Statutory PAIA & POPIA Section 51 Manual
Promoting access to information, personal data protection, and constitutional transparency under South African statutory law.
1. Entity Details & Statutory Framework
This Manual is prepared in accordance with Section 51 of the Promotion of Access to Information Act No. 2 of 2000 (PAIA) and the Protection of Personal Information Act No. 4 of 2013 (POPIA).
- Platform Operator: Braai (Pty) Ltd (Registration in South Africa)
- Statutory Role: Private Body under PAIA · Responsible Party under POPIA
- Designated Information Officer: Office of the Chief Compliance Officer, Braai (Pty) Ltd
- Statutory Contact Email:
[email protected] - Registered Domicile: Cape Town / Johannesburg, Republic of South Africa
2. Guide of the Information Regulator (PAIA Section 51(1)(b)(i))
The South African Information Regulator has compiled an official guide on how to exercise your rights under PAIA. This guide is accessible on the Information Regulator’s portal (https://inforegulator.org.za) or upon written request to our Information Officer.
3. Records Automatically Available Without Formal Request
The following categories of records are publicly accessible via the Braai platform and websites without lodging a formal PAIA request:
- Platform Terms of Service, Privacy Policy, Merchant Agreement, and Guidelines.
- Publicly published merchant catalogs, business profiles, and event listings.
- Open-source documentation and developer API specifications.
4. Records Subject to Formal Request Procedures
Access to non-public corporate records may be requested subject to the statutory provisions of PAIA:
- Operational Records: Technical infrastructure logs and architectural governance files.
- Financial & Statutory Records: Audited financial statements, VAT Act 89/1991 s54(1) agency settlement ledgers, and corporate filings.
- Human Resources: Employment contracts, personnel records, and internal codes of conduct.
5. Processing of Personal Information (POPIA Section 51(1)(c))
- Purpose of Processing: Enabling sovereign cryptographic identity (DIDs), non-custodial community commerce, in-person Point of Sale (POS) checkouts, and on-device minor safety protection.
- Categories of Data Subjects: Community members, registered merchants, verified professionals, and corporate partners.
- Cross-Border Data Flows (POPIA Section 72): Data transmitted to international cloud hosting facilities operates strictly under POPIA Section 72 Standard Contractual Clauses (SCC) guaranteeing recipient adherence to equivalent data privacy principles.
- Information Security Measures: End-to-end cryptographic encryption (W3C DIDs, ISO/IEC 18013-5), local Drift SQLite vaults, PowerSync TLS-encrypted sync streams, and zero-knowledge proof verification.
6. Procedure for Requesting Access to Records (Form 2)
- The requester must complete the prescribed Form 2 (Request for Access to Record of Private Body) available on the Information Regulator website.
- Submit the completed form along with proof of identification to
[email protected]. - Pay the statutory request fee prescribed under the PAIA Regulations (unless exempted).
- The Information Officer will evaluate and respond to the request within 30 calendar days.
Proprietary compliance architecture. Do not reproduce.