PAIA Annual Report 2026 FAQs Businesses Must Answer Before 30 June
There are compliance deadlines you can recover from. This is not one of them.
If your business misses the PAIA Annual Report deadline on 30 June 2026, you cannot simply submit it late – not even the next day. Once the reporting window closes, your business may have to wait until the next year to submit, leaving a visible compliance gap that can affect your reputation, tenders, audits, funding applications, client trust, and overall regulatory standing. The most dangerous part? Many businesses only discover something is missing when they try to submit.
By then, time is running out fast. To help business owners understand exactly what needs to happen before the deadline, we asked Vivian Dube, PAIA Specialist at Company Partners, to explain the most frequently asked questions you should go through before submitting your PAIA Annual Report.
The PAIA Annual Report is a yearly submission to the Information Regulator that records how your business handled requests for access to information during the reporting period.
It shows whether your business received requests for records, how those requests were processed, whether access was granted or refused, and whether your business has the correct access-to-information processes in place. In simple terms, it is not just a formality. It is an annual compliance checkpoint.
PAIA Annual Report Submission
Avoid missing the 30 June deadline and keep your business compliant with the Information Regulator.
Many businesses confuse these three requirements or treat them as separate issues. They are connected.
POPIA deals with how your business protects personal information as stated in the POPI Act and enforced by the Information Regulator.
PAIA deals with how people can request access to information held by your business.
Your PAIA Manual explains what information your business holds, who the Information Officer is, how requests can be made, and what process must be followed.
Your PAIA Annual Report tells the Information Regulator what happened during the reporting period in relation to access-to-information requests.
Think of it like this:
- POPIA protects information.
- PAIA gives access to information.
- Your PAIA Manual explains the process.
- Your PAIA Annual Report proves you are maintaining the process.
The main responsibility usually sits with the Information Officer or Head of the Private Body, depending on the structure of the organisation.
For many companies, this may be the director or person legally responsible for the business. Deputy Information Officers may also be appointed to assist with compliance duties, especially where the business has multiple departments, branches or admin processes.
The Information Officer is not simply a name listed on a form. This person plays a pivotal role in ensuring that the business takes POPIA and PAIA compliance seriously.
The Information Officer is responsible for helping the business manage how personal information is protected, how access-to-information requests are handled, and how compliance is monitored on an ongoing basis.
This includes:
- Encouraging compliance with POPIA’s lawful processing requirements
- Ensuring the business has proper internal policies and procedures
- Handling requests made to the business under POPIA and PAIA
- Working with the Information Regulator during assessments or investigations
- Ensuring that the business develops, updates and makes its PAIA Manual available
- Making sure the business has internal systems to process information requests
- Ensuring that staff understand their responsibilities through awareness and training
- Checking that personal information risks are identified and managed
- Supporting the PAIA Annual Report submission process
In practical terms, the Information Officer must help ensure that the business not only has documents in place but also that the correct processes are actually being followed.
This is why Information Officer registration is such an important part of PAIA Annual Report readiness. If the correct person is not registered, or if the business does not understand who is responsible for what, the Annual Report submission process can become delayed or incomplete.
Yes. Many businesses assume they only need to submit a PAIA Annual Report if someone requested information during the year. That assumption can create unnecessary risk.
Even if your business received no formal access-to-information requests, your report should still reflect the correct reporting position for the period. A zero-request year does not mean zero responsibility. The Annual Report is not only about the number of requests. It is also about showing that your business understands and maintains its reporting obligations.
Before submitting your PAIA Annual Report, your business should check that the following are in order:
- Your Information Officer is registered.
- Your Head of Private Body details are correct.
- Any Deputy Information Officers are registered where applicable.
- Your PAIA Manual is complete and up to date.
- Your PAIA Manual is publicly accessible or available on request.
- Your POPIA compliance documents and processes are aligned.
- Your access-to-information request records are available.
- You know whether any requests were received, granted, refused or partially granted.
- You have access to the correct Information Regulator portal profile.
- Your submission information is accurate before the deadline.
If any of these are missing, your business may not be ready to submit.
Check Your PAIA Compliance
Make sure your Information Officer, PAIA Manual, and reporting requirements are in place.
This is one of the most common problems businesses face. You may have a director, manager, or owner who acts as the responsible person internally, but if the Information Officer registration has not been completed correctly with the Information Regulator, your submission process can be delayed or blocked.
That becomes especially risky close to the 30 June deadline. Your business should not wait until the final days of June to confirm whether the correct person is registered. If there is a mistake, missing detail, or outdated registration, there may not be enough time to fix it before the window closes.
A PAIA Manual is a formal document that explains how your business handles access-to-information requests. It should include details such as:
- Business information
- Information Officer details
- Contact information for PAIA requests
- Categories of records held by the business
- How a person can request access to records
- Applicable forms and processes
- Fees where relevant
- POPIA-related information
- The type of personal information processed
- Who personal information may be shared with
- Security measures and request procedures
Your PAIA Manual should not be a generic template that sits in a forgotten folder. It must reflect how your actual business works. If your business services, structure, contact details, information processes, or data handling practices have changed, your PAIA Manual may need to be updated.
POPIA and PAIA often meet at the same point: information. A customer, employee, supplier, attorney, client, or third party may request access to certain records. Some of those records may contain personal information. Your business must then understand both sides of the responsibility. You may need to provide access under PAIA. You must also protect personal information under POPIA.
This is why the Information Officer role is so crucial. The business must know how to process requests correctly, protect sensitive information, respond within the correct framework, and keep proper records.
The most common mistakes include:
- Thinking POPIA compliance automatically covers PAIA.
- Creating a PAIA Manual once and never updating it.
- Not registering the Information Officer.
- Forgetting to keep a record of information requests.
- Assuming no requests means no report.
- Leaving the Annual Report submission until the last few days.
- Using outdated company or contact details.
- Not knowing who is responsible internally.
- Waiting until a tender, audit, or client request exposes the gap.
The biggest risk is not always the fine or penalty. It is the exposure. Once your business is flagged as non-compliant, it can affect how clients, partners, funders, and regulators view your business.
If you miss the PAIA Annual Report deadline, your business will not be able to submit before next year’s submission period. That means your business will remain non-compliant until the next reporting cycle. This can create several risks, including:
- Being flagged for non-compliance
- Increased scrutiny from the Information Regulator
- Problems during tenders or funding applications
- Reputational damage
- Client trust concerns
- Internal compliance pressure
- Possible regulatory consequences if non-compliance continues
The deadline should therefore be treated as a serious compliance cut-off, not an admin reminder.
Before 30 June, every business must be able to answer these questions confidently:
- Is our Information Officer registered?
- Is our PAIA Manual complete and updated?
- Is our POPIA compliance aligned?
- Did we receive any access-to-information requests?
- Do we have records of how those requests were handled?
- Can we access the Information Regulator portal?
- Do we have the correct submission information ready?
- Have we allowed enough time to fix any issues?
If the answer to any of these questions is “I’m not sure,” your business should act immediately.
Avoid PAIA Compliance Gaps
Protect your business from compliance risks, delays, and unnecessary scrutiny.
PAIA compliance can feel technical, confusing, and time-consuming, especially when the deadline is so close. Company Partners assists businesses with the full compliance process, including:
- Information Officer registration
- PAIA Manual preparation
- PAIA Manual updates
- PAIA Annual Report submission
- POPIA alignment support
- Guidance on required information
- Correct submission through the Information Regulator process
Instead of guessing what needs to be done, Company Partners helps ensure the correct steps are completed before the deadline.
Don’t Let 30 June Expose Your Business
The PAIA Annual Report is more than a yearly submission. It is a reflection of whether your business has taken its access-to-information and personal information responsibilities seriously.
If your Information Officer is not registered, your PAIA Manual is outdated, documents are incomplete, or your Annual Report has not been submitted, your business could be exposed. There is not much time left. Only one week to be precise. You can’t afford to wait any longer.
- Do not wait until your business is flagged.
- Do not wait until a tender asks for compliance proof.
- Do not wait until the portal deadline has passed.
Get your PAIA Annual Report submitted correctly and on time. Contact Company Partners at 0800 007 269 (toll-free) to assist or speak to a consultant today. If you need help before 30 June, the time to act is now!