Conversational AI
Is a WhatsApp AI chatbot POPIA compliant? What SA businesses need to know
Is an AI chatbot POPIA compliant?
There's no such thing as a POPIA-certified chatbot. The Protection of Personal Information Act doesn't approve software — it regulates how a business processes personal information, whatever tool does the processing. A WhatsApp bot is compliant or not based on how you configure it and what you do with the data it collects.
Section 4 of POPIA sets out eight conditions for lawful processing: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards, and data subject participation. Translated into what a WhatsApp bot actually does:
- Processing limitation and minimality — only ask for the phone number, name, or booking detail you actually need. A plumber's booking bot doesn't need a customer's ID number.
- Purpose specification and openness — tell people what you're using their information for, ideally in a short line the bot sends on first contact ("we use your name and address to schedule your callout").
- Security safeguards — the platform storing conversation data (your CRM, spreadsheet, or booking system) needs reasonable technical and organisational protection, not just the chat itself.
- Data subject participation — a customer can ask what you hold on them and ask you to correct or delete it. Someone at the business needs to be able to action that request.
None of this requires exotic engineering. It requires a business owner to decide, deliberately, what the bot asks for and where that data goes — the same discipline you'd want from a WhatsApp chatbot built to handle real conversations rather than a script that hoovers up everything a customer types.
Do I need consent to message customers on WhatsApp?
It depends on what kind of message. POPIA draws a hard line between someone messaging your business first (inbound, customer-initiated) and your business messaging them first (outbound, business-initiated) — particularly for marketing.
Section 69 of POPIA prohibits direct marketing by electronic communication — which includes WhatsApp — unless the data subject has consented, or is an existing customer of yours under the "soft opt-in" conditions: you got their details in the context of a sale, you're marketing your own similar products or services, and you gave them a reasonable, free way to object at collection and with every message. Where consent is required and you don't have it, POPIA lets you approach the person once to ask for it — not repeatedly.
In practice, for most small businesses this means a customer messaging your WhatsApp number to ask about a service, book an appointment, or get support doesn't need special marketing consent — that's a service conversation they started. Sending unsolicited promotions, price drops, or newsletter-style broadcasts to numbers you've collected does need consent or the existing-customer exception.
Layer WhatsApp's own opt-in policy on top of that. Meta requires businesses to get permission before messaging someone on the WhatsApp Business Platform, and that opt-in must clearly name your business and state that the person is agreeing to receive WhatsApp messages from you. It can be collected off-platform — on a website form, at checkout, over the phone — as long as those two things are disclosed. Meta and POPIA overlap here but aren't identical: satisfying one doesn't automatically satisfy the other, so check both.
| Obligation | What POPIA requires | What that looks like in a chatbot build |
|---|---|---|
| Consent to message | Section 69 prohibits direct marketing by electronic communication unless the person has consented, or is an existing customer approached about your own similar products or services under the soft opt-in conditions. | Marketing sends are gated behind a stored consent record. A reply inside a conversation the customer started is a service message and sits outside that gate. |
| Opt-out | Section 69 requires a reasonable opportunity to object, free of charge, both when the details are collected and with every marketing communication, plus contact details for a request that communications cease. | A stop keyword the bot honours immediately, written back to the customer record so no later template can reach them, and the sending business named in the message itself. |
| Data minimality | Section 10 allows processing only where the information is adequate, relevant and not excessive, given the purpose it is processed for. | The conversation asks for the fields the job needs and then stops. No identity or banking details collected “in case we need them later”. |
| Retention | Section 14 says records must not be kept longer than necessary for the purpose, unless a law, a contract or the data subject’s consent requires it, and must then be destroyed or de-identified. | A stated retention period per data type, with deletion or de-identification actually scheduled — rather than a chat archive that grows forever because nobody owns the decision. |
| Operator agreements | Sections 20 and 21 govern anyone processing on your behalf and require a written contract covering permitted use, security measures and breach notification. | A signed agreement with whoever builds or hosts the bot, naming where conversation data is stored, who may access it, and how quickly a breach reaches you. |
| Automated decision-making | Section 71 says a person may not be subject to a decision carrying legal consequences, or affecting them to a substantial degree, based solely on automated processing intended to profile them — subject to the exceptions in section 71(2), where the safeguards include a chance to make representations and information about the underlying logic. | The bot gathers, answers and routes. Anything that decides about a person — declining an application, setting a price tier, blocking an account — goes to someone who can review it and explain the reasoning. |
Does a chatbot need the WhatsApp Business API?
For anything beyond a single person manually replying from the free WhatsApp Business app, yes. An AI chatbot that auto-responds, qualifies leads, or books appointments at scale needs to run on the WhatsApp Business Platform (what most people still call "the API"), accessed through a Meta-approved provider.
Two mechanics matter for compliance and cost. First, the 24-hour customer service window: once a customer messages you, you can reply freely for 24 hours. After that window closes, you can only reach them again using a pre-approved message template — free-form replies aren't allowed. Second, marketing-category templates sent to reopen a conversation are treated as direct marketing under POPIA if that's what they contain, which pulls Section 69 back into play. A workflow built around this — rather than bolted on afterwards — is where automating the booking and follow-up steps around the conversation earns its keep, because the handoffs between "customer replied," "window closing," and "needs a human" are exactly where consent and data-handling mistakes happen.
Who is responsible for data a chatbot collects?
You are — even if someone else built the bot. Under POPIA, your business is the "responsible party": the entity that determines why personal information is collected and how it's used. That accountability doesn't transfer to a chatbot vendor, a WhatsApp provider, or an AI platform just because they process the data on your infrastructure.
The vendor or developer is typically an "operator" — someone processing personal information on your behalf, under your instruction. Sections 20 and 21 of POPIA govern that relationship, and Section 21 requires a written contract with any operator: what they may do with the data, how they must secure it, and how they must flag a breach. If you're using a third party to build or host a WhatsApp chatbot, that contract isn't optional paperwork — it's the mechanism that keeps your obligations enforceable against theirs.
Practically, this means knowing exactly where chatbot conversation data lands (a spreadsheet, a custom CRM you control, a database managed by your provider), who can access it, and how long you keep it. "The chatbot company handles that" is not a compliance answer the Information Regulator will accept — your business remains on the hook.
A practical compliance checklist
- Write down what personal information the bot collects and why — one sentence per data field is enough.
- Collect only what the conversation actually needs (minimality) — resist adding fields "just in case."
- Get explicit opt-in before sending marketing messages, and log how and when consent was given.
- Give every customer an easy, free way to opt out or ask you to delete their data.
- Put a written operator agreement in place with whoever builds or hosts your chatbot.
- Know where conversation data is stored, who can see it, and for how long you keep it.
- Nominate someone (often your Information Officer) who can handle a data-subject access or deletion request.
If you're weighing a chatbot against other ways to automate customer-facing work, our piece on practical AI workflow automation examples for small businesses covers where the same data-handling questions show up outside WhatsApp.
This article is general information based on publicly available POPIA text and Information Regulator and Meta guidance — it isn't legal advice. If you're processing sensitive data (health, financial, biometric) or running marketing at volume, get a POPIA-registered Information Officer or attorney to review your specific setup.
Related reading
- What a WhatsApp AI chatbot does for a South African business
- Custom CRM development — owning where customer data actually lives
- Can an AI chatbot handle South African languages?
- What drives the cost of a Cognexa build
Quick answers
What personal information can a WhatsApp chatbot legally collect?
Whatever the specific interaction genuinely requires, and no more. A booking bot can ask for a name, number, and appointment slot; it has no lawful reason to ask for an ID number or banking details unless that data is actually needed for the service being delivered. This is POPIA's minimality condition in practice.
Do I need a privacy notice for a WhatsApp chatbot?
Yes. POPIA's openness condition requires you to tell people what information you're collecting and why, generally at the point of collection. For a chatbot this can be a short first message plus a link to a fuller privacy policy on your website — it doesn't need to be a legal wall of text.
What happens if my WhatsApp chatbot breaches POPIA?
The Information Regulator can investigate, issue enforcement notices, and impose administrative fines; serious breaches can also carry criminal penalties for the responsible party. Beyond formal penalties, a data subject who suffers harm from a breach can claim civil damages. Getting the basics right — minimal data, clear disclosure, consent for marketing, a secure storage location — avoids the vast majority of real-world risk.
Can a WhatsApp chatbot store customer chat history?
Yes, provided you have a lawful reason to keep it, you secure it appropriately, and you don't hold onto it indefinitely without justification. POPIA's further processing limitation means chat history collected for one purpose (booking a service) shouldn't quietly get reused for something unrelated (bulk marketing) without fresh consent.
Sources & further reading
- Information Regulator South Africa — Guidance Notes
- POPIA Section 4 — Lawful processing of personal information
- POPIA Section 69 — Direct marketing by means of unsolicited electronic communications
- POPIA Section 71 — Automated decision making
- Protection of Personal Information Act 4 of 2013 — full text (Department of Justice)
- Meta for Developers — Get opt-in for WhatsApp
- Protection of Personal Information Act 4 of 2013 — South African Government
- Michalsons — Does an operator process your personal information? Operator agreements