Ask a private company for its section 51 manual and the usual answer is a pause, followed by a question: our what? Yet since 1 January 2022 every private body in South Africa — companies of every size, close corporations, non-profits, bodies corporate, partnerships and sole traders alike — has been required to compile one and to make it available to the public. The exemption that had spared smaller bodies for years was extended one final time, to 31 December 2021, and then allowed to lapse. More than four years on, the obligation is settled, unglamorous and, in this practice’s experience, very widely ignored.
What the manual is for
The Promotion of Access to Information Act 2 of 2000 gives effect to section 32 of the Constitution: the right of access to information held by the State and, where the information is required for the exercise or protection of a right, to information held by anyone else. For a private body that qualification matters — under section 50 a requester must identify the right at stake and explain why the record is needed for it — but the right is real, and the manual is the map that makes it usable. It tells a member of the public who to ask, what the body holds, what can be had without asking, how to ask, what it costs, and what to do if the answer is no. Since the Protection of Personal Information Act amended section 51, it also tells them how the body processes personal information.
Why it stopped being optional
Three things changed in 2021, and together they explain why a document that once lived in a filing cabinet now lives on the website. First, POPIA’s amendments to PAIA took effect on 30 June 2021: oversight of the Act moved from the Human Rights Commission to the Information Regulator, and the required contents of the manual were widened to include a description of the body’s personal-information processing. Second, new PAIA Regulations followed in August 2021, prescribing the forms, the fees and the manner of publication. Third, the ministerial exemption for smaller private bodies was extended for a final six months and then expired on 31 December 2021.
The practical consequence is easy to miss. Manuals are no longer filed with a regulator. Instead, the body must publish the manual on its website, keep it available for inspection at its principal place of business, and provide it to the Regulator on request. The compliance burden did not disappear; it moved from a filing to a publication — which is precisely why non-compliance is now visible to anyone who cares to look, including a requester, a counterparty running due diligence, a tender evaluator, or the Regulator.
What it must contain
Section 51(1), read with the Regulator’s template for private bodies, requires seven things:
- Who to ask. The contact details of the Information Officer — who, for a private body, is its head, and who must be registered with the Regulator — and of any deputy.
- The Regulator’s Guide. A description of the Guide the Regulator publishes under section 10 on how to use PAIA and POPIA, and how to obtain it.
- What is available without asking. The categories of records the body makes available automatically — website content, a company profile, a B-BBEE affidavit.
- What other legislation already opens. Records accessible under other Acts: the registers and financial statements the Companies Act makes available, tax records, FICA verification records and the like.
- What the body holds. The subjects on which it keeps records, and the categories of records under each subject — in enough detail to let a requester frame a request.
- How it processes personal information. The purpose of processing; the categories of data subjects and of their information; the recipients to whom it may be supplied; planned transborder flows; and a general description of the security measures in place.
- How to request, what it costs, and what to do if refused. The prescribed form, the request fee, the access fees, the thirty-day decision period, the grounds on which access may be refused, and the remedies — a complaint to the Regulator or an application to court.
Where borrowed manuals fail
The Regulator’s template is a form, not an answer. Filled in from another body’s manual, or from a generic download, it fails in the same predictable ways. It names an Information Officer who has left, or nobody at all — and no one has been registered with the Regulator. It describes records the body does not hold and omits the ones it does. It declares that no personal information leaves the Republic while the organisation runs on cloud email and hosting whose servers are abroad. Its security description was written for a company with an IT department, by a company with an IT department. It carries no date of compilation or revision, so nobody can say whether it was ever reviewed. And it is “on the website” in the sense that a file exists on a server, unreachable by any link a visitor would find.
None of these is a technicality. The manual is a public statement about the organisation, and when a request or a complaint arrives it will be read against the privacy notice, the operator agreements and what actually happens in practice. A manual that contradicts them is not a shield; it is the first exhibit. The POPIA section, in particular, sits alongside the documentation the Act already requires a responsible party to maintain, and it should say the same things.
Writing one that tells the truth
The good news is that an honest manual is a modest piece of work, because it is compiled from records the organisation already keeps. Five moves do it. Decide who the Information Officer is, confirm it in a resolution, and register that person with the Regulator before anything else. Inventory the records by subject — statutory and governance, clients, finance, insurance, marketing, personnel, information governance — and describe what sits under each. Write the personal-information section from the organisation’s actual record of processing: the real purposes, the real recipients, the real systems and where their servers are, the security measures that are genuinely in place. State the forms, fees and time periods exactly as the 2021 Regulations prescribe them, and say plainly that a private body offers no internal appeal. Then publish it where it will be found — a labelled link in the site footer, a copy at the registered office — and diarise the review: at least annually, and whenever the particulars, services or processing change materially, with the dates of compilation and last revision on the face of the document.
This practice compiled and adopted its own manual in August, from its own registers, and published it with a review date a year out. A one-person advisory did it in days. A board can do the same.
The document the law requires you to publish
The section 51 manual is the least glamorous thing an organisation will ever publish. It is also the only document the law requires a private body to publish about itself — and the one a stranger is entitled to test it against. That is what compliance looks like at the level where it actually operates: a dated document, on the website, that tells the truth.
MBM Valkyrie Advisory prepares section 51 manuals, privacy notices and the POPIA documentation behind them — compiled from the organisation’s own records, for companies, boards, statutory bodies and non-profits.
Start a conversationOr see what one looks like: our own PAIA & POPIA Manual, published in terms of section 51.
This piece is general commentary on compliance practice. It is not legal advice on any specific matter, and no professional relationship arises from reading it.
