models or those of your subcontractors? A vendor whose answer lives only in a marketing FAQ has not answered it. The same discipline applies to retention: how long do prompts and completions sit on the model provider's side, and what deletes them.

Ten questions to send before you connect anything

  1. Who is the responsible party and who is the operator in this arrangement, in your own words?
  2. Send me the written contract that satisfies section 21, including the operator's obligation to maintain section 19 security measures.
  3. Name every sub-operator, including the model provider, hosting provider and messaging provider.
  4. Where does the database physically sit, and where is each model call processed?
  5. Which section 72 ground do you rely on for each transfer, and where is the binding agreement that supports it?
  6. Does that agreement include provisions substantially similar to section 72 governing onward transfers?
  7. Are inputs or outputs used to train or improve any model? Put the answer in the contract.
  8. What is the retention period on the model provider's side, and how is deletion evidenced?
  9. How and how fast will you notify us of a compromise, and what will the notification contain, so that we can meet section 22?
  10. What can we export, in what format, if we leave — and what is deleted, and when?

Send those ten to every vendor on the shortlist, including us. A vendor that answers them in writing has done this before. A vendor that answers with a security badge on a web page has not. If you are still at the stage of deciding whether automation belongs in a regulated inbox at all, our comparison of a chatbot versus supervised AI for brokers is the earlier conversation.

What ORIS looks like against that list

Answering our own questionnaire, briefly and without varnish. The client book sits in a self-hosted Postgres database on a cloud virtual machine that we run, not in a shared multi-tenant product database; ask us which region yours is in and we will tell you in writing. WhatsApp transport is the Meta Cloud API, so Meta is a sub-operator by definition, and Meta access tokens are held encrypted rather than in configuration files. The AI features — reply classification, sentiment and urgency analysis, suggested drafts, rule-bound auto-replies — call Anthropic's Claude models, so Anthropic is the model sub-operator. Text written by a client is fenced before it enters a prompt and the system prompts treat it as data to analyse rather than instructions to follow. Audit logs record who did what, and the whole book exports to CSV.

What ORIS does not do is make the POPIA determinations for you. Whether health information in your book may go to a given processor, which section 72 ground you rely on, and whether you need prior authorisation are your calls as responsible party, on your paperwork. The related question of what automated scoring does to your obligations sits in section 71 rather than here, and we worked through it in the guide to risk scores and POPIA section 71. If the vocabulary is unfamiliar, start with the POPIA entry in our glossary.

Frequently asked questions

Does POPIA require client data to stay in South Africa?

No. Section 72 does not impose localisation; it imposes conditions on transfer. Personal information may leave the country where the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection, or where one of the other listed grounds applies. Data sovereignty marketing sometimes blurs that, but the statute is a conditions regime, not a border.

We are a five-person brokerage. Is a written operator contract really expected of us?

Section 21 draws no distinction by size. It says a responsible party must, in terms of a written contract, ensure the operator maintains the section 19 measures. In practice this is a document you request rather than draft: any vendor selling to regulated businesses has one, and the effort is in reading it against sections 19, 21 and 72 rather than in writing it.

How do we know whether the client information we are sending is special personal information?

Look at what your advisers actually type. Health is the common one for brokers, and it arrives through underwriting answers, claim descriptions, medical scheme and gap cover applications and disability enquiries. Children's information arrives through dependants on funeral and medical cover. If either flows into the AI tool, section 57 needs a considered answer rather than an assumption.

What if the vendor says our data is anonymised before the model sees it?

Test the claim. Removing a name from a WhatsApp thread that discusses a specific policy, vehicle, address and claim does not usually make it non-personal, because identifiability is about reasonable means of re-identification, not about which field was deleted. If the vendor means pseudonymisation, POPIA still applies and the section 21 and 72 questions still need answering.

Do we have to tell clients that AI is involved?

Notification under POPIA turns on the purposes of processing rather than the technology, so a materially new purpose needs to reach your privacy notice. Separately, the FAIS duty to treat clients fairly makes a plain sentence about how the brokerage uses assistive tools in its inbox a low-cost, high-trust disclosure. Clients object far less than brokerages expect, provided a named human remains accountable for what is sent.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo