Here is the mistake that costs South African organisations the most time: they debate the tool before they classify the data.
Six weeks go into comparing providers, regions and contracts — for a use case that turns out to involve no personal information whatsoever, where any of the options would have been fine. Or, worse, the opposite: a tool is rolled out organisation-wide and only later does someone ask what staff have been pasting into it.
Sort the data first. The tool choice mostly falls out of it.
Green: nothing personal in it
A great deal of real AI use involves no personal information at all, and this is the category people consistently underestimate.
Drafting marketing copy. Summarising a public policy document. Rewriting a job advertisement. Explaining a technical concept for a board pack. Generating test data. Turning your own product documentation into a FAQ. Improving the tone of an internal announcement.
None of that is about an identifiable person. POPIA governs the processing of personal information — where there is none, the transborder question does not arise at all.
This matters more than it sounds, because it means you can start. Organisations that have frozen entirely, waiting for a residency answer before touching anything, are usually sitting on a large pile of perfectly unproblematic use cases. Getting those moving builds the experience and the confidence you will need when a harder case arrives.
The one trap: it is very easy for personal information to wander into a "green" task. Someone drafting a customer apology letter pastes in the actual complaint, with the customer's name and account number. The task was green; the material was not. That is a training and habit problem, not a legal one, and it is addressed in the last article of this series.
Amber: ordinary personal information
Names, ID numbers, contact details, account numbers, a customer's query, an employee record, a citizen's application.
This is where section 72 applies, and where the previous article's five routes come in. Sending this to an AI service in another country is permitted — through one of those routes, with the paperwork actually in place.
Amber does not mean stop. It means check which door you are going through, and be able to point at it. For most organisations using a mainstream provider under a proper data processing agreement, that door already exists. The work is confirming it, not creating it.
Amber also means think about whether you need to send it at all. A great many services can be designed so the identifying details never leave your systems — the AI handles the language while your own database handles the person. That is a design choice available to you, and it converts an amber problem into a green one.
Red: special personal information
POPIA treats some categories differently, and the difference is fundamental. For ordinary personal information, the Act asks you to have a lawful basis. For these, section 26 starts from a prohibition and then permits specific exceptions.
The categories are: religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and information about alleged criminal behaviour or related proceedings.
Look at that list against real AI ideas and you will see how easily it is triggered. A patient-facing assistant is health data. A face or fingerprint login is biometric. A recruitment tool that infers demographics touches race. A case management assistant in a legal or enforcement context touches alleged criminal behaviour. A member-services bot for a union touches union membership.
None of these are impossible. They are genuinely done, lawfully, by careful organisations. But the starting posture is different, and the practical consequence is straightforward: if your use case touches this list, the next conversation is with your privacy or legal people, not with a vendor.
Children's personal information sits outside section 26, under its own separate and stricter rules. Treat anything about a person under 18 as at least as sensitive as the section 26 list.
The fourth question people forget: whose data is it?
There is a layer that cuts across the traffic light entirely, and public-sector readers need it.
If you are a government department, a state-owned entity, or a private company processing government data, the National Data and Cloud Policy applies on top of everything above. Government data concerning national security and sovereignty must be stored on infrastructure inside South Africa. Sector regulators in financial services and telecommunications add their own requirements, and tax information has its own approval process.
So the honest classification question is not just how sensitive is this data but also whose rules attach to it. Two organisations holding identical data can face different answers because one of them is processing it on behalf of the state.
Doing this in practice
You do not need a data governance programme to run this exercise. You need a list and an afternoon.
Write down the actual use cases. Not "AI for customer service" — the specific things: draft replies to enquiries, summarise a call, look up an order status, screen a CV.
For each one, write what the AI would see. The real fields. If someone writes "customer data", push back until you get a list.
Colour them. Green, amber, red, using the bands above. Most lists come out more green than anyone expected.
Start the green ones. Immediately. They need no residency work.
For amber, find the door. Which of the five routes, and where is it written.
For red, get advice before design. Not after a pilot, when changing course is expensive.
The output is a single page that tells you what you can do this month, what needs a contract check, and what needs a lawyer. That page is worth more than any vendor comparison.
What to take from this article
Classify the data before you compare tools. The tool choice mostly follows from the classification.
Green is bigger than you think. A lot of valuable AI use touches no personal information, and it is being blocked by a concern that does not apply to it.
Amber means check the door, not stop.
Red means talk to a lawyer before you design anything. Health, biometrics, race, religion, politics, union membership, criminal matters — and anything about children.
Plain-language explainer, not legal advice. The categories described here have real statutory detail behind them, and applying them to your situation is your legal and privacy team's job.
How CloudNala can help
We run this classification with clients as a short workshop, and the outcome is nearly always the same shape: a list of things that can start now, a smaller list needing a contract check, and one or two that genuinely need legal input. The value is not the classification itself — it is that the organisation stops treating "AI" as a single decision requiring a single answer.
Work with CloudNala
CloudNala helps organisations move from technology ambition to practical execution across cloud, AI, data, platform engineering and digital services.
Whether you are exploring AI, modernising your cloud environment, building a public-sector digital service, or turning an idea into a working MVP, we can help you shape the roadmap and deliver the next step.
Book an AI Readiness Workshop or write to us at consult@cloudnala.co.za