- Purpose: To facilitate access to records held by Legacy Risk as a private body, fostering constitutional transparency, accountability, and good corporate governance.
- Responsible Entity: Legacy Risk (A South African Private company).
- Designated Officer: Bryan Botha (bryan@legacyrisk.co.za).
- Procedure: Formal requests must be lodged using prescribed Form 2, accompanied by payment of the statutory request fee and verifiable identification.
1. Introduction & Nature of Business
The Promotion of Access to Information Act, No. 2 of 2000 ("PAIA") gives effect to the constitutional right of access to any information held by the State, and any information that is held by another person and that is required for the exercise or protection of any rights.
This Manual applies to Legacy Risk ("Legacy Risk"), a private body incorporated under the company laws of South Africa. Legacy Risk develops digital forensic ecosystems, automated cybersecurity diagnostic scanning engines (A1 Audit), and security workforce management software (EasyTrac).
2. Contact Details of the Information Officer
In terms of Section 51(1)(a) of PAIA and Section 55 of POPIA, the designated Information Officer of Legacy Risk is detailed below:
Entity: Legacy Risk
Designated Information Officer: Bryan Botha
Physical Location: Republic of South Africa (Gauteng / National Operations)
Direct Email: bryan@legacyrisk.co.za
Telephone: 081 806 8993
Official Website: https://legacyrisk.co.za
3. The Information Regulator’s Section 10 Guide
The Information Regulator has compiled a comprehensive guide containing practical information to assist any person wishing to exercise their rights under PAIA and POPIA.
This Guide is available in all eleven official languages of South Africa and can be downloaded from the Information Regulator’s website or requested from their offices:
- Website: https://inforegulator.org.za/
- General Enquiries Email: enquiries@inforegulator.org.za
- Postal Address: P.O Box 31533, Braamfontein, Johannesburg, 2017
- Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
4. Records Automatically Available (Section 51(1)(c))
Certain records are publicly accessible without the need to submit a formal PAIA request. These include:
- Public marketing materials, product whitepapers, and software feature overviews.
- Publicly available diagnostic scanner interfaces (A1 Website Security Audit).
- Informational articles, guides, and Generative Engine Optimization insights.
- Our published Privacy Policy and Terms of Service.
5. Records Held in Accordance with Other South African Legislation
Legacy Risk retains records in compliance with statutory obligations under the following South African laws:
Companies Act 71 of 2008, Value-Added Tax Act 89 of 1991, Income Tax Act 58 of 1962, Financial Intelligence Centre Act (FICA).
Basic Conditions of Employment Act 75 of 1997, Labour Relations Act 66 of 1995, Occupational Health and Safety Act 85 of 1993, NBCPSS Sectoral Determination 6.
Protection of Personal Information Act 4 of 2013, Cybercrimes Act 19 of 2020, Electronic Communications & Transactions Act 25 of 2002, PSIRA Act 56 of 2001.
6. Subjects and Categories of Records Held by Legacy Risk
The records held by Legacy Risk are categorized as follows (access remains subject to PAIA statutory grounds for refusal):
- Statutory Company Records: Memorandum of Incorporation, registration certificates, director registers, and official board minutes.
- Financial & Accounting Records: Annual financial statements, VAT returns, tax assessments, banking records, and invoicing ledgers.
- Human Resources: Employment agreements, staff credentials, disciplinary records, and payroll documentation.
- Client & Technical Records: Client service agreements, diagnostic scan logs, system architecture blueprints, and encrypted audit trails.
7. Procedure for Requesting Access to Records (Section 53)
To request access to a record not automatically available, the requester must follow the prescribed procedure:
- Complete Prescribed Form 2: Obtain and complete Form 2 (Request for Access to Record of Private Body), available from the Information Regulator’s website.
- Identify the Record: Provide sufficient detail in the request form to enable the Information Officer to clearly identify the record and the requester.
- State the Right Being Exercised: Specify the constitutional or legal right the requester wishes to exercise or protect, and provide an explanation of why the requested record is required for that purpose.
- Submit Identification: Provide certified proof of identification (or proof of capacity if acting on behalf of another person).
- Submit to Information Officer: Deliver or email the completed application to bryan@legacyrisk.co.za.
8. Prescribed Fees (Section 54)
PAIA provides for two types of statutory fees:
- Request Fee: A statutory, non-refundable fee (prescribed by the Minister of Justice under the PAIA regulations) payable upon submitting the request, unless the requester is exempt under the Act.
- Access Fee: If access to the record is granted, the requester is liable for search, preparation, and reproduction costs (photocopying, electronic transfer, transcription, and postage).
9. Grounds for Statutory Refusal of Access
In terms of Chapter 4 of PAIA, Legacy Risk is legally entitled or mandated to refuse access to records on the following statutory grounds:
- Mandatory protection of the privacy of a third party who is a natural person (including deceased individuals), in accordance with POPIA.
- Mandatory protection of the commercial information of a third party (including trade secrets, proprietary algorithms, financial, or technical information).
- Mandatory protection of confidential information of third parties protected by contractual agreement.
- Mandatory protection of the safety of individuals and the physical or digital security of property or computer systems.
- Mandatory protection of records privileged from production in legal proceedings.
10. Statutory Remedies for Refusal & Information Regulator Complaints
If a request for access to records is refused, or if the requester is dissatisfied with the fees assessed:
The requester may lodge a formal complaint with the South African Information Regulator within 180 days of the decision, using prescribed Form 5:
Email for PAIA Complaints: PAIAComplaints@inforegulator.org.za
Email for POPIA Complaints: POPIAComplaints@inforegulator.org.za
Postal Address: P.O Box 31533, Braamfontein, Johannesburg, 2017
Questions Regarding Our Compliance Manual or Data?
Our dedicated Information Officer and compliance specialists are available to answer your statutory inquiries.
Contact Information Officer