COMPUREP / Information governance

COMPUREP PAIA Manual

A private-body manual prepared for review under section 51 of the Promotion of Access to Information Act 2 of 2000, as amended.

Version 1.0 — review draftPrepared 10 October 2026

Open your browser’s print options to print this document or save a PDF. The document status is included in the printed copy.

Prepared for company review

Review draft. The legal entity, registration number and Information Officer contact are confirmed. The head of the private body, postal details, officer registration, final record inventory, processing arrangements and adoption must still be verified. This draft must be completed and approved before being represented as the company’s final statutory manual.

This manual explains how to request records from COMPUREP - COMPUTER SPECIALISTS CC, which public information can be accessed directly, and how personal-information processing is addressed in the proposed records framework.

Legal entity
COMPUREP - COMPUTER SPECIALISTS CC
Registration
1995/034469/23
Information Officer contact
Keagan Booysen · IT Solutions Lead

The private body and contact particulars

Legal entity: COMPUREP - COMPUTER SPECIALISTS CC. Registration number: 1995/034469/23. COMPUREP provides IT solutions and support across Microsoft Cloud, Cybersecurity and IT Operations.

Business address: 13 Bruton Road, Bryanston Ridge Office Park, Bryanston, Sandton, Gauteng, South Africa. Telephone: +27 87 012 5296. Website: www.compurep.co.za.

Information Officer contact supplied by COMPUREP: Keagan Booysen, IT Solutions Lead, keagan@compurep.co.za. Requests and queries can be directed to this contact. The identity and direct particulars of the statutory head, postal address and fax availability, Information Officer registration and any deputy appointments require confirmation before adoption.

What PAIA covers and where to find help

PAIA provides a route to existing recorded information held or controlled by a body. For a private body, the requester must identify the right to be exercised or protected and explain why the requested record is required for that purpose. Access remains subject to the Act’s procedures and lawful refusal grounds.

The Information Regulator publishes a guide explaining PAIA and access to personal information, available in multiple official languages. Contact the Information Officer for assistance obtaining the guide or making a sufficiently clear request. A request for a new report, explanation or answer is not necessarily a request for an existing record.

Information available without a formal request

The public website provides service descriptions, company and team information, published contact details, the Microsoft licensing guide and the Trust & Security Centre’s notices. You can read these pages directly without identifying a right under PAIA. Browser print options are provided for this manual and the Website Privacy Notice.

This list describes material already made public. It does not establish a section 52 notice or make private client, staff, commercial or security records automatically accessible. Any formal section 52 notice must be recorded here if issued.

Subjects and categories of records

The following working inventory reflects the kinds of records relevant to an ICT and managed-services business. COMPUREP must validate what it actually holds or controls before approving this manual. Inclusion is not a promise that a particular record exists or that access will be granted.

Record inventory for operational confirmation
SubjectCategories to validate
Business governanceRegistration and founding documents, member or management decisions, delegations, policies and statutory submissions.
Finance and procurementAccounting, tax, invoices, payment, asset-purchase, supplier and contractual records.
People and employmentRecruitment, employment, payroll, training, leave and related workplace records.
Client relationshipsEnquiries, proposals, agreements, authorised contacts, service scope, correspondence and reviews.
Service deliveryTickets, work records, project documentation, asset and licence inventories, configuration and diagnostic records within the agreed scope.
Security and continuityAuthorisation records, access logs, incident records, risk reviews, backup and recovery records where maintained.
Suppliers and operatorsSupplier agreements, service-provider details, processing instructions and relevant confidentiality terms.
Information governancePAIA and privacy requests, outcomes, consent records where relevant, processing inventories and policy versions.

Records under other legislation

COMPUREP’s final inventory must identify the records it maintains under legislation that actually applies to its entity, employment, tax and service activities. Being listed under a law does not remove that law’s access conditions or make a record automatically public.

Legislative mapping to confirm before adoption
AreaRecords and legislation to assess
Close corporationFounding, member and accounting records under the Close Corporations Act 69 of 1984 and any applicable company-law provisions.
Tax and accountingTax and financial records under the Income Tax Act 58 of 1962, Tax Administration Act 28 of 2011 and, where applicable, Value-Added Tax Act 89 of 1991.
EmploymentRelevant records under the Basic Conditions of Employment Act 75 of 1997 and Labour Relations Act 66 of 1995, plus applicable employment-equity, UIF, compensation and skills legislation.
Privacy and accessProcessing and access-request records under POPIA 4 of 2013 and PAIA 2 of 2000.
Electronic business and servicesApplicable transaction, communications and service records, including any requirements of the Electronic Communications and Transactions Act 25 of 2002. Sector-specific duties depend on the service and legal role.

How to request a record

For a general service query, use the normal sales or support channel. For a POPIA objection or correction/deletion request, see the Website Privacy Notice: PAIA Form 2 is not a universal requirement for all privacy rights.

  1. Complete the current prescribed PAIA Form 2. Identify the requester and provide contact details, the record or sufficiently precise description, the requested form of access and the right to be exercised or protected. Explain why the record is required for that right.
  2. If acting for another person or organisation, provide the authority required by the form. Proportionate identity or authority checks may be necessary; do not send passwords or authentication codes.
  3. Address the request to the Information Officer contact, Keagan Booysen, at keagan@compurep.co.za, or contact him to arrange delivery at the business address. Ask for assistance if you cannot complete the form or need an accessible process.
  4. Keep a copy of the completed request, supporting correspondence and delivery information. COMPUREP must assess the request under PAIA; a submission or fee does not guarantee disclosure.

Decisions, time periods and fees

For an ordinary private-body request, the decision must be made as soon as reasonably possible and generally within 30 days after the request or required particulars are received. PAIA permits one extension of up to a further 30 days in the specified circumstances, with a notice explaining the extension. Third-party notification procedures can affect the applicable timetable.

The outcome should identify the decision and, if access is granted, the form of access and applicable fees. A refusal must give adequate reasons based on PAIA and explain the available remedies. If a record cannot be found or does not exist, PAIA provides for an affidavit or affirmation explaining the search. Severable material must be considered where only part of a record is lawfully withheld.

Prescribed request and access fees may apply. The Information Officer must communicate any applicable fee or deposit using the prescribed process. The current private-body tariff is linked below; it is separate from COMPUREP service pricing. Do not make a payment to an unverified account. Public-body fee exemptions should not be assumed to apply to private-body requests.

Disclosure limits and remedies

PAIA contains grounds protecting, among other matters, third-party privacy, confidential commercial information, safety, security and legal privilege, as well as a public-interest override in specified circumstances. Each request needs an assessment under the Act. A general confidentiality label is not, by itself, an automatic refusal.

The statutory internal appeal procedure for certain public bodies does not apply to this private body. If a request is refused or not answered within the applicable period, a requester may use the Regulator’s complaint process. Its published guidance provides for a complaint within 180 days of the relevant refusal or non-response; use the current guidance for the precise process and any condonation request. Court remedies are also available under PAIA, subject to the applicable procedure and time limits.

Personal-information processing

The proposed processing purposes are enquiries and proposals, client and supplier administration, agreed IT service delivery, employment administration, security, recordkeeping and legal obligations. The operational inventory must confirm the lawful basis, records and systems for each purpose. COMPUREP may be a responsible party for its own records and an operator for client-controlled information.

Processing description for section 51 review
ItemCOMPUREP framework to validate
Data subjects and informationProspects and client contacts: work identity and service needs. Authorised client users: relevant device, account and support details. Employees/applicants: relevant employment records. Suppliers: business and payment details.
RecipientsAuthorised personnel and client contacts; relevant contracted cloud, communications and service providers; professional advisers; legally authorised recipients. Confirm the actual recipients and operator agreements.
Planned international flowsCloud services and remote support may involve overseas processing. Confirm suppliers, destinations and the applicable POPIA section 72 transfer basis before finalising this section. No universal local-residency claim is made.
General security measuresProposed measures include role-appropriate access, confidentiality, suitable authentication, secure handling and maintenance, recovery arrangements and incident escalation. Verify implemented safeguards, ownership and evidence for the actual systems.
RetentionApprove a category-based retention schedule covering purpose, statutory duties, contractual requirements, backups and disposal. This draft does not establish a blanket retention period.

Regulator, availability and maintenance

Information Regulator (South Africa): Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191. Telephone: 010 023 5200 or 0800 017 160. General enquiries: enquiries@inforegulator.org.za.

PAIA complaints: PAIAComplaints@inforegulator.org.za. POPIA complaints: POPIAComplaints@inforegulator.org.za. Follow the relevant official complaint form and process.

The adopted manual must be available on COMPUREP’s website, for public inspection at its principal business premises during normal business hours, on request subject to a reasonable reproduction charge where applicable, and to the Information Regulator on request. The head must arrange regular updates. The public website currently provides this clearly marked review draft, including a browser print option.

Version 1.0 was prepared for review on 10 October 2026. Confirm the outstanding particulars and inventory, obtain the appropriate company approval and record the effective date before replacing this draft with the adopted manual.

Official references

Sources checked on 10 October 2026. These links provide the legislation and regulatory guidance used when preparing this document; they are not endorsements of COMPUREP.

Need help with a request?

Contact Keagan Booysen at keagan@compurep.co.za. Please start with a description of your enquiry and avoid including confidential records or credentials.

Return to the Trust & Security Centre