From Notification to Governance: Prior Authorisation in the Age of AI and King V

From notification to governance — prior authorisation in the age of AI and King V

Prior authorisation under the Protection of Personal Information Act (POPIA) is often approached as a procedural requirement. A form is completed, submitted to the Information Regulator, and the organisation waits for a response. While the process is procedural, its purpose is substantive. It exists to ensure that certain higher-risk forms of processing are examined before they begin, and that data subjects are protected from processing that carries particular potential for harm.

Treating the requirement purely as a notification exercise underestimates both its legal weight and its governance significance. This is especially true as organisations adopt artificial intelligence and other advanced digital systems, and as boards operate under the clearer expectations set out in King V.

Higher-risk processing in modern systems

The four categories that trigger prior authorisation — secondary use of unique identifiers with linking, processing of information on criminal or objectionable conduct on behalf of third parties, credit reporting, and cross-border transfers of special personal information or children’s data — are increasingly present in contemporary technology environments.

Artificial intelligence systems frequently rely on the reuse and combination of identifiers, automated profiling, biometric processing, and large-scale data analysis. Many AI platforms depend on cloud infrastructure located outside South Africa. Fraud prevention tools, background screening systems, credit-related models, health applications and educational platforms can all engage one or more of the prior authorisation triggers. The fact that these activities are becoming more common does not reduce the legal obligation. It increases the practical importance of identifying them early.

From procedure to accountability

POPIA requires responsible parties to process personal information lawfully and to implement appropriate safeguards. Information Officers must ensure that Personal Information Impact Assessments are conducted. Where prior authorisation is also required, these obligations converge. The assessment becomes the analytical foundation for the application, and the application becomes the formal engagement with the Regulator.

King V adds a further dimension. Governing bodies are expected to oversee data, information and technology in a way that supports organisational objectives while maintaining ethical conduct, accountability and effective control. Processing that requires prior authorisation is processing that the law itself has flagged as higher risk. Boards that lack visibility of these activities, or that rely only on high-level assurances, are less able to demonstrate the oversight expected of them.

Effective governance in this area depends on more than the existence of a policy. It depends on processes that identify relevant processing activities, assess their privacy implications with care, support well-prepared applications where required, and ensure that processing does not proceed unlawfully. These are operational disciplines, not purely legal formalities.

The cost of treating it lightly

The consequences of non-compliance are significant. Failing to notify the Regulator, proceeding with processing before the investigation is complete, or ignoring a statement issued by the Regulator can result in criminal liability, imprisonment, or administrative fines of up to R10 million. These penalties reflect the seriousness with which the law regards the underlying risks to data subjects.

Organisations that approach prior authorisation as a last-minute administrative step increase both their legal exposure and their project risk. Delays in authorisation can disrupt implementation timelines, particularly where artificial intelligence or cross-border systems are involved. Weak assessments can lead to extended investigation or refusal. In both cases, the organisation pays a practical price for insufficient preparation.

Building a more coherent approach

A more effective approach integrates prior authorisation into the organisation’s broader privacy and project processes. Processing activities are examined against the four statutory categories at an early stage. Where the requirement is triggered, a thorough Personal Information Impact Assessment is completed. The application is prepared with care and submitted in good time. Processing remains suspended until the Regulator has completed its work. Records of the assessment, the application and the outcome are retained as evidence of accountability.

This approach aligns the legal requirement with good governance. It treats higher-risk processing as something that must be understood and controlled, not merely notified. It also provides boards with clearer visibility of activities that carry elevated privacy and regulatory risk.

Prior authorisation is a specific mechanism within POPIA. Its value, however, extends beyond the completion of a form. In an environment shaped by artificial intelligence, cross-border data flows and heightened expectations of board oversight under King V, it serves as a practical test of whether organisations are managing higher-risk processing with the care the law requires. Those that move from notification to genuine governance are better placed to protect data subjects, to meet their legal obligations, and to demonstrate accountability in substance rather than in form alone.