PAIA coverage that turns every request into a closed file
Every access request tracked from intake to decision with a named owner, a counted deadline, the reasoning recorded and the annual return compiled from live data.
Compliance at a glance
What PAIA requires
Requests caught on day one
A single intake point logs every request, classifies it and starts the deadline clock. Nothing sits unrecognised in a general inbox.
Deadlines counted down, not guessed
Every request carries its remaining days, an owner and an escalation path. Deemed refusal from inaction becomes structurally impossible.
Decisions with reasoning attached
Where access is refused, the ground relied on and the reasoning are recorded with the decision. The file an appeal or complaint would test already exists.
Annual return from live data
The return to the Regulator is compiled from the request register rather than reconstructed from correspondence. Statistics reconcile to the underlying records by construction.
PAIA compliance, covered by default
PAIA requests arrive infrequently and unpredictably, then run on a statutory clock that does not care how busy the organisation is. Dimeri provides a single intake, deadline tracking, decision recording and annual reporting so nothing lapses into a deemed refusal.
PAIA manual management
The PAIA manual held with its version, review date and record categories. Updated as the organisation changes rather than left describing a structure that no longer exists.
Request intake and routing
A single published route for requests, logged automatically and classified as PAIA or POPIA at intake, with the statutory deadline calculated from the date of receipt.
Deadline countdown
Every request carries its statutory deadline with a countdown, owner assignment and escalation that triggers well before the period expires. Deemed refusal is an outcome the organisation never chose.
Decision and reasoning record
Where access is refused, the specific ground relied on and the reasoning are recorded with the decision. If the matter goes to appeal or the Regulator, the basis exists as it stood at the time.
Annual return from live data
The annual return to the Information Regulator compiled from the request register rather than reconstructed from correspondence. Statistics that reconcile to the underlying records by construction.
The obligations Dimeri tracks
PAIA is a small number of obligations with hard dates attached. Dimeri holds the dates, the owners and the reasoning behind each decision.
The PAIA manual
A manual compiled, updated and made available, setting out the body's structure, the records it holds, the request procedure and the information officer's contact details.
- Manual held with its version and review date
- Record categories maintained as the body changes
- Publication and availability evidenced
- Review cycle with a named owner
Information officer and deputies
An information officer with statutory duties under both PAIA and POPIA, supported by deputy information officers where the body needs them.
- Role holders recorded with delegations
- Deputy designations held with their scope
- Registration status tracked
- Handover recorded when a role holder changes
Request intake and acknowledgement
Requests received in the prescribed form, recognised as PAIA requests, logged and acknowledged so the statutory period is being managed from day one.
- Single intake point with automatic logging
- Request classified as public or private body route
- Fees recorded where applicable
- Acknowledgement evidenced with its date
Decision within the statutory period
A decision taken and communicated within the period the Act allows, including where an extension is permitted and the requester is notified of it.
- Deadline calculated and counted down
- Extension recorded with its ground and notification
- Escalation before the deadline rather than after
- Deemed refusal exposure flagged early
Grounds for refusal
Where access is refused, the ground relied on must be identified and adequate reasons given, including mandatory protection of third party information and the public interest override.
- Refusal ground recorded against the specific section
- Third party notification and representations tracked
- Public interest consideration documented
- Internal appeal or complaint status followed
Annual reporting
Annual reporting to the Information Regulator on requests received, granted, refused and the grounds relied on.
- Return compiled from the live request register
- Statistics reconcile to the underlying records
- Submission evidenced with its date
- Trends reviewed for recurring request types
Getting PAIA coverage in place
4 steps from where you are today to a PAIA position your auditor can rely on.
Book a demoThe current PAIA manual is loaded with its review date, and the categories of records it describes are held so they can be maintained as the organisation changes.
How Dimeri covers PAIA
One intake, two statutes
A request that arrives may be a PAIA access request, a POPIA data subject access request, or both. Dimeri classifies it at intake and applies the correct route and deadline rather than leaving that judgement to whoever opened the email.
Decisions with their reasoning attached
Where access is refused, the section relied on and the reasoning are recorded with the decision. If the matter goes to internal appeal or to the Regulator, the basis of the original decision exists as it stood at the time.
The manual kept current
The manual has to reflect the records the body actually holds. Dimeri holds it against a review cycle with an owner, so a restructure does not quietly leave the published manual describing an organisation that no longer exists.
PAIA questions
Does PAIA apply to private companies?
Yes. PAIA applies to public bodies and to private bodies, and a private body includes a juristic person carrying on a trade, business or profession. Private bodies must have a PAIA manual and must deal with requests for records that a requester needs for the exercise or protection of a right. Exemptions from the manual requirement have applied to some categories of private body at various times, so confirm the current position with your legal advisers.
What happens if we do not respond in time?
Failure to decide within the statutory period is treated as a refusal of the request, which the requester can then take further by internal appeal in the case of a public body or by complaint or application. The organisation ends up defending an outcome it never actually decided, which is why deadline tracking matters more than the quality of the eventual answer.
How does PAIA interact with POPIA?
They share the information officer role and a great deal of the underlying record keeping. POPIA also amended parts of PAIA, including in relation to requests for personal information. In Dimeri both sit under the same information officer with a shared intake, and a request is classified to the correct route at the point it arrives.
Can Dimeri hold the actual records requested?
Dimeri holds the request, the decision, the reasoning and the evidence of what was provided. The underlying records stay in the systems where they live. The point is that the process around the request is tracked and defensible, not that the platform becomes a document repository.
Is this a substitute for legal advice?
No. Refusal grounds, exemptions and the public interest override involve legal judgement, and the position for private bodies has changed over time. This page describes how Dimeri structures PAIA obligations for tracking. Your legal advisers should confirm what applies to you.
Ready to Transform Your GRC?
Join governance, risk, and compliance teams using AI to work smarter.