Back to Frameworks

South Africa Promotion of Access to Information Act (PAIA)

South Africa
v2000 (as amended)
4 domains
4 controls

The Promotion of Access to Information Act 2 of 2000 (PAIA) gives effect to the constitutional right of access to information held by the state and private bodies. It establishes voluntary and mandatory grounds for disclosure, sets out procedures for requesting information, and defines exemptions. Administered by the South African Human Rights Commission (SAHRC) and the Information Regulator.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Cooperation

1 controls
Controls in the Cooperation domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-4Information Regulator Cooperation and Appeals

Exemptions

1 controls
Controls in the Exemptions domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-3Exemptions, Grounds for Refusal

Manuals

1 controls
Controls in the Manuals domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-1PAIA Manuals for Public and Private Bodies

Right of Access

1 controls
Controls in the Right of Access domain of South Africa Promotion of Access to Information Act (PAIA)1 controls
CodeTitle
SAPAIA-2Right of Access and Request Processes

Your Compliance Coverage

If you comply with South Africa Promotion of Access to Information Act (PAIA), you already cover:

Maps to 61 other frameworks

4 total controls
ISO/IEC 38500:2024 - Governance of IT
2 source controls mapped|2 target controls covered
50%
ITU-T X.805 - Security Architecture for End-to-End Communications
2 source controls mapped|2 target controls covered
50%
NIST Privacy Framework
2 source controls mapped|4 target controls covered
50%
UK AI Regulation Framework
2 source controls mapped|2 target controls covered
50%
SASB Standards
2 source controls mapped|2 target controls covered
50%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|3 target controls covered
25%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|2 target controls covered
25%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
25%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|2 target controls covered
25%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|2 target controls covered
25%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|3 target controls covered
25%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|1 target controls covered
25%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|1 target controls covered
25%
ISO/IEC 27400:2022
1 source controls mapped|2 target controls covered
25%
25%
GDPR
1 source controls mapped|3 target controls covered
25%
Azure Security Benchmark
1 source controls mapped|1 target controls covered
25%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
25%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
25%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
25%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|3 target controls covered
25%
Australian Privacy Principles (APPs)
1 source controls mapped|3 target controls covered
25%
Bahrain PDPL
1 source controls mapped|3 target controls covered
25%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
1 source controls mapped|1 target controls covered
25%
Barbados Data Protection Act 2019
1 source controls mapped|3 target controls covered
25%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|3 target controls covered
25%
APPI
1 source controls mapped|3 target controls covered
25%
ISO/IEC 23894:2023
1 source controls mapped|1 target controls covered
25%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
25%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
1 source controls mapped|1 target controls covered
25%
25%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|2 target controls covered
25%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|1 target controls covered
25%
South Korea PIPA
1 source controls mapped|1 target controls covered
25%
PDPA Singapore
1 source controls mapped|2 target controls covered
25%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|4 target controls covered
25%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
25%
Texas Data Privacy Act
1 source controls mapped|1 target controls covered
25%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|4 target controls covered
25%
Taiwan PDPA
1 source controls mapped|2 target controls covered
25%
Student Privacy Pledge 2020
1 source controls mapped|1 target controls covered
25%
Qatar DPL
1 source controls mapped|2 target controls covered
25%
POPIA
1 source controls mapped|2 target controls covered
25%
Peru DPL
1 source controls mapped|2 target controls covered
25%
PDPA Thailand
1 source controls mapped|2 target controls covered
25%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|1 target controls covered
25%
NIST Cybersecurity Framework 2.0
1 source controls mapped|3 target controls covered
25%
ISO/IEC 27031:2011
1 source controls mapped|2 target controls covered
25%
ITIL 4
1 source controls mapped|1 target controls covered
25%
FFIEC IT Examination Handbook
1 source controls mapped|3 target controls covered
25%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
25%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|2 target controls covered
25%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|3 target controls covered
25%
APRA CPS 234
1 source controls mapped|3 target controls covered
25%
PSD2 SCA
1 source controls mapped|1 target controls covered
25%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|1 target controls covered
25%
COBIT 2019
1 source controls mapped|1 target controls covered
25%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
25%
ISO/IEC 25012:2008 - Data Quality Model
1 source controls mapped|1 target controls covered
25%
ISO 20000-1
1 source controls mapped|1 target controls covered
25%

Frequently Asked Questions

What is South Africa Promotion of Access to Information Act (PAIA)?

South Africa Promotion of Access to Information Act (PAIA) is a compliance framework from South Africa with 4 domains and 4 controls. The Promotion of Access to Information Act 2 of 2000 (PAIA) gives effect to the constitutional right of access to information held by the state and private bodies. It establishes voluntary and mandatory grounds for disclosure, sets out procedures for requesting information, and defines exemptions. Administered by the South African Human Rights Commission (SAHRC) and the Information Regulator. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does South Africa Promotion of Access to Information Act (PAIA) have?

South Africa Promotion of Access to Information Act (PAIA) has 4 controls organised across 4 domains. The largest domains are Cooperation (1 controls), Exemptions (1 controls), Manuals (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does South Africa Promotion of Access to Information Act (PAIA) map to?

South Africa Promotion of Access to Information Act (PAIA) maps to 61 other compliance frameworks. The top mapping partners are ISO/IEC 38500:2024 - Governance of IT (50% coverage), ITU-T X.805 - Security Architecture for End-to-End Communications (50% coverage), NIST Privacy Framework (50% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with South Africa Promotion of Access to Information Act (PAIA) compliance?

Start your South Africa Promotion of Access to Information Act (PAIA) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about South Africa Promotion of Access to Information Act (PAIA) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 4 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required