Legal

PAIA & POPIA Manual

The Big Data Showroom (Pty) Ltd · 2025/921835/07 Version 1.0 Issued 30 November 2025 Last updated 20 August 2026

1. Introduction & purpose of this manual

This manual has been compiled in accordance with the Promotion of Access to Information Act 2 of 2000 ("PAIA") and the Protection of Personal Information Act 4 of 2013 ("POPIA") to:

  • assist any person wishing to request access to records held by The Big Data Showroom (Pty) Ltd ("TBDS");
  • ensure that data subjects are aware of their rights under POPIA, including the right to access and correct personal information;
  • set out how TBDS processes personal information; and
  • promote transparency while safeguarding personal information in line with our legal obligations.

Every private body must have this manual, whatever its size. The exemption that previously covered smaller private bodies expired on 31 December 2021.

2. Contact details of the Information Officer

Information Officer
Ruan Petrus Greeff
Position
Director
Email
admin@thebigdatashowroom.com
Telephone
021 007 5899
Physical address
Available upon request
Postal address
Available upon request

The Information Officer is registered with the Information Regulator (South Africa) under registration number 2026-001232, registered 29 January 2026, appointment effective 26 November 2025.

No Deputy Information Officer has been designated.

3. Description of business

TBDS is a data services company. We provide contact tracing, identity verification and compliance screening to vetted South African businesses for purpose-built use cases. Clients submit a reference they are lawfully entitled to use, and we return a specific answer — current contact details, a verification result, or a screening outcome — recorded against the user, the time and the purpose they registered.

Access is not open to the public. Every account is vetted before activation, and contact tracing is further restricted to eligible professions. We do not sell personal information and we do not supply it in bulk.

4. Automatically available records

TBDS does not make any personal information automatically available without a formal request. Publicly accessible information is limited to:

All other information is securely stored and released only on formal request in terms of PAIA or POPIA.

5. Categories of records held by TBDS

The following categories of record are held and may be subject to a formal access request.

5.1 Client records

  • Access applications and supporting documentation, including company registration and professional registration details.
  • Vetting records and eligibility decisions, including declined applications.
  • The lawful purpose recorded against each account.
  • Correspondence with clients.
  • Account, seat and credential records.

5.2 Service operation records

  • Search logs — the user, the timestamp and the stated purpose for every search.
  • Audit records and usage monitoring records.

TBDS does not maintain its own database of contact information. Searches are answered by querying our data sources at the time of the request. We retain the record of the search, not the result.

5.3 Data supply records

  • Agreements and licence terms with data suppliers.
  • Operator agreements with service providers.

5.4 Financial records

  • Invoices, credit purchases and payment records.
  • Bank account records relating to transactions with clients or service providers.
  • Tax records and returns.

5.5 Operational & administrative records

  • Contracts and agreements with service providers and partners.
  • Internal policies and procedures, including security policies.
  • Company secretarial records — incorporation documents, MOI, registers, resolutions.

5.6 Human resources records

  • Employee contracts and personal files.
  • Payroll and leave records.

5.7 Information governance records

  • This manual and our privacy notice.
  • Records of data subject requests and objections.
  • Security compromise records.
  • Any legitimate interest assessment or impact assessment conducted.

6. Processing of personal information

6.1 Purpose of processing

To provide contact tracing, identity verification and screening results to vetted clients for a recorded lawful purpose; to vet and administer client accounts; to bill for the service; to log and audit use and investigate misuse; and to meet our legal obligations.

6.2 Categories of data subjects and of personal information

Data subjectsPersonal information
Search subjectsNames and surnames; identity numbers; contact telephone numbers
Client usersName, position, work contact details, credentials, recorded purpose, search logs
ApplicantsCompany and registration details, professional registration, vetting records
EmployeesEmployment, payroll and personnel information
Suppliers and service providersBusiness contact details, contract records

6.3 Recipients

The vetted client who ran the search; our data suppliers, to the extent a search must be passed to them to be answered; operators who host, secure, support or bill for the service; regulators, courts and law enforcement where the law requires; and our professional advisers.

6.4 Cross-border transfers

See section 14.

6.5 Security measures

Our systems run on Google Cloud Platform and Firebase, with personal information encrypted in transit and at rest. We operate two-factor authentication on every account, role-based access control, logging of every search against a user, timestamp and purpose, monitoring and audit of usage, vetting of every account before activation, and written operator agreements with service providers.

7. Grounds for refusal of access

In terms of PAIA, TBDS may refuse access to a record if:

  • the record contains personal information of a third party;
  • disclosure would reveal trade secrets, confidential commercial information, or financial information of TBDS or a third party;
  • disclosure would breach a duty of confidence owed to a third party, including a data supplier;
  • disclosure could reasonably be expected to endanger the life or physical safety of an individual;
  • the record is subject to legal privilege;
  • disclosure would contravene legislation or a court order; or
  • the requester has not shown that the record is required for the exercise or protection of a right.

Note on search subjects. A person asking what information TBDS holds about them is exercising a POPIA section 23 right — see section 10 — and that is a different request from asking for a record about someone else. We will not disclose which client ran a search where doing so would endanger a person or prejudice a lawful investigation.

8. Request procedure

To request access to a record:

  1. Complete the prescribed request form — PAIA Form 02 (Request for Access to Record), available from the Information Regulator's website.
  2. Submit it to the Information Officer by email or post, with adequate proof of identity.
  3. State whether the request is made under PAIA (a general record) or under POPIA section 23 (your own personal information).
  4. If you are acting for someone else, supply proof of your authority.
  5. Pay the applicable request or access fee — see section 9.
  6. TBDS will process the request within the prescribed timeframe, usually 30 days.

9. Fees

Fees are determined by the PAIA Fee Regulations:

ItemFee
Photocopy or printed A4 pageR1.10
Printed copy from an electronic file, per pageR0.75
Copy on compact discR70.00
PostageActual cost
Search and preparation time, per hour or part thereofR30.00
  • For non-personal requests under PAIA, a request fee may apply before processing begins.
  • For personal information requests under POPIA section 23, no request fee is payable, but an access fee may apply where reproduction or preparation exceeds one hour.
  • Where search and preparation costs exceed R100, a deposit of one third of the estimated cost may be required.

10. POPIA section 23 — access to personal information

Under section 23 of POPIA, a data subject may request:

  • confirmation, free of charge, of whether TBDS holds personal information about them;
  • access to that personal information; and
  • a description of the information held, including the identity of all third parties who have, or have had, access to it.

Requests are processed within a reasonable time, in an understandable format, and subject to any applicable access fee. We will verify your identity before releasing anything — that protection exists for you.

11. POPIA section 24 — correction or deletion

A data subject may request TBDS to:

  • correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained; or
  • destroy or delete a record of personal information that TBDS is no longer authorised to retain.

Use POPIA Form 2, with proof of identity. A data subject may also object to processing on reasonable grounds using POPIA Form 1, where we rely on legitimate interest as our lawful basis. If you object, we must stop processing your information on that basis.

The two Acts have separate forms with clashing numbers. PAIA Form 02 and POPIA Form 2 are different documents. Current versions of both sets are on the Regulator's website.

12. Remedies

If you are dissatisfied with our response, you may lodge a complaint with the Information Regulator:

Address
Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
Postal
P.O. Box 31533, Braamfontein, Johannesburg, 2017
Telephone
010 023 5200
Toll-free
0800 017 160
General
enquiries@inforegulator.org.za
POPIA complaints
POPIAComplaints@inforegulator.org.za
PAIA complaints
PAIAComplaints@inforegulator.org.za
Website
inforegulator.org.za

A PAIA complaint uses PAIA Form 05 and a POPIA complaint uses POPIA Form 5, generally lodged through the Regulator's eServices Portal. You may also institute proceedings in a court of competent jurisdiction.

13. Availability of this manual

This manual is available:

  • on this website, free of charge;
  • by requesting a copy from the Information Officer by email;
  • for inspection at our head office during business hours; and
  • to the Information Regulator on request.

14. Cross-border transfers of personal information

TBDS may transfer or store personal information on secure data servers located in the European Union. Such transfers are conducted in accordance with section 72 of POPIA, on the basis that the recipients are subject to laws providing protection substantially similar to POPIA — namely the General Data Protection Regulation.

Issued by: Ruan Petrus Greeff, Director, Information Officer.
Date: 30 November 2025