TallifyGuides › POPIA and AI for financial advisors

POPIA and AI for financial advisors

Pasting a client's meeting notes into a public AI chat tool is, in most practices, a POPIA breach waiting to be noticed. Using AI with client information is entirely possible; it has to be done with the right structure. This guide explains the rules and gives a practical set of them for a practice.

Published 2026-09-04. Updated 2026-09-04. Written by the Tallify team for South African financial advisors.

The short version: POPIA does not prohibit AI. It requires that personal information is processed lawfully, for a defined purpose, with appropriate safeguards, and that any transfer outside South Africa meets section 72. The practical consequence is that identifiable client information should not go into consumer AI tools, and AI features used in a practice should either run inside the practice or receive only de-identified information.

The roles

An AI provider that receives identifiable client information is an operator, and an overseas one triggers section 72 as well. An AI provider that receives only de-identified facts is, in POPIA terms, not processing personal information at all, although a careful practice still records the arrangement.

The conditions that bite

De-identification as the design principle

POPIA does not apply to information that has been de-identified so that it cannot reasonably be re-identified. That makes de-identification the cleanest way to use a cloud AI model for analysis and drafting. Done properly it means:

  1. Identity fields are removed before anything is sent: name, identity number, date of birth, email, phone, address.
  2. Those values are also scrubbed from free text, because a summary that says "Ms Fortuin, a conveyancer in Sea Point" identifies the client as surely as a field does.
  3. The model works with placeholders, and identity is put back inside the practice.
  4. The process is tested, not assumed. A practice should be able to show what the model received for a given case.

This is how Tallify is built: document reading and extraction run on the practice's own server on local models; only a de-identified set of facts goes to the drafting model; identity is substituted locally; and an automated test asserts on every change that no identity string survives into the outbound data.

Practical rules for a practice

  1. No client information in consumer AI chat tools, on any device, by anyone. Write it into the acceptable use policy.
  2. Any AI tool used with client data must be either on-premise, or contracted as an operator with an agreement that covers security, no training on your data, and breach notification, or receive de-identified information only.
  3. Record AI processing in the practice's POPIA processing records and mention it in the client privacy notice.
  4. Keep a log of what was sent to any external model, by whom and when.
  5. The adviser reviews and signs everything AI drafts. No communication goes to a client without a named person approving it.
  6. Communications consent is captured and enforced: no automated client updates without a recorded yes.
  7. Retention follows FAIS (five years minimum for advice records) and the practice's own schedule; AI drafts that were superseded can be deleted.
  8. Test the de-identification once and then every time the tool changes.

This guide is a practical summary, not legal advice. The practice's information officer and compliance officer remain responsible for its POPIA programme.

Questions

Can I paste client notes into ChatGPT to write a Record of Advice?

Not if the notes identify the client and the tool processes the data outside South Africa on terms you have not assessed. Using a consumer AI chat with identifiable client information typically fails the section 72 transfer conditions and the safeguards condition. Using a business API with a proper agreement and de-identified data is a different matter.

Is de-identified information still personal information under POPIA?

POPIA does not apply to information that has been de-identified to the extent that it cannot be re-identified again. Removing names, identity numbers, dates of birth and contact details, and scrubbing them from free text, is the standard; the practice should be able to show how it is done.

Who is the responsible party when a practice uses Tallify?

The practice. Tallify runs on the practice's own server; BlueBird Digital, which builds it, only becomes an operator if the practice grants access for support. The drafting model provider processes de-identified facts only.

Do I need client consent to use AI in producing their advice?

Processing for the advisory relationship rests on the contract and the FAIS duties, not on consent, so consent is not the lawful basis for drafting. Consent matters for communications: a practice should only send automated updates to clients who have agreed to receive them. Transparency still applies: tell clients in your privacy notice that AI tools are used and how their information is protected.

More guides

See it on your own book.

A 30-minute walkthrough on a demo practice, then a pilot on your data, on your server. Pricing is per practice, not per seat.

Book a demo