South African businesses that upload staff or job applicant information to AI tools such as ChatGPT, Gemini and Claude could face risks under POPIA, two lawyers said.
Melissa Cogger and Talita Laubscher, partners at law firm Bowmans, said businesses must understand how the Protection of Personal Information Act applies when AI is used in human resources, Daily Investor reported.
Employers now use AI to screen job applications, rate staff performance, help with hiring and process employee records. This can involve a lot of personal information, such as CVs, interview recordings, health details and performance data.
Under POPIA, the employer stays responsible for making sure this information is handled lawfully and safely.
The lawyers pointed to Section 71 of the Act. It limits decisions made only by automated systems when the result has legal effects on a person or affects them in a serious way.
In a workplace, this could apply when an AI system gives an employee a performance score, picks someone for promotion or demotion, or advises turning down a job applicant.
There are exceptions linked to contracts, but the affected person must get a chance to respond. They must also be told enough about how the system reached its result.
According to the lawyers, this is hard for many businesses because some AI systems do not explain how they reach a result. This is often called the “black box” problem, and it makes it hard for employers to account for decisions.
Job applicants who are left out may need a chance to challenge the decision and speak to a human, the lawyers said.
Section 18 of POPIA also requires businesses to tell people what information is being collected and why. Where relevant, people must also know where their information may be sent. Staff and applicants should be told when AI is used to process their details.
Businesses must also check whether personal information will be sent to other countries when they use cloud-based AI systems.
The lawyers said POPIA requires businesses to use only the information they really need. Information must be collected for a specific purpose, kept safe and not stored for longer than needed.
Some types of information get extra protection. These include health details, religious beliefs, race, trade union membership, political views, biometric data and criminal records. Facial recognition tools, for example, may process biometric data or guess a person’s race.
Many employers use recruitment agencies or outside AI providers. Cogger and Laubscher said the employer is still the “responsible party” under POPIA, even when another company does the processing.
This means contracts with AI vendors and agencies should cover data security, limits on use, how long data is kept and POPIA compliance. Outsourcing the work does not remove the employer’s duties, the lawyers said.
Another risk comes when workers use public AI tools on the job. An employee could upload a colleague’s details, customer information or other private data to an AI platform, creating a POPIA problem for the business.
The lawyers said businesses should set clear AI policies on what staff may and may not upload. They said employers should use closed or enterprise AI systems where possible, or remove identifying details before data goes into an AI tool. They added that staff training is also important.
Source: this article is based on reporting by Daily Investor. Image: Daily Investor. Written with the help of AI and published by the Tzaneen Voice Business desk. See our Editorial Standards.
Anelisa Nkuna covers business and money news for Tzaneen Voice. Anelisa reports on the rand, fuel prices, interest rates, jobs, Eskom, Transnet, farming and company results. The aim is simple: explain what the numbers mean for household budgets, small businesses and workers in South Africa.