Most companies only think about the Promotion of Access to Information Act (PAIA) when it is too late. You’ve heard of PAIA, your company probably has a Manual somewhere, and there is likely someone formally designated as an Information Officer. But when last did you actually think about what that role requires beyond the paperwork?
The 2025/26 submission window is now open and closes on 30 June 2026. The Regulator has been explicit: no extensions will be granted.
A straightforward guide for every information officer
The annual report is the compliance checkpoint that confirms your business is meeting its legal obligations. With the Information Regulator ramping up enforcement activity across both PAIA and POPIA, this requirement is becoming harder to ignore.
What your business is required to do
- Have a designated, registered Information Officer.
- Maintain a PAIA manual that describes the records your company holds and how to request them.
- Respond to any PAIA requests within the prescribed timeframes.
- Submit an annual report to the Information Regulator each year detailing your requests and responses.
FAQs about the PAIA annual report
Do I need to submit if we received zero requests?
Yes. The most common mistake is assuming a nil report is not needed. If your company received zero PAIA requests this year, you still need to submit the report to reflect that. The obligation to report is unconditional.
When is the deadline for the 2025/26 period?
The window closes on 30 June 2026. The Regulator has specifically asked companies to submit early to prevent system congestion. A technical issue on 29 June is not grounds for an extension.
What happens if my Information Officer is not registered?
Submission requires a registered Information Officer. If yours has not been formally registered with the Regulator, you must sort that first before attempting to file your report.
What good compliance looks like in practice
We have worked with companies who treated their first PAIA annual report submission as more than a tick box exercise. They used it as an opportunity to:
- Review and update their PAIA manual to reflect current business operations.
- Confirm their Information Officer’s registration details were accurate.
- Document their internal process for receiving and tracking PAIA requests.
- Create a simple compliance calendar to avoid the same scramble next year.
The result is a clean submission, a stronger compliance record, and one less liability sitting quietly in the background. When regulators, investors, or enterprise clients start asking questions about your data governance, this is the kind of detail that builds confidence.
Three months goes faster than you think
The window is open and the deadline is fixed. The only variable is how prepared your business is when you submit. If you are not sure whether your company is in scope, have not submitted before, or want to make sure this year’s report is accurate and complete, talk to us.
ITLawCo helps Information Officers across industries get this right, simply and efficiently.
→ Book a PAIA compliance review with ITLawCo. Let’s get it done.
This article is intended for general information purposes and does not constitute legal advice. For advice specific to your business circumstances, please consult with an ITLawCo attorney.




