A legal requirement that almost nobody knows about
The Promotion of Access to Information Act (PAIA) has been in force since 2000. It gives people the right to request access to information held by organisations - both public bodies and private businesses. To make that right practical, the law requires private businesses to publish a document called a PAIA manual (sometimes called a Section 51 manual) that explains what information the business holds, why, and how someone can request access to it.
That's the short version. Here's what it means for your small business.
Who needs a PAIA manual?
In short: every private body that processes personal information. Under PAIA, a "private body" includes any natural or juristic person that carries on a trade, business, or profession. That means sole proprietors, partnerships, close corporations, PTY Ltd companies, NPOs, trusts - effectively every business in South Africa, regardless of size.
There is no small business exemption. A restaurant with five employees has the same PAIA manual requirement as a listed corporation with five thousand. The scope of your manual will be simpler, but the obligation exists.
The Information Regulator (the same body that enforces POPIA) has been increasingly clear that this is not optional. They've published guidance specifically encouraging small and medium businesses to comply.
What a PAIA manual actually is
A PAIA manual is a document that tells the public:
- What your business does and how to contact you
- What categories of records (information) your business holds
- How someone can request access to those records
- What the process is for making a request, including any fees
- What grounds exist for refusing a request
It's not a privacy policy. Your privacy policy (required under POPIA) explains how you handle personal information - what you collect, why, and how you protect it. Your PAIA manual explains what records your business holds and how someone can formally request access to them. They serve different purposes, and you need both.
Think of the privacy policy as telling people what happens to their data. The PAIA manual tells people how to formally ask to see what information you hold, whether about them or about your business operations more generally.
What your PAIA manual needs to contain
Section 51 of PAIA sets out the required contents. For a small business, here's what that looks like in practice:
1. Contact details
Your business name, registration number (if applicable), physical and postal address, phone number, email address, and the name and contact details of your Information Officer. For most small businesses, the Information Officer is the owner or a director.
If you've also designated a Deputy Information Officer, include their details too.
2. The Section 10 guide
A reference to the South African Human Rights Commission's guide on how to use PAIA. You don't need to reproduce it - just mention that it exists and provide the SAHRC's contact details or a link to their website.
3. Categories of records held
This is where most small business owners get stuck, because it sounds complicated. It isn't. You need to list the types of records your business keeps, grouped by category. For a typical small business, these might include:
- Company records - registration documents, memorandum of incorporation, minutes of meetings
- Financial records - invoices, receipts, tax returns, bank statements, annual financial statements
- Employment records - employment contracts, payroll records, leave records, disciplinary records (if you have employees)
- Client records - client contact details, correspondence, contracts, order history, invoices
- Supplier records - supplier contracts, invoices, delivery records
- Operational records - policies, procedures, insurance records, lease agreements
- Website records - contact form submissions, email subscriber lists, analytics data, customer account data (if applicable)
You don't need to list every individual document. You're listing categories - the types of information your business holds, not specific files.
4. How to request access to records
Describe the process someone would follow to request access to your records. Under PAIA, requests must be made using the prescribed form (Form 2 for private bodies), submitted to your Information Officer, and responded to within 30 days.
Include:
- Where to send the request (physical address or email)
- That the request must be made on the prescribed form
- That fees may apply (PAIA allows reasonable fees for search and preparation, and reproduction of records)
- That you will respond within 30 days
5. Grounds for refusal
PAIA allows you to refuse access to certain records in specific circumstances - for example, records that would reveal trade secrets, records subject to legal privilege, or records whose disclosure would endanger someone's safety. List the sections of PAIA that may apply to your records.
You don't need to write this from scratch. The relevant sections are 62-70 of PAIA, and you can reference them rather than reproducing the full legal text.
6. Availability of the manual
State how people can access your PAIA manual - on your website, at your business premises, from the Information Regulator, or on request.
Where to put it on your website
The simplest approach is a dedicated page on your website, linked from the footer alongside your privacy policy. Common URL patterns are /paia-manual, /paia, or /section-51-manual.
Some businesses publish it as a downloadable PDF. That works, but a web page is easier to find via search, easier to update, and better for accessibility. If you want to offer both, publish the web page as the primary version and provide a PDF download link on that page.
Make it easy to find. If someone is looking for your PAIA manual - whether a member of the public, a customer, or the Information Regulator - they shouldn't have to dig through your sitemap to locate it.
Common myths about PAIA manuals
"Only big companies need one." Not true. Every private body that processes personal information needs a PAIA manual, regardless of size. The Information Regulator has explicitly stated this.
"My privacy policy covers it." It doesn't. A privacy policy and a PAIA manual are different documents with different legal bases and different purposes. You need both.
"Nobody ever actually requests access." That may be true for your business right now, but the obligation to have the manual exists regardless of whether anyone uses it. And access requests do happen - disgruntled employees, former clients, regulatory investigations.
"I can just copy one from the internet." You can use a template as a starting point (the Information Regulator publishes guidance), but your manual needs to reflect your actual business - the categories of records you actually hold, your actual contact details, your actual Information Officer. A generic copied manual that doesn't match your business isn't compliant.
"There's no enforcement." The Information Regulator has the power to enforce PAIA compliance and has been increasingly active. While small businesses aren't the primary enforcement target, non-compliance is a risk that's straightforward to eliminate.
How we handle this for clients
When we build a website for a client, we include a PAIA manual page in the site structure. We can't write the legal content for you - the manual needs to reflect your specific business operations - but we set up the page, structure it correctly, and guide you through what each section needs to say.
For existing clients, adding a PAIA manual page is a quick addition. The structure is standardised, so the main work is listing your categories of records accurately and confirming your Information Officer details.
A minimum viable PAIA manual outline
If you want to get started, here's an outline you can work from. Fill in the specifics for your business:
1. Introduction
- Business name, trading name, registration number
- Nature of business (one or two sentences)
2. Contact details of Information Officer
- Full name, position, phone, email, physical address
3. Guide in terms of Section 10
- Reference to the SAHRC's guide on how to use PAIA
- SAHRC contact details or website link
4. Records held by the business
- Company records (list categories)
- Financial records (list categories)
- Employment records (list categories, if applicable)
- Client/customer records (list categories)
- Supplier records (list categories)
- Operational records (list categories)
- Website and digital records (list categories)
5. Request procedure
- Requests must be made on the prescribed form (Form 2)
- Submit to the Information Officer at [address/email]
- Fees may apply as prescribed
- Response will be provided within 30 days
6. Grounds for refusal
- Reference to Sections 62-70 of PAIA
- Brief description of applicable grounds
7. Availability of the manual
- Available on this website at [URL]
- Available for inspection at [physical address]
- Available from the Information Regulator
Getting it done
A PAIA manual is one of those compliance items that feels intimidating until you sit down and do it. For most small businesses, the actual work is an hour or two - listing what records you hold, filling in your details, and publishing the page.
The risk of not having one is small today but growing. The Information Regulator is building capacity and expanding enforcement. Getting your manual in place now means one less thing to worry about later - and it signals to customers, partners, and regulators that your business takes its legal obligations seriously.
If you'd like help adding a PAIA manual page to your website, or you're not sure what your manual needs to include for your specific business, get in touch. We'll point you in the right direction.