Home / PAIA Manual

PAIA manual

Manual of Trio-Data Special Services (Pty) Ltd in terms of section 51 of the Promotion of Access to Information Act 2 of 2000.

Version 1.0 · effective 23 September 2026.

1. Acronyms

PAIA, the Promotion of Access to Information Act 2 of 2000. POPIA, the Protection of Personal Information Act 4 of 2013. The Regulator, the Information Regulator (South Africa). The company, Trio-Data Special Services (Pty) Ltd. The head, the head of the private body as PAIA defines it.

2. Purpose of this manual

This manual tells any person what records the company holds, how to ask for access to them, who to ask, what it costs and how long it takes. PAIA section 51 requires it. It also states, as section 51(1) has required since 30 June 2021, why the company processes personal information, whose information it holds, who receives it, whether any of it leaves South Africa, and how it is protected. Nothing in it limits a right of access given by another law, and nothing in it promises that a request will be granted: PAIA sets out when access must or may be refused.

3. Contact details

  • Trio-Data Special Services (Pty) Ltd, trading as Trio-Data Special Services Cape.
  • Registration number 2013/068495/07.
  • Head of the body: Peter Muir, Director and founder.
  • Information Officer: Marius Fritz, Branch Manager.
  • Deputy Information Officer(s): None are designated at the date of this manual.
  • Registered address: Unit 1, Canal Edge 3, Fountain Road, Tyger Waterfront, Bellville, 7530. Postal address: Unit 1, Canal Edge 3, Fountain Road, Tyger Waterfront, Bellville, 7530.
  • Telephone: Unit 1, Canal Edge 3, Fountain Road, Tyger Waterfront, Bellville, 7530. Email for access requests: Unit 1, Canal Edge 3, Fountain Road, Tyger Waterfront, Bellville, 7530.
  • Website: www.trio-data.co.za
  • The manual may be inspected at the registered address during 08:00 to 16:30 on business days.

4. The Regulator's guide, and how to make a request

The Regulator publishes a plain-language guide on how to use PAIA, free of charge, in every official language, at inforegulator.org.za. A copy, in at least two official languages, is kept at our registered office for public inspection.

Information Regulator (South Africa), Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. Switchboard 010 023 5200. Toll-free 0800 017 160.
enquiries@inforegulator.org.za · PAIAComplaints@inforegulator.org.za

To request a record from us:

  1. Complete PAIA Form 2, the request for access to a record of a private body. It is linked from this page and available from us on request.
  2. Say which right you are seeking to exercise or protect, and why the record is required for it.
  3. Send it to the Information Officer at the address in section 3, with proof of identity.
  4. Pay the prescribed request fee where one applies. The amounts are set by regulation and change, so we quote the current fee when we acknowledge the request rather than printing a figure here that may be out of date.
  5. We decide and notify you as soon as reasonably possible, and in any event within 30 days. We may extend that once, by up to 30 days, with reasons, and we will tell you inside the first 30 days if we do. If we do not decide in time, the request is regarded as refused.
  6. If we refuse, we give adequate reasons, and we tell you that you may complain to the Information Regulator or apply to court, and how.

5. Records available without a request

The company has not published a notice under section 52(2) of PAIA. Compiling one is voluntary.

These are freely available on request or from the website without a formal PAIA request:

6. Records held under other legislation

Records the company keeps because another law requires it, without limiting what else it holds:

  • Companies Act 71 of 2008: registers, financial records, minutes.
  • Basic Conditions of Employment Act 75 of 1997: employment particulars, time and pay records.
  • Labour Relations Act 66 of 1995: disciplinary and dispute records.
  • Employment Equity Act 55 of 1998: equity plans and reports where applicable.
  • Income Tax Act 58 of 1962, Tax Administration Act 28 of 2011, Value Added Tax Act 89 of 1991: tax records.
  • Unemployment Insurance Act 63 of 2001, Compensation for Occupational Injuries and Diseases Act 130 of 1993: statutory employment returns and injury records.
  • Occupational Health and Safety Act 85 of 1993: health and safety records.
  • Protection of Personal Information Act 4 of 2013: consent, request and incident records.
  • Private Security Industry Regulation Act 56 of 2001: registration and related records, where and to the extent that the company renders a security service as that Act defines it.

7. Subjects and categories of records

Subject Categories of records held
Clients and engagements Engagement letters, instructions, correspondence, case files, reports, invoices
Investigations and intelligence work Evidence, statements, notes, photographs and recordings gathered under an engagement, and the reports produced from them
Candidates and placements Applications, CVs, supporting documents, interview notes, vetting and check results, placement records
Employees and contractors Personnel files, contracts, payroll, leave, training, disciplinary records
Training Class registers, assessments, results, certificates
Suppliers Contracts, correspondence, invoices, banking details
Company Statutory registers, financial records, insurance, policies, security and access records
Website and enquiries Enquiry and newsletter records, website logs

8. Personal information the company processes

Purposes. Delivering investigation, intelligence, vetting and training services to clients; recruiting, placing and employing people; running the business, including invoicing, payroll and compliance with the law; responding to enquiries and, with consent, sending updates.

Categories of data subjects and the information held. Clients and their staff: names, roles, contact details, engagement correspondence. Subjects of an investigation: whatever the engagement lawfully requires, which may include identity details, employment history, conduct records, and evidence gathered lawfully in the course of the work. Candidates: names, contact details, demographic details they supply, work history, skills, CVs, supporting documents, vetting and check results. Employees: the full personnel record. Suppliers: contact and banking details. Website visitors: enquiry content and technical data.

Recipients. Our own staff on a need-to-know basis; the client who commissioned an engagement or for whom a candidate is placed; service providers processing on our written instruction (hosting, email, recruitment and case systems, accounting and payroll); and any person to whom a law requires disclosure, including a court, the police or a regulator.

Planned transborder flows. This website, and any document submitted through it, is hosted by Hostinger on servers in the European Union; at the date of this manual the site resolves to infrastructure in Lithuania and in Cyprus. That is a transfer under section 72, and it rests on our written agreement with the provider requiring protection substantially similar to POPIA. Our email runs on South African infrastructure. No other transborder flow is planned.

Security measures. Access limited to people whose work requires it; individual accounts and passwords; encrypted connections to the website and its forms; uploaded documents stored in access-controlled locations; premises and paper records secured; written contracts with processors requiring equivalent protection; and an incident process that notifies the Regulator and affected people where POPIA requires it.

Special personal information. Where an engagement or a vetting check involves criminal records or information about alleged conduct, we process it only where POPIA permits it and on the client's confirmed lawful ground, and we restrict who can see it.

9. Availability of this manual

  • On this website at www.trio-data.co.za/paia-manual.html, and as a PDF in the downloads section.
  • At the registered office during business hours, for public inspection.
  • To any person on request, on payment of a reasonable fee for the copy.
  • To the Information Regulator on request.

10. Approval and review

Version 1.0, effective 23 September 2026. Approved by Peter Muir, Director and founder. Next review due 23 September 2027, and immediately whenever the facts change.