Home » Insights » Before You Use That AI Tool: A POPIA Compliance Checklist for Psychologists

Before You Use That AI Tool: A POPIA Compliance Checklist for Psychologists

POPIA compliance for an AI tool used in therapy practice

AI tools are entering psychology practice faster than most practitioners have had time to evaluate them properly. Session scribes, telehealth platforms, assessment tools, and general-purpose AI assistants all have one thing in common: they handle your clients’ personal information. Under South African law, that means each one must be a POPIA-compliant AI tool before you use it in clinical or administrative work. The updated HPCSA Booklet 20 guidelines, published in November 2025, make this a professional obligation — not just a legal one (Health Professions Council of South Africa, 2025). You can read a full overview of what Booklet 20 requires in our guide to AI and digital ethics in psychology practice.

The problem most psychologists face is not unwillingness to comply — it is knowing what to actually check. POPIA is a detailed piece of legislation, and most compliance resources are written for large organisations, not solo practitioners or small group practices. Consequently, this post cuts that down to three specific questions you should ask before adopting any AI tool that touches client data. For guidance on what to do once a tool is in use, see our article on documenting AI session notes compliantly.

Why POPIA compliance matters for your AI tools

The Protection of Personal Information Act governs how personal information is collected, stored, used, and shared in South Africa. Client information processed through any AI tool — including audio recordings, session transcripts, assessment responses, and clinical notes — qualifies as personal information under POPIA. Furthermore, psychological records qualify as special personal information under Section 26 of the Act, which carries a higher standard of protection (Information Regulator of South Africa, 2020).

HPCSA Booklet 20 is explicit on this point: any AI platform used in your practice must comply with POPIA, and you must verify that compliance before adoption — not after a data incident (Health Professions Council of South Africa, 2025). The HPCSA also requires that adequate data processing agreements are in place for any third-party platform handling client data.

Non-compliance carries significant risk. The Information Regulator of South Africa moved from awareness-raising to active enforcement from 2022 onwards, issuing enforcement notices against Dis-Chem, the South African Police Service, and the Department of Justice. The maximum penalty under POPIA is R10 million (Information Regulator of South Africa, 2020). More immediately, a data breach involving client psychological records constitutes a professional ethics matter as well as a legal one.

Ready to earn your ethics CEUs and build your knowledge of digital compliance? Browse the 2026 PsyCampus CPD packages — HPCSA-accredited and designed around current practice requirements.

Question 1: Where is my client’s data stored and processed?

The first question to ask of any AI tool is where — physically — your client’s data goes when the tool processes it. This matters because POPIA places restrictions on transferring personal information outside South Africa’s borders (Information Regulator of South Africa, 2020).

Many popular AI tools — including widely used cloud-based transcription services and general-purpose AI assistants — are hosted on servers in the United States or European Union. An international platform does not automatically meet South African legal standards, even if it complies with GDPR or similar frameworks. You must verify that the platform either stores and processes data within South Africa, or meets the specific cross-border transfer conditions set out in Section 72 of POPIA.

Specifically, you need to check the platform’s privacy policy or terms of service for its data residency policy. Look for language specifying where data is stored and processed. If the document is vague on this point, contact the provider directly and ask in writing. If they cannot give you a clear answer, that is itself a compliance concern.

What to look for

  • Data residency policy — where servers are physically located
  • Whether client audio, text, or records leave South Africa’s borders
  • Whether the platform relies on sub-processors (third parties who also handle your data) and where those sub-processors are based

Question 2: Does a data processing agreement exist?

The second question is whether a formal data processing agreement — sometimes called a data processing addendum — is available for the platform. POPIA requires that where a third party processes personal information on your behalf, a written agreement must govern that relationship (Information Regulator of South Africa, 2020).

As the responsible party under POPIA, you are the one who must ensure this agreement exists. The platform being a large, well-known company does not create the agreement automatically — you must locate it, review it, and retain a copy for your records. Most reputable platforms provide a standard data processing agreement that can be signed online or downloaded. If a platform does not offer one, it is not suitable for use with client data under South African law.

A compliant agreement should include confirmation of what data is processed and for what purpose, what security measures the processor maintains, how data breaches are reported to you, and conditions for deleting client data when you end the relationship with the platform.

What to look for

  • A dedicated data processing agreement available on the platform’s website or on request
  • Confirmation that the processor will only process data according to your instructions
  • A breach notification obligation — the platform must inform you promptly if your client data is compromised
  • A data deletion clause — your client’s records must be deleted when you terminate the service

Question 3: Does my informed consent documentation cover this tool?

The third question is whether your current client informed consent documentation discloses the use of this AI tool and gives clients a meaningful opportunity to decline. Under both POPIA and HPCSA Booklet 20, informed consent for AI use must be specific — it must identify what the tool does, what data it accesses, how that data is stored, and what the client’s right to decline looks like in practice (Health Professions Council of South Africa, 2025).

General consent to digital record-keeping is not sufficient if you are using a third-party AI tool for session documentation or clinical decision support. Furthermore, if a client declines the use of an AI tool, the HPCSA is clear: that client may not be disadvantaged or refused access to your services. You must have a non-AI pathway available for every clinical function where AI is currently used. For a practical guide to setting up that pathway, see our article on what to do when a client declines an AI tool.

Additionally, if you update your AI tools or adopt new platforms, your consent documentation must be updated accordingly and existing clients must be informed of the change before it takes effect.

What to look for

  • Specific disclosure of the AI tool by name or category in your intake or consent forms
  • Plain-language explanation of what data is collected and where it goes
  • An explicit opt-out option with confirmation that declining will not affect access to services
  • A process for updating consent documentation when your tools change

A practical approach to POPIA compliance for AI tools

Working through these three questions for every AI tool in your practice does not need to be a lengthy exercise. Most of the information you need is available in the platform’s privacy policy, terms of service, and data processing agreement — documents that are usually publicly available and searchable.

A useful starting point is to list every digital tool that handles client information — including your practice management software, telehealth platform, transcription service, and any AI assistant you use for documentation. For each tool, work through the three questions above and document your findings. Where a tool cannot satisfy all three questions, you have two options: contact the provider to resolve the gap, or stop using that tool with client data until the gap is resolved.

The HPCSA expects this evaluation to be ongoing — not a one-time exercise. Booklet 20 requires practitioners to review their AI tools as the tools themselves evolve and as the regulatory environment continues to develop (Health Professions Council of South Africa, 2025).

If you are looking to build your understanding of AI ethics, POPIA, and HPCSA digital practice requirements, explore the PsyCampus 2026 CPD packages — or check whether you qualify for a recent graduate discount of up to 40%.

References

Scroll to Top