Promotion of Access to Information Act (PAIA) Manual

Prepared in terms of Section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended) for Globerisk (Pty) Ltd

List of Acronyms and Abbreviations

CEO

Chief Executive Officer

IO

Information Officer

PAIA

Promotion of Access to Information Act No. 2 of 2000

POPIA

Protection of Personal Information Act No. 4 of 2013

Regulator

The South African Information Regulator

Republic

Republic of South Africa

Purpose of this PAIA Manual

This Manual is useful for the public to:

  • Check the categories of records held by us which are available without a formal PAIA request.
  • Understand how to submit a formal request for access to a record.
  • Know the contact details of the Information Officer who will assist the public.
  • Understand how we process, transfer (cross-border), and secure Personal Information under POPIA.

Key Contact Details for Access to Information

All formal requests or queries must be directed to our designated Information Officer:

  • Chief Information Officer: Anton van der Merwe (CEO)
  • Deputy Information Officer: Quinten van Lill (Director)
  • Physical Address: First Floor, Building 7, Atterbury Estate, 19 Frikkie de Beer Street, Menlyn Maine, Pretoria
  • Postal Address: PO Box 12259, Clubview, 0014
  • Direct Telephone: +27 12 824 0430
  • Compliance Email: info@globerisk.co.za
  • Website: www.globerisk.co.za

Guide on How to Use PAIA

The Information Regulator has compiled a comprehensive, easy-to-read Guide in all official languages to assist the public in exercising their rights under PAIA and POPIA.

You can inspect or download this official Guide directly from the South African Information Regulator’s portal at: https://inforegulator.org.za/paia-guidelines/

Categories of Records Available Without a Formal Request

The following records are automatically available to the public without needing to fill out a formal PAIA request form:

  • Public marketing brochures and brand material.
  • All public-facing content hosted across our web domain.
  • Our published POPIA Privacy Policy, accessible at www.globerisk.co.za/privacy-policy

Records Available in Accordance with Other South African Legislation

We maintain records in terms of the following statutory local legislation, among others:

  • Basic Conditions of Employment Act 75 of 1997
  • Broad-Based Black Economic Empowerment Act 53 of 2003
  • Companies Act 71 of 2008
  • Compensation for Occupational Injuries and Diseases Act 130 of 1993
  • Consumer Protection Act 68 of 2008
  • Electronic Communications and Transactions Act 25 of 2002
  • Financial Intelligence Centre Act 38 of 2001
  • Income Tax Act 58 of 1962
  • Labor Relations Act 66 of 1995
  • Occupational Health and Safety Act 85 of 1993
  • Protection of Personal Information Act 4 of 2013
  • Promotion of Access to Information Act 2 of 2000
  • Value Added Tax Act 89 of 1991

Description of Subjects and Categories of Internal Records Held

The list below describes the subjects on which our company holds operational records and the categories of records held under each:

  • Corporate Administration & Governance: Memorandum of Incorporation, CIPC filings, statutory registers, director resolutions, and internal policies.
  • Financial & Accounting: Annual financial statements, tax returns, accounting ledgers, invoices, asset registers, and banking details.
  • Human Resources: Employment contracts, payroll records, statutory HR submissions, internal personnel profiles, and leave logs.
  • Client & Operations: Customer databases, active service contracts, governance and risk consulting project documentation, delivery schedules, and historical project files.
  • Information Technology & Systems: Network operational records, software licenses, data protection policies, system backups, and infrastructure documentation.

Processing of Personal Information (POPIA requirements)

Purpose of Processing

We process Personal Information to execute client contracts, manage supplier pipelines, communicate service updates, perform accounting operations, execute payroll, maintain site security, and respond to voluntary digital queries.

Categories of Data Subjects and Information Processed

  • Customers / Clients: Names, physical/postal addresses, registration/ID numbers, email addresses, contact phone numbers, billing history, and risk consulting engagement data.
  • Service Providers / Suppliers: Trade names, VAT numbers, physical banking details, contact person details, and commercial agreements.
  • Employees: ID numbers, addresses, banking details, tax profiles, qualifications, and employment histories.

Planned Transborder Flows of Personal Information

To maintain website functionality, secure digital communications, and data analytics integrity, we store or route information through cloud-based platform Operators located outside of South Africa, specifically:

  • Anti-Spam by CleanTalk: Cloud-based security infrastructure routing form submission payloads, names, email addresses, and IP addresses to external validation servers for spam checks.
  • Elementor / Elementor Pro: Dynamic layout frameworks and native contact form builders processing user inquiries via cloud infrastructure.
  • Site Kit by Google: Global site performance reporting, search analytics, and visitor cookie tracking processed across Google’s international server network.
  • InfiniteWP – Client: Administrative maintenance bridge transmitting system diagnostics and administrative access logs to remote server endpoints.
  • Microsoft 365 Cloud: Remote corporate email hosting, document management, and client correspondence storage.


We ensure these foreign Operators adhere to strict contractual confidentiality frameworks and data protection standards that align with POPIA requirements.

Information Security Measures

We deploy appropriate technical and organizational safeguards to maintain the confidentiality and integrity of personal data, including:

  • SSL Data Encryption: Secure HTTPS socket layer encryption across our web domain.
  • Local Web Infrastructure Security: Active cyberattack defense, IP address monitoring, and brute-force mitigation executed locally via Kadence Security Basic and Log cleaner for Solid Security.
  • Database Maintenance & Minimization: Automated local database optimization, image compression, and temporary cache purging using WP-Optimize.
  • Access Protocols: Restricted, password-managed access controls and multi-factor authentication for internal databases.

Formal Request Procedure for Records

To request a private record from us that is not automatically public, you must follow the formal PAIA workflow:

  1. Download and complete the official PAIA Form 2 (Request for Access to Record) here.
  2. Submit the completed Form 2 to our Information Officer at info@globerisk.co.za.
  3. State the clear constitutional or legal right you are seeking to protect or exercise within the form context.
  4. Pay the statutory, regulated access fee if applicable before your request can be processed.

Availability and Updating of this Manual

This manual is available for public inspection at our physical head office during normal business hours, is published live on our web domain, and is updated on a regular basis by our Information Officer.

Please note: If a request is made on behalf of another individual, the requester must submit proof of the capacity in which they are making the request, to the reasonable satisfaction of our Information Officer.

Issued by: Anton van der Merwe

Title: CEO / Chief Information Officer