Skip to main content

The Bloc Studio (Pty) Ltd

DISCLAIMER: General information only, not legal advice. Privacy law changes frequently and your obligations depend on your specific circumstances. Speak to a qualified attorney before acting on anything here.

In South Africa you are required to have a PAIA Manual. But how exactly do you get one? Do you really have to pay thousands for it? Is a lawyer needed to get involved? 

I’m excited to tell you to firstly, please calm down. And secondly, no lawyers are needed and no money needed. This article explains briefly what the PAIA Manual is for and how to get one done yourself. Or, if the tasks still seems daunting, how to ask The Bloc Studio for help. Keep reading.

A special note: A PAIA manual is different to the PAIA Annual Report that gets submitted to the Regulator.

Looking for something specific?

Subscribe to
The Bloc Journal

Stay in the loop of what’s happening and how it affects YOUR website.

In just 7 Days

You could have your own website that will be found by Google, seen by Ai and is compliant!

What is a PAIA manual?

You’ve probably heard business owners around you talking about PAIA, usually somewhere between confused and mildly panicked. Most of that panic is actually about a different, deadline-driven requirement (the PAIA Annual Report, due every year by 30 June). The PAIA manual is a separate, calmer thing: a once-off document you put together and publish, with no annual cutoff hanging over it. But if your business doesn’t have one yet, now’s a good time to sort it out, because it’s one less thing to worry about once the deadline-driven stuff comes around.

A PAIA manual is a document required under the Promotion of Access to Information Act (PAIA), which tells the public what records your business holds. This does not only apply to government, but both private and public bodies. That includes you, business owner. 

No matter the size of your business, whether you sell keychains online to your local town, or you run a multi-billion dollar enterprise, if you collect data then you are required to have one and display it publicly. You aren’t getting out of this one. The Information Regulator is actually cracking down on businesses that do not have this. They’re quite serious about this- for once.

There may, however, be a small exemption for small private bodies that are below a certain turnover or employee threshold. But generally, if you have a website (especially if it has a contact form) then you should have a PAIA anyway to align with POPIA and create credibility.

What Information Does the PAIA need?

The Information Regulator requires all information about your business that would be involved in the collection and storing of personal information. The sections you will need to fill in would pertain (but not limited) to:

  • Company details
  • Information Officer details
  • Deputy Information Officer details
  • Categories of records held
  • Categories of records available without a request
  • Request procedure

No doubt you would have this kind of information on hand (usually). But I have had a few clients having to go back and check with their team with what’s up. And you would be surprised at what systems are actually collection and storing data – all of which the Infomation Regulator would want to know.

PAIA Manuals are Free

The Information regulator was nice enough to not let us poor South Africas scramble around in the dark (sort of). They have provided templates for all bodies to download, fill in and submit as is. 

They even highlight in bold yellow the areas you need to fill in! I doubt they could have made it simpler than that. 

Call your lawyer or accountant and tell them you got this and you won’t be paying thousands for this document! Check out the link here to download your template to fill in:

But what’s a category record? How do you write this correctly? What format do you save it in? Do I need to keep it updated?

Don’t Want to Do It Yourself?

You’re running a business. We get it! Nobody really has time for all these little annoying documents that need to be filled in and displayed and the admin is just too much. 

We have a questionnaire that asks you in simple terms for the details about your business, systems and processes. You submit to The Bloc Studio and only pay R800 fee. We then turn it into a properly formatted, ready-to-publish PAIA manual in 24 hours that is ready to display on your website. 

How to Get your PAIA Manual in 24 hours!

  1. Contact us at hey@thebloc.studio 
  2. We give you the questionanire to fill in
  3. You fill in the questionnaire and pay the R800 fee
  4. In less than 24 hours you receive your PAIA manual ready to publish!

Disclaimer

This article is provided by The Bloc Studio for general information and educational purposes only. It does not constitute legal advice, and it is not a substitute for advice from a qualified attorney admitted to practise in your jurisdiction. No attorney–client relationship. Reading this article, or contacting us about it, does not create an attorney–client or any other professional advisory relationship between you and The Bloc Studio. We are not a law firm and we do not provide legal services. Your circumstances are specific. Data protection obligations depend heavily on facts we cannot know — the nature of your business, the categories of personal information you process, your lawful basis for processing, where your data subjects are located, where your data is stored and transferred, your sector-specific regulations, and your contractual commitments. General guidance cannot account for any of these. Do not act, or refrain from acting, on the basis of this article alone. Information may be out of date. Privacy law moves quickly. Penalty amounts are adjusted for inflation, regulators issue new guidance and codes of conduct, courts reinterpret existing provisions, and new legislation is enacted regularly. Figures and enforcement examples cited here were accurate as at the date of publication and may since have changed. Always verify current requirements against primary sources — the Information Regulator of South Africa, the relevant EU supervisory authority or the EDPB, and the California Privacy Protection Agency. Multiple jurisdictions, simplified. This article summarises POPIA, the GDPR and the CCPA/CPRA at a high level and unavoidably omits exceptions, exemptions, derogations, sector-specific rules and national variations. GDPR in particular is implemented differently across EU and EEA member states. A summary is not the law.

On penalties

References to maximum fines and terms of imprisonment describe the statutory ceilings available to regulators and courts. They are not predictions of outcome in any particular case. Actual penalties depend on the nature of the contravention, the regulator’s discretion, mitigating and aggravating factors, and judicial process. No liability. To the fullest extent permitted by law, The Bloc Studio accepts no liability for any loss or damage — direct, indirect, or consequential — arising from reliance on this article or on any third-party resource linked from it. Links to external sources do not constitute endorsement. If in doubt, get advice. If you are uncertain about your obligations, or you have experienced or suspect a data breach, consult a qualified privacy or data protection attorney promptly. Breach notification deadlines are short and begin running from awareness, not from the date you finish investigating.

Not sure if your website is Compliant?

We give free audits!

Frequently Asked Questions

If you don’t see your answer in the list then you are welcome to ask us your questions by filling in the fields below.

Do I legally need a privacy policy on my website?

Yes, if your site collects any personal information, even just through a contact form or email signup. In the EU and UK this falls under GDPR, in South Africa under POPIA, and in the US under whichever state privacy laws apply to your visitors. There’s no small business exemption for having the policy itself, only for some of the more detailed obligations.
You risk fines and, in South Africa’s case, potential imprisonment. GDPR penalties reach up to €20 million or 4% of global turnover, UK GDPR mirrors this at up to £17.5 million, and POPIA carries fines up to R10 million plus possible imprisonment under Section 107. Most enforcement starts with a complaint or correction notice, not an immediate maximum fine.
No, but they’re closely related. POPIA is South Africa’s data protection law and was drafted with GDPR’s predecessor as a reference point, so the core principles overlap heavily. The key difference is enforcement: POPIA is the only one of the two with imprisonment (up to 10 years for serious offences) written into the law itself.
Yes. There is no size-based exemption from the requirement to have a PAIA Manual under Section 51 of PAIA, it applies to all private bodies regardless of size. Not having one is itself a criminal offence under Section 90, punishable by a fine or up to two years imprisonment.
A Privacy Policy governs how you handle personal data. Terms and Conditions govern the transaction, relationship, and liability between you and your customer. A PAIA Manual governs how someone can request access to records your business holds, both personal and non-personal. All three are separate legal requirements, not interchangeable documents.
Not safely. A template referencing the wrong governing law, wrong regulator, or wrong consumer protection act is misleading and non-compliant, even if the general structure looks right. A South African business using a UK-governed template, for example, is stating something false about which law actually applies to its customers.
Often yes. GDPR and UK GDPR apply based on where your website visitors are located, not where your business is registered. A South African business serving UK or EU clients typically needs to comply with those regions’ laws too, not just POPIA.
Ignoring a formal enforcement notice under Section 77K of PAIA is a criminal offence carrying a fine and/or up to three years imprisonment, a heavier penalty than simply never having had a manual at all. The Information Regulator has actively issued and followed through on these notices in 2026.
Not automatically. A cookie banner only helps if it actually blocks non-essential scripts like Google Analytics or Meta Pixel until the visitor consents, opt-in consent is required under GDPR and UK GDPR. A banner that displays but doesn’t stop tracking beforehand isn’t a compliant mechanism, it’s decoration.