Your data is leaving South Africa every time your team opens a consumer AI tool
Consumer AI tools process your company data on foreign servers, outside POPIA's reach. This calculator estimates what that exposure could cost.
Estimated potential exposure
—
—
—
In practice, enforcement outcomes are often settled at a fraction of the statutory exposure — in some cases around 50% or less. The figure above represents the estimated upper boundary, not a guaranteed outcome.
Your exposure, explained
Shadow AI users in your organisation
—
Annual data transfers outside South Africa
—
Estimated fine per infringement
—
Compliance risk
How your data sovereignty is being violated
—
—
Industry-specific regulatory risk
This calculator provides illustrative estimates only and does not constitute legal, financial, compliance, or any other form of professional advice. The figures shown represent potential exposure under POPIA's enforcement framework — they are not predictions of actual fines, settlements, or penalties. POPIA fine ranges derive from the Protection of Personal Information Act, 2013 (Sections 72, 99, 107, 109). Per-infringement estimates are modelled on Section 109(2) severity factors and are not published by the Information Regulator. Actual enforcement outcomes depend on the Regulator's discretion, the specific circumstances of each case, the degree of cooperation, and potential settlement negotiations. Enforcement cases referenced are sourced from Information Regulator media statements and reporting by Bowmans, ITWeb, Michalsons, and Werksmans. Sector-specific consequences are based on published legislation. Consult qualified legal counsel for advice specific to your organisation. © Cuumulo Nymbis.