Qualysec
Blog

Complete PAIA Compliance Checklist: Manuals & Requirements

Ensure your organization meets South Africa’s PAIA requirements. Explore our complete compliance checklist, PAIA manual guides, and step-by-step setup tips.

Published on August 16, 2026
Read Time: 18 min
CONNECT WITH US

Someone requests information about your organization and nobody knows how to respond because you’ve never properly documented what information you hold or where it is stored. Your management team realizes you probably need something called a PAIA manual, but nobody’s certain what that means. You wonder whether the Promotion of Access to Information Act even applies to your organization or whether it’s only for government.

Your compliance officer mentions POPIA and PAIA seem related but different, which leaves you confused about whether POPIA vs PAIA integration is something you need to handle. A PAIA compliance checklist removes this confusion by showing exactly which steps your organization needs to take.

What Is PAIA?

PAIA stands for the Promotion of Access to Information Act, and it’s South Africa’s transparency law that gives the public a right of access to records held by organisations. For private bodies, that right only applies when the record is required for the exercise or protection of any rights.

What PAIA actually covers:

  • Records held by your organization, whether you’re a private company or government agency
  • Information about individuals, decisions that affect people, and how your business operates
  • Documents, emails, databases, and essentially any record regardless of format
  • Information even if it’s old unless specific legal reasons allow you to refuse

What your organization must do:

  • Keep your records organized so you know what information you actually hold and where it sits
  • Appoint someone officially responsible for handling information access requests from the public
  • Respond to valid requests within the 30-day legal timeframe (or the single permitted extension)
  • Only refuse requests when actual legal exemptions clearly apply to the situation
  • Make your PAIA compliance checklist and procedures easy to find so people know how to request information

Who Must Comply with PAIA?

Most organizations think PAIA only applies to government, but that’s wrong.

Organizations that must comply:

  • Government departments and municipal councils
  • Private companies operating in South Africa
  • Nonprofits and educational institutions
  • Healthcare organizations and banks
  • Professional associations and regulatory bodies
  • Trusts that carry on business and charitable organisations

Size doesn’t save you. A small business holding customer records must comply just like a large corporation. If your organisation is a public body or a private body (a company, close corporation, trust carrying on business, nonprofit, sole proprietor carrying on a trade, etc.) and it holds records, PAIA applies. Size does not create an exemption.

What Is a PAIA Manual?

A PAIA manual is basically your rule book telling people what information you hold and how they can get it from you. It’s called a Section 51 manual because that is the part of the Act that requires them to create one. Public bodies compile theirs under section 14. Either way, it serves as your official transparency guide.

Why you need a PAIA manual:

  • It’s your legal requirement under the Promotion of Access to Information Act
  • It shows you’re transparent about what information you hold
  • It prevents people from guessing whether you have records they can request
  • It protects you by proving you follow formal procedures
  • It ensures everyone in your organization handles requests the same way
  • It reduces confusion about which information you’ll actually release to people

Overwhelmed by compliance requirements? Speak with our security experts to get your PAIA setup right the first time.

Complete PAIA Compliance Checklist

A proper PAIA compliance checklist guides your organization through implementation and ongoing maintenance.

1. Determine Whether Your Organization Requires a PAIA Manual

Figuring out whether you need one is actually your first step before doing anything else.

When your organization definitely needs a PAIA manual:

  • You are a private company (or other private body) operating in South Africa
  • You are a nonprofit, trust that carries on business, or professional association
  • You are a public entity or government organisation
  • You fall within the definition of a public body or private body under section 1 of PAIA

Implementation step:

Write down your answer showing whether PAIA applies to your organisation based on what you actually do and whether you qualify as a public or private body under the Act. This documentation protects you later if someone questions whether you are complying.

2. Appoint an Information Officer

Someone in your organization needs to be the official person handling information access requests from the public and managing your PAIA compliance checklist, because if nobody’s officially responsible, requests get lost and you end up breaking the law without realizing it happened.

What the Information Officer does:

  • Must be registered with the Information Regulator before performing any duties
  • Receives and logs access requests
  • Determines whether the organisation holds the requested records
  • Decides whether to grant or refuse access according to the Act
  • Responds within the required 30-day timeframe (or permitted extension)
  • Keeps records of every request and the decision taken
  • Updates and maintains your Section 51 manual so it stays accurate
  • Informs the requester of the available remedies if access is refused (complaint to the Regulator or court)

Your Information Officer also handles the annual PAIA report that every public and private body is expected to submit to the Information Regulator. The report covers all access requests received between 1 April and 31 March and is filed through the eServices portal. Even if you received zero requests, you still submit a nil return. The 2025/26 deadline was 30 June 2026. Unregistered officers cannot file the report.

3. Prepare and Maintain a PAIA Manual

Your PAIA manual is the document that tells the public everything they need to know about your organization and how to request information from you, so it needs to cover the basics about who you are and the specifics about what you hold and how you handle requests.

Your PAIA manual must include:

  • Your organisation’s name and contact details
  • The Information Officer’s name and contact details
  • A description of the official Guide on how to use PAIA and how to obtain it
  • Categories of records available without a formal request (if any)
  • A description of the subjects on which you hold records and the categories of records held on each subject
  • Records available in terms of other legislation
  • How people can request records (the procedure and forms)
  • The prescribed fees and response timeframes
  • The grounds on which access may be refused
  • The available remedies if a request is refused (complaint to the Information Regulator or application to court)
  • The POPIA particulars required by section 51 (purpose of processing, categories of data subjects and information, recipients, transborder flows, and a general description of security measures)

4. Publish and Make the PAIA Manual Easily Accessible

Publishing your PAIA manual means nothing if nobody can actually find it or access it, so putting it in places people actually look is more important than just creating the document itself.

Where to publish your manual:

  • Put it on your website in a location people can find easily with clear labeling so they don’t have to hunt for it
  • Keep a physical copy at your main office for people who visit in person and want to see it
  • Send an emailed copy to anyone who requests it instead of making them jump through hoops
  • Make it available to the Information Regulator upon request
  • Update it regularly whenever your organization’s details, structure, or procedures change

When people can’t find your manual or access it easily, they assume you’re hiding something even if you’re trying to comply with the law.

5. Establish Procedures for Processing Access Requests

Without written procedures, different people in your organization handle requests differently, which creates problems when someone questions your decisions or notices you treated them unfairly compared to someone else.

Your procedures must address:

  • How people submit requests through online forms, email, or other channels
  • How fast you acknowledge their request
  • How you figure out whether your organization actually holds what they asked for
  • How you decide what to release and what to refuse
  • How you count the 30-day response deadline
  • How you prepare documents and notify the requester
  • How people can challenge a refusal (complaint to the Information Regulator or application to court)

Timeframes you must follow:

  • Decide on the request and notify the requester as soon as reasonably possible, but in any event within 30 days of receiving a complete request
  • You may extend the period once by not more than 30 days if the conditions in section 57 apply and you notify the requester of the extension within the original 30 days
  • If you refuse the request, inform the requester that they may lodge a complaint with the Information Regulator or apply to court (within 180 days)

6. Maintain Accurate Records and Document Management Practices

You can’t respond to someone’s request for information if you don’t even know what records your organization holds or where they’re sitting, which means your record management directly affects whether you can actually comply with the Promotion of Access to Information Act.

What effective records management includes:

  • Keep a centralized list of all records showing where they’re located and what category they fall under
  • Label everything clearly so you can find information quickly when someone requests it
  • Use digital systems tracking where documents are stored and what they contain
  • Organize paper records safely so they don’t get damaged or lost
  • Archive emails properly so communications don’t disappear
  • Remove outdated records regularly according to retention schedules
  • Store everything securely so unauthorized people can’t access sensitive information

7. Implement Information Security Controls

POPIA requires you to protect personal information from unauthorised access, and your PAIA manual must include a general description of those security measures. Having proper controls is therefore essential for compliance with both laws and for keeping sensitive records safe from theft or misuse.

Security controls to implement:

  • Restrict access so only the staff who need to see sensitive records actually get to see them
  • Use passwords and authentication to protect digital records from hackers
  • Encrypt sensitive information both when it’s stored and when you’re sending it somewhere
  • Keep paper records physically secure so unauthorized people can’t wander in and take them
  • Establish visitor policies preventing random people from accessing record storage areas
  • Create backup systems so you can recover information if your primary systems fail
  • Track who accessed what records and when so you have an audit trail
  • Remove access immediately when employees leave your organization

8. Conduct Regular Security Risk Assessments

You need to periodically check whether your security is actually working and whether vulnerabilities exist that could cause problems, because security gaps create risk before anyone exploits them and causes damage.

What assessments should evaluate:

  • Whether the physical locations where you store records are actually secure or if anyone can walk in
  • Whether your digital systems have proper access controls limiting who can see sensitive data
  • Whether your employees actually understand how to handle information properly
  • Whether your backup systems would actually work if you needed to recover information
  • Whether former employees still have access to systems they shouldn’t access anymore
  • Whether your visitor policies are actually being followed or if they’re ignored
  • Whether your records inventory is accurate or if information is stored in undocumented locations
  • Whether your audit trails are working and tracking who accessed what

Secure Your Business with a Expert-Led Security Assessment

Partner with certified security specialists to identify, prioritize, and remediate real-world risks across your systems.

Book a Security Assessment

Security Assessment

9. Perform Vulnerability Assessments and Penetration Testing

Technical testing finds security weaknesses before attackers discover them and exploit them, which means you’re checking your defenses while you still have time to fix problems instead of finding out too late when damage happens.

What these accomplish:

  • Vulnerability scanning identifies technical weaknesses in your systems
  • Penetration testing simulates actual attacks, so you know whether attackers can break in
  • Access control testing verifies only authorized users can access sensitive data
  • Encryption verification confirms sensitive information is actually protected
  • Backup testing confirms you can actually recover information if systems fail

Most organizations skip this step, thinking they’re secure until someone actually tests them and finds exploitable gaps. Qualysec’s vulnerability assessments and penetration testing tell you exactly what needs fixing before regulators or attackers discover the problems.

10. Review Third-Party Service Providers

External vendors handling your records or providing services need to meet security standards similar to your own, which means you can’t just hire someone and hope they’re doing things right without actually checking.

Due diligence before engaging vendors:

  • Request their information security policies in writing so you have documentation of what they promised
  • Understand where they store your records and how they protect them from theft or unauthorized access
  • Confirm they will cooperate with access requests and that records they hold for you remain subject to PAIA
  • Establish written agreements clarifying what they’re responsible for and what you’re responsible for
  • Get their commitment in writing that they’ll notify you immediately if a breach affects your information
  • Verify they’ll cooperate with your compliance reviews and audits

11. Train Employees on PAIA and Information Security

Your staff handles records every day, so they need to understand PAIA requirements and security practices because if employees don’t know what they’re supposed to do, they’ll make mistakes that expose your organization to liability.

Training must cover:

  • What PAIA is and why it matters for your organization
  • What records they handle daily and how to protect them properly
  • How to handle access requests if they receive them before forwarding to your Information Officer
  • Security practices like password management and not sharing access credentials
  • What information is sensitive and requires special protection
  • What to do if they discover a security breach or unauthorized access
  • How to dispose of records securely when they’re no longer needed
  • Confidentiality obligations and what happens if they violate them

12. Conduct Regular Compliance Reviews and Update the PAIA Manual

Annual reviews keep your PAIA compliance checklist working properly because your organization changes constantly and your manual needs to reflect those changes, which means reviewing it once and forgetting about it guarantees it’ll become outdated.

Annual review should assess:

  • Whether your manual still accurately describes what records your organization holds
  • If new types of records are being created that the manual doesn’t address
  • Whether your access request procedures are actually working well or causing problems
  • If you’ve been denying access appropriately using valid exemptions
  • Whether staff are consistently following security practices you established
  • Changes in security threats or vulnerabilities affecting how you protect information
  • How well third-party vendors are performing if they handle your records

Ready to run a smooth review? Check out our Comprehensive Compliance Audit Guide to stay on top of your policies.

PAIA Manual Requirements

Section What’s Required Why It Matters
Organizational Details Name, address, and contact details of the head of the body People know who they’re dealing with
Information Officer Details Name, phone, email, address Clear contact point for access requests
Guide on how to use PAIA Description of the official Guide and how to obtain it Helps requesters understand their rights
Records available without a formal request Categories of records that can be obtained without a PAIA request (if any) Saves unnecessary formal applications
Records under other legislation Description of records available in terms of other laws Shows what is already publicly accessible by law
Records Description Subjects on which you hold records and the categories of records on each subject People know whether you have the information they need
Access Procedures Step-by-step process for requesting records Clear procedures prevent confusion
Timeframes Response deadlines (30 days, with possible extension) Legal requirement ensuring timely response
Grounds for Refusal Exemptions and why you may withhold information Transparency about access refusals
Available Remedies How to lodge a complaint with the Information Regulator or apply to court Recourse if access is wrongly refused
Fee Schedule Costs for copies and delivery Transparency about what you charge
POPIA Particulars Purpose of processing, categories of data subjects and information, recipients, planned transborder flows, and a general description of security measures Required by the amended section 51

Common PAIA Compliance Mistakes

Organizations make these mistakes repeatedly because they don’t take PAIA seriously or they misunderstand how the law works, which creates problems when regulators investigate or someone challenges your decisions.

Mistakes to avoid:

  • Assuming PAIA only applies to government when it actually covers private organizations too
  • Appointing an Information Officer without giving them time, authority, or resources to do the job properly
  • Creating a manual and then never updating it as your organization changes
  • Publishing your manual in a location so buried that people can’t find it
  • Responding to requests without documenting your decisions and the reasons behind them
  • Withholding information under exemptions that don’t actually apply to the situation
  • Taking longer than 30 days to respond without legitimate reasons to extend the timeframe
  • Destroying records without considering whether someone might request access to them later

Best Practices for PAIA Compliance

Following these practices shows regulators and the public that you take PAIA seriously and you’re not just going through the motions to avoid getting caught breaking the law.

Practices that actually work:

  • Create a simple one-page summary of your manual, so people understand your processes without reading the full formal document
  • Publish your manual prominently on your website with clear labeling so people can find it immediately
  • Establish an online form for submitting access requests, making it easy for people to formally request information
  • Maintain detailed records of every request and decision so you can track patterns
  • Train all staff annually on PAIA requirements so everyone understands their responsibilities
  • Respond to requests promptly even when you’re planning to refuse because responsiveness builds trust
  • Document your refusal reasons with specific exemption references showing your decisions aren’t arbitrary
  • Review denied requests periodically, ensuring you apply exemptions consistently

How Cybersecurity Supports PAIA Compliance

POPIA requires protecting personal information from unauthorised access, and your PAIA manual must describe the security measures you have in place. Cybersecurity is therefore critical infrastructure for compliance with both laws. Without proper security, anyone could access records they shouldn’t, defeating the purpose of controlled access under PAIA.

How cybersecurity enables compliance:

  • Access controls ensure only authorized staff view sensitive information
  • Encryption protects records if stolen or intercepted
  • Audit trails track who accessed what and when
  • Backup systems enable recovery if records are lost
  • Firewalls and monitoring detect unauthorized access attempts
  • Training prevents employees from accidentally exposing information

Prepare for Your Next Cybersecurity Audit with Qualysec

Choose a partner that helps you identify and fix real security risks before attackers do. We are here to help.

Talk to an Expert

Talk to a Cybersecurity Expert

Most organizations don’t know where their security gaps are until someone tests them. Qualysec conducts vulnerability assessments and penetration testing to find weaknesses before attackers do, which means you can fix problems while you still have time instead of after damage happens.

How Qualysec Helps Organizations Meet PAIA and POPIA Requirements

POPIA requires you to implement reasonable security measures protecting personal information, and your PAIA manual must include a general description of those measures. Most organisations, however, don’t know whether their security actually works until someone tests it properly.

Qualysec uses a Human-Led, AI-Powered model: Layer 1 (Automated scanning) → Layer 2 (AI analysis) → Layer 3 (Human expert validation).

What Qualysec provides:

What Qualysec Does What Qualysec Doesn’t Do
Security audits and vulnerability assessments Write PAIA manuals or policies
Penetration testing on web, mobile, cloud systems Appoint Information Officers
Access control and encryption verification Provide compliance training
Third-party vendor security review Handle administrative compliance tasks
Audit-ready compliance reports Manage access request procedures

Qualysec provides technical proof that your security meets regulatory standards, giving you documentation showing regulators you took reasonable steps to protect sensitive information.

Conclusion

A PAIA compliance checklist takes the confusing Promotion of Access to Information Act and breaks it into real steps your organization can actually do. Without a checklist, compliance stays vague, and you’re just reacting to problems. With one, you’re being organized and thinking ahead.

Organizations that take PAIA seriously keep their records organized, document every decision they make about access requests, and protect information from unauthorized access. Your PAIA compliance checklist doesn’t need to be complicated. Start by appointing an Information Officer, documenting what records you hold, establishing how people request information, protecting sensitive records, and responding to requests on time. Each step shows you’re complying with the law and builds trust with the public.

FAQs

Who is required to have a PAIA manual?

Private companies, nonprofits, trusts, professional associations, educational institutions, and any entity in South Africa holding records must maintain a PAIA manual complying with the law.

How do POPIA and PAIA work together in South Africa?

POPIA protects how organizations collect personal data. PAIA requires transparency, giving people access to records. POPIA vs PAIA integration means protecting sensitive data while responding to legitimate access requests.

Where must a company submit its PAIA manual?

Publish your manual prominently on your website and keep a copy available at your principal place of business for public inspection. Provide it to anyone who requests a copy, and make it available to the Information Regulator upon request.

How does cybersecurity help with compliance?

Cybersecurity protects records from unauthorised access. This supports POPIA’s security requirements and allows you to include an accurate description of your security measures in the PAIA manual, while still responding to legitimate access requests.

 

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

How CREST Penetration Testing Helps Meet MAS TRM Requirements
August 14, 2026

How CREST Penetration Testing Helps Meet MAS TRM Requirements

On July 28, 2026, the Monetary Authority of Singapore and the Association of Banks in Singapore jointly established the AI-Driven Cyber and Technology Risk Taskforce, an industry-wide response to frontier AI’s growing ability to identify and exploit vulnerabilities at scale. It’s a direct signal from Singapore’s regulator that the technology risk landscape financial institutions operate […]

What Are the Best CREST-Accredited Penetration Testing Services Available in Australia
August 14, 2026

What Are the Best CREST-Accredited Penetration Testing Services Available in Australia?

Securing digital assets in today’s threat landscape requires stringent and independent verification of security assessments. Enterprise buyers, cyber insurance companies, and regulatory authorities depend on CREST-accredited penetration testing services in Australia to ensure technical competency, high ethical standards, and audit ready reporting. Leading CREST-approved cybersecurity companies in the region, like CyberCX, Qualysec, Sekuro, and Tesserent, […]

FINRA Compliance Requirements A Complete Guide for Financial Firms
August 14, 2026

FINRA Compliance Requirements: A Complete Guide for Financial Firms (2026)

In 2025 alone, FINRA Compliance Requirements filed 625 new disciplinary actions (the highest number since 2021) and mandated $99.6m worth of fines and disgorgement penalties on member firms and individuals (the highest number since 2022). These statistics are listed on FINRA’s ‘Key Statistics’ page. These stats don’t just include major market institutions making big news […]

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.