Back to Frameworks

South Africa Promotion of Access to Information Act (PAIA)

South Africa
v2000 (as amended)
11 domains
23 controls

The Promotion of Access to Information Act 2 of 2000 (PAIA) gives effect to the constitutional right of access to information held by the state and private bodies. It establishes voluntary and mandatory grounds for disclosure, sets out procedures for requesting information, and defines exemptions. Administered by the South African Human Rights Commission (SAHRC) and the Information Regulator.

Verified

South Africa Promotion of Access to Information Act (PAIA) is a compliance framework from South Africa with 11 domains and 23 controls that map to 71 other frameworks. The largest domains are Request Handling, Fees and Forms (5 controls), Grounds for Refusal and Third Parties (3 controls), Information Officer, Manual and Training (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (11)

Appeals and Personal Information Requests

2 controls
Controls in the Appeals and Personal Information Requests domain of South Africa Promotion of Access to Information Act (PAIA)2 controls
CodeTitle
PAIA-INT-07Internal appeal mechanism
PAIA-PRV-11Personal information requests by data subjects

Cooperation

1 controls
Controls in the Cooperation domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-4Information Regulator Cooperation and Appeals

Exemptions

1 controls
Controls in the Exemptions domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-3Exemptions, Grounds for Refusal

Grounds for Refusal and Third Parties

3 controls
Controls in the Grounds for Refusal and Third Parties domain of South Africa Promotion of Access to Information Act (PAIA)3 controls
CodeTitle
PAIA-3P-06Third party notification and intervention
PAIA-COM-12Mandatory disclosure where public interest overrides exemption
PAIA-GRD-05Mandatory and discretionary grounds for refusal

Information Officer, Manual and Training

3 controls
Controls in the Information Officer, Manual and Training domain of South Africa Promotion of Access to Information Act (PAIA)3 controls
CodeTitle
PAIA-IO-01Designation of Information Officer
PAIA-MAN-02PAIA manual under section 51
PAIA-TRG-09Staff training on PAIA

Manuals

1 controls
Controls in the Manuals domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-1PAIA Manuals for Public and Private Bodies

Objects of the Act and Guides

2 controls
Controls in the Objects of the Act and Guides domain of South Africa Promotion of Access to Information Act (PAIA)2 controls
CodeTitle
PAIA-1.1Objects of Act (Section 9)
PAIA-1.2Guide on How to Use Act (Section 10)

Records Management and Proactive Disclosure

2 controls
Controls in the Records Management and Proactive Disclosure domain of South Africa Promotion of Access to Information Act (PAIA)2 controls
CodeTitle
PAIA-EXT-17Voluntary disclosure and proactive publication
PAIA-REC-10Records management

Reporting and Self Assessment

2 controls
Controls in the Reporting and Self Assessment domain of South Africa Promotion of Access to Information Act (PAIA)2 controls
CodeTitle
PAIA-AUD-16Information Officer audit and self assessment
PAIA-RPT-08Annual report to Information Regulator

Request Handling, Fees and Forms

5 controls
Controls in the Request Handling, Fees and Forms domain of South Africa Promotion of Access to Information Act (PAIA)5 controls
CodeTitle
PAIA-FEE-04Fees for access
PAIA-FRM-13Forms and prescribed format compliance
PAIA-FRV-15Frivolous or vexatious requests
PAIA-REQ-03Request handling procedure
PAIA-SEV-14Severability and partial access

Right of Access

1 controls
Controls in the Right of Access domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-2Right of Access and Request Processes

Your Compliance Coverage

If you comply with South Africa Promotion of Access to Information Act (PAIA), you already cover:

Maps to 71 other frameworks

23 total controls
SASB Standards
3 source controls mapped|3 target controls covered
13%
ISO/IEC 38500:2024 - Governance of IT
2 source controls mapped|2 target controls covered
9%
UK Open Banking Standard
2 source controls mapped|3 target controls covered
9%
ITU-T X.805 - Security Architecture for End-to-End Communications
2 source controls mapped|2 target controls covered
9%
NIST Privacy Framework
2 source controls mapped|4 target controls covered
9%
UK AI Regulation Framework
2 source controls mapped|2 target controls covered
9%
ISO 26000:2010
1 source controls mapped|3 target controls covered
4%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
4%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
4%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
4%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
4%
FedRAMP High
1 source controls mapped|1 target controls covered
4%
UNESCO Recommendation on the Ethics of AI
1 source controls mapped|1 target controls covered
4%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
4%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|2 target controls covered
4%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|2 target controls covered
4%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
4%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|2 target controls covered
4%
South Korea ISMS-P
1 source controls mapped|3 target controls covered
4%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|1 target controls covered
4%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|3 target controls covered
4%
ISO/IEC 27400:2022
1 source controls mapped|2 target controls covered
4%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|6 target controls covered
4%
4%
GDPR
1 source controls mapped|5 target controls covered
4%
Azure Security Benchmark
1 source controls mapped|1 target controls covered
4%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
4%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|3 target controls covered
4%
Australian Privacy Principles (APPs)
1 source controls mapped|3 target controls covered
4%
Bahrain PDPL
1 source controls mapped|3 target controls covered
4%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
1 source controls mapped|1 target controls covered
4%
Barbados Data Protection Act 2019
1 source controls mapped|3 target controls covered
4%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|3 target controls covered
4%
APPI
1 source controls mapped|3 target controls covered
4%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
4%
ISO/IEC 29134:2023
1 source controls mapped|1 target controls covered
4%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
4%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
1 source controls mapped|1 target controls covered
4%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|2 target controls covered
4%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
4%
South Korea PIPA
1 source controls mapped|1 target controls covered
4%
PDPA Singapore
1 source controls mapped|2 target controls covered
4%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|4 target controls covered
4%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
4%
Texas Data Privacy Act
1 source controls mapped|1 target controls covered
4%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|4 target controls covered
4%
Taiwan PDPA
1 source controls mapped|2 target controls covered
4%
Student Privacy Pledge 2020
1 source controls mapped|1 target controls covered
4%
Qatar DPL
1 source controls mapped|2 target controls covered
4%
POPIA
1 source controls mapped|2 target controls covered
4%
Peru DPL
1 source controls mapped|2 target controls covered
4%
PDPA Thailand
1 source controls mapped|2 target controls covered
4%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
4%
NIST Cybersecurity Framework 2.0
1 source controls mapped|3 target controls covered
4%
ISO/IEC 27031:2011
1 source controls mapped|2 target controls covered
4%
ITIL 4
1 source controls mapped|1 target controls covered
4%
FFIEC IT Examination Handbook
1 source controls mapped|3 target controls covered
4%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
4%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
4%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|3 target controls covered
4%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|3 target controls covered
4%
APRA CPS 234
1 source controls mapped|2 target controls covered
4%
PSD2 SCA
1 source controls mapped|1 target controls covered
4%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|1 target controls covered
4%
COBIT 2019
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
4%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
4%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|1 target controls covered
4%
ISO 20000-1
1 source controls mapped|1 target controls covered
4%

What is South Africa Promotion of Access to Information Act (PAIA) and who does it apply to?

South Africa Promotion of Access to Information Act (PAIA) is a compliance framework from South Africa with 11 domains and 23 controls. The Promotion of Access to Information Act 2 of 2000 (PAIA) gives effect to the constitutional right of access to information held by the state and private bodies. It establishes voluntary and mandatory grounds for disclosure, sets out procedures for requesting information, and defines exemptions. Administered by the South African Human Rights Commission (SAHRC) and the Information Regulator. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does South Africa Promotion of Access to Information Act (PAIA) actually require?

South Africa Promotion of Access to Information Act (PAIA) has 23 controls organised across 11 domains. The largest domains are Request Handling, Fees and Forms (5 controls), Grounds for Refusal and Third Parties (3 controls), Information Officer, Manual and Training (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of South Africa Promotion of Access to Information Act (PAIA) do I already cover?

South Africa Promotion of Access to Information Act (PAIA) maps to 71 other compliance frameworks. The top mapping partners are SASB Standards (13% coverage), ISO/IEC 38500:2024 - Governance of IT (9% coverage), UK Open Banking Standard (9% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement South Africa Promotion of Access to Information Act (PAIA)?

Start your South Africa Promotion of Access to Information Act (PAIA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about South Africa Promotion of Access to Information Act (PAIA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 23 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required