A paia manual small business owners in South Africa must compile is a formal document required under section 51 of the Promotion of Access to Information Act 2 of 2000. Since 1 January 2022, all private bodies must compile a PAIA manual — there are no size exemptions, regardless of how many employees you have or how long you have been trading.

If your business is a company, close corporation, trust, partnership or even a sole trader who runs a commercial operation, you need this document as part of your broader website compliance obligations in South Africa. Most small business owners discover the requirement only when a client or investor asks to see the manual, at which point they realise they have been exposed for years.

PAIA gives anyone the right to request access to records held by your business. Your manual tells them who to contact, what records you hold, what the process is, what it costs, and what to do if you refuse. The Information Regulator — which took over PAIA enforcement from the South African Human Rights Commission on 30 June 2021 — publishes a free PAIA manual for private bodies on its official website, but the template alone does not discharge your obligation. You must also register your Information Officer, keep the manual updated, and file an annual report — three separate actions that most compliance checklists collapse into one.

This guide walks through all three obligations in plain language, so you can assess where your business stands today and know exactly what to do next.

Quick Answer

A paia manual small business requirement applies to every South African private body — no size exemption exists since 1 January 2022. Under section 51 of PAIA, your manual must document your information officer, your record categories, your request procedure, your fees, and remedies available to requesters. The head of the business must also register as Information Officer with the Information Regulator (free, under 30 minutes) and submit an annual PAIA report each year between 1 April and 30 June. Non-compliance under section 90 of PAIA carries a fine or imprisonment of up to two years.

Not sure whether your website is PAIA-ready?

Send us your site URL and we will tell you which compliance documents are missing and what needs to be added to meet your section 51 obligations.

Get a free compliance check

PAIA Manual Small Business Requirements: Who Must Comply?

Every private body operating in South Africa must have a PAIA manual in terms of section 51. A private body is any natural person who carries on a business, and any juristic person — company, close corporation, trust, partnership, or non-profit organisation — that conducts trade, business, or a profession. If you invoice clients, hold employee records, or process customer data, you are a private body under the Act.

What changed on 1 January 2022

Before 2022, the Information Regulator (and before it, the SAHRC) granted rolling exemptions to smaller private bodies. Those exemptions expired on 31 December 2021. From 1 January 2022, the obligation is universal — a one-person e-commerce store has the same section 51 requirement as a listed company. Size determines nothing about your obligation; it may affect how detailed your manual needs to be, but it does not remove the need for one.

Businesses commonly believe they are covered because they have a privacy policy on their website. A privacy policy addresses POPIA obligations — what data you collect and how you use it. A PAIA manual addresses a different question: how can someone formally request to see the records your business holds? The two documents serve different purposes, and neither substitutes for the other.

What Your Section 51 PAIA Manual Must Include

The paia manual requirements under section 51 of PAIA specify eight categories of information your manual must cover, and POPIA has since expanded that list to include data protection details as well. A correctly structured section 51 paia manual should address all the following:

Required elementWhat it means in practice
1. Contact details of the head of the bodyThe full name, title, postal address, phone number and email of your designated Information Officer
2. Description of records heldWhich records are automatically available to the public versus available only on request
3. Request procedureStep-by-step process for submitting a formal access request, including the prescribed request form available from the Information Regulator's PAIA page
4. Records held under other legislationRecords kept to comply with the Companies Act, SARS obligations, labour law, or sector-specific regulations
5. Record subjects and categoriesA breakdown of the subjects your records cover (e.g. finance, HR, clients, marketing, IT) and the categories within each
6. FeesThe prescribed fees a requester must pay — request fee and access fee — detailed in PAIA regulations and the Information Regulator's published fee structure
7. Remedies for refused requestsInternal appeal procedure and the right to complain to the Information Regulator or approach a court
8. Facilitation detailsAny additional information that helps a requester access records — postal address, turnaround times, language options

Beyond these eight, POPIA requires the manual to also cover: the categories of data subjects whose personal information you process, what that personal information relates to, who receives it, whether any cross-border transfers of personal information are planned, and what security safeguards protect the data. In practice this means your paia manual small business document and your POPIA compliance programme should be drafted together, not separately.

Typical record categories for a small business

Most SA small businesses hold records across six main categories: financial records (invoices, bank statements, SARS correspondence), HR records (contracts, payroll, leave records), client records (orders, quotes, communications), legal records (registration documents, contracts, insurance), marketing records (contact lists, campaign data), and IT and communications records (email archives, system logs). Every category must be named in your section 51 manual even if the records themselves are not publicly accessible.

Section 51(2) of PAIA requires the head of the body to keep the manual up to date. A manual that still names a director who left last year, or that lists record categories you no longer maintain, is non-compliant — not just outdated. Schedule an annual review to coincide with your annual report submission.

Appointing and Registering Your Information Officer

The paia manual information officer is the person responsible for handling access requests and overseeing your business's compliance with both PAIA and POPIA. By default, the CEO, managing director or managing member holds this role automatically — they do not need to be formally "appointed" for the role to apply to them. What they do need to do is register with the Information Regulator before they can discharge POPIA duties or submit annual reports.

What the registration process looks like

Registration is free and takes under 30 minutes. Go to inforegulator.bizportal.gov.za using your CIPC credentials. Complete the registration form with the Information Officer's personal details, any deputy information officers, and details about the responsible party. You receive a confirmation certificate on completion — this is your official proof of registration. If you prefer not to use the online portal, contact the Information Regulator directly via their official contact channels for alternative registration options.

The Information Officer may delegate specific duties to a deputy — typically an operations or compliance manager — but accountability for the overall programme stays with the CEO. If your business has subsidiaries, each separate legal entity needs its own Information Officer registration.

Once registered, the Information Officer's core duties include: handling data subject rights requests within 30 days; managing data breach notifications to the Regulator and affected individuals; developing and maintaining a POPIA compliance framework; and serving as the primary point of contact for the Information Regulator in any investigation or enforcement action.

CIPC compliance visibility is increasing

In its June 2025 enforcement sweep, the Companies and Intellectual Property Commission publicly flagged companies that had not registered an Information Officer or submitted their annual PAIA report by the 30 June 2025 deadline. This kind of public compliance signal — visible to investors, clients and counterparties — appears set to recur annually as enforcement matures. Registration costs nothing and takes less time than most licence renewals.

Combining Your PAIA and POPIA Obligations

PAIA and POPIA are distinct Acts, but they share an information officer and now share a manual. The most efficient compliance path treats the section 51 PAIA manual and the POPIA compliance programme as one integrated document rather than two separate exercises.

POPIA determines how you process personal information — the lawful bases, consent requirements, retention periods, and security measures. PAIA determines how people can access the records your business holds. Where they overlap is in the description of personal information: your PAIA manual must now describe what categories of personal information you hold, who receives it, and how it is protected. If you have already done a POPIA data mapping exercise, much of that work feeds directly into the PAIA manual.

If you have not yet addressed your POPIA operator agreements, that is the appropriate next step alongside the PAIA manual — both stem from the same information governance obligation and are administered by the same regulator. Businesses that tackle them together avoid duplicating effort on data inventories and record-keeping structures.

Putting Your Manual on Your Website

Section 51 requires your PAIA manual to be available at your principal place of business and — if your business has a website — accessible on that website. This is not optional. A manual stored only in a filing cabinet, or emailed to a client on request, does not satisfy the requirement.

In practice, most businesses publish the manual as a PDF page accessible from the footer of their website. The page should be findable — not buried three levels deep — and the document itself must be the current version. If your web design was built without a compliance document structure, adding PAIA and related documents is a straightforward task that belongs in the website's information architecture from the start.

If you are reviewing your site's legal documentation as part of a broader digital compliance project, start with our guide to disclaimers SA businesses actually need and the ECT Act and your online store — both are closely related requirements that should be addressed in the same audit cycle. The web design process is also the right moment to embed your PAIA manual into the site's footer structure so it remains accessible as the Act requires.

Building or redesigning your website?

Tell us your launch date and we will show you exactly which compliance pages — PAIA manual, POPIA notice, terms and conditions — need to be in place before your site goes live.

Check your launch compliance

The Annual PAIA Report Every Business Must Submit

Beyond compiling the manual, every private body must submit an annual PAIA report to the Information Regulator. The report covers the period 1 April to 31 March and must be submitted between 1 April and 30 June of the following year — the Regulator has made clear that no extensions will be granted.

The report records: how many information requests your business received during the year; how many were granted in full, partially or refused; the grounds for any refusals; whether any response timeframes were extended; and any internal appeals or complaints received. For most small businesses with zero formal requests received, all fields reflect zero — the submission still takes under 30 minutes at eservices.inforegulator.org.za.

What happens if you miss the deadline

Missing the annual report window — even once — can trigger an own-initiative PAIA compliance assessment by the Regulator, which includes physical inspections and document reviews. It also flags your business for potential POPIA non-compliance, because the same Information Officer registration that enables PAIA reporting underpins your POPIA programme. One missed submission creates a compounding exposure across two regulatory frameworks.

If your Information Officer has changed — which happens in any business with management turnover — update the registration before the next submission window opens. An annual report filed by an unregistered person is treated as a defective submission.

Why South African Businesses Choose Growth Pulse Media

Most web design conversations focus on aesthetics and speed. At Growth Pulse Media, the conversation starts with what your site must do — including what it must contain to be legally compliant. Every website we build includes a structured footer for compliance documents, and we flag PAIA manual, POPIA notice and ECT Act requirements before a site goes live, not after.

Our web design service is operator-built — the person overseeing your project has run South African online operations and dealt with information governance requirements directly.

We work with a limited client load, which means every site gets senior attention and we can identify compliance gaps that generalist agencies tend to miss. We are not lawyers and will not draft your PAIA manual — but we build the structure that makes it publicly accessible and ensures your site is not the reason you fail a compliance check.

Who This Is NOT For

Listed public companies and government bodies

If your organisation is a government department, municipality, parastatal or listed public company, your PAIA obligations fall under section 14 (public bodies) rather than section 51 (private bodies). The requirements differ significantly, including who you report to and what the manual must contain. This guide covers section 51 for private bodies only.

Businesses expecting a privacy policy to substitute

If you have a POPIA-compliant privacy policy on your website and assume that covers your PAIA obligation, it does not. A privacy policy tells visitors how you process their data — a PAIA manual tells anyone how to formally request access to your records. They are different documents serving different legislative purposes, and the Information Regulator treats them as distinct compliance items.

Those who need a bespoke legal opinion

If your business holds sensitive records in a regulated sector — financial services, healthcare, mining — or if you have had a formal PAIA request that you are unsure whether to grant, you need qualified legal counsel, not a practical guide. This post gives you the framework; a specialist attorney gives you the tailored advice your specific circumstances require.

Businesses treating compliance as a once-off exercise

If you compile a section 51 manual once and file it away, you will fail your next review. PAIA compliance is a live obligation: the manual must be kept current, the Information Officer registration must reflect whoever actually holds the role, and the annual report must be submitted every year without exception. One document drafted in 2022 that has never been updated is not compliance — it is a paper trail that shows you knew about the requirement and then ignored it.

Need your website's compliance documents structured correctly?

Book a quick audit call and we will walk through your current site against a compliance checklist — PAIA, POPIA, ECT Act and consumer protection requirements — in under 30 minutes.

Book a compliance audit call

Frequently Asked Questions

Is a PAIA manual compulsory for a one-person business in South Africa?

Yes. Since 1 January 2022, the requirement applies to every private body regardless of size. A sole trader who operates a commercial business — even a freelancer with a registered entity — is a private body under PAIA and must compile a section 51 manual. The exemption that previously protected smaller businesses expired on 31 December 2021.

What is the penalty for not having a PAIA manual?

Under section 90 of PAIA, the head of a private body who wilfully or in a grossly negligent manner fails to comply with section 51 commits an offence. On conviction, the penalty is a fine or imprisonment for a period not exceeding two years. The Information Regulator also has the power to issue enforcement notices and may conduct own-initiative compliance assessments.

Do I need a lawyer to draft my PAIA manual?

Not necessarily. The Information Regulator publishes a free PAIA manual template for private bodies on its website that most small businesses can adapt. You will need to populate it with your specific record categories, Information Officer details, and POPIA-related data processing information. If your business operates in a regulated sector or has complex data holdings, a legal practitioner's review adds value — but the template is a legitimate starting point for a straightforward operation.

Where must the PAIA manual be made available?

Your manual must be kept at your principal place of business and, if you have a website, published on that website so members of the public can access it without having to ask. Most businesses publish it as a PDF linked from the website footer. It must also be made available free of charge to any person who requests it — you may not charge for access to the manual itself, only for formal record access requests processed under the Act.

What is the difference between a PAIA manual and a POPIA privacy notice?

A POPIA privacy notice (sometimes called a privacy policy) explains to data subjects how your business collects, uses, stores and protects their personal information. A PAIA manual explains how anyone can formally request access to records your business holds, who your Information Officer is, what the process costs, and what remedies exist if a request is refused. Both are required; one does not substitute for the other.

Get Your Website Compliance-Ready

Growth Pulse Media builds websites that include the compliance document structure SA law requires — PAIA manual placement, POPIA notice, ECT Act disclosures — as part of the build, not as an afterthought. We work with a limited number of clients at a time, so every site gets direct senior attention from someone who has run South African digital operations and knows where compliance gaps tend to appear.

No obligation — we will get back to you within 24 hours.

Talk to us about your website
Dirk van Greuning — Founder, Growth Pulse Media
Dirk van Greuning Founder, Growth Pulse Media

Founder of Growth Pulse Media and a specialist in South African search dominance. Dirk translates his experience in scaling South African businesses into high-velocity digital strategies for B2B and retail leaders. He writes about SEO, lead generation, and paid media from an operator's perspective — prioritising pipeline value over impressions.

Connect on LinkedIn