PAIA Manual
Promotion of Access to Information Act (PAIA) Manual
This manual explains what records Phandu Communications holds, how to request access to them under PAIA, and how the company processes personal information under POPIA — prepared in terms of Section 51 of the Promotion of Access to Information Act 2 of 2000.
Definitions
| Term | Description |
|---|---|
| CEO | Chief Executive Officer |
| Client | Any natural or juristic person that received or receives services from the company |
| Complainant | Any person who lodges a complaint with the Information Regulator |
| Complaint | A matter reported to the Regulator under section 74(1)/(2), a complaint under section 76(1)(e) and 92(1), or a matter reported under other legislation regulating the Regulator's mandate |
| Conditions for Lawful Processing | The conditions set out in chapter 3 of POPI and in section 12 of this manual |
| Data Subject | The person to whom personal information relates |
| Day | A calendar day — excluding a Sunday or public holiday if the last day of a period falls on one |
| DIO | Deputy Information Officer |
| Information Officer / IO | The individual legally appointed to ensure compliance with POPIA and PAIA |
| Manual | This manual |
| Minister | Minister of Justice and Correctional Services |
| Office Hours | 08:00–16:00 Mon–Fri (Regulator, excl. public holidays); operating hours for designated offices |
| PAIA | The Promotion of Access to Information Act, No. 2 of 2000 |
| Personal Information | Information relating to an identifiable living person or existing juristic person — including race, gender, contact info, biometrics, correspondence, opinions, and identifiers |
| Personnel | Anyone who works for or provides services to the company for remuneration, including permanent, temporary and part-time staff, directors, and contractors |
| POPI / POPIA | The Protection of Personal Information Act, No. 4 of 2013 |
| POPI Regulations | Regulations promulgated under section 112(2) of POPI |
| Private Body | A natural person conducting business; a business partnership; a juristic person that is not a public body |
| Processing | Any operation concerning personal information — collection, storage, dissemination, or destruction |
| Regulator | The Information Regulator established under POPIA |
| Republic | Republic of South Africa |
| Signature | Any legally accepted form of signature, including electronic signature |
| Writing | As referred to in section 12 of the Electronic Communications and Transactions Act, 2002 |
Purpose of the PAIA Manual
This manual helps members of the public to:
- 2.1Check which categories of records are available without submitting a formal PAIA request.
- 2.2Understand how to request access to a record, including the subjects and categories of records held.
- 2.3Know which records are available under other legislation.
- 2.4Access the contact details of the IO and DIO who assist with records requests.
- 2.5Know how to obtain the Regulator's guide on how to use PAIA.
- 2.6Know whether personal information is processed, why, and who the affected data subjects are.
- 2.7Know the recipients or categories of recipients personal information may be supplied to.
- 2.8Know whether personal information is transferred outside South Africa, and to whom.
- 2.9Know whether appropriate security measures protect the confidentiality, integrity and availability of that information.
Key contact details
P.O. Box 11386, Erasmuskloof, 0048
+27 12 742 0600 · phandu.co.za
Guide on how to use PAIA
- 4.1The Regulator has, under section 10(1) of PAIA, published a revised guide on how to use PAIA, in an easily comprehensible form.
- 4.2The guide is available in every official language and in braille.
- 4.3The guide describes:
- 4.3.1The objects of PAIA and POPIA
- 4.3.2Postal, physical, phone and email details of every IO and DIO
- 4.3.3The manner and form of a request — for public or private body records, internal appeals, Regulator complaints, and court applications
- 4.3.4The duty to compile a manual under sections 14 and 51, and how to access one
- 4.3.5Voluntary disclosure of record categories under sections 15 and 52
- 4.3.6Fee notices under sections 22 and 54
- 4.3.7Regulations made under section 92
- 4.3.8Assistance available from an IO under PAIA and POPIA
- 4.3.9Assistance available from the Regulator under PAIA and POPIA
- 4.3.10All legal remedies available, and how to lodge them
- 4.3.1
- 4.4Members of the public may inspect or copy the guide at the offices of public and private bodies, including the Regulator, during normal working hours.
- 4.5The guide can also be requested from the IO, or downloaded from justice.gov.za/inforeg.
- 4.6A copy is available for inspection in each official language:AfrikaansNdebeleXhosaisiZuluSwatiSepediSeSothoTswanaVendaTsonga
Statutory references: s.56(a) POPIA — designation of deputy information officers · s.11 PAIA — access to public body records · s.50 PAIA — access to private body records · s.14 / s.51 PAIA — manual update duties (public/private, every 12 months) · s.15 / s.52 PAIA — notice update duties (every 12 months) · s.22 / s.54 PAIA — access fee notices · s.92(11) PAIA — Regulator updates the guide every 2 years.
Guide of the Information Regulator
- 5.1A guide to PAIA, published under section 10 of PAIA, explains how to access information under the Act.
- 5.2It contains the information an individual needs to exercise their PAIA rights.
- 5.3A copy can be requested from the IO using the contact details above.
- 5.4It can also be inspected at the company's offices during ordinary working hours.
- 5.5Or requested directly from the Information Regulator:Information RegulatorP O Box 31533, Braamfontein, Johannesburg, 2017
+27 (10) 023-5200
inforegulator.org.za
PAIACompliance.IR@justice.gov.za
Section 52(2) notices
At this stage, no notices have been published on categories of records available without requiring a formal PAIA request.
Availability of certain records
7.1 — Categories available without a formal request:
| Category of records | Types of record | Website | On request |
|---|---|---|---|
| PAIA Manual | Company's current PAIA Manual | ✓ | |
| Company overview | Company profile, business activities, contact details | ✓ | |
| Policies (public-facing) | Privacy policy, website cookies policy | ✓ | |
| Legal disclosures | Consumer protection notices, disclaimers, terms & conditions | ✓ | |
| News and announcements | Newsletters, media releases, service updates | ✓ | |
| Public marketing materials | Brochures, product offerings, service descriptions | ✓ | |
| POPIA / PAIA training certificates | Attendance registers for POPIA and PAIA training | ✓ | |
| Public tender / supplier information | Supplier registration forms, B-BBEE certificate | ✓ | |
| Contact information for IO | Name, designation, email address, contact number | ✓ |
7.2 — Records available under other legislation:
| Category of records | Applicable legislation |
|---|---|
| MOI, company registration, board minutes, share register | Companies Act, 71 of 2008 |
| Employment contracts, attendance, payroll, leave records | Basic Conditions of Employment Act, 75 of 1997 |
| Disciplinary records, grievances, union agreements, CCMA docs | Labour Relations Act, 66 of 1995 |
| EE plans, EE reports, committee minutes | Employment Equity Act, 55 of 1998 |
| Tax returns, IRP5s, PAYE records | Income Tax Act, 58 of 1962 |
| Workplace Skills Plans, training reports, learnerships | Skills Development Act, 97 of 1998 |
| UIF contributions, declarations, benefit claims | Unemployment Insurance Act, 63 of 2001 |
| H&S audits, incident reports, risk assessments | Occupational Health and Safety Act, 85 of 1993 |
| VAT returns, input/output records, SARS correspondence | Value-Added Tax Act, 89 of 1991 |
| WCA claims, injury-on-duty reports | COID Act, 130 of 1993 |
| B-BBEE certificates, ownership & supplier development | B-BBEE Act, 53 of 2003 |
| Client contracts, complaints, marketing disclaimers | Consumer Protection Act, 68 of 2008 |
| Consent forms, privacy notices, operator agreements | Protection of Personal Information Act, 4 of 2013 |
| PAIA Manual, access request logs, training records | Promotion of Access to Information Act, 2 of 2000 |
| E-comms policies, e-signature consents, website T&Cs | Electronic Communications and Transactions Act, 25 of 2002 |
| Retention/disposal schedules, archive logs | National Archives and Records Service Act, 43 of 1996 |
| Newsletters, brochures, posters, price lists | PAIA — automatic availability per s.51(1)(c) |
Additional legislation that may apply per the Section 51 manual: Administration of Estates Act · Attorneys Act · Arbitration Act · Auditing Profession Act · Banks Act · Close Corporations Act · Competition Act · Criminal Procedure Act · Copyright Act · Currency and Exchanges Act · Debt Collectors Act · Designs Act.
7.3 — Records held for PAIA and POPIA purposes:
- PAIA: PAIA Manual, PAIA guides, PAIA records, submission records, awareness training
- POPIA: IO Registration Certificate, data breach records, retention records, awareness training
- Further information may be made available on request
Request process
- 8.1Requesters must follow all procedures laid down in PAIA.
- 8.2Complete PAIA Form 2 and submit it to the IO.
- 8.3Submit the form, request fee, and deposit (if applicable) via the postal address, physical address, fax, or email on record.
- 8.4The form must clearly identify:
- The record(s) requested
- The identity of the requester
- What form of access is required
- The requester's postal address or fax number
- 8.5The requester must state which right they are exercising or protecting, and why the records are needed for that purpose.
- 8.6Requests are handled within 30 days of receipt, unless special grounds justify a faster response.
- 8.7The 30-day period may be extended by up to 30 further days for large volumes or records held elsewhere — the IO notifies the requester in writing.
- 8.8The IO responds using PAIA Form 3, covering:
- The decision
- Fees payable
- 8.9If search and preparation would exceed six hours, the requester is asked for a deposit of up to one-third of the total fee.
- 8.10Requesters who need help with the form or process should contact the IO.
- 8.11Requesters unable to complete the form due to illiteracy or disability may request orally; the IO completes it on their behalf and provides a copy.
- 8.12POPIA Form 2 — request correction or deletion of inaccurate, outdated, incomplete, or unlawfully obtained personal information (s.24(1) POPIA).
- 8.13POPIA Form 3 — an industry body applies for a Code of Conduct under s.61(1)(b) POPIA.
- 8.14POPIA Form 4 — request a data subject's consent for direct marketing under s.69(2) POPIA.
- 8.15POPIA Form 5 — lodge a complaint with the Regulator about unlawful interference with personal information.
Grounds for refusal
Subject to the exceptions in Chapter 4 of PAIA, a request may be refused on these grounds:
- 9.1Mandatory protection of a third party's privacy — including a deceased person — where disclosure would be unreasonable.
- 9.2Mandatory protection of a third party's commercial information, where the record contains:
- 9.2.1Trade secrets of that third party
- 9.2.2Financial, commercial, scientific or technical information whose disclosure could cause harm
- 9.2.3Information disclosed in confidence that could disadvantage the third party commercially
- 9.2.1
- 9.3Mandatory protection of confidential third-party information protected by agreement.
- 9.4Mandatory protection of the safety of individuals and of property.
- 9.5Mandatory protection of records privileged in legal proceedings.
- 9.6Protection of the company's own commercial information, which may include trade secrets, financial/commercial/scientific/technical information, negotiation-sensitive information, or copyrighted computer programs.
- 9.7Research information whose disclosure would seriously disadvantage the research or researcher.
- 9.8Requests that are clearly frivolous, vexatious, or an unreasonable diversion of resources.
Remedies should a request be refused
- 10.1Phandu Communications has no internal appeal procedure — a decision by the IO is final.
- 10.2Under sections 56(3)(c) and 78 of PAIA, the requester may apply to a court for relief within 180 days of being notified of the decision.
Fees
| Detail | Fee |
|---|---|
| Request fee (payable on every request) | R140.00 once-off |
| Photocopy of an A4 page or part thereof | R2.00 per page |
| Printed copy of an A4 page or part thereof | R2.00 per page |
| Hard copy on flash drive (requester supplies drive) | R40.00 once-off |
| Hard copy on CD (requester supplies CD) | R40.00 once-off |
| Hard copy on CD (company supplies CD) | R60.00 once-off |
| Transcription of visual images, per A4 page | Per service provider quotation |
| Copy of visual images | Per service provider quotation |
| Transcription of an audio record | R24.00 per A4 page |
| Copy of audio on flash drive (requester supplies) | R40.00 once-off |
| Copy of audio on CD (requester supplies) | R40.00 once-off |
| Copy of audio on CD (company supplies) | R60.00 once-off |
| Base rate — search & prepare record for disclosure | R145.00 per hour after the first hour, capped at R435.00 per request |
| Standard rate — search & prepare record for disclosure | R435.00 per hour after the first hour, capped at total cost |
| Postage, email, or other electronic transfer | Actual expense, if any |
Processing of personal information
12.1 — Purpose of processing:
- 12.1.1Providing HR, labour relations, payroll, skills development, health & safety, and related business support services, which requires processing personal information of employees, clients, contractors, and service providers.
- 12.1.2Complying with applicable law — BCEA, LRA, Skills Development legislation, OHS Act, EE Act, and POPIA — which require retention, use, and disclosure of certain categories of information.
- 12.1.3Legitimate business purposes: client and employee records, contract administration, payroll and benefits, compliance monitoring, audits, training, risk management, security, and stakeholder communication.
12.2 — Categories of data subjects and information processed:
| Category of data subject | Personal information that may be processed |
|---|---|
| Customers / clients | Name and surname · company name/registration number · ID/passport number (if applicable) · contact details · employment status (where relevant) · bank account details · tax/VAT information · service and contractual records |
| Service providers | Name and surname (or representative) · company/CC registration number · VAT and tax information · business address and contact details · trade/technical/commercial information · bank account details · contractual and payment history |
| Employees | Full name and surname · ID/passport number · residential and postal address · contact details · qualifications, skills, training and employment history · demographic information · employment records · financial details · medical, disability or health information (where required for statutory compliance) · next-of-kin/emergency contacts · internal security details |
Recipients of personal information
| Categories of personal information | Recipients or categories of recipients | Purpose |
|---|---|---|
| ID numbers, names, contact details | South African Police Services | Criminal and background checks |
| Qualifications, professional registrations, training records | SAQA, professional councils, accredited training providers | Verification of qualifications and credentials |
| Employment history, references, disciplinary records | Previous/prospective employers, recruitment agencies | Employment screening and placement |
| Credit and payment history | Credit bureaus, banks, financial institutions | Credit checks, payroll, financial risk assessment |
| Tax numbers, income details, banking details | SARS, banks, payroll service providers | Payroll administration, statutory compliance, payments |
| Medical information, disability status, H&S records | Medical aid providers, insurers, occupational health practitioners | Employee benefits and workplace health & safety compliance |
| Contact and ID details of employees/clients | Insurers, brokers, benefit administrators, underwriters, claims assessors | Benefits, insurance, and claims administration |
| Contract and compliance documentation | Attorneys, auditors, tracing agents, debt collectors, courts, trustees, executors, curators | Legal proceedings, dispute resolution, debt recovery, audits |
| Personal information related to regulatory compliance | Dept. of Employment and Labour, Information Regulator, CCMA, B-BBEE Commission, other authorities | Statutory reporting and regulatory oversight |
| Client and employee information processed during service delivery | Contractors, suppliers, business partners, cloud/IT service providers | Service delivery, IT support, contracted operations |
| Personal information where required by law | Law enforcement, fraud prevention agencies, ombudsmen, regulators | Compliance with statutory obligations and official requests |
| Personal information for internal use | Phandu Communications employees, management, group companies and affiliates | HR administration, internal governance, day-to-day operations |
Planned transborder flows of personal information
Phandu Communications uses cloud-based platforms and service providers to store and process personal information. This may involve cross-border transfers to jurisdictions with adequate data protection laws, such as EU member states and the United States.
Information that may be transferred includes:
- Customers/clients: contact information, registration numbers, financial details, contractual records
- Service providers: business registration details, VAT numbers, banking details, contracts
- Employees: HR records, payroll and tax information, demographic data, training and development information
14.1 — Security measures protecting confidentiality, integrity and availability:
- 14.1.1Technical safeguards
- ·Data encryption in transit and at rest
- ·SSL/TLS protocols for secure communications
- ·Role-based access control, strong passwords, multi-factor authentication
- ·
- 14.1.2Administrative safeguards
- ·Policies governing data processing, retention, and disposal
- ·Confidentiality agreements signed by employees, contractors, and third parties
- ·Regular training and awareness programs on POPIA and internal security policy
- ·
- 14.1.3Physical and monitoring safeguards
- ·Physical access controls — security personnel, access cards, CCTV
- ·Anti-virus, anti-malware, and intrusion detection, regularly updated
- ·Regular backups and disaster recovery planning
- ·
Availability of the manual
- 15.1A copy of the manual is available:
- 15.1.1At Phandu Communications' office for public inspection during business hours, by appointment
- 15.1.2To any person on request, on payment of a reasonable prescribed fee
- 15.1.3To the Information Regulator on request
- 15.1.1
- 15.2A fee, as set out in Annexure B of the Regulations, is payable per A4-size photocopy.
Objection to processing by a data subject
- 16.1A data subject objecting to processing under s.11(3)(a) or (b) of POPIA may submit the objection at any time during office hours, free of charge.
- 16.2Objections use a form substantially similar to POPIA Form 1, submitted free of charge by hand, fax, post, email, SMS, WhatsApp, or any manner convenient to the data subject.
- 16.3When collecting personal information, Phandu Communications notifies the data subject of their right to object, per s.18(1)(h)(iv).
- 16.4Telephonic objections are electronically recorded and, on request, made available to the data subject — including a transcription.
Request for correction / deletion of personal information
- 17.1A data subject may, under s.24 of POPIA, request correction, destruction, or deletion of their personal information.
- 17.2Correction or deletion may be requested at any time, free of charge, if information is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained (s.24(1)(a)).
- 17.3Destruction or deletion of a record may be requested at any time, free of charge, if the company is no longer authorised to retain it under s.14 (s.24(1)(b)).
- 17.4Requests use a form substantially similar to POPIA Form 2, submitted free of charge by hand, fax, post, email, SMS, WhatsApp, or any convenient manner.
- 17.5Telephonic requests are recorded and made available to the data subject on request, free of charge, including a transcription.
- 17.6The company notifies the data subject in writing of the action taken, within 30 days of the outcome.
Updating of the manual
The head of Phandu Communications will update this manual on a regular basis.
Document controls
| Document owner | Document authoriser | Approval date | Next review date |
|---|---|---|---|
| Takalani Savhase | Takalani Savhase | 26 July 2026 | 26 July 2027 |
Applicable forms
PAIA Forms
POPIA Forms