Legal

PAIA Manual

Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (as amended)
IDToday Secure Data Solutions South Africa (Pty) Ltd · Reg no 2026/233950/07
Version 2 — 3 August 2026

1. List of acronyms and abbreviations

TermMeaning
“CEO”Chief Executive Officer
“Data Subjects”As defined in POPIA
“End User”An individual (or representative/beneficial owner of a juristic person) who submits information via IDToday’s Service at the request of, or for the purposes of, a Client’s Know Your Client, customer due diligence or anti-money-laundering obligations
“FICA”Financial Intelligence Centre Act 38 of 2001
“IDToday” / “IDToday South Africa” / “the Company”IDToday Secure Data Solutions South Africa (Pty) Ltd, registration number 2026/233950/07
“IO”Information Officer
“PAIA”Promotion of Access to Information Act No. 2 of 2000 (as amended)
“Personal Information”As defined in POPIA
“POPIA”Protection of Personal Information Act No. 4 of 2013
“Regulator”The Information Regulator (South Africa)
“Republic”Republic of South Africa
“Service”The IDToday software application, the idtodaykyc.com websites, and all related services

2. Purpose of PAIA Manual

This PAIA Manual is useful for the public to—

3. Key contact details for access to information of IDToday South Africa

3.1 Information Officer

Name: Gerhardus Jacobus le Roux
Tel: +27 79 692 4985
Email: gerhard@idtodaykyc.com
Information Regulator Registration Number: 2026-024122 (registered in terms of section 55 of POPIA)

3.2 Access to information general contacts

Email: gerhard@idtodaykyc.com

3.3 Registered / Head Office

Company: IDToday Secure Data Solutions South Africa (Pty) Ltd
Registration number: 2026/233950/07
Physical Address: 15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570, Republic of South Africa
Tel: +27 79 692 4985
Email: gerhard@idtodaykyc.com
Website: https://www.idtodaykyc.com/

4. Guide on how to use PAIA and how to obtain access to the Guide

4.1 The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.

4.2 The Guide is available in the official languages, as described on the Regulator’s website (please refer to https://inforegulator.org.za/paia-guidelines/).

4.3 The aforesaid Guide, inter alia, includes the description of the following —

4.4 The Guide can also be obtained —

5. Categories of records of IDToday South Africa which are available without a person having to request access

Below are the categories of records held by IDToday South Africa which are available without a person having to request access.

Category of recordsTypes of the Record
Public InformationGeneral company information available in the public domain, on the IDToday website (https://www.idtodaykyc.com/) and on social media
Terms and Conditions and Privacy PolicyIDToday’s published Terms and Conditions and Privacy Policy
PAIA ManualThis manual, prepared in terms of the Promotion of Access to Information Act 2 of 2000, as amended

6. Description of the records of IDToday South Africa held in accordance with other legislation

Below are the records which are created and stored in accordance with applicable South African legislation. To gain access to the records below, a person must follow the Request for Access to Record Procedure, as further described in section 10 of this PAIA Manual.

Category of RecordsApplicable Legislation
Memorandum of Incorporation and other statutory informationCompanies Act 71 of 2008, as amended
Tax recordsIncome Tax Act 58 of 1962, as amended; Value-Added Tax Act 89 of 1991, as amended
Employment recordsBasic Conditions of Employment Act 75 of 1997, as amended; Labour Relations Act 66 of 1995
Health and Safety recordsOccupational Health and Safety Act 85 of 1993, as amended
Know Your Client / customer due diligence and screening records processed on behalf of ClientsFinancial Intelligence Centre Act 38 of 2001, as amended

7. Description of the subjects on which IDToday South Africa holds records and categories of records held on each subject

Below are the subjects in respect of which IDToday South Africa holds records and the categories of records held on each subject. To gain access to the records below, a person must follow the Request for Access to Record Procedure, as further described in section 10 of this PAIA Manual.

Subjects on which IDToday South Africa holds recordsCategories of records
Financial Records, Strategic Documents, Plans, ProposalsAnnual Audited Financial Records and Reports; Strategic Plan; Proposals
InsuranceBusiness Insurance Policies
Information security and data protectionInformation security policies and framework; Penetration test / vulnerability assessment results; Security compromise / incident registers
Intellectual PropertySource code; Trade secrets, processes, designs and plans; Trademarks, etc.
ContractsClient SaaS Agreements and Schedules (including POPIA Operator Agreements and, where applicable, GDPR Data Processing Agreements); Sub-operator / supplier agreements; Non-Disclosure Agreements and other agreements
Client and End User KYC / screening recordsIdentification data (name, date of birth, nationality, ID or passport number, ID document images); Contact data and proof of address; Financial / source-of-funds information; Sanctions, watchlist, adverse media and Prominent Influential Person screening results; Biometric data (facial images, liveness/selfie checks) where enabled by a Client; Beneficial ownership, directorship and representative capacity information
Website and platform recordsWebsite visitor enquiry and demo-request records; Cookies and technical data (IP address, device/browser information, log and audit records); Client personnel administration records (names, work contact details, login and audit records)

Note: for personal information processed by IDToday as an operator on the instructions of a Client for Know Your Client, customer due diligence or anti-money-laundering purposes, the Client is the responsible party. Requests relating to that information should, in the first instance, be directed to the relevant Client’s Information Officer. See section 8.1 below.

8. Processing of Personal Information

8.1 IDToday’s two roles under POPIA

POPIA distinguishes between a “responsible party” (who decides why and how personal information is processed) and an “operator” (who processes it on the responsible party’s behalf). IDToday South Africa is sometimes one and sometimes the other.

8.1.1 Where IDToday is an OPERATOR: for personal information submitted by or about an End User for Know Your Client, customer due diligence or anti-money-laundering purposes, the relevant Client is the responsible party and IDToday South Africa is the operator. IDToday processes that information only on the Client’s documented instructions. End Users who wish to access, correct, delete or object to the processing of their information should direct their request to the Client that requested the information; if a request is received directly by IDToday, it will be forwarded to the Client’s Information Officer within 3 (three) business days, and IDToday will notify the requester that their request has been redirected in this manner, as confirmed in the signed-off Privacy Policy.

8.1.2 Where IDToday is a RESPONSIBLE PARTY: for personal information of website visitors, Client personnel who administer or use the Service, IDToday’s own business administration, billing, security and record-keeping. For this processing, requests may be directed to IDToday’s Information Officer using the contact details in section 3 above.

8.2 Purpose of Processing Personal Information

In general, Personal Information is processed by IDToday South Africa for business administration purposes and in the ordinary course of operation, which includes:

8.3 Description of the categories of Data Subjects and of the information or categories of information relating thereto

Below are the categories of Data Subjects in respect of whom IDToday South Africa processes Personal Information and the nature or categories of the Personal Information being processed.

Categories of Data SubjectsPersonal Information that may be processed
ClientsName, address, registration numbers or identity numbers, contact details, email addresses, correspondence, VAT numbers, transactional information and bank details
Client personnel (administrators/users of the Service)Name, work contact details, login credentials, audit and usage records
End Users (individuals verified via the Service on a Client’s instructions)Identification data, contact data, proof of address, financial/source-of-funds information, screening data, biometric data, beneficial ownership/relationship data
Service Providers / Sub-operatorsName, address, registration numbers or identity numbers, contact details, email addresses, correspondence, VAT numbers and bank details
EmployeesAddress, qualifications, salary details, bank details, gender, next of kin information, medical information, correspondence, race and biometric information (for access control purposes)
Website visitorsIP address, device and browser information, cookie identifiers, enquiry and demo-request form data
Shareholders and DirectorsName, address, registration numbers or identity numbers, contact details, email addresses, correspondence and bank details

8.3A Special Personal Information (Biometrics)

Biometric data (facial images and liveness/selfie checks) is special personal information under section 26 of POPIA. IDToday always obtains the End User’s explicit, unbundled consent to this processing under section 27(1)(a), regardless of onboarding channel. Where onboarding is conducted remotely (i.e., not face-to-face), biometric verification is also necessary to satisfy the Client’s customer identification and verification requirements under FICA, providing an additional lawful basis under section 33 read with section 27(1)(f). Where consent is withdrawn but verification remains a precondition of a Client’s regulated remote-onboarding process, the Client’s underlying statutory obligation continues to apply and access to the Service may be affected accordingly.

8.4 The recipients or categories of recipients to whom the Personal Information may be supplied

Below are the persons or categories of persons to whom IDToday South Africa may disclose Personal Information.

Category of Personal InformationRecipients or Categories of Recipients
Identity number and names of employees, for criminal/background checksSouth African Police Services
Identity, KYC and screening information processed as operatorThe relevant Client, in accordance with the applicable SaaS Agreement / POPIA Operator Agreement
Sanctions, watchlist, adverse media and Prominent Influential Person dataFactiva Limited (a Dow Jones company) — risk, PEP, RCA and sanction screening data feeds, United States of America. Per the Privacy Policy (Annex A), Factiva is confirmed as an independent controller of its own Watchlist database, not IDToday’s sub-processor; IDToday is a separate controller of the screening results it receives.
Form and enquiry dataCognito Forms — cloud-based form provider, United States of America (used solely as a transient intake channel; submissions transfer automatically to IDToday’s secure hosting environment on receipt and are not separately retained by Cognito Forms thereafter)
Platform data (hosting, database, compute)Google Cloud Platform (Firestore), Belgium (European Union)
Back-up dataAmazon Web Services, Johannesburg, Republic of South Africa
Platform operation and support (intra-group)IDToday Secure Data Solutions (Pty) Ltd, Republic of Namibia
Identity number and names of employeesSouth African Revenue Service
Personal or other confidential informationPer request from, and to the extent required by, a regulatory authority or as required by law

This list is kept up to date and Clients are notified of material changes in advance, in accordance with IDToday’s Privacy Policy. This table has been reconciled with, and mirrors, Annex A (Reconciled Sub-Operator & Recipient List) to IDToday’s signed-off Terms and Conditions and Privacy Policy.

8.5 Planned transborder flows of Personal Information

The Personal Information collected by IDToday South Africa from Data Subjects may be transferred to, processed or stored by recipients located outside the Republic, including in the United States of America (screening and form-processing service providers), Belgium (cloud hosting), and the Republic of Namibia (intra-group platform operation and support). As confirmed in the signed-off Privacy Policy, each such transfer is made in reliance on section 72(1)(a) of POPIA: the recipient is bound by a data processing agreement imposing safeguards substantially similar to POPIA’s conditions for lawful processing, and is restricted from transferring the information onward save on equivalent terms.

Transfers to the Republic of Namibia are made pursuant to a Binding Intra-Group Data Transfer Agreement between IDToday South Africa and IDToday Secure Data Solutions (Pty) Ltd (Namibia), as required by section 72 of POPIA in the absence of comprehensive data protection legislation currently in force in Namibia. As confirmed in the signed-off Privacy Policy, this agreement incorporates, on a clause-by-clause basis, the eight conditions for lawful processing set out in Chapter 3 of POPIA, and remains binding on IDToday Namibia notwithstanding termination of the underlying SaaS relationship or of the intra-group relationship between the two entities.

8.6 General description of Information Security Measures

IDToday South Africa implements technical and organisational security safeguards to ensure the confidentiality, integrity and availability of the Personal Information under its care, in accordance with section 19 of POPIA, including access controls, encryption, audit logging, and contractual security obligations imposed on sub-operators.

8.6A Security Compromise Notification (POPIA Section 22)

Section 19 safeguards are distinct from IDToday’s section 22 duty to notify following a confirmed or reasonably suspected security compromise. As confirmed in the signed-off Privacy Policy: where IDToday acts as operator, it will notify the affected Client(s) immediately on becoming aware of a compromise, and in any event within 48 hours of confirmation, to enable the Client’s own notification obligations to the Information Regulator (this 48-hour period is IDToday’s own operational commitment to Clients and is not itself the statutory deadline under section 21(2), which requires operator-to-responsible-party notification “immediately”); where IDToday acts as responsible party, it will notify the Information Regulator and affected data subjects as soon as reasonably possible in accordance with section 22.

8.7 Rights of Data Subjects

In accordance with section 5 of POPIA, and without limiting section 10 of this Manual, a Data Subject whose Personal Information is processed by IDToday South Africa as a responsible party (see section 8.1.2 above) has the right to: be notified that Personal Information is being collected and of the purpose of collection; establish whether IDToday South Africa holds Personal Information about them and to request access to it; request correction, destruction or deletion of their Personal Information; object, on reasonable grounds, to the processing of their Personal Information; and lodge a complaint with the Information Regulator regarding an alleged interference with the protection of their Personal Information, or approach a competent court, in terms of Chapter 10 of POPIA. These rights may be exercised by contacting the Information Officer using the details in section 3 above.

9. Availability of the PAIA Manual

9.1 A copy of this Manual is available —

9.2 A fee for a copy of the Manual, as contemplated in Annexure B of the Regulations, shall be payable per each A4-size photocopy made, currently R2.00 per page or part thereof.

10. Access Requests

10.1 Request for Access to Record Procedure

10.1.1 Completion of Request for Access to Record Form

To facilitate a timely response to requests for access, all requesters should take note of the following when seeking to obtain access:

10.1.2 Submission of Request for Access to Record Form

10.1.3 Payment of Fees and Outcome of Request

10.1.4 Appeal against refusal to grant access

11. Updating of the PAIA Manual

As required, this manual will be updated and an updated version will be published as set out in section 9 above.

Issued by
Chris Botha
Chief Executive Officer
IDToday Secure Data Solutions South Africa (Pty) Ltd

Annexure A: Form 2 — Request for Access to Record [Regulation 7]

Note: Proof of identity must be attached by the requester. If the request is made on behalf of another person, proof of such authorisation must be attached to the form. The official Form 2 can be downloaded from the Regulator’s website at inforegulator.org.za/paia-forms/, or requested from the Information Officer.

Submit to: The Information Officer, IDToday Secure Data Solutions South Africa (Pty) Ltd, 15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570 · E-mail: gerhard@idtodaykyc.com

The form requires the following particulars:

The requester will be notified in writing whether the request has been approved or denied and, if approved, of the costs relating to the request, if any.

Annexure B: Form 3 — Outcome of Request and of Fees Payable [Regulation 8]

If a request is granted — (a) the amount of the deposit (if any) is payable before the request is processed; and (b) the requested record (or portion of the record) will only be released once proof of full payment is received. The reference number provided must be used in all future correspondence.

1. Request fee

The initial request fee payable by every requester (other than a personal requester) is R140.00, prescribed in terms of Annexure B to the PAIA Regulations, 2021.

2. Fees payable with regard to a request

ItemAmount
Photocopy of A4-size pageR2.00 per page or part thereof
Printed copy of A4-size pageR2.00 per page or part thereof
Copy in computer-readable form: flash drive (provided by requestor)R40.00
Copy on compact disc (provided by requestor)R40.00
Copy on compact disc (provided to the requestor)R60.00
Transcription of visual images, per A4-size pageOutsourced service — dependent on service provider’s quotation
Copy of visual imagesOutsourced service — dependent on service provider’s quotation
Transcription of an audio record, per A4-size pageR30.00
Copy of an audio record: flash drive (provided by requestor)R40.00
Copy of an audio record: compact disc (provided by requestor)R40.00
Copy of an audio record: compact disc (provided to the requestor)R60.00
Postage, e-mail or any other electronic transferActual cost

3. Deposit

Where the search for a record exceeds six hours, a deposit may be payable, calculated as one third of the total amount per request.

4. Outcome and payment

The Information Officer will indicate on Form 3 whether the request has been approved or denied, together with reasons, and will provide the applicable payment details (bank, account holder, account number, branch code and reference number) and where to submit proof of payment.