PAIA and POPIA Manual
Manual compiled in terms of section 51(1) of the Promotion of Access to Information Act 2 of 2000 (PAIA), which since its substitution by section 110 of the Protection of Personal Information Act 4 of 2013 (POPIA) also carries the POPIA particulars in section 51(1)(c), for:
Veriflow (Pty) Ltd (registration number 2023/584644/07)
| Document | Veriflow PAIA and POPIA Manual (the “manual”) |
|---|---|
| Version | 1.0 |
| Date compiled | 2 October 2026 |
| Date last updated | 5 October 2026 |
| Review cycle | Updated on a regular basis as section 51(2) of PAIA requires, and in any event reviewed annually, together with the annual review of the Information Officer’s particulars. |
| Effective date | 5 October 2026 |
| Approved by | Marcin Jacek Bizior, Director, as head of the private body (clause 2.2). |
| Language | English. |
1. Purpose of this manual, and the capacities in which Veriflow holds records
1.1 PAIA gives effect to the constitutional right of access to information. Section 51(1) of PAIA requires the head of every private body to make available a manual that helps members of the public understand what records the body holds and how to request access to them. The last exemption granted under section 51(4) ran for six months only, from 1 July 2021 to 31 December 2021, and expired. Since 1 January 2022 the duty applies to all private bodies without exemption, irrespective of headcount or turnover, and Veriflow, incorporated in 2023, was never within the exempt window at all. Nothing in this manual claims any exemption.
1.2 The source of the duty. This manual is made under section 51 of PAIA, as substituted by section 110 of POPIA with effect from 30 June 2021, and carries the POPIA particulars required by section 51(1)(c) in the same document.
1.3 Veriflow operates an identity-verification and know-your-customer software platform for South African businesses. Veriflow’s clients, which may include accountable institutions under the Financial Intelligence Centre Act 38 of 2001 (FICA), use the platform, through the web portal at veriflowportal.co.za and through the application programming interface, to run verifications including SA identity verification against Department of Home Affairs data, facial match and liveness verification, contact detail verification, bank account verification, credit score and collection date indicator verifications sourced from a registered credit bureau, CIPC company and director verifications, public-servant employment verification, and AML and PEP screening. This context shapes the records Veriflow holds, described in clauses 6 and 7.
1.4 The capacities in which Veriflow processes
Veriflow’s role is allocated by activity and never globally.
Veriflow acts in two distinct capacities under the Protection of Personal Information Act 4 of 2013. For every verification a client initiates, the client is the responsible party and Veriflow is its operator. For its own defined processing — account administration and client vetting, billing records, platform security and audit logs, its own legal compliance, and the screening database used for AML and PEP screening — Veriflow is the responsible party in its own right.
A third position exists upstream of both, and is dealt with at clause 7.3: a publisher or licensor that supplies screening list data to Veriflow and receives no personal information from Veriflow is a data supplier, and is neither an operator nor a sub-operator of Veriflow.
| Activity | Veriflow’s capacity | Where in this manual |
|---|---|---|
| Verifications a client initiates: the identifiers the client submits, the running of the verification on them, and the result returned to and stored for that client | Operator. The client determines the purpose and the means and is the responsible party for the personal information of the people it verifies. Veriflow processes only with the knowledge or authorisation of the client, as section 20(a) of POPIA requires | Clauses 6.2, 7.1, 7.2, 8.6 |
| The screening database used for AML and PEP screening | Responsible party in its own right. No client asked Veriflow to acquire, refresh, index or keep that data, and a responsible party cannot authorise what it never asked for. Veriflow decides what the database contains, how often it is refreshed and how long entries are kept | Clauses 6.5, 7.1, 7.2, 7.4, 7.6, 8.7, 9 |
| Account administration and client vetting, billing and wallet records, platform security and audit logs, website visitors and prospective clients, employees and suppliers, and Veriflow’s own legal compliance | Responsible party in its own right. Veriflow is accountable alone under section 8 of POPIA | Clauses 6.1, 6.3, 6.4, 7.1, 7.2 |
| Upstream publishers and licensors of screening list data | Veriflow is the recipient; they are data suppliers. They are not operators, sub-operators or recipients of personal information from Veriflow | Clause 7.3 |
1.5 This manual is also the documentation of processing operations
1.5 Section 17 of POPIA requires a responsible party to maintain the documentation of all processing operations under its responsibility as referred to in section 51 of PAIA. This manual serves as that documentation, which is why clauses 6 and 7 list processing operations rather than only describing a request procedure.
1.6 Veriflow is not a credit bureau
1.6 In the statements in clauses 1.6, 1.7 and 7.2.4, “Client” means a business that uses Veriflow’s verification services, “Services” means those services, “Result” means the result of a verification, and “Verification Subject” means the person or entity a verification is about.
Veriflow is not registered as a credit bureau under section 43 of the National Credit Act 34 of 2005 and does not conduct business as one. Veriflow does not receive reports of, investigate, compile, maintain, score or issue consumer credit information as defined in section 70(1) of that Act, and reports no information to any registered credit bureau or to the National Credit Register. Where a Result originates from a registered credit bureau, that bureau is and remains the author and issuer of that information and the party to whom the Client's certification of prescribed purpose is given.
Accordingly, the National Credit Act is not listed in clause 5 as legislation under which Veriflow holds records. No National Credit Act dispute route, disputes department or adverse-listing removal procedure is offered anywhere in this manual; where a person disputes data originating from a registered credit bureau, Veriflow refers that person to the instructing client, as responsible party, and to the dispute process of the bureau concerned. No retention period in this manual relies on the National Credit Act or its regulations.
1.7 No status, and no compliance outcome
Veriflow holds no registration, licence, accreditation, authorisation, certification or approval from any regulator or standards body in respect of the Services, and does not hold itself out as holding any. Nothing in the Services, and no Result, constitutes legal or compliance advice or a determination that the Client has met any obligation under FICA, the NCA, POPIA or any other law.
This manual records what Veriflow holds, in which capacity, and how a request is made and decided.
2. Company details and contact particulars
2.1 The private body
| Item | Detail |
|---|---|
| Legal name and registration number | Veriflow (Pty) Ltd · 2023/584644/07 |
| Trading name | Veriflow |
| Street address | 51 Ingersol Road, Lynnwood Glen, Pretoria, 0081 |
| Postal address | As for the street address |
| Telephone | +27 83 209 0827 |
| Fax number | None |
| support@veriflow.co.za | |
| Website | https://www.veriflow.co.za/ |
| Client portal | https://veriflowportal.co.za |
2.2 Head of the private body: contact particulars
2.2.1 The contact particulars of the head of the private body, as section 51(1)(a)(i) of PAIA requires, are:
| Item required by section 51(1)(a)(i) | Detail |
|---|---|
| Street address of the head of the body | 51 Ingersol Road, Lynnwood Glen, Pretoria, 0081 (the private body’s address, clause 2.1) |
| Postal address of the head of the body | As for the street address above |
| Telephone number | +27 83 209 0827 |
| Fax number | None |
| Electronic mail address (if available) | support@veriflow.co.za marked for the attention of the head of the private body |
2.2.2 Who the head is, and how the office is filled. For a juristic person, section 1(c) of PAIA defines the head as the chief executive officer or equivalent officer, the person acting as such, or a person duly authorised by that officer or acting person. Veriflow’s head of the private body is Marcin Jacek Bizior, Director.
2.3 Information Officer
2.3.1 There is no separate POPIA appointment of an information officer for a private body. Paragraph (b) of the definition in section 1 of POPIA imports the PAIA definition: the information officer of a private body is the head of that body as contemplated in section 1 of PAIA. The two offices are one office, and this manual uses “Information Officer” and “head of the private body” accordingly.
| Item | Detail |
|---|---|
| Information Officer | Marcin Jacek Bizior, Director. As head of the private body under section 1(c) of PAIA, he is the Information Officer under paragraph (b) of the definition in section 1 of POPIA |
| Deputy Information Officer(s) | None designated. Requests are handled by the Information Officer. |
| Email for PAIA requests and POPIA matters | support@veriflow.co.za marked for the Information Officer’s attention. This mailbox is monitored during normal business hours |
| Telephone | +27 83 209 0827 |
| Fax number | None |
| Physical and postal address | 51 Ingersol Road, Lynnwood Glen, Pretoria, 0081 |
2.4 Keeping these particulars current
2.4 Other Veriflow documents reach the Information Officer by role, at the single contact address in clause 2.3. Where the particulars in clause 2.3 change, they change here first and any registration with the Information Regulator is updated to match. They are reviewed at intervals of not more than one year.
3. The section 10 Guide and the Information Regulator
3.1 Section 51(1)(b)(i) of PAIA requires this manual to describe the guide referred to in section 10 of PAIA, if available, and to say how to obtain access to it. The Information Regulator has published such a Guide. It explains, in easy-to-understand language, the objects of PAIA, the particulars of the Regulator and of every public and private body, the manner and form of a request, the assistance available, the remedies in law available in respect of an act or failure to act, and the fees payable. Any person wishing to exercise a right under PAIA should read it.
3.2 The Guide is obtainable from the Information Regulator (South Africa):
| Item | Detail |
|---|---|
| Website | https://inforegulator.org.za |
| eServices portal | https://eservices.inforegulator.org.za |
| Physical address | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
| Telephone | 010 023 5200; toll-free 0800 017 160 |
| General enquiries and complaints | General enquiries: enquiries@inforegulator.org.za · PAIA complaints: PAIAComplaints@inforegulator.org.za · POPIA complaints: POPIAComplaints@inforegulator.org.za |
These particulars were checked against the Information Regulator’s website on 5 October 2026.
3.3 A copy of the Guide, in at least two official languages, is available for public inspection at Veriflow’s head office (clause 2.1) during normal business hours, free of charge, as regulation 3 of the PAIA Regulations requires. Anyone may ask the Information Officer (clause 2.3) for a copy on Form 1 (Request for a copy of the Guide), and no fee is charged. The Guide may also be inspected at the offices of the Information Regulator or downloaded from its website.
3.4 Veriflow does not charge for, and does not gate, access to the Guide. A requester who cannot obtain it may ask the Information Officer (clause 2.3) for assistance in obtaining it.
4. Records available without a PAIA request
4.1 The section 52(2) notice. Section 51(1)(b)(ii) of PAIA refers to “the latest notice in terms of section 52 (2), if any”. Section 52(2) was deleted by section 110 of POPIA with effect from 30 June 2021, so no such notice exists, and Veriflow has published none.
4.2 Information published without a request. The following are available without a PAIA request. Listing them here does not make any other record available without a request.
| Category of record | Available on the website | Available on request, free of charge |
|---|---|---|
| Marketing and product information about the Veriflow platform and its verifications | Yes: https://www.veriflow.co.za | Yes |
| This manual | Yes | Yes, and no charge is made for a copy supplied electronically |
| The Veriflow Privacy Notice, and the other published legal and policy pages of the website | Yes | Yes |
4.3 Nothing in this clause limits a person’s right to request any other record under clause 8, and nothing in it is an undertaking that a request for any other record will be granted.
5. Records available in terms of other legislation
5.1 Section 51(1)(b)(iii) of PAIA requires a description of the records of the body which are available in accordance with any other legislation. Where a record is requested under other legislation, that legislation and not PAIA governs the request. The most common examples are a data subject’s request for access to their own personal information under section 23 of POPIA, and a shareholder’s or other person’s rights of access to company records under the Companies Act 71 of 2008. The table below lists the main legislation concerned and is not exhaustive.
| Legislation | Records held, and the access route it creates |
|---|---|
| Protection of Personal Information Act 4 of 2013 | Records containing personal information across every category in clause 6. Access by the data subject under section 23; correction or deletion under section 24; objection under section 11(3). See clause 7.6 |
| Promotion of Access to Information Act 2 of 2000 | All records of the body. Access under section 50 by a requester who shows the record is required for the exercise or protection of a right. See clause 8 |
| Electronic Communications and Transactions Act 25 of 2002 | Website and electronic-transaction records, supplier information required to be disclosed on an offering website, and data messages |
| Financial Intelligence Centre Act 38 of 2001 | Verification records generated on client instruction, which support clients’ own customer due-diligence and record-keeping duties. Those verification records are records of the client’s process, held by Veriflow as operator. See clauses 6.2 and 8.6 |
| Companies Act 71 of 2008 | Incorporation documents, registers, minutes and resolutions, share records, annual financial statements and accounting records. Access by the persons and on the terms the Companies Act provides |
| Income Tax Act 58 of 1962, Tax Administration Act 28 of 2011 and, to the extent it applies to Veriflow, the Value-Added Tax Act 89 of 1991 | Accounting, payroll and tax records. Retention and inspection are governed by those Acts, which include an open-ended retention obligation where a dispute or audit is pending |
| Basic Conditions of Employment Act 75 of 1997 and Labour Relations Act 66 of 1995 | Employment, payroll, leave and disciplinary records |
5.2 What is deliberately not in this table. The National Credit Act 34 of 2005 is not listed. Veriflow does not hold records under that Act, does not compile or issue consumer credit information as defined in section 70(1) of it, and offers no dispute route under it. See clause 1.6. A person who disputes information that originated from a registered credit bureau is directed to that bureau and to the client that instructed the verification.
6. Subjects and categories of records held by Veriflow
Section 51(1)(b)(iv) of PAIA requires sufficient detail to facilitate a request, a description of the subjects on which the body holds records, and the categories of records held on each subject. Veriflow holds records on the five subjects below. Listing a category here does not mean a request for it will be granted: every request is assessed under PAIA, including the grounds for refusal in clause 9. The capacity in which Veriflow holds each subject is stated, because that capacity determines who may deal with a request about it (clauses 8.6 and 8.7).
6.1 Client (business customer) records: held as responsible party
| Category | Examples | Principal legislation |
|---|---|---|
| Account and onboarding records | Registration details, client-vetting and onboarding documentation submitted by clients, approval records | POPIA; ECTA |
| Contracts and commercial records | Client agreements, operator agreements, schedules of services, pricing arrangements | POPIA; the law of contract |
| Billing and wallet records | Prepaid wallet transactions, invoices, statements, payment records | Tax legislation; Companies Act; POPIA |
| User administration records | Authorised portal users, roles and permissions, departmental configuration | POPIA |
| Support and correspondence | Support tickets, emails, enquiry records | POPIA |
| Platform security and audit records | Authentication and access logs, security event records, audit trails of administrative action | POPIA sections 19 and 22 |
6.2 Verification records: held as operator, on client instruction
This category covers only records generated by a verification a client asked Veriflow to run: the identifiers the client submitted, the enquiry, and the result returned to and stored for that client. The client determines the purpose and the means and is the responsible party. This category does not include the screening database, which no client instructed Veriflow to acquire or maintain and which Veriflow holds as responsible party in its own right; that is a separate subject at clause 6.5.
| Category | Examples | Principal legislation |
|---|---|---|
| Identity verification records | SA identity verification requests and results verified against Department of Home Affairs data; contact detail verification records | POPIA, including the section 18(1)(a) source-disclosure duty; FICA (clients’ due-diligence and record-keeping duties) |
| Biometric records | Facial images, liveness artefacts, facial match results and liveness results | POPIA sections 26 and 27 (special personal information); see clause 7.2.4 |
| Financial verification records | Bank account verification results; and a credit score and a collection date indicator generated and supplied by a registered credit bureau, which Veriflow relays and neither computes nor derives | POPIA. The National Credit Act is not cited as Veriflow’s own authority for these records. See clause 1.6 |
| Screening records returned to a client | The screening match, or the absence of a match, returned to the instructing client for the person that client asked Veriflow to screen. The reference data these results are matched against is not in this category. See clause 6.5 | POPIA; FICA (clients’ own screening duties) |
| Company verification records | CIPC company verification results and director search results | POPIA, which protects identifiable juristic persons as well as natural persons |
| Employment verification records | Public-servant employment verification results | POPIA |
| Technical records | Application programming interface logs, audit trails of verification requests, and result documents generated for the client | POPIA |
Retention of verification records
Verification records are stored for the instructing client for the period the client configures (clause 7.1(a)). Questions may be sent to the Information Officer (clause 2.3).
Retention of the screening database is dealt with at clause 6.5.6.
6.3 Marketing and website records: held as responsible party
| Category | Examples | Principal legislation |
|---|---|---|
| Website enquiries | Enquiry form submissions (name, work email address, company, optional phone number, topic and message) | POPIA; ECTA |
| Direct-marketing records | Where obtained or maintained: consents to direct marketing on the prescribed form under the POPIA Regulations, and records of persons who have refused or withdrawn consent | POPIA section 69 |
6.4 Human resources, company and financial records: held as responsible party
| Category | Examples | Principal legislation |
|---|---|---|
| Company statutory records | Incorporation documents, registers, resolutions, minutes, share records | Companies Act 71 of 2008 |
| Financial and tax records | Annual financial statements, accounting records, tax returns | Companies Act; tax legislation |
| Employment records | Employee and applicant records, contracts, payroll, leave, disciplinary and performance records | BCEA; LRA; tax legislation; POPIA |
| Supplier records | Supplier and service-provider contracts and payment records | The law of contract; POPIA |
6.5 The screening database: held by Veriflow as responsible party in its own right
6.5.1 What it is. For AML and PEP screening, Veriflow obtains copies of published watchlist data, holds its own copies, refreshes them from the publishing or supplying source on a periodic cycle, and performs the name match against those copies. A screening result therefore reflects the state of the copy Veriflow holds as at its last successful refresh, and not the state of the publishing source at the moment of the verification. The other verifications are unaffected; they remain enquiries to third-party data sources.
6.5.2 Why it is a separate subject. This database is recorded as its own subject, and deliberately not under clause 6.2, because Veriflow holds it as responsible party and not as operator. No client asked Veriflow to acquire or maintain it, and a responsible party cannot authorise what it never asked for. It contains personal information about people who are not Veriflow’s clients, are not its clients’ customers, have no relationship with Veriflow of any kind, and are for the most part not in the Republic. POPIA attaches to that processing without any nationality or residence qualifier, because it is carried out by a company domiciled in the Republic. It is not held on behalf of any client.
6.5.3 Scope. The screening database described in this clause consists of sanctions and money-laundering watchlist data.
| Category | Examples | Principal legislation |
|---|---|---|
| Sanctions and targeted financial sanctions listings | Copies of published consolidated designation lists and the identifying particulars they contain: names, aliases and transliterations, dates and places of birth, nationalities, identifiers and document numbers, office held, entity affiliations, and listing and delisting dates | POPIA, including sections 8, 11, 13, 14, 16, 18 read with 18(4), 19 and 23 to 24; FICA (clients’ targeted financial sanctions scrutiny and freezing duties) |
| Money-laundering watchlist listings | Copies of published money-laundering watchlist entries and the identifying particulars they contain | POPIA, as above. Whether any part of this content is information concerning criminal behaviour under section 26(b), and therefore special personal information, is not asserted either way here. See clause 7.2 |
| Ingest, refresh and version records | Refresh and ingest logs, and list-version and “as at” records | POPIA sections 16 and 19 |
6.5.4 Population held. The number of listed persons held is not stated in this manual.
6.5.5 Provenance. The datasets are obtained from their publishing or supplying sources (clause 6.5.1). Where a publisher or licensor receives no personal information from Veriflow, it is a data supplier and not a recipient (clause 7.3.2).
6.5.6 Retention. Questions about how long entries in the screening database are kept may be sent to the Information Officer (clause 2.3).
7. Processing of personal information (POPIA particulars)
7.0.1 This clause contains the five particulars required by section 51(1)(c) of PAIA as substituted by section 110 of POPIA: the purpose of the processing (paragraph (i)); a description of the categories of data subjects and of the information relating to them (paragraph (ii)); the recipients or categories of recipients to whom the personal information may be supplied (paragraph (iii)); planned transborder flows of personal information (paragraph (iv)); and a general description allowing a preliminary assessment of the suitability of the information security measures (paragraph (v)).
7.1 Purposes of processing (section 51(1)(c)(i))
(a) Processing Veriflow performs as operator, where the purpose is the client’s
For these purposes the client is the responsible party. The client determines why a person is verified, decides what to do with the result, and holds the lawful ground under section 11 of POPIA and, where special personal information is involved, the authorisation under section 27. Veriflow processes only with the knowledge or authorisation of the client.
- performing identity, biometric, financial, screening, company and employment verifications on the instruction of a client, which the client requires for its own regulatory duties, notably customer due diligence under FICA, and for its own risk-management purposes;
- returning the result of that verification to the instructing client, and storing it for that client for the period the client configures;
- maintaining the request and audit records of those verifications, so that the client can evidence its own process.
Veriflow does not use client data, or the personal information of any person verified, to build, enrich, train or improve any Veriflow product, model, dataset or screening database, and takes no licence to do so.
(b) Processing Veriflow performs as responsible party, where the purpose is its own
- onboarding, vetting and administering client accounts, including review of client onboarding documentation, user management, wallet management and billing;
- operating, securing and supporting the platform, the portal and the application programming interface, including authentication, logging, monitoring and audit;
- responding to enquiries and providing support;
- direct marketing, only as section 69 of POPIA permits;
- administering employment, supplier and corporate relationships, and keeping the company, accounting and tax records the law requires;
- holding, refreshing, indexing and matching against the screening database described in clause 6.5, for use in AML and PEP screening. Veriflow determines this purpose itself; it is not a purpose determined by any client;
- establishing, exercising or defending legal rights, and complying with Veriflow’s own legal obligations.
7.2 Categories of data subjects and of personal information (section 51(1)(c)(ii))
| Data subjects | Categories of personal information | Veriflow’s capacity |
|---|---|---|
| Persons verified through the platform: natural persons, and identifiable juristic persons, which POPIA also protects | Identity numbers and identity data verified against Department of Home Affairs records; names and contact details; addresses; facial images, liveness artefacts, facial match results and liveness results (special personal information); bank account details; a credit score and a collection date indicator supplied by a registered credit bureau; screening matches; company and directorship information; government employment information | Operator. The instructing client is the responsible party |
| Persons appearing in the screening database (clause 6.5): listed and designated persons. These persons have no relationship with Veriflow, are not its clients and are not its clients’ customers, and are for the most part not in the Republic | Names, aliases and transliterations; dates and places of birth; nationalities; addresses; identifiers and document numbers where a source records them; office held and entity affiliations; the listing or designation itself; listing, delisting and version dates | Responsible party in its own right. There is no client to whom a request about this information can be referred. See clauses 8.7 and 9.4 |
| Clients and their authorised users | Business and contact details, onboarding documentation, login credentials, roles and permissions, usage and billing records | Responsible party |
| Website visitors and prospective clients | Names, contact details, company and enquiry content | Responsible party |
| Employees and job applicants | Recruitment, employment, payroll, leave, disciplinary and performance information | Responsible party |
| Suppliers, service providers and sub-operators | Business and contact details, contract and payment records | Responsible party |
7.2.1 Information not collected from the data subject. Much of the information about a person verified is not collected from that person directly. It is drawn from the sources queried in the course of the verification, or supplied by the client. The categories of source are listed in clause 7.3.1. The client that instructed the verification, as responsible party, gives the person verified the notice section 18 of POPIA requires.
7.2.2 The source of a screening result has two layers. The immediate source of a screening result is the screening database Veriflow itself holds (clause 6.5). That database in turn consists of copies of the published watchlist data described in clause 6.5. Where an upstream publisher or licensor receives no personal information from Veriflow, it is a data supplier and not a recipient (clause 7.3.2).
7.2.3 Persons in the screening database are not collected from directly. Questions may be sent to the Information Officer (clause 2.3).
7.2.4 Special personal information. Facial match and liveness verification process biometric information, which is special personal information under section 26 of POPIA and may not be processed unless an authorisation under section 27 applies. Veriflow processes that information as the Client's operator; the Client is responsible for identifying and holding the section 27 ground for each Verification Subject and must be able to produce the record of it. Consent, where relied on, must be voluntary, specific and informed and must be obtained separately and unbundled from any other terms and conditions provided to the data subject. Selfies and photographs captured for a verification are kept for the retention period the client sets on the flow, then deleted automatically.
7.3 Recipients or categories of recipients (section 51(1)(c)(iii))
7.3.1 Personal information may be made available to:
- the client that instructed the verification, which is the responsible party for its own customers’ information;
- the data sources queried in the course of a verification, to the extent needed to run it: official registers, registered credit bureaux, the Companies and Intellectual Property Commission, banks and other established data providers;
- sub-operators that process personal information on Veriflow’s behalf in performing the services (hosting, monitoring, support, storage, security tooling and communications providers), which section 21(1) of POPIA requires to be bound by a written contract imposing the security measures required by section 19;
- regulators, law-enforcement bodies and courts, where disclosure is required by law;
- professional advisers under obligations of confidence.
7.3.2 The publishers and licensors of screening list data are not recipients.
A publisher or licensor that supplies screening list data to Veriflow, and receives no personal information from Veriflow, is a data supplier. It is disclosed as a source of information under section 18(1)(a) of POPIA. It is not an operator, a sub-operator or a recipient of personal information from Veriflow, and Veriflow does not list it as one.
7.4 Planned transborder flows of personal information (section 51(1)(c)(iv))
7.4.1 The statutory word is “planned”. This item therefore covers flows that are contemplated as well as flows that occur.
7.4.2 Screening. For AML and PEP screening, Veriflow matches against copies of published watchlist data that it holds (clause 6.5). Any transfer outside the Republic in connection with screening is dealt with under clause 7.4.4.
7.4.3 Website and mail. This website, and the mail service that receives enquiries sent through it, are hosted in South Africa.
7.4.4 Other flows. Personal information may be transferred outside the Republic where a service provider used for hosting, backup, support, screening data or another component of the services operates outside it. Any such transfer is made only as section 72 of POPIA permits.
7.5 General description of information security measures (section 51(1)(c)(v))
7.5.1 Section 19 of POPIA requires appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and unlawful access to or processing of it. The following is the general description section 51(1)(c)(v) of PAIA requires. Detailed security configurations are not published.
- access control on a need-to-know basis, including role-based and departmental permission restrictions on the platform;
- encryption of information in transit;
- logging and monitoring;
- formal change control; and
- periodic review of these measures against identified risks.
7.6 Data-subject rights, and how they interact with this manual
7.6.1 Subject to POPIA, a data subject may request access to their personal information under section 23; request correction or deletion under section 24; object to processing under section 11(3), including objecting to direct marketing at any time; withdraw consent where the processing is based on consent; and complain to the Information Regulator, whose particulars are in clause 3.2. This manual deals with the request route and the fees; the Information Officer (clause 2.3) will help with any other question about exercising these rights. The prescribed forms are listed in Annexure A.
7.6.2 Where Veriflow processes as operator, the responsible party is the client that instructed the verification. A request under POPIA directed to Veriflow will be referred to that client, and Veriflow will assist the client to respond. This is not true of a request under PAIA, which is dealt with at clause 8.6 and which Veriflow must decide itself.
7.6.3 Where the request comes from a person appearing in the screening database, there is no instructing client to refer it to, and Veriflow deals with the request itself. Veriflow cannot change a listing at its source; it deals with a request under section 24 of POPIA as that section provides, and directs the requester to the publishing body.
8. How to request access to a record
8.1 Who may request. Any person may request access to a record of Veriflow. Because Veriflow is a private body, section 50(1) of PAIA applies: a requester must be given access to a record if the record is required for the exercise or protection of any rights, the procedural requirements of PAIA have been complied with, and no ground of refusal applies. A request that does not identify the right, or does not explain how the record would exercise or protect it, may be refused on that ground. Section 50(3) makes it explicit that a request under section 50(1) includes a request for a record containing personal information about the requester, or about the person on whose behalf the request is made.
8.2 Your own personal information. Veriflow will confirm, free of charge, whether it holds personal information about you (section 23(1)(a) of POPIA). To ask for the record itself, use Form 2 (clause 8.3), as section 25 of POPIA requires, with adequate proof of identity; the fees in Annexure A may apply, and Veriflow will give you a written estimate before any fee is charged. A request for correction or deletion under section 24 of POPIA (POPIA Form 2) and an objection under section 11(3) (POPIA Form 1) are free of charge.
8.3 How to make a request. Complete the prescribed request form, Form 2 (Request for Access to Record), and send it to the Information Officer at the contact details in clause 2.3. The prescribed forms are made under the Regulations Relating to the Promotion of Access to Information, 2021 (GN R.757 in GG 45057 of 27 August 2021), are set out in Annexure A to those Regulations, and are available from the Information Regulator at https://inforegulator.org.za and from Veriflow on request, free of charge. Use the current prescribed form listed in Annexure A. The request must:
- identify the record or records requested in enough detail for Veriflow to find them;
- state which right the record is required to exercise or protect, and explain how the record would do so;
- specify the form of access preferred: inspection, a paper copy, or an electronic copy;
- give a postal address or fax number in the Republic (an email address and telephone number may also be given);
- attach proof of the requester’s identity;
- if the request is made on behalf of another person, include proof of the authority to do so;
- state whether the requester wishes to be informed of the decision in any manner other than in writing, and if so how.
8.4 Fees. A request fee is payable before a request is processed, and access, reproduction, search and preparation fees, and in some cases a deposit, may be payable before access is given, all as prescribed by the Regulations and set out in Annexure A. Veriflow charges no fee for a copy of this manual supplied electronically (clause 11.1), and charges nothing for the section 10 Guide.
8.5 Timing, and what Veriflow undertakes. Veriflow must decide a compliant request within 30 days of receiving it, as section 56 of PAIA requires. Section 57 of PAIA allows that period to be extended once, by no more than 30 further days, only on the grounds that section sets out (for example, a request for a large number of records); where Veriflow extends it, Veriflow will tell the requester within the original 30 days, giving the period of the extension and the reasons for it. If no decision is given within this period, the request is regarded as refused (section 58 of PAIA), and the requester may complain under clause 10. Where a record may contain a third party’s personal, commercial, confidential or research information, Veriflow must take reasonable steps to tell that third party within 21 days; the third party has 21 days to respond, and Veriflow then decides within 30 days after every third party was informed (sections 71 to 73 of PAIA). In addition, Veriflow undertakes that:
- receipt of a request will be acknowledged in writing as soon as reasonably possible;
- the decision, and the fees payable, will be communicated on the prescribed outcome form, Form 3;
- any refusal will give adequate reasons, including the provisions of PAIA relied on, and state the remedies available under clause 10, as section 56(3) of PAIA requires;
- where only part of a record may be withheld, Veriflow will grant access to the remainder rather than refusing the request as a whole (clause 9.3);
- where a request is refused because the record does not exist or cannot be found, Veriflow will say so in an affidavit or affirmation describing the steps taken to find it.
8.6 Verification records Veriflow holds as operator. Where the record requested is a verification record generated by a verification a client instructed, the client is the responsible party for that information. A request for such a record may be made to Veriflow, which holds it, and Veriflow decides the request within the periods in clause 8.5. Where section 71 of PAIA applies, Veriflow will notify the client concerned, for example where the record contains that client’s commercial information or a third party’s personal information. The requirements of section 50(1) and the grounds of refusal in clause 9 apply, including the mandatory ground protecting the personal information of anyone other than the requester.
8.7 Records in the screening database. Veriflow holds the screening database as responsible party, so a request about an entry in it cannot be referred to any client and must be dealt with by Veriflow itself. Veriflow will answer a request for confirmation of whether it holds information about the requester, and for a description of that information, directly.
8.8 Assistance. A requester who cannot read or write, or who has a disability, or who is otherwise unable to complete the prescribed form, may make the request orally to the Information Officer, who will reduce it to writing on the prescribed form (Form 2), provide a copy to the requester, and deal with it as if it had been made in writing.
9. Grounds on which access may be refused
9.1 Chapter 4 of Part 3 of PAIA sets out the grounds on which the head of a private body must or may refuse access to a record. Two of them are most often relevant to Veriflow’s records, and are stated below with their section numbers.
| Ground | Character | How it applies to Veriflow |
|---|---|---|
| Section 63(1): disclosure would involve the unreasonable disclosure of personal information about a third party, including a deceased individual | Mandatory. The head of a private body must refuse | This is the ground most often engaged, because most Veriflow records contain other people’s personal information: identity numbers, biometric information, financial information and screening matches. The refusal is compulsory. It does not assist against a data subject’s request for their own record, because that information is not a third party’s. |
| Section 68(1): the record contains trade secrets of the private body, or financial, commercial, scientific or technical information of the body whose disclosure would be likely to cause harm to its commercial or financial interests | Discretionary. The head of a private body may refuse | Discretionary, so each case is decided on its own facts. |
9.2 The remaining grounds in Chapter 4 of Part 3 are, in substance: commercial information of a third party, including information supplied in confidence (section 64(1), mandatory); a breach of a duty of confidence owed to a third party under an agreement (section 65, mandatory); danger to the life or physical safety of an individual (section 66(a), mandatory), or prejudice to the security of property or of a system (section 66(b), discretionary); a record privileged from production in legal proceedings unless the privilege has been waived (section 67, mandatory); and research information of a third party (section 69(1), mandatory) or of the body itself (section 69(2), discretionary). Section 70 adds a mandatory public-interest override, which requires disclosure despite any of the grounds in Chapter 4, including the two above, where the record would reveal evidence of a substantial contravention of, or failure to comply with, the law, or of an imminent and serious public-safety or environmental risk, and the public interest in disclosure clearly outweighs the harm contemplated by the ground.
9.3 Severance. Where a record contains information that may or must be refused together with information that may not, section 59 of PAIA requires every part that can reasonably be severed to be disclosed, and Veriflow will disclose the remainder of the record with the protected part severed, rather than refusing the request in full. In practice this means most records containing personal information about persons other than the requester will be provided in redacted form.
9.4 The screening database. A request from a person appearing in the screening database is decided on its own facts under the grounds in this clause, including sections 63(1), 64 and 65 of PAIA.
10. Remedies if a request is refused
10.1 PAIA does not provide an internal appeal against a decision of a private body. The decision of the head of the private body is the body’s final decision.
10.2 Within 180 days of the decision, a requester may lodge a complaint with the Information Regulator on Form 5 (section 77A of PAIA). A complaint may be made about a refusal, including a refusal regarded as made under section 58, and about a decision on fees or a deposit (section 54), an extension (section 57(1)) or the form of access (section 60). A third party may complain, within 180 days, about a decision on a request that concerns it.
10.3 Under section 78 of PAIA, an application to court may be made only after the Information Regulator’s complaint procedure has been exhausted, and within the period that section allows. Veriflow has no internal appeal, so nothing has to be exhausted with Veriflow itself, and Veriflow will not treat the making of a complaint as a breach of any agreement. The Information Regulator’s particulars appear in clause 3.2.
11. Availability and updating of this manual
11.1 The four channels. Section 51(3) of PAIA requires the manual to be made available through four channels. Veriflow’s position on each is stated below.
| Channel required by section 51(3) | Veriflow’s position |
|---|---|
| (a) on the website of the private body | Veriflow has a website, so this channel is mandatory. This manual is published at https://www.veriflow.co.za/legal/paia-manual.html. |
| (b) at the principal place of business, for public inspection during normal business hours | A copy is held for inspection at 51 Ingersol Road, Lynnwood Glen, Pretoria, 0081, during normal business hours. |
| (c) to any person upon request and upon payment of a reasonable amount | The statutory words are “a reasonable amount”, not a prescribed fee. Veriflow charges nothing for an electronic copy of this manual, and nothing for the copy on the website. Where a paper copy is requested, no more than the reasonable cost of reproduction is charged. |
| (d) to the Information Regulator upon request | Provided on request, without a PAIA request and without notice. Veriflow keeps a current copy ready to be produced. |
11.2 Updating. Section 51(2) of PAIA requires the head of a private body to update the manual on a regular basis. Veriflow updates this manual whenever the records held, the processing purposes, the categories of data subjects, the recipients, the transborder position, the security description or the contact particulars change materially, and in any event reviews it annually. The Information Officer’s particulars in clause 2.3 are reviewed at intervals of not more than one year and any registration with the Information Regulator is updated to match (clause 2.4). The date of each update is recorded in the version block at the head of this manual.
11.3 Language. This manual is published in English.
Annexure A: Prescribed forms and fees
A.1 The forms and fees below are prescribed by the Regulations Relating to the Promotion of Access to Information, 2021, GN R.757 in GG 45057 of 27 August 2021. That instrument contains 18 regulations, Annexure A (the forms) and Annexure B (the fees). It prescribes no additional content for a private body’s manual and contains no regulation dealing with section 51.
A.2 Use the current prescribed forms listed below.
A.3 The form numbers and amounts below were checked against the Regulations and the Information Regulator’s website on 5 October 2026.
| Item | Prescribed reference | Where to get it |
|---|---|---|
| A copy of the section 10 Guide | Form 1: Request for a copy of the Guide (regulation 3) | From the Information Officer (clause 2.3), free of charge |
| Request for access to a record of a private body | Form 2: Request for Access to Record (regulation 7) | https://inforegulator.org.za; or from the Information Officer (clause 2.3), free of charge |
| Outcome of a request, and of the fees payable | Form 3: Outcome of request and of fees payable (regulation 8) | Issued by Veriflow in response to a request |
| Complaint to the Information Regulator | Form 5: Lodging of complaint (regulation 10) | https://inforegulator.org.za |
| Fees: request fee, access, reproduction, search and preparation fees, deposits | Fees payable to a private body (Annexure B):
|
https://inforegulator.org.za |
| Copy of this manual | Electronic copy: no charge. Paper copy: no more than a reasonable amount under section 51(3)(c) of PAIA | From the Information Officer (clause 2.3), or on the website |
A.4 Related POPIA forms. The Regulations Relating to the Protection of Personal Information, 2018 (GoN 1383 in GG 42110, RG 10897, 14 December 2018), as amended by GoN 6126 in GG 52523 of 17 April 2025, prescribe Form 1 for an objection to processing under section 11(3), Form 2 for a request for correction or deletion under section 24, Form 4 for a request for consent to direct marketing under section 69, and Form 5 for a complaint to the Information Regulator. Objections and requests for correction or deletion are free of charge.
Annexure B: The statutory text this manual is drafted to
B.1 This annexure reproduces the text of section 51 of PAIA, under which this manual is made.
- PAIA section 51(1), as substituted by section 110 of POPIA with effect from 30 June 2021
- “(1) The head of a private body must make a manual available in terms of subsection (3) containing- (a) in general- (i) the postal and street address, phone and fax number and, if available, electronic mail address of the head of the body; and (ii) such other information as may be prescribed; (b) insofar as this Act is concerned- (i) a description of the guide referred to in section 10, if available, and how to obtain access to it; (ii) the latest notice in terms of section 52 (2), if any, regarding the categories of record of the body which are available without a person having to request access in terms of this Act; (iii) a description of the records of the body which are available in accordance with any other legislation; and (iv) sufficient detail to facilitate a request for access to a record of the body, a description of the subjects on which the body holds records and the categories of records held on each subject; (c) insofar as the Protection of Personal Information Act, 2013, is concerned- (i) the purpose of the processing; (ii) a description of the categories of data subjects and of the information or categories of information relating thereto; (iii) the recipients or categories of recipients to whom the personal information may be supplied; (iv) planned transborder flows of personal information; and (v) a general description allowing a preliminary assessment of the suitability of the information security measures to be implemented by the responsible party to ensure the confidentiality, integrity and availability of the information which is to be processed.”
- PAIA section 51(2) and section 51(3)
- “(2) The head of a private body must on a regular basis update the manual... (3) The manual... must be made available- (a) on the web site, if any, of the private body; (b) at the principal place of business of the private body for public inspection during normal business hours; (c) to any person upon request and upon the payment of a reasonable amount; and (d) to the Information Regulator upon request.”