PAIA Forms to be published on your website

General comments on PAIA Requirements

There is some confusion in the marketplace regarding the PAIA Guide, the PAIA Manual, and the PAIA forms versus the POPIA forms. This article focuses on the PAIA aspects as prescribed initially by the Human Rights Commission and now by the Information Regulator. The Information Officer in terms of PAIA and POPIA are the same individual.

The PAIA Manual

All Bodies need to create a PAIA Manual, and publish it on their websites, and have a copy available at their facilities. This PAIA Manual describes the organisation, the type of information that it has in general (Not just personal information), what is available without requiring an access request process, and what may be available subject to a compliant request. With the advent of POPIA, the PAIA manual requires information related to POPIA to also be included, such as types of data subjects processed, type of personal information processed, security controls in place etc. The PAIA manual should be comprehensive enough that it guides a requestor as to how to make a request. The Regulator has published a new template for PAIA Manuals, and we will gladly hep organisations complete the manual in the correct format.

The PAIA Guide

The PAIA Manual is also required to contain at least a link to the PAIA Guide, which is a separate document published by the Regulator, and which contains full details regarding PAIA. NOTE: Organisations do NOT create the Guide. It is a document created and published by the Information Regulator and is on their website in all official South African languages.

PAIA Access request forms

The Information Regulator requires certain forms to be completed for both POPIA and PAIA. A full list is available at:

POPIA Forms - Information Regulator (inforegulator.org.za)

PAIA Forms - Information Regulator (inforegulator.org.za)

Recent PAIA Compliance notice from the Information Regulator

On the 6th October 2023 the Information Regulator published a Compliance notice in terms of Section 83(3)(d) of the Promotion of Access to Information Act 2 of 2000. Whist it was directed at Government bodies, it includes all Deputy Information Officers. 

In this notice they list forms that have been repealed and should no longer be used or appear on your website alongside your PAIA Manual. In addition, they have listed forms that should be updated on your website to appear alongside your PAIA Manual. These are:

Form 2: Request for access to record

Form 3: Outcome of request and fees payable

Form 4: Internal Appeal form

Please contact us for any assistance you need in completing your new PAIA Manual or getting access to the forms.
  

CONTACT US NOW!

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.