PAIA MANUAL
- Remove the current class from the content27_link item as Webflows native current state will automatically be applied.
- To add interactions which automatically expand and collapse sections in the table of contents select the content27_h-trigger element, add an element trigger and select Mouse click (tap)
- For the 1st click select the custom animation Content 27 table of contents [Expand] and for the 2nd click select the custom animation Content 27 table of contents [Collapse].
- In the Trigger Settings, deselect all checkboxes other than Desktop and above. This disables the interaction on tablet and below to prevent bugs when scrolling.
NRS Solutions (Pty) Ltd — PAIA Manual
Registration Number: 2022/682414/07 ("the Company")
Prepared in terms of section 51 of the Promotion of Access to Information Act, No. 2 of 2000, as amended.
Version 3.0 | Date of compilation: 09/06/2021 | Date of revision: 30/09/2025
1. Definitions
| Term | Definition |
|---|---|
| CEO | Chief Executive Officer |
| Client | Any natural or juristic person that received or receives services from the company |
| Complainant | Any person who lodges a complaint with the Information Regulator |
| Complaint | (a) A matter reported to the Information Regulator in terms of section 74(1) and (2) of the Act; (b) A complaint referred to in section 76(1)(e) and 92(1) of the Act; (c) A matter reported or referred to the Information Regulator in terms of other legislation that regulates the mandate of the Information Regulator |
| Conditions for Lawful Processing | The conditions for the lawful processing of personal information as fully set out in chapter 3 of POPI and in section 12 of this manual |
| Data Subject | The person to whom Personal Information relates |
| Day | A calendar day, unless the last day of a specified period happens to fall on a Sunday or public holiday, in which case it is calculated exclusive of that Sunday or public holiday (Interpretation Act, 1957 - Act No. 33 of 1957) |
| DIO | Deputy Information Officer |
| Information Officer/IO | The individual who is identified herein and legally appointed to ensure compliance with POPIA and PAIA |
| Manual | This manual |
| Minister | Minister of Justice and Correctional Services |
| Office Hours | (a) For the Information Regulator: 08:00–16:00, Monday to Friday (excluding public holidays); (b) For designated offices: Hours during which the offices operate |
| PAIA | The Promotion of Access to Information Act, No. 2 of 2000 |
| Personal Information | Information relating to an identifiable living person, or an identifiable existing juristic person, including but not limited to race, gender, contact info, biometrics, correspondence, opinions, and identifiers |
| Personnel | Any person who works for or provides services to or on behalf of the company and receives or is entitled to receive remuneration, including permanent, temporary and part-time staff, directors, and contractors |
| POPI/POPIA | The Protection of Personal Information Act, No. 4 of 2013 |
| POPI Regulations | Regulations promulgated in terms of section 112(2) of POPI |
| Private Body | (a) A natural person conducting business; (b) A business partnership; (c) A juristic person not being a public body |
| Processing | Any operation or activity concerning personal information, including collection, storage, dissemination, or destruction |
| Regulator | Information Regulator established in terms of POPIA |
| Republic | Republic of South Africa |
| Signature | Any legally accepted form of signature, including electronic signature where applicable |
| Writing | As referred to in section 12 of the Electronic Communications and Transactions Act, 2002 (Act No. 25 of 2002) |
2. Purpose of the PAIA Manual
This PAIA Manual is useful for the public to:
The PAIA Manual serves as a public guide to the information held by the organisation and how it can be accessed. It outlines the categories of records available without a formal request, the subjects on which records are maintained, and details of records accessible under other legislation. The manual also provides the official contact details of the Information Officer (IO) and Deputy Information Officer (DIO), who are responsible for assisting the public in exercising their right of access.
The manual further explains how to use the PAIA process and where to obtain the official guide published by the Regulator. It describes whether and how the organisation processes personal information, including the purposes of processing, the categories of data subjects involved, and the recipients (local or international) to whom such information may be supplied. The manual further confirms that appropriate security safeguards are in place to protect the confidentiality, integrity, and availability of personal information.
3. Contact Details for Access to Information Requests
Information Officer
| Name | Vincent Bezuidenhout |
| Contact number | 011 824 3977 |
| Email address | vincent@n-r-s.co.za |
Deputy Information Officer
| Name | Pryce Robinson |
| Contact number | 011 824 3977 |
| Email address | pryce@n-r-s.co.za |
National or Head Office
| Postal address | 41, Dudley Road, Parkwood, Johannesburg, 2193. |
| Physical address | 41, Dudley Road, Parkwood, Johannesburg, 2193. |
| Contact number | 011 824 3977 |
| vincent@n-r-s.co.za | |
| Website | http://n-r-s.co.za/ |
4. Guide on How to Use PAIA and How to Obtain Access to the Guide
The Information Regulator has published a revised PAIA Guide in terms of section 10(1) of PAIA (as amended). This guide is designed to help any person who wishes to exercise rights under PAIA or POPIA, and it is available in all official languages as well as in braille to ensure accessibility.
The Guide serves two key purposes:
- Access to Personal Information (POPIA): It explains how individuals (data subjects) can exercise their rights to request confirmation of whether personal information is held about them, to access that information (including details of third-party recipients), and to request correction, deletion, or destruction of personal information that is inaccurate, outdated, excessive, or unlawfully obtained.
- Access to Records (PAIA): It provides step-by-step guidance on how to request records from public or private bodies, including the required forms, the process for appeals or complaints, and how to approach a court if necessary.
In addition, the Guide offers:
- An overview of the objectives of PAIA and POPIA.
- Contact details of Information Officers (IOs) and Deputy Information Officers (DIOs).[1]
- Manner and form of a request for access to a record of a public body and private body.[2]
- Guidance on compiling or accessing PAIA Manuals.[3]
- Information on voluntary disclosures of records, prescribed access fees, and applicable regulations.[4]
- How to lodge an internal appeal, a complaint with the Regulator, or apply to court against a decision by the IO of a public body, a decision on internal appeal, a decision by the Regulator, or a decision of the head of a private body.
- Insight into how PAIA has been amended following the implementation of POPIA.
The guide can also be obtained:
- Upon request to the IO: Request for a Copy of the Guide from an Information Officer [Regulation 3].
- From the website of the Regulator: www.inforegulator.org.za.
- From the offices of the Regulator: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, or by email: enquiries@inforegulator.org.za.
A copy of the guide is also available in the following three official languages, for public inspection during normal office hours:
- English
- Afrikaans
- Zulu
5. Latest Notices in terms of Section 52(2) of PAIA
At this stage, no notice(s) has/have been published on the categories of records that are available without having to request access to them in terms of PAIA.
6. Availability of Certain Records in terms of PAIA
Categories of records available without a person having to request access
| Category of Records | Types of the Record | Available on Website | Available on Request |
|---|---|---|---|
| PAIA Manual | Current PAIA Manual with version and effective date | X | X |
| Company overview | Manufacturer of specialised and instrumentation cables, product range summary, factory location, head office contact details | X | X |
| Product catalogue | Cable families, voltage ratings, conductor types, insulation and sheath options, temperature ratings, application notes | X | X |
| Technical datasheets | PDF specs per cable code, dimensions, tolerances, electrical characteristics, materials, approvals | X | X |
| Compliance certificates | RoHS, REACH, CE where applicable, local conformity statements | X | X |
| Quality management | ISO 9001 certificate, QA policy, inspection and test plan high level | X | X |
| Test reports samples | Type test summaries, routine test examples with all identifiers removed | - | X |
| Manufacturing records | Batch travelers, process parameters, in-process inspection logs, final inspection checklists | - | X |
| Traceability register | Batch and reel numbers, date codes, materials lots, release status | - | X |
| Materials and SDS | Copper, PVC, XLPE, LSZH compounds, armouring materials, SDS library index | - | X |
| Drawings | Standard construction drawings, cross-sections, termination guidance | - | X |
| Custom build files | Client-specific specifications, deviations, PPAP or FAIR packs where contracted | - | X |
| Supplier and procurement | Approved vendor list at category level, B-BBEE certificate copy, bank confirmation letter | X | X |
| Corporate identifiers | Registered name, CIPC number, registered address, VAT number | - | X |
| Legal disclosures | POPIA and PAIA statements, website disclaimers | X | X |
| Privacy and cookies | Privacy Policy, Cookies Policy | X | X |
| Information Officer contacts | IO and DIO names, roles, direct emails, contact numbers | X | X |
| Health, safety, environment | HSE policy, PPE requirements, environmental policy, waste and recycling summary | X | X |
| Calibration and equipment | Calibration certificates index for key test equipment, next due dates | - | X |
| Maintenance and safety logs | Machine maintenance schedules, lockout and incident logs summary | - | X |
| Logistics and delivery | Packing standards, reel labelling, barcoding formats, Incoterms options, lead-time bands | X | X |
| Warranty and returns | Warranty terms, non-conformance and RMA process | X | X |
| Contracts snapshot | Standard terms of sale, payment terms summary, NDAs template reference | X | X |
| Tax and compliance attestations | SARS TCS PIN, COID LOGS, UIF proof | - | X |
| Insurance confirmations | Public and product liability summary, limits, insurer, validity dates | - | X |
| Company secretarial | Directors as filed at CIPC, principal place of business | - | X |
| Whistleblowing and complaints | Confidential hotline, PAIA and POPIA complaint routes, escalation to the Regulator | X | X |
| Careers and recruitment | Vacancies, application process, candidate privacy notice | X | X |
| CSR | Local manufacturing support initiatives, skills development | X | X |
Records / subjects available in accordance with any other legislation
| Category of Records | Applicable Legislation |
|---|---|
| Memorandum of Incorporation, CIPC filings, board minutes, share register | Companies Act, 2008, Act 71 of 2008 |
| Employment contracts, attendance, overtime, payroll, leave | Basic Conditions of Employment Act, 1997, Act 75 of 1997 |
| Minimum wage schedules for factory, warehouse and logistics staff | National Minimum Wage Act, 2018, Act 9 of 2018. Basic Conditions of Employment Act, 1997, Act 75 of 1997 |
| Disciplinary and grievance files, union correspondence, CCMA case files | Labour Relations Act, 1995, Act 66 of 1995 |
| Employment Equity plan, annual EE reports, committee minutes | Employment Equity Act, 1998, Act 55 of 1998 |
| Recruitment ads, shortlist records, background screening outcomes | Employment Services Act, 2014, Act 4 of 2014. Protection of Personal Information Act, 2013, Act 4 of 2013 |
| Work permission for foreign nationals | Immigration Act, 2002, Act 13 of 2002 |
| UIF declarations, contributions, benefit claims | Unemployment Insurance Act, 2001, Act 63 of 2001 |
| Skills plans, annual training reports, learnership agreements | Skills Development Act, 1998, Act 97 of 1998 |
| Levy declarations, merSETA registrations, grants | Skills Development Levies Act, 1999, Act 9 of 1999 |
| PAYE, IRP5, EMP201, EMP501, tax directives | Income Tax Act, 1962, Act 58 of 1962 |
| VAT returns, input and output schedules, SARS correspondence | Value Added Tax Act, 1991, Act 89 of 1991 |
| COIDA registration, Return of Earnings, Letter of Good Standing, IOD claims | Compensation for Occupational Injuries and Diseases Act, 1993, Act 130 of 1993 |
| OHS policy, risk assessments for extrusion, wire drawing, armouring, QA labs, incident reports, safety minutes | Occupational Health and Safety Act, 1993, Act 85 of 1993 and regulations |
| Hazardous Chemical Agents inventories, SDS library, training records | Occupational Health and Safety Act, 1993, Act 85 of 1993. Hazardous Chemical Agents Regulations, 2021 |
| Electrical machinery registers, isolation and lockout logs, inspections | Occupational Health and Safety Act, 1993, Act 85 of 1993. Electrical Machinery Regulations |
| PPE issue registers, inspections, fit testing | Occupational Health and Safety Act, 1993, Act 85 of 1993. General Safety Regulations |
| Fire equipment servicing, evacuation drills, fire risk assessments | Fire Brigade Services Act, 1987, Act 99 of 1987. Applicable municipal by laws |
| Environmental management plans, waste manifests, recycling records | National Environmental Management. Waste Act, 2008, Act 59 of 2008 |
| Air emissions records where applicable, furnace or curing logs | National Environmental Management. Air Quality Act, 2004, Act 39 of 2004 |
| Effluent and water use records where applicable | National Water Act, 1998, Act 36 of 1998 |
| Product conformity files, cable technical files, routine and type test reports, material declarations | National Regulator for Compulsory Specifications Act, 2008, Act 5 of 2008. Legal Metrology Act, 2014, Act 9 of 2014. Relevant SANS and IEC standards |
| Calibration certificates for insulation resistance, HV and spark testers. MTE schedules | Legal Metrology Act, 2014, Act 9 of 2014 |
| QMS records, ISO 9001 certificate, audits, NCRs, CAPAs | ISO 9001 Quality Management Systems standard |
| Supplier approvals, procurement policy, due diligence packs, onboarding checklists | Protection of Personal Information Act, 2013, Act 4 of 2013. Common law of contract |
| Public and product liability policy schedules, endorsements, notifications | Insurance Act, 2017, Act 18 of 2017 |
| B BBEE certificate, ownership, skills, supplier and enterprise development evidence | Broad Based Black Economic Empowerment Act, 2003, Act 53 of 2003 and the Codes of Good Practice |
| Standard terms of sale, customer contracts, warranty and returns records | Consumer Protection Act, 2008, Act 68 of 2008. Common law of contract |
| Import and export files, bills of entry, SAD500, customs correspondence, machine import packs | Customs and Excise Act, 1964, Act 91 of 1964 |
| Deputy Information Officer designations and revocations, IO registration proof | Protection of Personal Information Act 4 of 2013 |
| Electronic communications policies, e signature consents, website terms, cookies records | Electronic Communications and Transactions Act, 2002, Act 25 of 2002 |
| Cyber incident register, takedown requests, forensic reports | Cybercrimes Act, 2020, Act 19 of 2020 |
Records kept as required by PAIA and POPIA
- PAIA records: PAIA Manual, official guides, submission records, and awareness training materials.
- POPIA records: Information Officer registration certificate, data breach records, retention records, and awareness training materials.
- Other relevant information may also be made available on request.
The tabulated records may be requested; however, it should be noted that there is no guarantee that the request will be honoured. Each request will be evaluated in terms of PAIA and any other applicable legislation.
7. Request Process
An individual who wishes to place a request must comply with all the procedures laid down in PAIA:
1. Initiating the request
Use the prescribed form. All requests must be made on the prescribed form (Form 2 – Request for Access to Record [Regulation 7]) – Request for Access to Record [Regulation 7].
Additional prescribed forms include:
- Form 2 – Request for Correction or Deletion (section 24 of POPIA). Used by a data subject to request the correction of inaccurate, outdated, incomplete, irrelevant, or misleading personal information, and/or the deletion or destruction of personal information that is no longer necessary or unlawfully obtained, in accordance with section 24(1) of POPIA. – Form link
- Form 3 – Application for a Code of Conduct (section 61 of POPIA). Used by an industry body, profession, or class of entities to apply for the issuance of a Code of Conduct under section 61(1)(b) of POPIA. – Form link
- Form 4 – Request for Consent for Direct Marketing (section 69 of POPIA). Enables a responsible party to formally request a data subject’s consent to receive direct marketing communications via unsolicited electronic means (e.g. SMS, email), as required under section 69(2) of POPIA. – Form link
- Form 5 – Complaint Regarding Interference with Personal Information. Allows a data subject or complainant to submit a complaint to the Regulator concerning unlawful interference with personal information, or a determination made by an adjudicator under POPIA. – Form link
Requests not submitted on the prescribed form may be rejected.
Assistance in the request process:
- If a requester is illiterate or disabled, they may make the request orally to the IO, who must complete the prescribed form on their behalf and provide them with a copy (section 18(3) of PAIA).
- The IO must provide reasonable assistance to any requester who requires help in completing the form or understanding the procedure.
2. Particulars of the request
The request must provide sufficient detail to enable the IO to identify and process it. This includes:
- A clear description of the record(s) requested.
- Full identity of the requester, with proof of identity where required.
- The preferred form of access (inspection, copy, electronic copy, etc.).
- The requester’s contact details (postal, physical, fax or email).
- A statement that the record is required to exercise or protect a right, specifying the nature of that right and explaining why the record is necessary.
- If a request is made on behalf of another person, proof of authorisation must be attached.
3. Submission of requests
The completed form, together with proof of payment of the prescribed request fee (if applicable), must be submitted to the Information Officer (IO) at the Company. Requests may be lodged by:
- Hand delivery to the physical address provided in this Manual;
- Postal delivery to the Company’s registered address;
- Fax; or
- Email to the address of the IO or DIO.
Where applicable, the IO may require a deposit in terms of section 22(2) of PAIA where search and preparation is expected to be time-consuming.
4. Fees and timeframes for response
- Requests will be processed and responded to within 30 (thirty) calendar days of receipt.
- In terms of section 26 of PAIA, the IO may extend this period once, by up to 30 additional days, if: the request involves a large number of records; consultation with third parties is required; or the records are located in another office and cannot reasonably be obtained within 30 days.
- If an extension is required, the requester will be notified in writing, with reasons for the extension.
- A request fee may be charged for non-personal requests.
- If the search and preparation of the record will exceed six (6) hours, the requester may be required to pay a deposit of up to one-third of the estimated fee.
- Access will only be granted once all required fees have been paid.
5. Outcome of request
The IO will notify the requester in writing, using Form 3 – Outcome of Request and of Fees Payable [Regulation 8], of the decision to grant or refuse access.
- If access is granted, the notice will specify the form of access and state the applicable access fees payable before access is given.
- If access is refused, the notice will set out the grounds for refusal as provided in Chapter 4 of PAIA.
6. Appeals and complaints
If access is refused or deemed refused (i.e. no decision within the prescribed period), the requester may:
- Lodge an internal appeal (for public bodies); or
- Refer the matter to the Information Regulator or approach a court of law (for private bodies).
The Regulator can be contacted using the details provided in this Manual.
8. Grounds for Refusal
In terms of Chapter 4 of PAIA, the Company may refuse a request for access to records on the following grounds (unless an exception applies):
- Privacy of individuals – To protect the personal information of a third party (including deceased persons) where disclosure would be unreasonable.
- Commercial interests of third parties – Records may be refused if they contain:
- Trade secrets;
- Financial, commercial, scientific, or technical information, where disclosure could cause harm; or
- Information provided in confidence, where disclosure could disadvantage or prejudice the third party in negotiations or competition.
- Confidentiality agreements – Information that is protected under a contract or agreement with a third party.
- Safety and security – Records that could endanger the life, health, or safety of a person, or the protection of property.
- Legal privilege – Records that would be privileged from disclosure in legal proceedings.
- Commercial interests of the Company – Records may be refused if they contain:
- Trade secrets;
- Financial, commercial, scientific, or technical information that could harm the Company’s interests;
- Information that could prejudice the Company in negotiations or competition; or
- Proprietary computer programs protected by copyright or intellectual property law.
- Research information – Where disclosure would place ongoing research or a researcher at a serious disadvantage.
- Frivolous or unreasonable requests – Requests that are clearly frivolous, vexatious, or that would cause an unreasonable burden on Company resources.
9. Remedies Should a Request be Refused
- If the Company does not have an internal appeal procedure in light of a denial of a request, decisions made by the IO are final.
- The requestor may, in accordance with sections 56(3)(c) and 78 of PAIA, apply to a court for relief within 180 (one hundred and eighty) days of notification of the decision for appropriate relief.
10. Fees
The following fees shall be payable upon request by a requestor:
| Details | Fee |
|---|---|
| Request fee (payable on every request) | R140.00 once-off |
| Photocopy of an A4 page or part thereof | R2.00 per page |
| Printed copy of an A4 page or part thereof | R2.00 per page |
| Hard copy on flash drive (flash drive to be provided by requestor) | R40.00 once-off |
| Hard copy on a compact disc (compact disc to be provided by requestor) | R40.00 once-off |
| Hard copy on a compact disc (compact disc to be provided by the company) | R60.00 once-off |
| Transcription of visual images per A4 page | As per quotation of service provider |
| Copy of visual images | As per quotation of service provider |
| Transcription of an audio record | R24.00 per A4 page |
| Copy of an audio record on flash drive (flash drive to be provided by requestor) | R40.00 once-off |
| Copy of an audio on a compact disc (compact disc to be provided by requestor) | R40.00 once-off |
| Copy of an audio on a compact disc (compact disc to be provided by the company) | R60.00 once-off |
| Base/starting rate to search for and prepare the record for disclosure | R145.00 per hour for each hour or part thereof, excluding the first hour, reasonably required for such search and preparation (cannot exceed R435.00 per request) |
| Rate to search for and prepare the record for disclosure | R435.00 per hour for each hour or part thereof, excluding the first hour, reasonably required for such search and preparation (cannot exceed total cost) |
| Postage, email or any other electronic transfer | Actual expense, if any |
11. Processing of Personal Information
The Company processes personal information in accordance with the conditions for lawful processing as set out in the Protection of Personal Information Act, 4 of 2013 ("POPIA"). Personal information is processed only for legitimate business purposes, which may include (but are not limited to):
- Employment-related purposes: Recruitment, administration of employment contracts, payroll, benefits, training, and compliance with labour laws.
- Client and supplier management: Entering into and performing contracts, maintaining relationships, processing payments, and responding to queries or complaints.
- Legal and compliance obligations: Compliance with statutory and regulatory requirements, record keeping, audits, and reporting.
- Security and risk management: Protecting company property, monitoring access, preventing fraud, and ensuring the safety of staff, clients, and visitors.
- Marketing and communication: Providing information about products or services, subject to obtaining the necessary consent under POPIA.
The Company ensures that personal information is processed lawfully, reasonably, and only for the purposes for which it was collected, and takes appropriate steps to protect the confidentiality and integrity of such information.
Categories of data subjects and related personal information
The Company processes personal information relating to various categories of data subjects. The categories of data subjects, and the types of personal information that may be processed in respect of each, include (but are not limited to) the following:
| Categories of Data Subjects | Personal Information that may be Processed |
|---|---|
| Customers and corporate clients including EPCs, OEMs, distributors, panel builders | Names, work titles, business contact details, company identifiers, ship to and bill to addresses, contract and PO records, orders, invoices, delivery notes, payment history, bank details, warranty and returns records, service tickets, communications, audit trails |
| Prospective clients and RFQ contacts | Names, business contact details, role, lead source, RFQs, quotes and proposals, meeting notes, communications |
| Channel partners and agents | Entity details, registration and VAT numbers, B-BBEE certificate details, bank details, contact persons, agreements, commission statements, performance records |
| Site contacts at customer plants and project sites | Names, roles, site and project identifiers, access windows, inductions and permits, sign off records, communications |
| Suppliers and service providers including raw materials, logistics, calibration, and maintenance | Entity details, registration and VAT numbers, B-BBEE certificate details, bank details, contact persons, contracts, security questionnaires, DPAs, delivery and performance records |
| Contractors and subcontractors | Company and contact details, scope of work, permits, induction and safety confirmations, incident logs, invoices, communications |
| Employees | Names, identity numbers, contact details, demographics, next of kin, contracts, performance, time and attendance, payroll and tax data, benefits, disciplinary records, training and induction completion, device assignments, access control logs, CCTV images, incident and injury files, medical fitness certificates where legally required |
| Temporary workers and interns | Names, identity numbers, contact details, assignment details, timesheets, inductions, training completion, supervision records |
| Drivers and fleet-related personnel | Names, licence and PDP details, contact details, vehicle assignments, telematics and GPS logs, incident and accident reports, infringement records |
| Job applicants | Names, contact details, CVs, qualifications, work history, references, background screening outcomes, right to work records, interview notes |
| Warranty claimants and product return contacts | Names, contact details, proof of purchase or project reference, claim details, test outcomes, replacement or credit records, delivery details |
| Training attendees for product, safety, or handling | Names, contact details, employer, course enrolments, completion status, assessments, certificates |
| Website and portal users | Names and contact details submitted via forms, device and browser identifiers, IP addresses, timestamps, basic analytics, cookie preferences, user account activity for portals |
| Social media users | Profile names, public handles, public posts directed at the company, direct message content related to service or products |
| Office and factory visitors, CCTV subjects | Names, ID or visitor card details, access logs, CCTV images and video, vehicle registration for parking, contractor company where applicable |
| Shareholders, directors, prescribed officers | Names, identity numbers, contact details, shareholding details, appointments, CIPC filings, beneficial ownership particulars, conflict registers |
| Government and regulatory officials | Names, role and institution, contact details, correspondence, inspection or enquiry records |
| Health, safety, and security incident subjects | Names, contact details, incident details, statements, injury information where legally required, outcomes, corrective actions |
| Whistleblowing reporters | Names and contact details where provided, report content, follow up records. Anonymous reports retained without identifiers |
| General public and other stakeholders | Information provided in emails, calls, surveys, or events. Names, contact details, signatures for acknowledgements, and the minimum content required for business or legal purposes |
12. Recipients or Categories of Recipients to whom the Personal Information may be Supplied
Personal information held by the Company may be disseminated to third parties only when lawful and necessary for business, contractual, or regulatory purposes. Categories of personal information and possible recipients include (but are not limited to):
| Category of Personal Information | Recipients or Categories of Recipients |
|---|---|
| Identity numbers, names, business and personal contact details | Government departments and regulatory authorities. Law enforcement on lawful request. Auditors. Banking partners for KYC where required. Business park or customer site security for access permits and inductions. Courier partners for document or product delivery. The Information Regulator for statutory submissions. |
| Qualifications, licenses, and professional history | SAQA. Professional bodies. Background screening providers. Recruitment service providers. Customer audit teams where contractually required. |
| Credit and payment history | Registered credit bureaus. Banks and payment processors. External accountants. Debt collection agencies where applicable. |
| Tax and payroll records | SARS. Payroll providers. Pension or provident fund administrators. Medical aid and employee benefit providers. UIF and COID administrators. |
| Health and safety information | Occupational health practitioners. Medical aid providers. Compensation Commissioner and COID administrators. Customer HSE representatives for site incidents where required by contract. Insurers and loss adjusters. |
| Contractual and business information | Customers. Insurers. Legal advisors. Auditors. Consultants. Logistics and freight subcontractors. Customs brokers. SANAS-accredited testing or calibration laboratories where contracted. |
| B-BBEE credentials and supplier data | Verification agencies. Client procurement departments. Tender and procurement portals requiring disclosure. |
| Training and induction records | merSETA for learnerships and grants. Customer site management for access approval and safety inductions. Auditors. |
| Direct marketing preferences and contact data | Email and SMS service providers. Campaign management vendors. Suppression list partners to honor opt outs. |
| Warranty and product return data | Customers and distributors. Testing laboratories for failure analysis. Insurers and loss adjusters where a product liability claim is raised. |
| CCTV footage, access control logs, visitor registers | Security service providers. Business park or facility security. Insurers. Law enforcement on lawful request. Forensic investigators. |
| Fleet, telematics, route and incident data | Telematics providers. Fleet insurers. Accident investigators. AARTO enforcement authorities. Panel beaters and tow services. |
| Financial records, invoices, bank details | Banks. External accountants. Auditors. Payment processors. Customers and suppliers for reconciliation. |
| Digital and IT records including user IDs, device IDs, logs, backups | Cloud hosting providers. Managed IT and cybersecurity vendors. SaaS analytics providers. Incident response partners. |
| Data protection governance records including ROPA, operator agreements, breach logs | The Information Regulator. Customers in their capacity as responsible parties where required by contract. Legal counsel. Cyber insurers. |
| Procurement and vendor onboarding packs | Due diligence providers. Screening databases. Client procurement teams. Group legal and risk. |
| Shareholder, director, and beneficial ownership details | CIPC. Banks for KYC. Auditors. Verification agencies where required by tender rules. |
13. Planned Transborder Flows of Personal Information
The Company may, where necessary and lawful, transfer or store personal information outside the Republic of South Africa. This could include, for example, the use of secure cloud-based service providers or international business partners. Where no transborder transfer is required, personal information will continue to be stored and processed within South Africa.
Any cross-border transfer of personal information will only take place in accordance with section 72 of POPIA, which requires that:
- The recipient country, organisation, or international organisation is subject to a law, binding agreement, or corporate rules that provide an adequate level of protection; or
- The transfer is necessary for the performance of a contract, with the consent of the data subject, or for another lawful reason recognised by POPIA.
14. Availability of the PAIA Manual
A copy of the manual is available:
- On the website or at any head office for public inspection during normal business hours;
- To any person upon request and upon the payment of a reasonable prescribed fee; and
- To the Information Regulator upon request.
A fee for a copy of the manual, as contemplated in the Regulations, shall be payable per each A4-size photocopy made.
15. Objection to the Processing of Personal Information by a Data Subject
- Any person ("data subject") has the right to object to the processing of their personal information in terms of section 11(3) of POPIA.
- An objection must be made on Form 1 – Objection to the Processing of Personal Information or a similar form. This is free of charge and can be sent by hand, post, fax, email, SMS, WhatsApp, or any other convenient method.
- When personal information is collected, the Company must inform the data subject of their right to object.
- If an objection is made by phone, the Company must record it electronically and provide a copy or written transcript to the data subject on request, at no cost.
16. Request for Correction / Deletion of Personal Information
A data subject has the right, under section 24 of POPIA, to request the correction, destruction, or deletion of their personal information at any time and free of charge. Correction or deletion may be requested if the personal information is:
- Inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained; or
- No longer lawfully permitted to be kept by the Company.
Requests must be made using Form 2 – Request for Correction or Deletion of Personal Information or a similar form. This can be submitted free of charge by hand, post, fax, email, SMS, WhatsApp, or any other convenient method.
- If a request is made by phone, the Company must record it electronically and provide a copy or written transcript to the data subject on request, at no cost.
- The Company must respond within 30 days of receiving the request and notify the data subject in writing of the outcome and any action taken.
17. Applicable Forms
PAIA Forms
- Form 01: Request for a Copy of the Guide from an Information Officer [Regulation 3]
- Form 02: Request for Access to Record [Regulation 7]
- Form 03: Outcome of Request and of Fees Payable [Regulation 8]
- Form 05: Complaint Form [Regulation 10]
- Form 13: PAIA Request for Compliance Assessment Form [Regulation 14(1)]
POPIA Forms
- Form 1: Objection to the Processing of Personal Information
- Form 2: Request for Correction or Deletion of Personal Information
- Form 3: Application for the Issue of a Code of Conduct
- Form 4: Application for Consent for Direct Marketing
- Form 5: Complaint Regarding Interference with the Protection of Personal Information
18. Updating of the Manual
The head of the Company will update this manual on a regular basis.
| Name of IO | Vincent Bezuidenhout |
| Title of the head of the body | Managing Director |
- Section 56(a) of POPIA – Every public and private body must, in line with section 17 of PAIA, appoint as many Deputy Information Officers as needed to carry out the duties and responsibilities set out in section 55(1) of POPIA. ↩
- In terms of PAIA, access to records of a public body (section 11) or a private body (section 50) must be granted if the requester meets PAIA’s procedural requirements, the request is necessary for exercising or protecting a right (in the case of private bodies), and no grounds for refusal in Chapter 4 apply. ↩
- In terms of sections 14 and 51 of PAIA, the Information Officer of every public and private body must update and publish their PAIA manual at least once every 12 months. ↩
- In terms of PAIA, public and private bodies must keep their PAIA manuals (sections 14 and 51) and notices (sections 15 and 52) updated and published at least once every 12 months. When access to a record is granted, the notice must also state any access fee payable by the requester (sections 22 and 54). In addition, the Information Regulator must update and publish the official PAIA Guide at least once every two years (section 92(11)). ↩