Insights / AI Governance · POPIA Section 71
AI Governance Insight · Celagenix® Academy

POPIA and Automated Decision-Making: The AI Obligation South Africa Already Has

A model declines a loan in four seconds and the organisation reaches for its month-old AI policy. The rule that actually governs the moment has been enforceable since July 2021.

In short: POPIA section 71 restricts decisions based solely on automated processing that profile a person and carry legal or substantial effect - and it has been enforceable since July 2021, well before the current AI-law debate. A human who merely rubber-stamps the model’s output does not remove a decision from the prohibition. Where an organisation relies on the section 71(2) contract route with “appropriate measures”, section 71(3) requires that the person can make representations and be given sufficient information about the underlying logic. The maximum administrative fine is a fixed ten million rand. Any future AI framework, including the EU AI Act, stacks on top of section 71 rather than replacing it.

An applicant applies for credit online at eleven at night. Within four seconds, the screen returns a decline. No branch was open. No officer reviewed the file. A model scored the application, compared it against a threshold, and produced the outcome on its own. The applicant asks the obvious question: who decided this, and on what basis? The organisation reaches for its brand-new AI governance policy, dated last month, and discovers something uncomfortable. The rule that governs this exact moment is not new at all. It has been on the South African statute book since 2013, and enforceable since July 2021.

Why this is not a future problem

There is a widespread belief that South Africa is waiting for an AI law, and that until it arrives, automated decisions sit in a grey zone. That belief is wrong on both counts. A Draft National Artificial Intelligence Policy was published for public comment on 10 April 2026 and withdrawn just sixteen days later, on 26 April 2026, after fabricated citations were found in its reference list. As at this writing there is no revised timeline and no current national AI policy. So the operative instrument is not coming - it is here now, it is POPIA, and section 71 has governed automated decision-making the entire time. Treating it as a future problem is itself the governance failure.

What section 71(1) actually prohibits

Section 71(1) provides that a data subject may not be subject to a decision which results in legal consequences for them, or which affects them to a substantial degree, where that decision is based solely on the automated processing of personal information intended to provide a profile of certain aspects of that person. Read it slowly, because every element does work. The decision must produce legal consequences or substantial effect. It must be based solely on automated processing, meaning no meaningful human involvement in reaching it. And the processing must be aimed at profiling aspects such as performance at work, creditworthiness, reliability, location, health, personal preferences or conduct. The credit decline meets all three: it affects the person substantially, it was reached solely by the model, and it profiles creditworthiness. That is why it falls inside the prohibition, not outside it.

The word that decides most cases

The word that decides most real cases is “solely”. A decision is caught only when there is no meaningful human involvement in the making of it, and this is where organisations quietly get it wrong. Putting a person at the end of the process who clicks “confirm” on whatever the model produced is not human involvement. That is a rubber stamp, and a rubber stamp leaves the decision solely automated in substance even if a human touched it in form. Genuine involvement means someone with the authority and the information to reach a different conclusion actually considers the case. Notice how much of this you cannot see from the boardroom by reading a policy. You can only see it by asking how a specific decision was really made.

The exceptions, and where the safeguards attach

A decision that falls inside the prohibition is not automatically unlawful, because section 71(2) provides exceptions. There are two broad routes: where the decision is taken in connection with the conclusion or execution of a contract and appropriate measures have been taken to protect the data subject’s legitimate interests; or where the decision is governed by a law or code of conduct that itself specifies such measures. The exception does not switch off the protection. It channels the decision into a route that carries its own conditions.

Here is the detail most often missed. Section 71(3) sets out specific safeguards, and they do not float across every exception equally. They attach specifically to the contract route where lawfulness rests on “appropriate measures” having been taken. On that route, section 71(3) requires that those measures give the data subject an opportunity to make representations about the decision, and that they provide sufficient information about the underlying logic of the automated processing to enable those representations to be made meaningfully. If your organisation is relying on the “appropriate measures” route, you owe the person a chance to be heard and an explanation of the logic. Miss that pairing, and the exception you thought you were relying on does not hold. This is the single element a board is most likely to sign off without ever having verified.

What “underlying logic” means in practice

The phrase “sufficient information about the underlying logic” does real governance work. It does not require you to hand over source code or a full model specification. It requires enough for the person to understand the basis of the decision and to challenge it intelligently. For the credit applicant, that means being told which factors drove the outcome and being given a genuine route to contest it, not a generic line that “the system decided”. A board testing this should ask a plain question of management: if the applicant we declined at eleven at night asked us to explain the logic and to make representations, could we? If the honest answer is no, the organisation is relying on an exception it has not actually satisfied.

The Regulator, and the ceiling

The Information Regulator is the body established under POPIA to monitor and enforce compliance, and automated decision-making sits squarely within its remit. The Act sets a maximum administrative fine of ten million rand for the more serious contraventions, alongside the possibility of criminal sanction in defined cases. The statutory ceiling is the honest figure to brief a board on - inventing a more precise penalty for a specific matter would be exactly the kind of fabricated particular a board must never be given. The governance point does not depend on the number. It is that a real regulator, with real enforcement powers, oversees the very decisions your automated systems are already making.

POPIA and the AI frameworks, together

A common misconception is that a new AI law will replace what came before. It will not. Where the European Union’s AI Act reaches an organisation, it applies alongside data-protection law, not instead of it - the Act says as much in Article 2(7), leaving data-protection law untouched so the two regimes operate concurrently. The lesson for a South African board is direct. POPIA section 71 is not superseded by anything on the horizon. It is the floor, and any AI framework that reaches you stacks on top of it. An organisation that has genuinely satisfied section 71 has not finished its AI governance, but it has done something many have not: it has met the obligation that already binds it.

The obligation you already hold

The most demanding AI obligation your organisation faces may not be the one still being drafted. It is the one that has been enforceable since July 2021, governing every solely automated decision that carries legal weight for a real person. Your board does not get to wait for an AI statute to take this seriously, because the statute for automated decisions is already on the books. Go back and ask the uncomfortable question about a live decision your systems are making tonight: could we explain the logic, and could the person be heard? If you cannot answer yes, you have found your first governance action.

Also available - the free AI Governance Oversight Checklist

Can your board answer the section 71 question?

The interactive AI Governance Oversight Checklist helps your board test whether it can explain the logic of its automated decisions and give affected people a route to be heard - no email required to start. Enrolment in Celagenix® Academy unlocks the full learning unit this article is drawn from.

Take the free AI Governance Oversight Checklist

Frequently asked questions

Does POPIA already regulate AI and automated decisions in South Africa?

Yes. Section 71 of the Protection of Personal Information Act has governed automated decision-making since the Act took effect, and it has been enforceable since July 2021. It restricts decisions based solely on the automated processing of personal information that profile a person and produce legal consequences or a substantial effect. There is no current national AI policy - a draft was published on 10 April 2026 and withdrawn on 26 April 2026 - so section 71 is the operative instrument, not a future one.

What does “solely” automated mean under section 71?

A decision is “solely” automated when there is no meaningful human involvement in reaching it. A person who simply clicks “confirm” on whatever the model produced is a rubber stamp and does not take the decision outside the prohibition. Genuine human involvement means someone with the authority and the information to reach a different conclusion actually considers the specific case.

When is a solely automated decision still lawful?

Section 71(2) provides exceptions: where the decision is taken in connection with concluding or executing a contract and appropriate measures protect the data subject’s legitimate interests, or where a law or code of conduct specifies such measures. On the contract route resting on “appropriate measures”, section 71(3) requires that the person can make representations and receive sufficient information about the underlying logic of the processing.

What does “sufficient information about the underlying logic” require?

It does not require disclosing source code or a full model specification. It requires enough for the person to understand the basis of the decision and to challenge it intelligently - which factors drove the outcome and a genuine route to contest it, rather than a generic statement that the system decided.

What is the maximum penalty for breaching section 71?

POPIA sets a maximum administrative fine of ten million rand for the more serious contraventions, enforced through the Information Regulator, with the possibility of criminal sanction in defined cases. The fixed statutory ceiling is the accurate figure to brief a board on; a more precise penalty for a specific matter should not be assumed.

← Back to Insights