The PAIA Manual: The Compliance Obligation Almost Every Small Business Has Never Heard Of
Ask most small business owners about PAIA and you'll get a blank look — it's one of the least-known compliance obligations genuinely applicable to almost every registered business in South Africa, precisely because the exemption that used to cover smaller businesses no longer exists.
What PAIA actually requires: the section 51 manual
The Promotion of Access to Information Act gives members of the public a right to request access to records held by a body — including a private company — subject to specific grounds on which access can be refused. Section 51 requires every private body to compile a manual explaining how this actually works in practice: the categories of records the body holds, the procedure for making a request, and the contact details of the person responsible (typically the same Information Officer already required under POPIA, covered elsewhere in this series).
This manual needs to be kept available at the company's principal place of business and, where the company has a website, published there — it does not need to be proactively submitted to the Information Regulator, but must genuinely be available and produced on request.
The exemption that used to exist, and doesn't anymore
Historically, a specific exemption under section 51(4) relieved smaller private bodies — companies with fewer than 50 employees, or turnover below a set threshold — from this requirement. That exemption's extension expired at the end of 2021, and since 1 January 2022, no public or private body is exempt from the section 51 manual requirement, regardless of size. A great many small businesses that would have genuinely qualified for the old exemption are, under current law, non-compliant simply by never having heard the requirement changed.
What happens if you don't have one
Non-compliance with section 51 carries a penalty under section 90 of the Act — a fine or imprisonment for a period not exceeding two years. This is a genuinely serious statutory penalty for what many businesses assume, if they're aware of PAIA at all, is a low-priority administrative task.
The separate, currently-open obligation: the annual PAIA report
Beyond the manual itself, section 83(4) of PAIA empowers the Information Regulator to require private bodies to submit an annual report on the access-to-information requests they've received and processed. For the current reporting cycle, the Information Regulator's online portal opened on 1 May 2026 and closes at 23:59 on 30 June 2026, covering requests received between 1 April 2025 and 31 March 2026. Critically, a business that received zero PAIA requests during that period must still submit a nil return — the obligation to report is not conditional on having actually received any requests, and "we got nothing to report" is not itself a reason to skip the submission.
What this actually requires you to do
- Compile a section 51 manual if you don't already have one — the Information Regulator has published template guidance to make this a manageable task rather than starting from a blank page.
- Make it genuinely accessible — at your principal place of business and on your website if you have one, not drafted once and then filed away where nobody, including your own staff, could actually locate it if asked.
- Track PAIA requests you receive throughout the year — the date received, the outcome, the response time, and any refusals — since this is exactly the data the annual report requires.
- Submit the annual report by 30 June, even if it's a nil return, rather than assuming no requests received means no submission required.
- Keep the same Information Officer coordinating both PAIA and POPIA obligations — the two Acts are administered by the same Information Regulator and often fall to the same person in a small business, making it sensible to handle them as one coordinated compliance task rather than two unrelated ones.
Why this matters even for a business that's never received a request
Many small business owners reasonably ask why this matters if nobody has ever actually requested their records. The honest answer is twofold: first, the manual and reporting obligations exist independently of whether a request has actually been made — the law requires the infrastructure to be in place, not just a reactive response if it's ever tested; second, a business that has never received a PAIA request could receive one at any point (from a former employee, a dissatisfied customer, a journalist, a competitor in litigation), and having no manual in place at that moment is a compliance failure discovered at exactly the wrong time.
Sources: sections 51, 83(4) and 90 of the Promotion of Access to Information Act 2 of 2000 (the manual requirement with no size exemption since 1 January 2022; the two-year imprisonment penalty for non-compliance; the Information Regulator's power to require annual private-body reporting) and the Information Regulator's published 2025/26 PAIA annual reporting window (portal open 1 May 2026, closing 30 June 2026, covering the period 1 April 2025 to 31 March 2026, nil returns required). This is general information, not legal advice — a business without a current PAIA manual should get this addressed properly, ideally alongside its existing POPIA compliance, rather than treating it as a low-priority task.
A worked example
A small business with 12 employees has never heard of PAIA and assumes, based on outdated advice a colleague once mentioned, that businesses their size are exempt from these requirements — true once, but not since January 2022. A former customer, involved in a dispute unrelated to the business, formally requests copies of records the company holds relating to a specific transaction. With no PAIA manual in place and no established procedure for handling the request, the business scrambles to understand its own obligations under real time pressure, rather than following an already-established process that a properly compiled manual and Information Officer designation would have made straightforward.
Frequently asked
Does a sole proprietor need a PAIA manual, or only registered companies? The requirement applies to "private bodies" broadly, which under PAIA's definition includes forms of business beyond only registered companies — a business trading as a sole proprietorship that holds records others might reasonably request should not assume the requirement doesn't apply simply due to its legal structure.
Can I use a generic template for my PAIA manual, or does it need to be custom to my business? A template is a genuinely useful starting point, but the manual should accurately reflect your specific business's actual categories of records and contact details — a template copied without adapting the specifics is better than nothing but risks being inaccurate in ways that undermine its purpose.
What's the difference between a PAIA request and a POPIA data subject access request? They're related but distinct — PAIA governs general access to records a body holds (with broader scope), while POPIA's access rights specifically concern a data subject's own personal information; a business can receive either type of request and should be able to distinguish which framework applies to respond correctly.
Do I need to submit the annual PAIA report even if I'm confident I received no requests? Yes — a nil return is still required by the same deadline; simply not submitting anything because nothing happened is treated as non-compliance, not as an acceptable default.
Who should be responsible for PAIA compliance in a small business? Often the same person designated as Information Officer under POPIA, since the two obligations overlap substantially in practice and are administered by the same regulator — formally designating one clear point of responsibility, rather than leaving it genuinely unowned, is the practical starting point.
How often does a PAIA manual need to be updated? There's no fixed statutory review cycle, but a manual should genuinely reflect current reality — the correct Information Officer, accurate categories of records, and up-to-date contact details — meaning it should be reviewed whenever these details actually change, not left untouched indefinitely from the day it was first compiled.
Can a request under PAIA be refused? Yes — the Act sets out specific, defined grounds on which a private body can lawfully refuse access to a record (commercial confidentiality, privacy of a third party, legal privilege, among others), but refusal has to be on one of these genuine statutory grounds and properly communicated, not simply declined because responding feels inconvenient.