Most South African businesses treat PAIA and POPIA as deadline obligations — something to think about in April when the Information Regulator opens the reporting window, and to ignore for the other nine months. The Regulator’s 2025/2026 enforcement posture makes that approach increasingly risky.
Neither law is an annual event. Both are year-round frameworks that the Regulator now audits, inspects and enforces continuously. This guide sets out what each requires, how they interact, and what your business has to keep up all year.
The difference, simply
POPIA — the Protection of Personal Information Act — governs how you collect, store, process and share personal information. It is about data protection: the rules for handling information about customers, employees and suppliers.
PAIA — the Promotion of Access to Information Act — governs how you respond when someone asks to see records you hold. It is about access: the right to request documents from government bodies and private companies where those records are needed to exercise a legal right.
Both are enforced by the Information Regulator, monitored through the same eServices portal, and assessed together. A PAIA inspection will look at your POPIA position, and the reverse. Fixing one does not insulate you on the other.
The four PAIA obligations
1. Information Officer registration
Every organisation holding personal information must appoint an Information Officer. By default that is the head of the private body — the CEO, managing director or sole proprietor. The appointment is automatic; the registration is not, and must be done with the Regulator at inforegulator.bizportal.gov.za. It is free and once-off unless the officer changes.
Deputy Information Officers can be appointed for day-to-day requests and must also be registered. If the officer changes through a new CEO, a director change or a restructure, register the new appointment promptly — ours is the step-by-step registration guide.
2. PAIA manual
Every private body must compile and maintain a PAIA manual setting out what categories of records it holds, how someone requests access, who the Information Officer is and how to reach them, and which forms and fees apply. It has to be publicly accessible, which in practice means on your website.
One specific trap: the old PAIA Form A is no longer compliant. Requests must use a form substantially corresponding to Form 2 under the 2021 PAIA Regulations. If your manual or website still references Form A, it needs updating — inspectors have been finding exactly this.
Organisations with fewer than 50 employees and annual turnover below R5 million qualify for a reduced manual. Everyone else compiles the full one.
3. PAIA request register
You must keep an ongoing register of every information request received: who asked, what they asked for, when it arrived, how you responded, the outcome, and whether an internal appeal followed. This register is the source document for the annual report, and it has to be maintained continuously rather than assembled each May.
4. The annual report, by 30 June
The annual report covers all PAIA requests received and processed in the reporting period, 1 April to 31 March, and is submitted through the Regulator’s eServices portal between 1 April and 30 June.
It must be submitted even if you received no requests at all. A nil return is still a return — and not submitting one is what puts you on the list of organisations that did not.
For the 2026/2027 cycle the reporting period runs 1 April 2026 to 31 March 2027, and the window opens on 1 April 2027 and closes on 30 June 2027. If you missed the 2026 deadline, our guide on what happens next covers where that leaves you.
The five POPIA obligations
1. Lawful processing
All personal information must be processed lawfully, for a specific purpose, and kept only as long as necessary. In practice, for most SMEs: have a lawful basis for collecting it — consent, contract, legal obligation or legitimate interest — collect only what you need, do not repurpose it, and delete or anonymise it when it is no longer needed.
2. Privacy notice and consent
Whenever you collect personal information, the person must be told, at or before collection, what it is for, what you will do with it, who you may share it with, and what their rights are. That applies to website forms, sign-ups, employee onboarding and every other collection point. A website privacy policy covers the public-facing side; employee privacy notices are separate and must be given to staff.
3. Breach notification
Where a breach is likely to affect someone adversely, you must notify both the Regulator and the affected people. Following the 2025/2026 plan, breach notifications go through the Regulator’s eServices portal rather than by email or post.
The notification has to describe what happened, what information was affected, what you are doing about it, and what the affected person can do. POPIA sets no fixed window in the way GDPR sets 72 hours — the duty is to notify as soon as reasonably possible after becoming aware.
4. Data subject rights requests
People have the right to ask whether you hold their information, to see it, to have it corrected or deleted, to object to processing, and to ask that processing be restricted. You must respond within 30 days. Failing to respond is itself a violation that can lead to an enforcement notice, so assign the responsibility to a named person and write down the process.
5. Operator agreements
If you share personal information with third parties — payroll, IT providers, cloud storage, marketing platforms — they are operators under POPIA, and you need a written agreement requiring them to process only on your instructions and to keep the information secure. One agreement per operator relationship.
What inspectors actually check
The Regulator’s 2025/2026 plan confirms inspectors are running proactive audits rather than waiting for complaints. The specific things they look for:
- PAIA annual report submitted for the current and prior cycles
- Information Officer registered and current on the eServices portal
- PAIA manual published, current, and using Form 2 rather than the old Form A
- Section 17 register of access requests maintained
- Website privacy policy current
- A documented breach notification procedure
- Operator agreements in place for every third-party processor
Findings so far have clustered on outdated forms, incomplete registers and stale manuals — the paperwork rather than the principles. That is worth knowing, because it is the cheapest category of problem to fix before anyone asks.
The compliance calendar
| Date | Obligation |
|---|---|
| Year-round | Maintain the PAIA request register |
| Year-round | Respond to data subject rights requests within 30 days |
| Year-round | Notify breaches as soon as reasonably possible |
| As needed | Re-register when the Information Officer changes |
| As needed | Update the PAIA manual when organisational details change |
| 1 April annually | PAIA annual report window opens |
| 30 June annually | PAIA annual report deadline |
| 1 April – 30 June 2027 | Window for the 2026/2027 report |
If you share client data with a compliance provider
This catches businesses that outsource compliance work, and it catches accountants and consultants who take client data in order to do it.
Sending personal information to a third party so they can assess or report on compliance is processing under POPIA. A data processing agreement has to be in place before any of it moves. Your PAIA manual should also reflect the categories of client information you hold as a result, and how those records can be requested.
And if someone is helping a client with a PAIA annual report, that client needs their own registered Information Officer first — nobody can submit on behalf of an organisation whose officer is not registered on the Regulator’s portal.
Where ClearComply fits
ClearComply tracks the PAIA annual report and POPIA Information Officer deadlines alongside your CIPC, COIDA, SARS and UIF ones, and tells you before each falls due. The work itself — the registration, the manual, the annual report — is done by a specialist firm we match you with. We do not file it, and this article is not a substitute for advice on your own situation.
You can see exactly where your company stands at CIPC at clearcomply.co.za/check, free and without signing up.
For the detailed submission walkthrough, see our PAIA annual report guide. For registration, see the Information Officer guide.
Sources: Protection of Personal Information Act 4 of 2013. Promotion of Access to Information Act 2 of 2000 as amended, and the 2021 PAIA Regulations. Information Regulator of South Africa, 2025/2026 Annual Performance Plan, presented 5 May 2026. Werksmans Attorneys, POPIA and PAIA enforcement analysis, May 2026. Moonstone Information Refinery, May 2026. Bowmans, “PAIA reporting season is here”, April 2026.