Before an AI tool touches your client book: the POPIA questions to put to a vendor
A demo tells you nothing about where client data goes. The POPIA operator, security and cross-border questions a South African brokerage should ask in writing.
Section 35 of the Data Protection Act, the DPIA that automated decisions trigger, and the ODPC registration a small Kenyan brokerage cannot skip.
A brokerage in Nairobi switches on the features every WhatsApp platform now ships with: the model labels each inbound reply, a score marks which clients look likely to lapse, and drafted answers appear for the team to send. Nobody in the office would describe that as a regulated activity. Under Kenyan law, at least two of those three things are processing that the Office of the Data Protection Commissioner has already written rules about, and one of them can require paperwork filed before you start.
This is not a reason to avoid automation. It is a reason to know which of your automated steps is a decision, because that single distinction determines almost everything the Data Protection Act 2019 asks of you.
Separate them on paper before you separate them in the settings screen.
Section 35 of the Act gives every data subject the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them. Two words carry the weight: solely and significantly. An adviser who reads a suggested draft, edits it and presses send has made a human decision, and section 35 does not bite. A rule that quietly removes clients above a score threshold from every renewal campaign is closer to the line than most brokerages assume.
The right is not absolute. The Act allows a solely automated decision where it is necessary for entering into or performing a contract with the data subject, where it is authorised by a law that lays down suitable safeguards, or where the data subject has consented. If you rely on one of those, obligations follow rather than disappear: you must notify the person in writing, as soon as reasonably practicable, that a decision was taken on a solely automated basis; the person may then ask you to reconsider it or to take a decision that is not based solely on automated processing; and you must consider the request, comply with it, and tell them in writing what you did.
| What the brokerage automates | Solely automated decision? | What to do |
|---|---|---|
| Labelling an inbound message as a complaint or a churn signal | No — an internal signal | Keep the label accurate and correctable; log it |
| Scoring lapse risk to order the call list | Not usually — it ranks work, it does not decide outcomes | Show the reason behind the score to the adviser |
| Auto-reply inside fixed rules, with escalation on negative sentiment | No, provided it does not decide anything about cover or money | Cap the number of auto-replies, escalate anything sensitive |
| Excluding a client from service messaging because a model marked them dormant | Arguably yes if it affects the service they get | Put a human check in front of it, or run the section 35 process |
| Any automated step that changes cover, price or a claim outcome | Yes — and it is not a broker function anyway | Do not automate it; that decision belongs to the insurer, with a human |
The cheapest compliance posture is also the best operational one: keep a person in the loop wherever the output touches the client, and the notification-and-reconsideration machinery never has to be built.
The Data Protection (General) Regulations 2021 list the processing operations treated as high risk for the purposes of section 31 of the Act. First on that list is automated decision making with legal or similar significant effect that includes the use of profiling or algorithmic means, or the use of sensitive personal data to determine access to services. If your automation crosses into that territory, a data protection impact assessment is not optional, and the Act contemplates consulting the Data Commissioner before the processing starts.
The regulations also set out what happens next: a controller may consult the Office on whether the identified risks and mitigations are viable, the Data Commissioner may recommend changes to be incorporated before processing begins, and where no communication is received within sixty days of submitting the report, processing may commence and the assessment is taken to have been approved. A brokerage may publish its assessment on its website if it wishes.
For a five-person firm this is a short document, not a project: what the model does, what data goes in, what decision comes out, who checks it, what happens when it is wrong, how a client objects, and how long the records are kept. Write it once, review it when the configuration changes.
Many small firms read the exemption and stop there. Under the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021, a controller or processor is exempt from mandatory registration only where it has an annual turnover below five million shillings and fewer than ten employees. Both conditions, not either.
Then comes the part that catches intermediaries. That exemption does not apply where the data is processed for the purposes listed in the Third Schedule, and the schedule includes the provision of financial services and businesses that are wholly or mainly in direct marketing. A brokerage that reaches its book by campaign messaging should assume it is in, register, and stop debating it. A certificate of registration runs for twenty-four months, and the fees are set out in the regulations — four thousand shillings to register a micro or small controller and two thousand to renew. Exempt firms still have to comply with the substantive obligations; the exemption is from the register, not from the Act.
None of the AI work changes the underlying rule for outbound: section 37 prohibits using personal data for commercial purposes without consent or another lawful basis, the regulations define commercial use broadly enough to cover most campaign messaging, and an opt-out route has to exist and be honoured. The ODPC has issued penalty notices over exactly this kind of processing, and the Act allows penalties up to five million shillings or one percent of annual turnover. Where the model chooses the audience, the model has inherited a consent problem — so the opt-in record and the opt-out list must sit upstream of any scoring, not downstream. On timing and payment channels for the messages themselves, our guide to premium reminders in Kenya covers the ground, and the Kenya country page summarises the wider market rules brokers work under, including the Insurance Regulatory Authority's remit.
That order is close to how ORIS is built to run: the classifier labels inbound messages and updates risk scores, drafted replies are held for a human unless a rule explicitly allows an automatic answer, negative sentiment always escalates to a person, opt-outs cut both queued messages and running journeys, and the audit log records the sequence. The comparable South African analysis of scoring under POPIA section 71 reaches the same conclusion from a different statute: supervision is the control that makes the rest of it defensible. Want to see it against your own book? Book a demo.
You remain the controller for your clients' personal data, and the platform processing it on your instructions is a processor. That means a written processing arrangement, a clear position on where data is processed and transferred, and enough detail in your privacy notice for a client to understand that automated analysis happens. Bringing a tool in does not move the accountability off your firm.
Consent is one lawful basis among several, and for service messaging about an existing policy the performance of a contract is often the better fit. Commercial or marketing use is different: section 37 requires consent or another lawful basis, and the burden of showing it sits with you. Do not fold a marketing permission into an onboarding tick-box and hope it carries both.
Ranking work for advisers who then decide what to do is not usually a decision taken solely by automated means, because a human still chooses the outcome. It becomes one when the ranking silently determines who gets a service at all. The test is whether a person exercised real judgement, not whether a person was technically able to intervene.
Where the assessment shows high risk, the Act requires consultation with the Data Commissioner before processing, and the regulations set a sixty-day window: if no communication comes back within sixty days of submission, processing may begin and the report is taken to have been approved. Keep the submission proof with the assessment.
Probably yes. The turnover and headcount exemption applies only if both limits are met, and it falls away entirely for the purposes in the Third Schedule, which include the provision of financial services and businesses wholly or mainly in direct marketing. Registration lasts twenty-four months and is cheap compared with an enforcement notice.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
A demo tells you nothing about where client data goes. The POPIA operator, security and cross-border questions a South African brokerage should ask in writing.
Sentiment models score lower on isiZulu and Sesotho than on English. How a brokerage should test its WhatsApp classifier before letting it reply on its own.
The FSCA and PA have mapped AI use in the sector. What POPIA section 71 and FAIS ask of a brokerage that scores client risk and drafts replies with AI.