1. List of acronyms and abbreviations
| Term | Meaning |
|---|---|
| “CEO” | Chief Executive Officer |
| “Data Subjects” | As defined in POPIA |
| “End User” | An individual (or representative/beneficial owner of a juristic person) who submits information via IDToday’s Service at the request of, or for the purposes of, a Client’s Know Your Client, customer due diligence or anti-money-laundering obligations |
| “FICA” | Financial Intelligence Centre Act 38 of 2001 |
| “IDToday” / “IDToday South Africa” / “the Company” | IDToday Secure Data Solutions South Africa (Pty) Ltd, registration number 2026/233950/07 |
| “IO” | Information Officer |
| “PAIA” | Promotion of Access to Information Act No. 2 of 2000 (as amended) |
| “Personal Information” | As defined in POPIA |
| “POPIA” | Protection of Personal Information Act No. 4 of 2013 |
| “Regulator” | The Information Regulator (South Africa) |
| “Republic” | Republic of South Africa |
| “Service” | The IDToday software application, the idtodaykyc.com websites, and all related services |
2. Purpose of PAIA Manual
This PAIA Manual is useful for the public to—
- 2.1 Check the categories of records held by IDToday South Africa which are available without a person having to submit a formal PAIA request;
- 2.2 Have a sufficient understanding of how to make a request for access to a record of IDToday South Africa, by providing a description of the subjects on which IDToday South Africa holds records and the categories of records held on each subject;
- 2.3 Know the description of the records of IDToday South Africa which are available in accordance with any other applicable legislation;
- 2.4 Access all the relevant contact details of the IO who will assist the public with the records they intend to access;
- 2.5 Know the description of the guide on how to use PAIA, as updated by the Regulator, and how to obtain access to it;
- 2.6 Know if IDToday South Africa processes Personal Information, the purpose of such processing, and the description of the categories of Data Subjects and of the information or categories of information relating thereto;
- 2.7 Know the description of the categories of Data Subjects and of the information or categories of information relating thereto;
- 2.8 Know the recipients or categories of recipients to whom the Personal Information may be supplied;
- 2.9 Know if IDToday South Africa has planned to transfer or process Personal Information outside the Republic and the recipients or categories of recipients to whom the Personal Information may be supplied; and
- 2.10 Know whether IDToday South Africa has appropriate security measures to ensure the confidentiality, integrity and availability of the Personal Information which is to be processed.
3. Key contact details for access to information of IDToday South Africa
3.1 Information Officer
Name: Gerhardus Jacobus le Roux
Tel: +27 79 692 4985
Email: gerhard@idtodaykyc.com
Information Regulator Registration Number: 2026-024122 (registered in terms of section 55 of POPIA)
3.2 Access to information general contacts
Email: gerhard@idtodaykyc.com
3.3 Registered / Head Office
Company: IDToday Secure Data Solutions South Africa (Pty) Ltd
Registration number: 2026/233950/07
Physical Address: 15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570, Republic of South Africa
Tel: +27 79 692 4985
Email: gerhard@idtodaykyc.com
Website: https://www.idtodaykyc.com/
4. Guide on how to use PAIA and how to obtain access to the Guide
4.1 The Regulator has, in terms of section 10(1) of PAIA, as amended, updated and made available the revised Guide on how to use PAIA (“Guide”), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
4.2 The Guide is available in the official languages, as described on the Regulator’s website (please refer to https://inforegulator.org.za/paia-guidelines/).
4.3 The aforesaid Guide, inter alia, includes the description of the following —
- 4.3.1 The objectives of PAIA and POPIA;
- 4.3.2 The manner and form of a request for access to a record of a private body contemplated in section 50;
- 4.3.3 The assistance available from the Regulator in terms of PAIA and POPIA;
- 4.3.4 All remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, or a court application;
- 4.3.5 The provisions of sections 14 and 51 requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual;
- 4.3.6 The provisions of sections 15 and 52 providing for the voluntary disclosure of categories of records by a public body and private body, respectively; and
- 4.3.7 The notices issued in terms of sections 22 and 54 regarding fees to be paid in relation to requests for access.
4.4 The Guide can also be obtained —
- 4.4.1 Upon request to the IO; or
- 4.4.2 From the website of the Regulator (https://inforegulator.org.za/paia-guidelines/).
5. Categories of records of IDToday South Africa which are available without a person having to request access
Below are the categories of records held by IDToday South Africa which are available without a person having to request access.
| Category of records | Types of the Record |
|---|---|
| Public Information | General company information available in the public domain, on the IDToday website (https://www.idtodaykyc.com/) and on social media |
| Terms and Conditions and Privacy Policy | IDToday’s published Terms and Conditions and Privacy Policy |
| PAIA Manual | This manual, prepared in terms of the Promotion of Access to Information Act 2 of 2000, as amended |
6. Description of the records of IDToday South Africa held in accordance with other legislation
Below are the records which are created and stored in accordance with applicable South African legislation. To gain access to the records below, a person must follow the Request for Access to Record Procedure, as further described in section 10 of this PAIA Manual.
| Category of Records | Applicable Legislation |
|---|---|
| Memorandum of Incorporation and other statutory information | Companies Act 71 of 2008, as amended |
| Tax records | Income Tax Act 58 of 1962, as amended; Value-Added Tax Act 89 of 1991, as amended |
| Employment records | Basic Conditions of Employment Act 75 of 1997, as amended; Labour Relations Act 66 of 1995 |
| Health and Safety records | Occupational Health and Safety Act 85 of 1993, as amended |
| Know Your Client / customer due diligence and screening records processed on behalf of Clients | Financial Intelligence Centre Act 38 of 2001, as amended |
7. Description of the subjects on which IDToday South Africa holds records and categories of records held on each subject
Below are the subjects in respect of which IDToday South Africa holds records and the categories of records held on each subject. To gain access to the records below, a person must follow the Request for Access to Record Procedure, as further described in section 10 of this PAIA Manual.
| Subjects on which IDToday South Africa holds records | Categories of records |
|---|---|
| Financial Records, Strategic Documents, Plans, Proposals | Annual Audited Financial Records and Reports; Strategic Plan; Proposals |
| Insurance | Business Insurance Policies |
| Information security and data protection | Information security policies and framework; Penetration test / vulnerability assessment results; Security compromise / incident registers |
| Intellectual Property | Source code; Trade secrets, processes, designs and plans; Trademarks, etc. |
| Contracts | Client SaaS Agreements and Schedules (including POPIA Operator Agreements and, where applicable, GDPR Data Processing Agreements); Sub-operator / supplier agreements; Non-Disclosure Agreements and other agreements |
| Client and End User KYC / screening records | Identification data (name, date of birth, nationality, ID or passport number, ID document images); Contact data and proof of address; Financial / source-of-funds information; Sanctions, watchlist, adverse media and Prominent Influential Person screening results; Biometric data (facial images, liveness/selfie checks) where enabled by a Client; Beneficial ownership, directorship and representative capacity information |
| Website and platform records | Website visitor enquiry and demo-request records; Cookies and technical data (IP address, device/browser information, log and audit records); Client personnel administration records (names, work contact details, login and audit records) |
Note: for personal information processed by IDToday as an operator on the instructions of a Client for Know Your Client, customer due diligence or anti-money-laundering purposes, the Client is the responsible party. Requests relating to that information should, in the first instance, be directed to the relevant Client’s Information Officer. See section 8.1 below.
8. Processing of Personal Information
8.1 IDToday’s two roles under POPIA
POPIA distinguishes between a “responsible party” (who decides why and how personal information is processed) and an “operator” (who processes it on the responsible party’s behalf). IDToday South Africa is sometimes one and sometimes the other.
8.1.1 Where IDToday is an OPERATOR: for personal information submitted by or about an End User for Know Your Client, customer due diligence or anti-money-laundering purposes, the relevant Client is the responsible party and IDToday South Africa is the operator. IDToday processes that information only on the Client’s documented instructions. End Users who wish to access, correct, delete or object to the processing of their information should direct their request to the Client that requested the information; if a request is received directly by IDToday, it will be forwarded to the Client’s Information Officer within 3 (three) business days, and IDToday will notify the requester that their request has been redirected in this manner, as confirmed in the signed-off Privacy Policy.
8.1.2 Where IDToday is a RESPONSIBLE PARTY: for personal information of website visitors, Client personnel who administer or use the Service, IDToday’s own business administration, billing, security and record-keeping. For this processing, requests may be directed to IDToday’s Information Officer using the contact details in section 3 above.
8.2 Purpose of Processing Personal Information
In general, Personal Information is processed by IDToday South Africa for business administration purposes and in the ordinary course of operation, which includes:
- Provision of the IDToday KYC / identity-verification platform and related services to Clients
- Performing sanctions, watchlist, adverse media and Prominent Influential Person screening on behalf of Clients
- Keeping Data Subject and Client records up to date
- Managing employees in general
- Managing supplier and sub-operator contracts in general
- Managing Clients and Client personnel access to the Service
- Enforcing debts and managing billing
- Processing enquiries, support requests and complaints
- Processing Personal Information of employees for labour law and administrative purposes
- Security monitoring, fraud prevention and record-keeping
8.3 Description of the categories of Data Subjects and of the information or categories of information relating thereto
Below are the categories of Data Subjects in respect of whom IDToday South Africa processes Personal Information and the nature or categories of the Personal Information being processed.
| Categories of Data Subjects | Personal Information that may be processed |
|---|---|
| Clients | Name, address, registration numbers or identity numbers, contact details, email addresses, correspondence, VAT numbers, transactional information and bank details |
| Client personnel (administrators/users of the Service) | Name, work contact details, login credentials, audit and usage records |
| End Users (individuals verified via the Service on a Client’s instructions) | Identification data, contact data, proof of address, financial/source-of-funds information, screening data, biometric data, beneficial ownership/relationship data |
| Service Providers / Sub-operators | Name, address, registration numbers or identity numbers, contact details, email addresses, correspondence, VAT numbers and bank details |
| Employees | Address, qualifications, salary details, bank details, gender, next of kin information, medical information, correspondence, race and biometric information (for access control purposes) |
| Website visitors | IP address, device and browser information, cookie identifiers, enquiry and demo-request form data |
| Shareholders and Directors | Name, address, registration numbers or identity numbers, contact details, email addresses, correspondence and bank details |
8.3A Special Personal Information (Biometrics)
Biometric data (facial images and liveness/selfie checks) is special personal information under section 26 of POPIA. IDToday always obtains the End User’s explicit, unbundled consent to this processing under section 27(1)(a), regardless of onboarding channel. Where onboarding is conducted remotely (i.e., not face-to-face), biometric verification is also necessary to satisfy the Client’s customer identification and verification requirements under FICA, providing an additional lawful basis under section 33 read with section 27(1)(f). Where consent is withdrawn but verification remains a precondition of a Client’s regulated remote-onboarding process, the Client’s underlying statutory obligation continues to apply and access to the Service may be affected accordingly.
8.4 The recipients or categories of recipients to whom the Personal Information may be supplied
Below are the persons or categories of persons to whom IDToday South Africa may disclose Personal Information.
| Category of Personal Information | Recipients or Categories of Recipients |
|---|---|
| Identity number and names of employees, for criminal/background checks | South African Police Services |
| Identity, KYC and screening information processed as operator | The relevant Client, in accordance with the applicable SaaS Agreement / POPIA Operator Agreement |
| Sanctions, watchlist, adverse media and Prominent Influential Person data | Factiva Limited (a Dow Jones company) — risk, PEP, RCA and sanction screening data feeds, United States of America. Per the Privacy Policy (Annex A), Factiva is confirmed as an independent controller of its own Watchlist database, not IDToday’s sub-processor; IDToday is a separate controller of the screening results it receives. |
| Form and enquiry data | Cognito Forms — cloud-based form provider, United States of America (used solely as a transient intake channel; submissions transfer automatically to IDToday’s secure hosting environment on receipt and are not separately retained by Cognito Forms thereafter) |
| Platform data (hosting, database, compute) | Google Cloud Platform (Firestore), Belgium (European Union) |
| Back-up data | Amazon Web Services, Johannesburg, Republic of South Africa |
| Platform operation and support (intra-group) | IDToday Secure Data Solutions (Pty) Ltd, Republic of Namibia |
| Identity number and names of employees | South African Revenue Service |
| Personal or other confidential information | Per request from, and to the extent required by, a regulatory authority or as required by law |
This list is kept up to date and Clients are notified of material changes in advance, in accordance with IDToday’s Privacy Policy. This table has been reconciled with, and mirrors, Annex A (Reconciled Sub-Operator & Recipient List) to IDToday’s signed-off Terms and Conditions and Privacy Policy.
8.5 Planned transborder flows of Personal Information
The Personal Information collected by IDToday South Africa from Data Subjects may be transferred to, processed or stored by recipients located outside the Republic, including in the United States of America (screening and form-processing service providers), Belgium (cloud hosting), and the Republic of Namibia (intra-group platform operation and support). As confirmed in the signed-off Privacy Policy, each such transfer is made in reliance on section 72(1)(a) of POPIA: the recipient is bound by a data processing agreement imposing safeguards substantially similar to POPIA’s conditions for lawful processing, and is restricted from transferring the information onward save on equivalent terms.
Transfers to the Republic of Namibia are made pursuant to a Binding Intra-Group Data Transfer Agreement between IDToday South Africa and IDToday Secure Data Solutions (Pty) Ltd (Namibia), as required by section 72 of POPIA in the absence of comprehensive data protection legislation currently in force in Namibia. As confirmed in the signed-off Privacy Policy, this agreement incorporates, on a clause-by-clause basis, the eight conditions for lawful processing set out in Chapter 3 of POPIA, and remains binding on IDToday Namibia notwithstanding termination of the underlying SaaS relationship or of the intra-group relationship between the two entities.
8.6 General description of Information Security Measures
IDToday South Africa implements technical and organisational security safeguards to ensure the confidentiality, integrity and availability of the Personal Information under its care, in accordance with section 19 of POPIA, including access controls, encryption, audit logging, and contractual security obligations imposed on sub-operators.
8.6A Security Compromise Notification (POPIA Section 22)
Section 19 safeguards are distinct from IDToday’s section 22 duty to notify following a confirmed or reasonably suspected security compromise. As confirmed in the signed-off Privacy Policy: where IDToday acts as operator, it will notify the affected Client(s) immediately on becoming aware of a compromise, and in any event within 48 hours of confirmation, to enable the Client’s own notification obligations to the Information Regulator (this 48-hour period is IDToday’s own operational commitment to Clients and is not itself the statutory deadline under section 21(2), which requires operator-to-responsible-party notification “immediately”); where IDToday acts as responsible party, it will notify the Information Regulator and affected data subjects as soon as reasonably possible in accordance with section 22.
8.7 Rights of Data Subjects
In accordance with section 5 of POPIA, and without limiting section 10 of this Manual, a Data Subject whose Personal Information is processed by IDToday South Africa as a responsible party (see section 8.1.2 above) has the right to: be notified that Personal Information is being collected and of the purpose of collection; establish whether IDToday South Africa holds Personal Information about them and to request access to it; request correction, destruction or deletion of their Personal Information; object, on reasonable grounds, to the processing of their Personal Information; and lodge a complaint with the Information Regulator regarding an alleged interference with the protection of their Personal Information, or approach a competent court, in terms of Chapter 10 of POPIA. These rights may be exercised by contacting the Information Officer using the details in section 3 above.
9. Availability of the PAIA Manual
9.1 A copy of this Manual is available —
- 9.1.1 On idtodaykyc.com;
- 9.1.2 To any person upon request to the IO and upon payment of a reasonable prescribed fee; and
- 9.1.3 To the Regulator upon request.
9.2 A fee for a copy of the Manual, as contemplated in Annexure B of the Regulations, shall be payable per each A4-size photocopy made, currently R2.00 per page or part thereof.
10. Access Requests
10.1 Request for Access to Record Procedure
10.1.1 Completion of Request for Access to Record Form
To facilitate a timely response to requests for access, all requesters should take note of the following when seeking to obtain access:
- The Request for Access to Record Form (Form 2), described in Annexure A below, and as published on the Regulator’s website at https://inforegulator.org.za/paia-forms/, must be completed by the requester.
- Proof of identity is required to authenticate the identity of the requester, in addition to submission of the completed Request for Access to Record Form. Requesters will be required to supply a certified copy of their identification document or a valid passport, or, if a legal entity, a certified copy of the company registration certificate.
- The successful completion and submission of a Request for Access to Record Form does not automatically constitute approval of access to the requested record. An application for access to a record is subject to certain limitations if the requested record falls within a category specified in PAIA, and access to records may be refused on reasonable grounds.
- If it is reasonably suspected that the requester has obtained access to records through the submission of materially false or misleading information, legal proceedings may be instituted against such requester.
- Where the requested record relates to personal information processed by IDToday as an operator on behalf of a Client (see section 8.1 above), the request will be forwarded to the relevant Client’s Information Officer, who will respond to the requester directly or through IDToday.
10.1.2 Submission of Request for Access to Record Form
- The completed Request for Access to Record Form, together with a certified copy of the requester’s identity document, must be addressed to the Information Officer and submitted via the contact details stated in section 3 of this PAIA Manual.
10.1.3 Payment of Fees and Outcome of Request
- An initial request fee of R140.00 (or as otherwise prescribed in Annexure B to the PAIA Regulations, and reflected in Form 3) is payable on submission of the Request for Access to Record Form. This prescribed fee is a legally allowable charge under PAIA. The charge does not need to be levied but the holder of the records is entitled to levy this fee to compensate for administrative effort incurred in making the record available to the requester.
- Payment details can be obtained from the IO and payment can be made via electronic transfer. Proof of payment must be supplied via the contact details stated in this PAIA Manual.
- The IO will, within 30 (thirty) days of receipt of the request, decide whether to grant or decline the request and give notice with reasons (if required) to that effect.
- This thirty-day period may be extended for a further period of not more than thirty days, if the request is for a large volume of information and the information cannot reasonably be obtained within the original 30 (thirty) day period. The requester will be notified in writing should an extension be sought.
- The Outcome of Request and of Fees Payable Form (Form 3), described in Annexure B below, will be used by the IO to communicate its decision regarding the access request and the prescribed fees payable if the request is granted.
10.1.4 Appeal against refusal to grant access
- If a requester is aggrieved by the refusal of the IO to grant a request for a record, the requester may, upon notification of the IO’s decision (or upon deemed refusal in terms of section 58 of PAIA), lodge a complaint with the Regulator or apply to court for appropriate relief within the timeframes prescribed by PAIA.
11. Updating of the PAIA Manual
As required, this manual will be updated and an updated version will be published as set out in section 9 above.
Issued by
Chris Botha
Chief Executive Officer
IDToday Secure Data Solutions South Africa (Pty) Ltd
Annexure A: Form 2 — Request for Access to Record [Regulation 7]
Note: Proof of identity must be attached by the requester. If the request is made on behalf of another person, proof of such authorisation must be attached to the form. The official Form 2 can be downloaded from the Regulator’s website at inforegulator.org.za/paia-forms/, or requested from the Information Officer.
Submit to: The Information Officer, IDToday Secure Data Solutions South Africa (Pty) Ltd, 15 Sterling Grove, Buh-Rein Estate, Kraaifontein, Cape Town, Western Cape, 7570 · E-mail: gerhard@idtodaykyc.com
The form requires the following particulars:
- Capacity: whether the request is made in the requester’s own name or on behalf of another person (with proof of authorisation).
- Personal information: full names, identity number, capacity in which the request is made, postal and street address, e-mail address and contact numbers; and, if made on behalf of another person, that person’s full names, identity number and postal/street address.
- Particulars of the record requested: a full description of the record (or relevant part of the record), the reference number if available, and any further particulars needed to locate the record.
- Type of record: written/printed form; visual images (photographs, slides, video recordings, computer-generated images, sketches, etc.); recorded words or information which can be reproduced in sound; or a record held on a computer or in electronic or machine-readable form.
- Form of access: printed copy; written or printed transcription of visual images; transcription of soundtrack; copy on flash drive or compact disc; or copy saved on a cloud storage server / sent electronically.
- Manner of access: personal inspection at IDToday South Africa’s registered address; postal or courier service; facsimile; e-mail; or cloud share / file transfer; and preferred language.
- Particulars of the right to be exercised or protected: which right is to be exercised or protected, and why the record is required for the exercise or protection of that right.
- Fees: a request fee must be paid before the request will be considered; the requester will be notified of the access fee payable, which depends on the form of access and the reasonable time required to search for and prepare the record; requesters who qualify for exemption should state the reason for exemption.
The requester will be notified in writing whether the request has been approved or denied and, if approved, of the costs relating to the request, if any.
Annexure B: Form 3 — Outcome of Request and of Fees Payable [Regulation 8]
If a request is granted — (a) the amount of the deposit (if any) is payable before the request is processed; and (b) the requested record (or portion of the record) will only be released once proof of full payment is received. The reference number provided must be used in all future correspondence.
1. Request fee
The initial request fee payable by every requester (other than a personal requester) is R140.00, prescribed in terms of Annexure B to the PAIA Regulations, 2021.
2. Fees payable with regard to a request
| Item | Amount |
|---|---|
| Photocopy of A4-size page | R2.00 per page or part thereof |
| Printed copy of A4-size page | R2.00 per page or part thereof |
| Copy in computer-readable form: flash drive (provided by requestor) | R40.00 |
| Copy on compact disc (provided by requestor) | R40.00 |
| Copy on compact disc (provided to the requestor) | R60.00 |
| Transcription of visual images, per A4-size page | Outsourced service — dependent on service provider’s quotation |
| Copy of visual images | Outsourced service — dependent on service provider’s quotation |
| Transcription of an audio record, per A4-size page | R30.00 |
| Copy of an audio record: flash drive (provided by requestor) | R40.00 |
| Copy of an audio record: compact disc (provided by requestor) | R40.00 |
| Copy of an audio record: compact disc (provided to the requestor) | R60.00 |
| Postage, e-mail or any other electronic transfer | Actual cost |
3. Deposit
Where the search for a record exceeds six hours, a deposit may be payable, calculated as one third of the total amount per request.
4. Outcome and payment
The Information Officer will indicate on Form 3 whether the request has been approved or denied, together with reasons, and will provide the applicable payment details (bank, account holder, account number, branch code and reference number) and where to submit proof of payment.