1. Introduction & purpose of this manual
This manual has been compiled in accordance with the Promotion of Access to Information Act 2 of 2000 ("PAIA") and the Protection of Personal Information Act 4 of 2013 ("POPIA") to:
- assist any person wishing to request access to records held by The Big Data Showroom (Pty) Ltd ("TBDS");
- ensure that data subjects are aware of their rights under POPIA, including the right to access and correct personal information;
- set out how TBDS processes personal information; and
- promote transparency while safeguarding personal information in line with our legal obligations.
Every private body must have this manual, whatever its size. The exemption that previously covered smaller private bodies expired on 31 December 2021.
2. Contact details of the Information Officer
- Information Officer
- Ruan Petrus Greeff
- Position
- Director
- admin@thebigdatashowroom.com
- Telephone
- 021 007 5899
- Physical address
- Available upon request
- Postal address
- Available upon request
The Information Officer is registered with the Information Regulator (South Africa) under registration number 2026-001232, registered 29 January 2026, appointment effective 26 November 2025.
No Deputy Information Officer has been designated.
3. Description of business
TBDS is a data services company. We provide contact tracing, identity verification and compliance screening to vetted South African businesses for purpose-built use cases. Clients submit a reference they are lawfully entitled to use, and we return a specific answer — current contact details, a verification result, or a screening outcome — recorded against the user, the time and the purpose they registered.
Access is not open to the public. Every account is vetted before activation, and contact tracing is further restricted to eligible professions. We do not sell personal information and we do not supply it in bulk.
4. Automatically available records
TBDS does not make any personal information automatically available without a formal request. Publicly accessible information is limited to:
- general information on our website — service descriptions, published rates and contact information;
- our Terms of Use;
- our Privacy & POPIA Notice; and
- this manual.
All other information is securely stored and released only on formal request in terms of PAIA or POPIA.
5. Categories of records held by TBDS
The following categories of record are held and may be subject to a formal access request.
5.1 Client records
- Access applications and supporting documentation, including company registration and professional registration details.
- Vetting records and eligibility decisions, including declined applications.
- The lawful purpose recorded against each account.
- Correspondence with clients.
- Account, seat and credential records.
5.2 Service operation records
- Search logs — the user, the timestamp and the stated purpose for every search.
- Audit records and usage monitoring records.
TBDS does not maintain its own database of contact information. Searches are answered by querying our data sources at the time of the request. We retain the record of the search, not the result.
5.3 Data supply records
- Agreements and licence terms with data suppliers.
- Operator agreements with service providers.
5.4 Financial records
- Invoices, credit purchases and payment records.
- Bank account records relating to transactions with clients or service providers.
- Tax records and returns.
5.5 Operational & administrative records
- Contracts and agreements with service providers and partners.
- Internal policies and procedures, including security policies.
- Company secretarial records — incorporation documents, MOI, registers, resolutions.
5.6 Human resources records
- Employee contracts and personal files.
- Payroll and leave records.
5.7 Information governance records
- This manual and our privacy notice.
- Records of data subject requests and objections.
- Security compromise records.
- Any legitimate interest assessment or impact assessment conducted.
6. Processing of personal information
6.1 Purpose of processing
To provide contact tracing, identity verification and screening results to vetted clients for a recorded lawful purpose; to vet and administer client accounts; to bill for the service; to log and audit use and investigate misuse; and to meet our legal obligations.
6.2 Categories of data subjects and of personal information
| Data subjects | Personal information |
|---|---|
| Search subjects | Names and surnames; identity numbers; contact telephone numbers |
| Client users | Name, position, work contact details, credentials, recorded purpose, search logs |
| Applicants | Company and registration details, professional registration, vetting records |
| Employees | Employment, payroll and personnel information |
| Suppliers and service providers | Business contact details, contract records |
6.3 Recipients
The vetted client who ran the search; our data suppliers, to the extent a search must be passed to them to be answered; operators who host, secure, support or bill for the service; regulators, courts and law enforcement where the law requires; and our professional advisers.
6.4 Cross-border transfers
See section 14.
6.5 Security measures
Our systems run on Google Cloud Platform and Firebase, with personal information encrypted in transit and at rest. We operate two-factor authentication on every account, role-based access control, logging of every search against a user, timestamp and purpose, monitoring and audit of usage, vetting of every account before activation, and written operator agreements with service providers.
7. Grounds for refusal of access
In terms of PAIA, TBDS may refuse access to a record if:
- the record contains personal information of a third party;
- disclosure would reveal trade secrets, confidential commercial information, or financial information of TBDS or a third party;
- disclosure would breach a duty of confidence owed to a third party, including a data supplier;
- disclosure could reasonably be expected to endanger the life or physical safety of an individual;
- the record is subject to legal privilege;
- disclosure would contravene legislation or a court order; or
- the requester has not shown that the record is required for the exercise or protection of a right.
Note on search subjects. A person asking what information TBDS holds about them is exercising a POPIA section 23 right — see section 10 — and that is a different request from asking for a record about someone else. We will not disclose which client ran a search where doing so would endanger a person or prejudice a lawful investigation.
8. Request procedure
To request access to a record:
- Complete the prescribed request form — PAIA Form 02 (Request for Access to Record), available from the Information Regulator's website.
- Submit it to the Information Officer by email or post, with adequate proof of identity.
- State whether the request is made under PAIA (a general record) or under POPIA section 23 (your own personal information).
- If you are acting for someone else, supply proof of your authority.
- Pay the applicable request or access fee — see section 9.
- TBDS will process the request within the prescribed timeframe, usually 30 days.
9. Fees
Fees are determined by the PAIA Fee Regulations:
| Item | Fee |
|---|---|
| Photocopy or printed A4 page | R1.10 |
| Printed copy from an electronic file, per page | R0.75 |
| Copy on compact disc | R70.00 |
| Postage | Actual cost |
| Search and preparation time, per hour or part thereof | R30.00 |
- For non-personal requests under PAIA, a request fee may apply before processing begins.
- For personal information requests under POPIA section 23, no request fee is payable, but an access fee may apply where reproduction or preparation exceeds one hour.
- Where search and preparation costs exceed R100, a deposit of one third of the estimated cost may be required.
10. POPIA section 23 — access to personal information
Under section 23 of POPIA, a data subject may request:
- confirmation, free of charge, of whether TBDS holds personal information about them;
- access to that personal information; and
- a description of the information held, including the identity of all third parties who have, or have had, access to it.
Requests are processed within a reasonable time, in an understandable format, and subject to any applicable access fee. We will verify your identity before releasing anything — that protection exists for you.
11. POPIA section 24 — correction or deletion
A data subject may request TBDS to:
- correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained; or
- destroy or delete a record of personal information that TBDS is no longer authorised to retain.
Use POPIA Form 2, with proof of identity. A data subject may also object to processing on reasonable grounds using POPIA Form 1, where we rely on legitimate interest as our lawful basis. If you object, we must stop processing your information on that basis.
The two Acts have separate forms with clashing numbers. PAIA Form 02 and POPIA Form 2 are different documents. Current versions of both sets are on the Regulator's website.
12. Remedies
If you are dissatisfied with our response, you may lodge a complaint with the Information Regulator:
- Address
- Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg
- Postal
- P.O. Box 31533, Braamfontein, Johannesburg, 2017
- Telephone
- 010 023 5200
- Toll-free
- 0800 017 160
- General
- enquiries@inforegulator.org.za
- POPIA complaints
- POPIAComplaints@inforegulator.org.za
- PAIA complaints
- PAIAComplaints@inforegulator.org.za
- Website
- inforegulator.org.za
A PAIA complaint uses PAIA Form 05 and a POPIA complaint uses POPIA Form 5, generally lodged through the Regulator's eServices Portal. You may also institute proceedings in a court of competent jurisdiction.
13. Availability of this manual
This manual is available:
- on this website, free of charge;
- by requesting a copy from the Information Officer by email;
- for inspection at our head office during business hours; and
- to the Information Regulator on request.
14. Cross-border transfers of personal information
TBDS may transfer or store personal information on secure data servers located in the European Union. Such transfers are conducted in accordance with section 72 of POPIA, on the basis that the recipients are subject to laws providing protection substantially similar to POPIA — namely the General Data Protection Regulation.
Issued by: Ruan Petrus Greeff, Director, Information Officer.
Date: 30 November 2025