PAIA MANUAL

Instructions
If you intend to use this component with Finsweet's Table of Contents attributes follow these steps:
  1. Remove the current class from the content27_link item as Webflows native current state will automatically be applied.
  2. To add interactions which automatically expand and collapse sections in the table of contents select the content27_h-trigger element, add an element trigger and select Mouse click (tap)
  3. For the 1st click select the custom animation Content 27 table of contents [Expand] and for the 2nd click select the custom animation Content 27 table of contents [Collapse].
  4. In the Trigger Settings, deselect all checkboxes other than Desktop and above. This disables the interaction on tablet and below to prevent bugs when scrolling.

NRS Solutions (Pty) Ltd — PAIA Manual

Registration Number: 2022/682414/07 ("the Company")

Prepared in terms of section 51 of the Promotion of Access to Information Act, No. 2 of 2000, as amended.

Version 3.0  |  Date of compilation: 09/06/2021  |  Date of revision: 30/09/2025

1. Definitions

TermDefinition
CEOChief Executive Officer
ClientAny natural or juristic person that received or receives services from the company
ComplainantAny person who lodges a complaint with the Information Regulator
Complaint

(a) A matter reported to the Information Regulator in terms of section 74(1) and (2) of the Act;

(b) A complaint referred to in section 76(1)(e) and 92(1) of the Act;

(c) A matter reported or referred to the Information Regulator in terms of other legislation that regulates the mandate of the Information Regulator

Conditions for Lawful ProcessingThe conditions for the lawful processing of personal information as fully set out in chapter 3 of POPI and in section 12 of this manual
Data SubjectThe person to whom Personal Information relates
DayA calendar day, unless the last day of a specified period happens to fall on a Sunday or public holiday, in which case it is calculated exclusive of that Sunday or public holiday (Interpretation Act, 1957 - Act No. 33 of 1957)
DIODeputy Information Officer
Information Officer/IOThe individual who is identified herein and legally appointed to ensure compliance with POPIA and PAIA
ManualThis manual
MinisterMinister of Justice and Correctional Services
Office Hours

(a) For the Information Regulator: 08:00–16:00, Monday to Friday (excluding public holidays);

(b) For designated offices: Hours during which the offices operate

PAIAThe Promotion of Access to Information Act, No. 2 of 2000
Personal InformationInformation relating to an identifiable living person, or an identifiable existing juristic person, including but not limited to race, gender, contact info, biometrics, correspondence, opinions, and identifiers
PersonnelAny person who works for or provides services to or on behalf of the company and receives or is entitled to receive remuneration, including permanent, temporary and part-time staff, directors, and contractors
POPI/POPIAThe Protection of Personal Information Act, No. 4 of 2013
POPI RegulationsRegulations promulgated in terms of section 112(2) of POPI
Private Body

(a) A natural person conducting business;

(b) A business partnership;

(c) A juristic person not being a public body

ProcessingAny operation or activity concerning personal information, including collection, storage, dissemination, or destruction
RegulatorInformation Regulator established in terms of POPIA
RepublicRepublic of South Africa
SignatureAny legally accepted form of signature, including electronic signature where applicable
WritingAs referred to in section 12 of the Electronic Communications and Transactions Act, 2002 (Act No. 25 of 2002)

2. Purpose of the PAIA Manual

This PAIA Manual is useful for the public to:

The PAIA Manual serves as a public guide to the information held by the organisation and how it can be accessed. It outlines the categories of records available without a formal request, the subjects on which records are maintained, and details of records accessible under other legislation. The manual also provides the official contact details of the Information Officer (IO) and Deputy Information Officer (DIO), who are responsible for assisting the public in exercising their right of access.

The manual further explains how to use the PAIA process and where to obtain the official guide published by the Regulator. It describes whether and how the organisation processes personal information, including the purposes of processing, the categories of data subjects involved, and the recipients (local or international) to whom such information may be supplied. The manual further confirms that appropriate security safeguards are in place to protect the confidentiality, integrity, and availability of personal information.

3. Contact Details for Access to Information Requests

Information Officer

NameVincent Bezuidenhout
Contact number011 824 3977
Email addressvincent@n-r-s.co.za

Deputy Information Officer

NamePryce Robinson
Contact number011 824 3977
Email addresspryce@n-r-s.co.za

National or Head Office

Postal address41, Dudley Road, Parkwood, Johannesburg, 2193.
Physical address41, Dudley Road, Parkwood, Johannesburg, 2193.
Contact number011 824 3977
Emailvincent@n-r-s.co.za
Websitehttp://n-r-s.co.za/

4. Guide on How to Use PAIA and How to Obtain Access to the Guide

The Information Regulator has published a revised PAIA Guide in terms of section 10(1) of PAIA (as amended). This guide is designed to help any person who wishes to exercise rights under PAIA or POPIA, and it is available in all official languages as well as in braille to ensure accessibility.

The Guide serves two key purposes:

  • Access to Personal Information (POPIA): It explains how individuals (data subjects) can exercise their rights to request confirmation of whether personal information is held about them, to access that information (including details of third-party recipients), and to request correction, deletion, or destruction of personal information that is inaccurate, outdated, excessive, or unlawfully obtained.
  • Access to Records (PAIA): It provides step-by-step guidance on how to request records from public or private bodies, including the required forms, the process for appeals or complaints, and how to approach a court if necessary.

In addition, the Guide offers:

  • An overview of the objectives of PAIA and POPIA.
  • Contact details of Information Officers (IOs) and Deputy Information Officers (DIOs).[1]
  • Manner and form of a request for access to a record of a public body and private body.[2]
  • Guidance on compiling or accessing PAIA Manuals.[3]
  • Information on voluntary disclosures of records, prescribed access fees, and applicable regulations.[4]
  • How to lodge an internal appeal, a complaint with the Regulator, or apply to court against a decision by the IO of a public body, a decision on internal appeal, a decision by the Regulator, or a decision of the head of a private body.
  • Insight into how PAIA has been amended following the implementation of POPIA.

The guide can also be obtained:

A copy of the guide is also available in the following three official languages, for public inspection during normal office hours:

  • English
  • Afrikaans
  • Zulu

5. Latest Notices in terms of Section 52(2) of PAIA

At this stage, no notice(s) has/have been published on the categories of records that are available without having to request access to them in terms of PAIA.

6. Availability of Certain Records in terms of PAIA

Categories of records available without a person having to request access

Category of RecordsTypes of the RecordAvailable on WebsiteAvailable on Request
PAIA ManualCurrent PAIA Manual with version and effective dateXX
Company overviewManufacturer of specialised and instrumentation cables, product range summary, factory location, head office contact detailsXX
Product catalogueCable families, voltage ratings, conductor types, insulation and sheath options, temperature ratings, application notesXX
Technical datasheetsPDF specs per cable code, dimensions, tolerances, electrical characteristics, materials, approvalsXX
Compliance certificatesRoHS, REACH, CE where applicable, local conformity statementsXX
Quality managementISO 9001 certificate, QA policy, inspection and test plan high levelXX
Test reports samplesType test summaries, routine test examples with all identifiers removed-X
Manufacturing recordsBatch travelers, process parameters, in-process inspection logs, final inspection checklists-X
Traceability registerBatch and reel numbers, date codes, materials lots, release status-X
Materials and SDSCopper, PVC, XLPE, LSZH compounds, armouring materials, SDS library index-X
DrawingsStandard construction drawings, cross-sections, termination guidance-X
Custom build filesClient-specific specifications, deviations, PPAP or FAIR packs where contracted-X
Supplier and procurementApproved vendor list at category level, B-BBEE certificate copy, bank confirmation letterXX
Corporate identifiersRegistered name, CIPC number, registered address, VAT number-X
Legal disclosuresPOPIA and PAIA statements, website disclaimersXX
Privacy and cookiesPrivacy Policy, Cookies PolicyXX
Information Officer contactsIO and DIO names, roles, direct emails, contact numbersXX
Health, safety, environmentHSE policy, PPE requirements, environmental policy, waste and recycling summaryXX
Calibration and equipmentCalibration certificates index for key test equipment, next due dates-X
Maintenance and safety logsMachine maintenance schedules, lockout and incident logs summary-X
Logistics and deliveryPacking standards, reel labelling, barcoding formats, Incoterms options, lead-time bandsXX
Warranty and returnsWarranty terms, non-conformance and RMA processXX
Contracts snapshotStandard terms of sale, payment terms summary, NDAs template referenceXX
Tax and compliance attestationsSARS TCS PIN, COID LOGS, UIF proof-X
Insurance confirmationsPublic and product liability summary, limits, insurer, validity dates-X
Company secretarialDirectors as filed at CIPC, principal place of business-X
Whistleblowing and complaintsConfidential hotline, PAIA and POPIA complaint routes, escalation to the RegulatorXX
Careers and recruitmentVacancies, application process, candidate privacy noticeXX
CSRLocal manufacturing support initiatives, skills developmentXX

Records / subjects available in accordance with any other legislation

Category of RecordsApplicable Legislation
Memorandum of Incorporation, CIPC filings, board minutes, share registerCompanies Act, 2008, Act 71 of 2008
Employment contracts, attendance, overtime, payroll, leaveBasic Conditions of Employment Act, 1997, Act 75 of 1997
Minimum wage schedules for factory, warehouse and logistics staffNational Minimum Wage Act, 2018, Act 9 of 2018. Basic Conditions of Employment Act, 1997, Act 75 of 1997
Disciplinary and grievance files, union correspondence, CCMA case filesLabour Relations Act, 1995, Act 66 of 1995
Employment Equity plan, annual EE reports, committee minutesEmployment Equity Act, 1998, Act 55 of 1998
Recruitment ads, shortlist records, background screening outcomesEmployment Services Act, 2014, Act 4 of 2014. Protection of Personal Information Act, 2013, Act 4 of 2013
Work permission for foreign nationalsImmigration Act, 2002, Act 13 of 2002
UIF declarations, contributions, benefit claimsUnemployment Insurance Act, 2001, Act 63 of 2001
Skills plans, annual training reports, learnership agreementsSkills Development Act, 1998, Act 97 of 1998
Levy declarations, merSETA registrations, grantsSkills Development Levies Act, 1999, Act 9 of 1999
PAYE, IRP5, EMP201, EMP501, tax directivesIncome Tax Act, 1962, Act 58 of 1962
VAT returns, input and output schedules, SARS correspondenceValue Added Tax Act, 1991, Act 89 of 1991
COIDA registration, Return of Earnings, Letter of Good Standing, IOD claimsCompensation for Occupational Injuries and Diseases Act, 1993, Act 130 of 1993
OHS policy, risk assessments for extrusion, wire drawing, armouring, QA labs, incident reports, safety minutesOccupational Health and Safety Act, 1993, Act 85 of 1993 and regulations
Hazardous Chemical Agents inventories, SDS library, training recordsOccupational Health and Safety Act, 1993, Act 85 of 1993. Hazardous Chemical Agents Regulations, 2021
Electrical machinery registers, isolation and lockout logs, inspectionsOccupational Health and Safety Act, 1993, Act 85 of 1993. Electrical Machinery Regulations
PPE issue registers, inspections, fit testingOccupational Health and Safety Act, 1993, Act 85 of 1993. General Safety Regulations
Fire equipment servicing, evacuation drills, fire risk assessmentsFire Brigade Services Act, 1987, Act 99 of 1987. Applicable municipal by laws
Environmental management plans, waste manifests, recycling recordsNational Environmental Management. Waste Act, 2008, Act 59 of 2008
Air emissions records where applicable, furnace or curing logsNational Environmental Management. Air Quality Act, 2004, Act 39 of 2004
Effluent and water use records where applicableNational Water Act, 1998, Act 36 of 1998
Product conformity files, cable technical files, routine and type test reports, material declarationsNational Regulator for Compulsory Specifications Act, 2008, Act 5 of 2008. Legal Metrology Act, 2014, Act 9 of 2014. Relevant SANS and IEC standards
Calibration certificates for insulation resistance, HV and spark testers. MTE schedulesLegal Metrology Act, 2014, Act 9 of 2014
QMS records, ISO 9001 certificate, audits, NCRs, CAPAsISO 9001 Quality Management Systems standard
Supplier approvals, procurement policy, due diligence packs, onboarding checklistsProtection of Personal Information Act, 2013, Act 4 of 2013. Common law of contract
Public and product liability policy schedules, endorsements, notificationsInsurance Act, 2017, Act 18 of 2017
B BBEE certificate, ownership, skills, supplier and enterprise development evidenceBroad Based Black Economic Empowerment Act, 2003, Act 53 of 2003 and the Codes of Good Practice
Standard terms of sale, customer contracts, warranty and returns recordsConsumer Protection Act, 2008, Act 68 of 2008. Common law of contract
Import and export files, bills of entry, SAD500, customs correspondence, machine import packsCustoms and Excise Act, 1964, Act 91 of 1964
Deputy Information Officer designations and revocations, IO registration proofProtection of Personal Information Act 4 of 2013
Electronic communications policies, e signature consents, website terms, cookies recordsElectronic Communications and Transactions Act, 2002, Act 25 of 2002
Cyber incident register, takedown requests, forensic reportsCybercrimes Act, 2020, Act 19 of 2020

Records kept as required by PAIA and POPIA

  • PAIA records: PAIA Manual, official guides, submission records, and awareness training materials.
  • POPIA records: Information Officer registration certificate, data breach records, retention records, and awareness training materials.
  • Other relevant information may also be made available on request.

The tabulated records may be requested; however, it should be noted that there is no guarantee that the request will be honoured. Each request will be evaluated in terms of PAIA and any other applicable legislation.

7. Request Process

An individual who wishes to place a request must comply with all the procedures laid down in PAIA:

1. Initiating the request

Use the prescribed form. All requests must be made on the prescribed form (Form 2 – Request for Access to Record [Regulation 7]) – Request for Access to Record [Regulation 7].

Additional prescribed forms include:

  • Form 2 – Request for Correction or Deletion (section 24 of POPIA). Used by a data subject to request the correction of inaccurate, outdated, incomplete, irrelevant, or misleading personal information, and/or the deletion or destruction of personal information that is no longer necessary or unlawfully obtained, in accordance with section 24(1) of POPIA. – Form link
  • Form 3 – Application for a Code of Conduct (section 61 of POPIA). Used by an industry body, profession, or class of entities to apply for the issuance of a Code of Conduct under section 61(1)(b) of POPIA. – Form link
  • Form 4 – Request for Consent for Direct Marketing (section 69 of POPIA). Enables a responsible party to formally request a data subject’s consent to receive direct marketing communications via unsolicited electronic means (e.g. SMS, email), as required under section 69(2) of POPIA. – Form link
  • Form 5 – Complaint Regarding Interference with Personal Information. Allows a data subject or complainant to submit a complaint to the Regulator concerning unlawful interference with personal information, or a determination made by an adjudicator under POPIA. – Form link

Requests not submitted on the prescribed form may be rejected.

Assistance in the request process:

  • If a requester is illiterate or disabled, they may make the request orally to the IO, who must complete the prescribed form on their behalf and provide them with a copy (section 18(3) of PAIA).
  • The IO must provide reasonable assistance to any requester who requires help in completing the form or understanding the procedure.

2. Particulars of the request

The request must provide sufficient detail to enable the IO to identify and process it. This includes:

  • A clear description of the record(s) requested.
  • Full identity of the requester, with proof of identity where required.
  • The preferred form of access (inspection, copy, electronic copy, etc.).
  • The requester’s contact details (postal, physical, fax or email).
  • A statement that the record is required to exercise or protect a right, specifying the nature of that right and explaining why the record is necessary.
  • If a request is made on behalf of another person, proof of authorisation must be attached.

3. Submission of requests

The completed form, together with proof of payment of the prescribed request fee (if applicable), must be submitted to the Information Officer (IO) at the Company. Requests may be lodged by:

  • Hand delivery to the physical address provided in this Manual;
  • Postal delivery to the Company’s registered address;
  • Fax; or
  • Email to the address of the IO or DIO.

Where applicable, the IO may require a deposit in terms of section 22(2) of PAIA where search and preparation is expected to be time-consuming.

4. Fees and timeframes for response

  • Requests will be processed and responded to within 30 (thirty) calendar days of receipt.
  • In terms of section 26 of PAIA, the IO may extend this period once, by up to 30 additional days, if: the request involves a large number of records; consultation with third parties is required; or the records are located in another office and cannot reasonably be obtained within 30 days.
  • If an extension is required, the requester will be notified in writing, with reasons for the extension.
  • A request fee may be charged for non-personal requests.
  • If the search and preparation of the record will exceed six (6) hours, the requester may be required to pay a deposit of up to one-third of the estimated fee.
  • Access will only be granted once all required fees have been paid.

5. Outcome of request

The IO will notify the requester in writing, using Form 3Outcome of Request and of Fees Payable [Regulation 8], of the decision to grant or refuse access.

  • If access is granted, the notice will specify the form of access and state the applicable access fees payable before access is given.
  • If access is refused, the notice will set out the grounds for refusal as provided in Chapter 4 of PAIA.

6. Appeals and complaints

If access is refused or deemed refused (i.e. no decision within the prescribed period), the requester may:

  • Lodge an internal appeal (for public bodies); or
  • Refer the matter to the Information Regulator or approach a court of law (for private bodies).

The Regulator can be contacted using the details provided in this Manual.

8. Grounds for Refusal

In terms of Chapter 4 of PAIA, the Company may refuse a request for access to records on the following grounds (unless an exception applies):

  • Privacy of individuals – To protect the personal information of a third party (including deceased persons) where disclosure would be unreasonable.
  • Commercial interests of third parties – Records may be refused if they contain:
    • Trade secrets;
    • Financial, commercial, scientific, or technical information, where disclosure could cause harm; or
    • Information provided in confidence, where disclosure could disadvantage or prejudice the third party in negotiations or competition.
  • Confidentiality agreements – Information that is protected under a contract or agreement with a third party.
  • Safety and security – Records that could endanger the life, health, or safety of a person, or the protection of property.
  • Legal privilege – Records that would be privileged from disclosure in legal proceedings.
  • Commercial interests of the Company – Records may be refused if they contain:
    • Trade secrets;
    • Financial, commercial, scientific, or technical information that could harm the Company’s interests;
    • Information that could prejudice the Company in negotiations or competition; or
    • Proprietary computer programs protected by copyright or intellectual property law.
  • Research information – Where disclosure would place ongoing research or a researcher at a serious disadvantage.
  • Frivolous or unreasonable requests – Requests that are clearly frivolous, vexatious, or that would cause an unreasonable burden on Company resources.

9. Remedies Should a Request be Refused

  • If the Company does not have an internal appeal procedure in light of a denial of a request, decisions made by the IO are final.
  • The requestor may, in accordance with sections 56(3)(c) and 78 of PAIA, apply to a court for relief within 180 (one hundred and eighty) days of notification of the decision for appropriate relief.

10. Fees

The following fees shall be payable upon request by a requestor:

DetailsFee
Request fee (payable on every request)R140.00 once-off
Photocopy of an A4 page or part thereofR2.00 per page
Printed copy of an A4 page or part thereofR2.00 per page
Hard copy on flash drive (flash drive to be provided by requestor)R40.00 once-off
Hard copy on a compact disc (compact disc to be provided by requestor)R40.00 once-off
Hard copy on a compact disc (compact disc to be provided by the company)R60.00 once-off
Transcription of visual images per A4 pageAs per quotation of service provider
Copy of visual imagesAs per quotation of service provider
Transcription of an audio recordR24.00 per A4 page
Copy of an audio record on flash drive (flash drive to be provided by requestor)R40.00 once-off
Copy of an audio on a compact disc (compact disc to be provided by requestor)R40.00 once-off
Copy of an audio on a compact disc (compact disc to be provided by the company)R60.00 once-off
Base/starting rate to search for and prepare the record for disclosureR145.00 per hour for each hour or part thereof, excluding the first hour, reasonably required for such search and preparation (cannot exceed R435.00 per request)
Rate to search for and prepare the record for disclosureR435.00 per hour for each hour or part thereof, excluding the first hour, reasonably required for such search and preparation (cannot exceed total cost)
Postage, email or any other electronic transferActual expense, if any

11. Processing of Personal Information

The Company processes personal information in accordance with the conditions for lawful processing as set out in the Protection of Personal Information Act, 4 of 2013 ("POPIA"). Personal information is processed only for legitimate business purposes, which may include (but are not limited to):

  • Employment-related purposes: Recruitment, administration of employment contracts, payroll, benefits, training, and compliance with labour laws.
  • Client and supplier management: Entering into and performing contracts, maintaining relationships, processing payments, and responding to queries or complaints.
  • Legal and compliance obligations: Compliance with statutory and regulatory requirements, record keeping, audits, and reporting.
  • Security and risk management: Protecting company property, monitoring access, preventing fraud, and ensuring the safety of staff, clients, and visitors.
  • Marketing and communication: Providing information about products or services, subject to obtaining the necessary consent under POPIA.

The Company ensures that personal information is processed lawfully, reasonably, and only for the purposes for which it was collected, and takes appropriate steps to protect the confidentiality and integrity of such information.

Categories of data subjects and related personal information

The Company processes personal information relating to various categories of data subjects. The categories of data subjects, and the types of personal information that may be processed in respect of each, include (but are not limited to) the following:

Categories of Data SubjectsPersonal Information that may be Processed
Customers and corporate clients including EPCs, OEMs, distributors, panel buildersNames, work titles, business contact details, company identifiers, ship to and bill to addresses, contract and PO records, orders, invoices, delivery notes, payment history, bank details, warranty and returns records, service tickets, communications, audit trails
Prospective clients and RFQ contactsNames, business contact details, role, lead source, RFQs, quotes and proposals, meeting notes, communications
Channel partners and agentsEntity details, registration and VAT numbers, B-BBEE certificate details, bank details, contact persons, agreements, commission statements, performance records
Site contacts at customer plants and project sitesNames, roles, site and project identifiers, access windows, inductions and permits, sign off records, communications
Suppliers and service providers including raw materials, logistics, calibration, and maintenanceEntity details, registration and VAT numbers, B-BBEE certificate details, bank details, contact persons, contracts, security questionnaires, DPAs, delivery and performance records
Contractors and subcontractorsCompany and contact details, scope of work, permits, induction and safety confirmations, incident logs, invoices, communications
EmployeesNames, identity numbers, contact details, demographics, next of kin, contracts, performance, time and attendance, payroll and tax data, benefits, disciplinary records, training and induction completion, device assignments, access control logs, CCTV images, incident and injury files, medical fitness certificates where legally required
Temporary workers and internsNames, identity numbers, contact details, assignment details, timesheets, inductions, training completion, supervision records
Drivers and fleet-related personnelNames, licence and PDP details, contact details, vehicle assignments, telematics and GPS logs, incident and accident reports, infringement records
Job applicantsNames, contact details, CVs, qualifications, work history, references, background screening outcomes, right to work records, interview notes
Warranty claimants and product return contactsNames, contact details, proof of purchase or project reference, claim details, test outcomes, replacement or credit records, delivery details
Training attendees for product, safety, or handlingNames, contact details, employer, course enrolments, completion status, assessments, certificates
Website and portal usersNames and contact details submitted via forms, device and browser identifiers, IP addresses, timestamps, basic analytics, cookie preferences, user account activity for portals
Social media usersProfile names, public handles, public posts directed at the company, direct message content related to service or products
Office and factory visitors, CCTV subjectsNames, ID or visitor card details, access logs, CCTV images and video, vehicle registration for parking, contractor company where applicable
Shareholders, directors, prescribed officersNames, identity numbers, contact details, shareholding details, appointments, CIPC filings, beneficial ownership particulars, conflict registers
Government and regulatory officialsNames, role and institution, contact details, correspondence, inspection or enquiry records
Health, safety, and security incident subjectsNames, contact details, incident details, statements, injury information where legally required, outcomes, corrective actions
Whistleblowing reportersNames and contact details where provided, report content, follow up records. Anonymous reports retained without identifiers
General public and other stakeholdersInformation provided in emails, calls, surveys, or events. Names, contact details, signatures for acknowledgements, and the minimum content required for business or legal purposes

12. Recipients or Categories of Recipients to whom the Personal Information may be Supplied

Personal information held by the Company may be disseminated to third parties only when lawful and necessary for business, contractual, or regulatory purposes. Categories of personal information and possible recipients include (but are not limited to):

Category of Personal InformationRecipients or Categories of Recipients
Identity numbers, names, business and personal contact detailsGovernment departments and regulatory authorities. Law enforcement on lawful request. Auditors. Banking partners for KYC where required. Business park or customer site security for access permits and inductions. Courier partners for document or product delivery. The Information Regulator for statutory submissions.
Qualifications, licenses, and professional historySAQA. Professional bodies. Background screening providers. Recruitment service providers. Customer audit teams where contractually required.
Credit and payment historyRegistered credit bureaus. Banks and payment processors. External accountants. Debt collection agencies where applicable.
Tax and payroll recordsSARS. Payroll providers. Pension or provident fund administrators. Medical aid and employee benefit providers. UIF and COID administrators.
Health and safety informationOccupational health practitioners. Medical aid providers. Compensation Commissioner and COID administrators. Customer HSE representatives for site incidents where required by contract. Insurers and loss adjusters.
Contractual and business informationCustomers. Insurers. Legal advisors. Auditors. Consultants. Logistics and freight subcontractors. Customs brokers. SANAS-accredited testing or calibration laboratories where contracted.
B-BBEE credentials and supplier dataVerification agencies. Client procurement departments. Tender and procurement portals requiring disclosure.
Training and induction recordsmerSETA for learnerships and grants. Customer site management for access approval and safety inductions. Auditors.
Direct marketing preferences and contact dataEmail and SMS service providers. Campaign management vendors. Suppression list partners to honor opt outs.
Warranty and product return dataCustomers and distributors. Testing laboratories for failure analysis. Insurers and loss adjusters where a product liability claim is raised.
CCTV footage, access control logs, visitor registersSecurity service providers. Business park or facility security. Insurers. Law enforcement on lawful request. Forensic investigators.
Fleet, telematics, route and incident dataTelematics providers. Fleet insurers. Accident investigators. AARTO enforcement authorities. Panel beaters and tow services.
Financial records, invoices, bank detailsBanks. External accountants. Auditors. Payment processors. Customers and suppliers for reconciliation.
Digital and IT records including user IDs, device IDs, logs, backupsCloud hosting providers. Managed IT and cybersecurity vendors. SaaS analytics providers. Incident response partners.
Data protection governance records including ROPA, operator agreements, breach logsThe Information Regulator. Customers in their capacity as responsible parties where required by contract. Legal counsel. Cyber insurers.
Procurement and vendor onboarding packsDue diligence providers. Screening databases. Client procurement teams. Group legal and risk.
Shareholder, director, and beneficial ownership detailsCIPC. Banks for KYC. Auditors. Verification agencies where required by tender rules.

13. Planned Transborder Flows of Personal Information

The Company may, where necessary and lawful, transfer or store personal information outside the Republic of South Africa. This could include, for example, the use of secure cloud-based service providers or international business partners. Where no transborder transfer is required, personal information will continue to be stored and processed within South Africa.

Any cross-border transfer of personal information will only take place in accordance with section 72 of POPIA, which requires that:

  • The recipient country, organisation, or international organisation is subject to a law, binding agreement, or corporate rules that provide an adequate level of protection; or
  • The transfer is necessary for the performance of a contract, with the consent of the data subject, or for another lawful reason recognised by POPIA.

14. Availability of the PAIA Manual

A copy of the manual is available:

  • On the website or at any head office for public inspection during normal business hours;
  • To any person upon request and upon the payment of a reasonable prescribed fee; and
  • To the Information Regulator upon request.

A fee for a copy of the manual, as contemplated in the Regulations, shall be payable per each A4-size photocopy made.

15. Objection to the Processing of Personal Information by a Data Subject

  • Any person ("data subject") has the right to object to the processing of their personal information in terms of section 11(3) of POPIA.
  • An objection must be made on Form 1Objection to the Processing of Personal Information or a similar form. This is free of charge and can be sent by hand, post, fax, email, SMS, WhatsApp, or any other convenient method.
  • When personal information is collected, the Company must inform the data subject of their right to object.
  • If an objection is made by phone, the Company must record it electronically and provide a copy or written transcript to the data subject on request, at no cost.

16. Request for Correction / Deletion of Personal Information

A data subject has the right, under section 24 of POPIA, to request the correction, destruction, or deletion of their personal information at any time and free of charge. Correction or deletion may be requested if the personal information is:

  • Inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained; or
  • No longer lawfully permitted to be kept by the Company.

Requests must be made using Form 2Request for Correction or Deletion of Personal Information or a similar form. This can be submitted free of charge by hand, post, fax, email, SMS, WhatsApp, or any other convenient method.

  • If a request is made by phone, the Company must record it electronically and provide a copy or written transcript to the data subject on request, at no cost.
  • The Company must respond within 30 days of receiving the request and notify the data subject in writing of the outcome and any action taken.

17. Applicable Forms

PAIA Forms

POPIA Forms

18. Updating of the Manual

The head of the Company will update this manual on a regular basis.

Name of IOVincent Bezuidenhout
Title of the head of the bodyManaging Director
Notes
  1. Section 56(a) of POPIA – Every public and private body must, in line with section 17 of PAIA, appoint as many Deputy Information Officers as needed to carry out the duties and responsibilities set out in section 55(1) of POPIA.
  2. In terms of PAIA, access to records of a public body (section 11) or a private body (section 50) must be granted if the requester meets PAIA’s procedural requirements, the request is necessary for exercising or protecting a right (in the case of private bodies), and no grounds for refusal in Chapter 4 apply.
  3. In terms of sections 14 and 51 of PAIA, the Information Officer of every public and private body must update and publish their PAIA manual at least once every 12 months.
  4. In terms of PAIA, public and private bodies must keep their PAIA manuals (sections 14 and 51) and notices (sections 15 and 52) updated and published at least once every 12 months. When access to a record is granted, the notice must also state any access fee payable by the requester (sections 22 and 54). In addition, the Information Regulator must update and publish the official PAIA Guide at least once every two years (section 92(11)).