For years, many businesses treated PAIA as a once-off admin task. Prepare a manual. Put it in a folder. Maybe upload it to the website. Forget about it.
That approach is becoming risky.
The Information Regulator is placing renewed focus on PAIA compliance, and the message is clear: businesses must be able to show that they have more than a template document. They need a working process.
What is PAIA?
PAIA is the Promotion of Access to Information Act. It gives effect to the constitutional right of access to information. Importantly, PAIA does not only apply to government. It also applies to private businesses where information is required for the exercise or protection of a right.
That means a company, trust, partnership, professional practice, school, body corporate, non-profit organisation or other private body may receive a PAIA request.
These requests can come from employees, former employees, clients, suppliers, shareholders, beneficiaries, attorneys, regulators or other interested parties.
Why the sudden focus?
PAIA has moved from the background into the spotlight because the Information Regulator is becoming more active.
The Regulator is now looking more closely at whether organisations:
- have a current PAIA manual;
- have properly appointed and registered Information Officers;
- know how to deal with PAIA requests;
- keep records of requests and responses;
- submit required PAIA reports; and
- align PAIA with POPIA and broader information governance.
In other words, the question is no longer only:
“Do you have a PAIA manual?”
The real question is:
“If someone submits a PAIA request tomorrow, would your business know what to do?”
PAIA and POPIA are now connected
Many businesses have spent time on POPIA, but PAIA is often overlooked. That is a problem because PAIA and POPIA frequently overlap.
POPIA deals with the protection of personal information. PAIA deals with access to information. A request for records may involve both.
For example, a former employee may ask for employment records. A client may ask for documents linked to a dispute. A beneficiary may request trust information. A shareholder may ask for company records.
The business then needs to decide:
- whether the requester is entitled to the information;
- whether the records contain personal information of other people;
- whether access must be granted or refused;
- whether any third parties must be notified; and
- how the response must be recorded.
This cannot be handled properly if no one in the business knows where the PAIA manual is or who is responsible for dealing with requests.
A manual is not enough
A PAIA manual should not be a generic template that no one understands. It should reflect the actual business. Common problems include:
- old contact details;
- incorrect Information Officer details;
- outdated director, trustee or member information;
- vague record categories;
- no link to POPIA processes;
- no internal request procedure;
- no PAIA request register; and
- staff who do not know what PAIA is.
The Information Regulator’s current approach suggests that “paper compliance” is no longer enough. Businesses must be able to demonstrate practical compliance.
What can go wrong?
Poor PAIA compliance can create real risk. A business may:
- miss statutory deadlines;
- refuse a request incorrectly;
- disclose confidential information by mistake;
- fail to protect personal information;
- trigger a complaint to the Information Regulator;
- create unnecessary litigation risk; or
- suffer reputational damage.
PAIA requests often arise when there is already tension — for example, in an employment dispute, shareholder dispute, trust dispute, contractual claim or potential legal matter. That makes it even more important to handle the request properly.
What should businesses do now?
We recommend that businesses do a quick PAIA health check. Ask the following questions:
- Do we have a PAIA manual?
- Is it up to date?
- Is it available on our website or otherwise accessible?
- Is our Information Officer registered?
- Do staff know who handles PAIA requests?
- Do we have a register of PAIA requests?
- Do we know the response deadlines?
- Does our PAIA manual align with our POPIA documents?
- Have we considered our annual PAIA reporting obligations?
- Can we prove compliance if asked?
If the answer to any of these questions is “no”, it is worth reviewing your position.
Final thought
PAIA is no longer something that can sit quietly in a compliance folder. The Information Regulator is moving toward a more active enforcement environment, and businesses should be ready. A good PAIA framework does not need to be complicated. It simply needs to be accurate, current and practical.
Please contact our office if you would like assistance reviewing or updating your PAIA manual, Information Officer registration, PAIA reporting or broader POPIA compliance framework.






