HomeBlogSomeone Asked for Their Data. Here Is Your 30 Days.

Someone Asked for Their Data. Here Is Your 30 Days.

The 30 day deadline, verifying who is asking, protecting other people in the record, when you may refuse, and what you are allowed to charge.

The clock started when the email arrived

Somebody has written to you asking what personal information you hold about them, and possibly asking for a copy. It might be a former employee, a customer who fell out with you, an attorney acting for someone, or a person who simply wants to know.

This is a data subject access request, and it is one of the few POPIA obligations with a running clock attached. Most businesses have never designed a process for it and improvise under time pressure, which is how avoidable mistakes happen: ignoring it, over-disclosing, handing information to the wrong person, or refusing without explaining why.

This is what the request is, what you owe, what you may refuse, and what to do in the next thirty days.

A request does not have to look like one

There are no magic words. An email saying "please send me everything you have about me" is a request. So is a letter from an attorney, and so is a message that arrives through your contact form.

Two practical consequences:

  • Anyone in your business might receive one. If it lands in a shared inbox or with a junior staff member who does not recognise it, the clock still runs. Staff need to know what to look for and who to send it to.
  • A prescribed form exists, but do not hide behind it. Access to personal information runs through the machinery of PAIA, which has a prescribed request form. If someone has not used it, the sensible response is to acknowledge the request and help them complete it. Where a request is incomplete, the Information Officer is expected to assist rather than to reject it on a technicality. Treating the form as a way to make the problem go away is exactly the behaviour that turns a request into a complaint.

Two different things they can ask for

Section 23 gives a data subject the right to ask for two distinct things, and they are treated differently.

Confirmation that you hold their information. A yes or no. This is free. You may not charge for telling someone whether you have a record about them.

The record itself, or a description of it. This is where a prescribed fee may apply, and where the real work sits.

Getting the distinction right matters, because a business that responds to "do you hold my information" with a fee demand has already made an error.

You have 30 days

The standard period for deciding on an access request is 30 days from receipt. It is extendable where the request genuinely warrants it, for instance where the volume of records is large or they are spread across systems, but an extension is something you notify, not something you assume.

Practically, treat the 30 days as a decision deadline rather than a delivery deadline, and do these things immediately:

  • Acknowledge receipt in writing and date it. This alone defuses most of the friction, because the common complaint is silence rather than refusal.
  • Diarise the deadline the day it arrives.
  • Start the search early. The delay is almost never the decision, it is finding the records.

If you need an extension, say so before the 30 days expire, explain why, and give a realistic date. Asking is far better received than going quiet.

Verify who is asking

Before you send anything, establish that the requester is who they say they are. Sending someone's personal information to an impersonator is itself a security compromise, and a more serious problem than a late response.

  • Ask for reasonable proof of identity, proportionate to the sensitivity of what is held.
  • If an attorney or family member is requesting on someone's behalf, ask for proof of the mandate.
  • Do not use verification as a delaying tactic. Repeatedly demanding more documents is transparent and will not read well later.
  • Verify through a channel you already have, rather than one supplied only in the request.

Other people are in your records too

This is the part that needs judgement. A record about one person frequently contains information about others: an email thread, a complaint naming a staff member, a CCTV clip with other customers in frame, a meeting note.

Those third parties have their own rights, and they do not evaporate because someone else asked. The usual approach is to give the requester their information while protecting other people's, by redacting names and identifying details, or by supplying an extract rather than a whole document.

What you should not do is either extreme. Refusing the whole request because a third party is mentioned is over-broad. Handing over the entire unredacted file is a disclosure of someone else's information that you will struggle to justify.

When you may refuse

The right of access is not unlimited. The grounds for refusal come from PAIA, and the ones that most often apply to a private business include:

  • Protection of a third party's privacy
  • Commercially sensitive information, trade secrets, or information that would harm your commercial interests
  • Legally privileged material, which is why correspondence with your attorney about a dispute is usually protected
  • Information whose disclosure would prejudice legal proceedings

Where you refuse, the refusal must be explained. Tell the requester that you are refusing, on what ground, and that they may complain to the Information Regulator. A bare "no" is not a lawful refusal, and a refusal notice should not describe the content of the record you are withholding.

Note also that a live dispute is not, by itself, a ground for refusal. A lot of requests arrive from people who are already unhappy with you. That is uncomfortable but not a legal answer.

What you may charge

Fees for access are prescribed rather than set by you, and a private body may not charge more than the prescribed amount. There is typically a request fee and a separate access fee based on what is involved in reproducing the record.

Two rules matter procedurally. Where a fee is payable, you must give the requester a written estimate before doing the work, and you may require a deposit. And confirmation of whether you hold information remains free.

In practice, for a small business responding to a straightforward request, the pragmatic move is often to waive the fee. The administrative cost of invoicing and collecting usually exceeds the amount, and charging tends to escalate an already tense situation.

The response itself

A good response is boring, complete and dated. Cover:

  • What you hold about them, in a form they can actually read
  • Where it came from, if not from them
  • What you use it for
  • Who it has been shared with, or the categories of recipient
  • How long you keep it
  • Anything you are withholding, and on what ground
  • Their rights to correct or delete, to object, and to complain to the Regulator

Send it in a way that protects the contents. Emailing a spreadsheet of someone's personal information to an unverified address is a poor ending to an otherwise careful process. And keep a copy of exactly what you sent and when, because if this becomes a complaint, that record is your defence.

Requests that are really something else

Several different rights arrive worded as "send me my information", and they run on different tracks:

  • Correction or deletion falls under section 24, and there is a prescribed form for it. If someone says your record is wrong, that is a correction request even if they did not use the word.
  • Objection to processing falls under section 11(3), with its own form. Common where someone objects to marketing.
  • Unsubscribe requests are usually a direct marketing matter under section 69 rather than an access request. See is cold emailing legal in South Africa.
  • A PAIA request from someone who is not the data subject, such as a journalist or a litigant seeking records about your business, is a different process again and one your PAIA manual should describe.

Work out which one you have received before you answer it.

Build the process before you need it

Thirty days is comfortable if you are ready and very short if you are not. A workable process for a small business fits on one page:

  • A named person who handles requests, which is your Information Officer by default.
  • A monitored address where requests can be sent, published in your privacy notice.
  • A short internal note telling staff how to recognise one and who to forward it to.
  • A list of systems to search: email, CRM, accounting, backups, the shared drive, WhatsApp. The list is the part people forget, and the reason responses come back incomplete.
  • A simple log of requests received, what you sent, and when.

That log is worth the effort on its own. Releasing someone's information is a disclosure, and being able to account for your disclosures is a real advantage if you are ever asked to explain yourself.

A short checklist for the request on your desk

  • Have you acknowledged it in writing and diarised 30 days?
  • Have you confirmed the requester's identity?
  • Do you know which right is actually being exercised?
  • Have you listed every system that might hold their information?
  • Have you checked what belongs to other people and redacted it?
  • If you are withholding anything, have you stated the ground?
  • If charging, did you give a written estimate first?
  • Are you sending it securely, and keeping a copy of what you sent?

POPIA Ready generates a privacy policy setting out how people can exercise these rights with you, a PAIA manual, and five other documents customised to your business. Free to preview. The free checklist will show you what else is missing.

General guidance on South African law as at August 2026, not legal advice. Access requests interact with PAIA, and a request involving litigation, privilege or a large volume of records deserves a professional opinion.

Get Compliant Today

Don't risk fines or reputational damage. Generate professional, POPIA compliant legal documents for your website in 60 seconds.

Generate Documents - Free to Preview

Continue Reading

Your WhatsApp Messages Are Records You Must Keep for Five Years

Read article →

Reading an Employee's Email Can Be a Criminal Offence

Read article →

Adding a Customer to a WhatsApp Group Shows Everyone Their Number

Read article →