Meeting the PAIA Manual requirements in South Africa can look deceptively simple.
Download a template, insert the company name, add the director’s details, save it as a PDF and place it on the website.
The problem with that approach is that the purpose of a PAIA Manual is not to produce a document that happens to contain the words “PAIA Manual” on the cover. It is supposed to describe how access to information works within a particular organisation.
That requires information about the actual business. Below are the ten PAIA Manual requirements every private body should address, and why each one needs to reflect your organisation rather than a template.
The purpose of the Section 51 PAIA Manual requirements
Section 51 of the Promotion of Access to Information Act deals with manuals for private bodies and sets out the core PAIA Manual requirements. If you are unsure whether your organisation needs a manual at all, start with who needs a PAIA Manual in South Africa.
The manual provides information that assists someone who wants to exercise a right of access to records held by the organisation. It identifies relevant people and contact details, describes records and explains how the PAIA request process works.
Following the implementation of POPIA, the manual also has an important personal-information component.
This makes the PAIA Manual part legal document, part information map and part procedural guide.
Company and contact information
At the most basic level, the manual needs to identify the organisation.
That sounds obvious, but company details are one of the reasons manuals become outdated. Businesses change addresses, contact details and responsible personnel while the manual published on the website remains untouched.
The details in the manual should therefore be linked to an ongoing process for reviewing the document when organisational information changes.
Information Officer details
Someone requesting access to information needs to know where the request should go.
The details of the relevant Information Officer therefore form an important part of the manual. If you are being asked to take on the role, read what you need to know before becoming an Information Officer.
This is another area where document-based compliance can become disconnected from operational compliance. If an Information Officer changes, updating the appointment or registration process without updating the PAIA Manual can leave conflicting information across the organisation’s compliance records.
Ideally, those processes should speak to one another.
The Information Regulator’s PAIA Guide
The Information Regulator maintains a guide explaining how PAIA works and how people can exercise their rights under the Act.
The PAIA Manual should appropriately refer to the Guide and provide the relevant information concerning its availability.
This gives someone reading the company’s manual access to the broader regulatory guidance governing the process.
Records that are automatically available
Not every piece of information necessarily requires somebody to go through a formal PAIA request process.
Among the PAIA Manual requirements, a manual should address categories of records that are automatically available, where applicable.
For a business, this requires an actual consideration of what it makes publicly available rather than simply accepting a generic list copied from somebody else’s manual.
Records held under other legislation
Businesses maintain records because many different laws require them to do so.
Depending on the organisation, this may include company records, tax records, employment records and other statutory information.
Under the PAIA Manual requirements, the document needs to consider the legislation relevant to the particular organisation.
This is another reason a template should be treated as a starting point rather than the final answer. The legislation relevant to a five-person consulting company may differ materially from the legislation relevant to a manufacturer employing hundreds of people.
Subjects and categories of records
This is one of the areas where the manual begins to describe the actual information environment of the business.
An organisation may hold company secretarial records, accounting records, tax records, customer information, supplier information, employment records, contracts, intellectual property documentation and various other categories of information.
The purpose is not simply to create the longest possible list.
The PAIA Manual requirements call for the manual to meaningfully describe the subjects and categories of records held by that organisation.
How someone requests access
The PAIA Manual requirements also include explaining the procedure for requesting access to a record.
The Information Regulator publishes the prescribed PAIA forms, including Form 2 for a request for access to a record.
For the business, this is where PAIA becomes a workflow rather than merely a policy.
Once a request arrives, somebody needs to identify it as a PAIA request, record it, deal with the prescribed process and retain evidence of the eventual outcome.
The quality of the manual therefore matters, but so does the process sitting behind it.
Fees and the request process
PAIA provides for prescribed fees in certain circumstances.
The manual should explain the applicable process so that a requester understands what may be required when seeking access to records.
Again, this part of the PAIA Manual requirements needs to remain aligned with current regulations rather than being inherited indefinitely from an old template.
Processing of personal information
This is where the relationship between PAIA and POPIA becomes particularly visible.
The PAIA Manual should contain information relating to the organisation’s processing of personal information.
That may require consideration of the purposes for which information is processed, categories of personal information, categories of data subjects, recipients of information and cross-border information flows, depending on the circumstances.
This is difficult to do properly if the person preparing the manual has no understanding of how the business actually handles information.
A generic document can therefore create the appearance of compliance without accurately describing the organisation.
Where the manual is available
The final document needs to be available to the people PAIA is intended to assist.
The Information Regulator’s current guidance states that organisations are required to develop their PAIA Manuals and make them available through their websites and in physical form at their offices.
That makes publication part of the compliance process rather than the final PDF simply disappearing into an internal folder.
The document needs to stay alive
Perhaps the most useful way to think about the PAIA Manual is as a snapshot of the organisation’s information environment.
When that environment changes materially, the snapshot may need to change with it. Meeting the PAIA Manual requirements is therefore not a once-off exercise.
This is why the compilation date and revision history matter, and why Intersect maintains the original compilation date while allowing subsequent versions of the manual to be generated as information changes.
A company should be able to tell which version is current and retain the historical compliance record.
Building the manual inside Intersect
Intersect’s PAIA compliance workflow guides the user through the sections required to compile the manual while using information already held against the organisation wherever possible.
Company information and Information Officer details can feed into the document, relevant record categories and legislation can be maintained, POPIA processing information can be captured and the completed manual can be generated as a versioned PDF.
The important distinction is that the document remains connected to the organisation and its broader compliance record.
For a professional firm managing PAIA for multiple clients, that becomes even more valuable because the question changes from “Where did we save Smith Trading’s PAIA Manual?” to “What is Smith Trading’s current PAIA compliance position?”
That is ultimately the difference between producing a PAIA document and managing PAIA compliance.
Explore Intersect’s PAIA compliance software to see how the PAIA Manual, Information Officer process and broader compliance record can be managed in one environment.