PAIA Manual
Manual published in terms of section 51 of the Promotion of Access to Information Act, 2000
MANUAL IN TERMS OF SECTION 51 OF THE PROMOTION OF ACCESS TO INFORMATION ACT, 2000
Incorporating the disclosures required by the Protection of Personal Information Act, 2013
| Document | SFT-PAIA-01 PAIA Manual (section 51) incorporating POPIA disclosures |
|---|---|
| Private body | Safety Toolbox (Pty) Ltd, trading as Safety Toolbox |
| Registration number | 2026/639216/07 |
| Information Officer | Deon Venter, Director. Information Regulator registration 2026-064239 |
| Effective date | 20 August 2026 |
| Version | Rev 1, deployed from HRT-PAIA-01 v1.1 generic master (19 August 2026). Reviewed annually and whenever the records or processing change materially. |
1. Why this manual exists
The Promotion of Access to Information Act gives everyone a right of access to records held by private bodies where the record is needed to exercise or protect a right. The Act requires a private body to publish a manual that explains what it does, what records it keeps, and how a person goes about asking for one. This is that manual.
Safety Toolbox (Pty) Ltd, trading as Safety Toolbox ("the Company"), is a private body for the purposes of the Act. Access to its records is governed by the Promotion of Access to Information Act. The way it handles personal information is governed by the Protection of Personal Information Act. The Information Regulator (South Africa) supervises both.
The Company sells and delivers occupational health and safety training online through its website. Most of the personal information it holds belongs to learners and to the employers who buy training for their staff, and the manual should be read with that in mind.
This manual is written for the public. It is not a legal opinion and it does not limit any right a requester has under either Act.
2. Particulars of the Company
| Registered name | Safety Toolbox (Pty) Ltd |
|---|---|
| Registration number | 2026/639216/07 |
| Trading name | Safety Toolbox |
| Head of the private body | Deon Venter, Director (sole director) |
| Information Officer | Deon Venter, Director. Information Regulator registration 2026-064239 |
| Deputy Information Officer | None appointed |
| Physical address | Dainfern Square, 1st Floor, Cnr William Nicol Drive & Broadacres Avenue, Dainfern, Johannesburg, Gauteng, 2191 |
| Postal address | The physical address above. The Company has no separate postal address. |
| Telephone | +27 82 087 6297 |
| Email for requests | training@safetytoolbox.co.za |
| Website | www.safetytoolbox.co.za |
The Information Officer is the person to whom every request under either Act must be addressed. Where a Deputy Information Officer has been designated, a request may also be addressed to that person.
3. The Guide compiled by the Information Regulator
The Information Regulator has compiled a guide, in an easily comprehensible form, on how to use the Promotion of Access to Information Act. Anyone who needs help exercising a right under the Act should start there. The guide is available from the Information Regulator at the contact details set out in this manual under The Information Regulator, and on the Regulator's website at www.inforegulator.org.za.
The Regulator publishes the guide in the official languages it has determined. A copy may be requested from the Regulator at no charge.
4. Records available without a formal request
4.1 Records the Company makes automatically available
A private body may voluntarily publish categories of records that anyone can have without following the formal request procedure. The Company has not published such a notice.
Categories currently available in this way: None. All requests follow the formal procedure in this manual.
4.2 Records available under other legislation
Some of the Company's records are already public because other law makes them public. Information filed with the Companies and Intellectual Property Commission is the common example, and it is obtained from that authority rather than from the Company. Records of this kind do not need a request under the Promotion of Access to Information Act.
5. Categories of records the Company holds
Subject to the grounds on which access may lawfully be refused, the Company holds records in the categories below. The list describes subject matter. It is not a promise that a particular record exists or that access to it will be granted.
| Subject category | Examples of records in that category |
|---|---|
| Company and statutory | Incorporation documents, memorandum of incorporation, share register, filings with the Companies and Intellectual Property Commission, board and shareholder resolutions and minutes |
| Human resources | Employment contracts, personnel files, payroll and remuneration records, time and attendance records, leave records, disciplinary and grievance records, employment equity and skills development records, retirement fund and medical scheme correspondence |
| Financial and tax | Management accounts, annual financial statements, ledgers, invoices and statements, records kept for income tax, value-added tax and employees tax purposes |
| Operational and commercial | Customer and supplier records, contracts and service agreements, quotations and tenders, project and job files, general correspondence |
| Health, safety and compliance | Occupational health and safety records, incident and injury reports, records kept under the Compensation for Occupational Injuries and Diseases Act, certificates, internal policies and procedures |
| Information and data | System and access records, records of processing activities, this manual, privacy notices, consent records and the request register |
| Insurance and risk | Policies, claims and correspondence with insurers and brokers |
| Learners and training | User accounts of learners and site subscribers, course enrolments, lesson and module completion records, assessment attempts and the answers given, marks and pass records, issued certificates and the certificate register, and messages exchanged with learners through the course messaging facility |
| Online store and transactions | Orders, invoices, payment gateway transaction references, refund records and refund notes, product and price records, and the terms on which each sale was concluded |
| Course development | Course specifications and build records, source material and statutory references relied on, assessment question banks and marking keys, diagrams and media, and the version history of each course including corrections issued after publication |
| Sector-specific | Course development records: the source material, statutory references and version history behind each course; assessment question banks and marking keys; and the records of course revisions and corrections |
6. Records kept because other legislation requires it
The Company keeps records in terms of, among others, the legislation listed below.
| Legislation | What is kept under it |
|---|---|
| Companies Act | Statutory and corporate records, registers, resolutions and financial records |
| Labour Relations Act | Employment and industrial relations records, disciplinary and dispute records. The Company had no employees as at the effective date of this manual, so no records exist in this category yet. Records commence on first employment. |
| Basic Conditions of Employment Act | Records of time worked, remuneration paid and leave taken. The Company had no employees as at the effective date of this manual, so no records exist in this category yet. Records commence on first employment. |
| Employment Equity Act | Equity plans, analyses and reports, where the entity is a designated employer. The Company had no employees as at the effective date of this manual, so no records exist in this category yet. Records commence on first employment. |
| Skills Development Act and Skills Development Levies Act | Training records and levy returns. The Company had no employees as at the effective date of this manual, so no records exist in this category yet. Records commence on first employment. |
| Compensation for Occupational Injuries and Diseases Act | Earnings returns, injury reports and claim records. The Company had no employees as at the effective date of this manual, so no records exist in this category yet. Records commence on first employment. |
| Unemployment Insurance Act and Unemployment Insurance Contributions Act | Declarations and contribution records. The Company had no employees as at the effective date of this manual, so no records exist in this category yet. Records commence on first employment. |
| Income Tax Act and Value-Added Tax Act | Tax records, returns and supporting documents |
| Occupational Health and Safety Act | Appointments, risk assessments, inspections and incident records. The Company had no employees as at the effective date of this manual, so no records exist in this category yet. Records commence on first employment. |
| Protection of Personal Information Act | Records of processing, consent records, breach records and this manual |
| Promotion of Access to Information Act | Requests received, decisions taken and the annual report to the Information Regulator |
| Electronic Communications and Transactions Act, and Consumer Protection Act | The information a supplier must publish on a website before a transaction, the terms on which each transaction was concluded, the record of each transaction and of any cancellation or refund |
7. How the Company processes personal information
The Company is the responsible party for the personal information it processes. It applies the eight conditions for lawful processing set out in the Protection of Personal Information Act: accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
7.1 The lawful basis on which the Company processes
Most of the Company's processing is necessary to perform a contract, to comply with a legal obligation, or to pursue a legitimate interest of the Company, the data subject or a third party. Processing of that kind is disclosed to data subjects in a privacy notice. The Company does not ask for blanket consent to processing it must carry out anyway.
Consent is asked for separately, and only where the processing is genuinely optional and the data subject is free to refuse without any adverse consequence. The instruments used for that purpose are described in the Data Protection and Privacy Policy.
7.2 What is processed, and about whom
| Aspect | Detail |
|---|---|
| Purposes | Selling and delivering online health and safety training: taking orders, taking payment, creating accounts and enrolments, recording progress, marking assessments and issuing certificates; answering enquiries and learner questions; keeping the transaction and training records the law requires; running and securing the website; and marketing the Company's own courses to people who have asked for it or who have bought one. Employment administration and payroll are listed because they will apply once the Company has employees; as at the effective date it has none. |
| Data subjects | Learners and site account holders, buyers of courses, employers who buy seats for their staff and the people they nominate, people who send an enquiry through the website, suppliers and service providers, and the Company's director. Employees and job applicants will fall in this list once the Company employs. |
| Categories of personal information | Identity and contact details, identity or passport number, banking details, remuneration and benefit information, qualifications and employment history, next of kin, images captured by closed-circuit television, and and, for learners, the course enrolment, lesson and module progress, assessment attempts, answers and marks, and the certificate issued on completion |
| Special personal information | None is processed as a matter of course. The Company does not collect health information, biometric information or trade union membership from learners, and asks people not to submit sensitive information through the website contact form. |
| Recipients and operators | The website and email hosting provider; the Payfast payment gateway; the transactional email service configured on the site; Google Analytics and Google Search Console; the Company's accountant and, when appointed, its auditors; and the South African Revenue Service |
| Transfers outside South Africa | The hosting, payment, email and analytics providers named above may process or store data outside South Africa in the ordinary operation of their services. Each is bound by contract to protect the information on terms substantially similar to those required by the Protection of Personal Information Act. The website and email hosting provider, 20i Ltd, states that it stores and processes data in datacentres located within the United Kingdom and the European Economic Area, together with other jurisdictions where required to provide the services. Payfast has its headquarters in Cape Town, South Africa, and states that data it collects may be transferred, stored and processed in a country different from the one in which it was collected. Google states that it may process personal data in any country in which it or its sub-processors maintain facilities. |
| Security safeguards | Reasonable technical and organisational measures, including access control to human resources records. See the Data Protection and Privacy Policy and, once issued, the Information Security and Breach-Response Procedure |
| How long records are kept | For the period the law prescribes, and thereafter only for as long as the Company has a lawful purpose. Retention periods are administered under this manual; the Company does not maintain a separate Records Retention Schedule. |
Website visitors, learners and buyers receive fuller detail in the Website Privacy Notice, which is published alongside this manual. The Employee Privacy Notice and the Supplier and Customer Privacy Notice in the same pack are deployed to this entity when it takes on employees and when its supplier base makes them useful; neither has been issued as at the effective date.
8. Making a request for access to a record
8.1 What the requester must do
Complete the prescribed request form for access to a record of a private body, being Form 02 under the Regulations to the Promotion of Access to Information Act. The Information Officer will supply the current form on request, and it is also available on the Information Regulator's website.
Send the completed form to the Information Officer at the postal address, physical address or email address given in Particulars of the Company.
Give enough detail to identify the record and the requester, state the right the requester is seeking to exercise or protect, and explain how the record will help exercise or protect it.
State the form of access required and how the requester wishes to be informed of the decision.
Where the request is made on behalf of someone else, attach proof of the requester's authority to act.
Pay the prescribed request fee, and any access fee, as set out in the Regulations. The Information Officer will confirm what is currently payable before the request is processed. The amounts are not reproduced in this manual because they are amended by regulation from time to time.
8.2 What happens next
The Information Officer decides the request within the period allowed by the Promotion of Access to Information Act, which is thirty days from receipt, and may extend that period where the Act permits. The requester is notified in writing of the decision, of any fee payable, and of the right to take the decision further.
Where the record contains information about a third party, the Information Officer must take the steps the Act requires to inform that third party and to allow them to make representations before a decision is taken.
8.3 Requests the Company receives about a learner
A request for a record about a learner, made by anyone other than that learner, is treated as a request affecting the privacy of a third party and is decided on that footing. Where an employer bought the training and asks whether its own nominated staff member completed the course, that is not a third-party request of that kind, because the employer is a party to the transaction and completion is what it paid for. A learner asking for their own personal information is exercising a data subject right, not making a request for access to a record, and is handled by directing the request to the Information Officer at the contact details given in Particulars of the Company. The same applies to a request about an employee once the Company has employees.
9. When access may be refused
The Promotion of Access to Information Act sets out the grounds on which access must or may be refused. The grounds most often relied on by a company of this kind are:
protection of the privacy of a third party who is a natural person, including an employee;
protection of commercial information of a third party, such as trade secrets, financial or commercial information, and information supplied in confidence;
protection of the Company's own commercial information on the same footing;
protection of information held in confidence, where disclosure would be a breach of a duty of confidence owed to a third party;
protection of the safety of individuals and the security of property;
records that are privileged from production in legal proceedings; and
records that cannot be found or do not exist, where the Information Officer has taken all reasonable steps to find them and confirms this by affidavit or affirmation.
Access may not be refused where the Act requires disclosure in the public interest. Where only part of a record may lawfully be withheld, the Company grants access to the rest.
10. Your rights over your own personal information
A data subject who proves their identity may:
ask whether the Company holds personal information about them, and ask for a description of it;
ask for a copy or a record of that information, against payment of the prescribed fee where one applies;
ask the Company to correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully;
ask the Company to destroy or delete a record of personal information it is no longer authorised to keep;
object, on reasonable grounds, to processing that is based on legitimate interest;
withdraw consent, where the processing was based on consent, without affecting anything lawfully done before the withdrawal;
refuse direct marketing by electronic means, and ask that it stop; and
complain to the Information Regulator, and apply to a competent court for relief.
Requests of this kind go to the Information Officer on the prescribed form. The Company responds within a reasonable time and, where it refuses, gives reasons.
11. If you are not satisfied
Raise the matter with the Information Officer first. Most difficulties are a misunderstanding about what was asked for or which record was meant, and are settled quickly.
If that does not resolve it, a complaint may be lodged with the Information Regulator, which may investigate and, in the case of the Promotion of Access to Information Act, issue an enforcement notice. A requester may also apply to a competent court for appropriate relief.
12. The Information Regulator
| Physical address | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
|---|---|
| Telephone | 010 023 5200 |
| Toll free | 0800 017 160 |
| Website | www.inforegulator.org.za |
| Access to information complaints | PAIAComplaints@inforegulator.org.za |
| Personal information complaints | POPIAComplaints@inforegulator.org.za |
| General enquiries | enquiries@inforegulator.org.za |
Confirm the Regulator's current contact details, prescribed forms and prescribed fees on www.inforegulator.org.za before this manual is issued, and again at each annual review.
13. Where to find this manual
The manual is available:
at the Company's registered address given in Particulars of the Company, by prior arrangement with the Information Officer, for inspection free of charge;
on the Company's website at www.safetytoolbox.co.za;
on request to the Information Officer, by email or in printed form, against payment of the prescribed fee for a copy; and
to the Information Regulator on request.
The Company keeps the manual current and republishes it whenever the particulars in it change.
14. Review and version control
This manual is reviewed at least once a year, and whenever the Company's records, structure, systems or processing change materially.
| Version | Date | Approved by | Change |
|---|---|---|---|
| Rev 0 | 20 August 2026 | Deon Venter, Director | Initial issue |
| Rev 1 | 20 August 2026 | Deon Venter, Director | Reissued on the Safety Toolbox letterhead; carries the HRT-PAIA-01 v1.1 fix dropping the references to a Records Retention Schedule and a Data-Subject and PAIA Request Procedure that were never written. |