Access to Information Manual
Prepared in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 and the Protection of Personal Information Act 4 of 2013.
1. Introduction
This manual is published by Mendelson Attorneys Inc, trading as Mendelsons Attorneys, in terms of section 51 of the Promotion of Access to Information Act 2 of 2000 (“PAIA”).
PAIA gives effect to the constitutional right of access to information held by the State and to information held by another person where that information is required for the exercise or protection of any right.
This manual is intended to assist requesters who wish to request access to records held by Mendelsons Attorneys. It also provides information relating to the processing of personal information in terms of the Protection of Personal Information Act 4 of 2013 (“POPIA”).
This manual should be read together with our Privacy Policy, which explains how we collect, use, store, share and protect personal information.
2. Definitions
In this manual, unless the context indicates otherwise:
“Client” means a prospective, current or former client of Mendelsons Attorneys.
“Data subject” means the person to whom personal information relates, including an identifiable living natural person and, where applicable, an identifiable existing juristic person.
“Information Officer” means the person responsible for dealing with requests made under PAIA and for overseeing POPIA compliance within Mendelsons Attorneys.
“Mendelsons Attorneys”, “we”, “us” and “our” mean Mendelson Attorneys Inc, trading as Mendelsons Attorneys.
“PAIA” means the Promotion of Access to Information Act 2 of 2000, as amended, including any regulations made under it.
“Personal information” has the meaning given to it in POPIA and includes information relating to identifiable living natural persons and, where applicable, identifiable existing juristic persons.
“POPIA” means the Protection of Personal Information Act 4 of 2013, including any regulations or codes of conduct made under it.
“Processing” means any operation or activity concerning personal information, including collection, receipt, recording, organisation, storage, updating, retrieval, use, dissemination, restriction, erasure or destruction.
“Record” means recorded information, regardless of form or medium, in the possession or under the control of Mendelsons Attorneys, whether or not it was created by Mendelsons Attorneys.
“Requester” means any person requesting access to a record in terms of PAIA.
“Special personal information” has the meaning given to it in POPIA and includes, among other things, information relating to health, race or ethnic origin, biometric information, criminal behaviour, religious or philosophical beliefs, political persuasion, trade-union membership or sex life.
3. Purpose of this manual
The purpose of this manual is to:
identify the contact details of Mendelsons Attorneys and its Information Officer;
explain how a person may request access to records held by Mendelsons Attorneys;
describe the categories of records that may be held by Mendelsons Attorneys;
identify records that may be available without a formal PAIA request;
explain the prescribed request process and fees;
identify circumstances in which access may be refused;
provide information required under POPIA in relation to personal information processed by Mendelsons Attorneys; and
identify the remedies available to a requester if access is refused.
4. About Mendelsons Attorneys
Mendelsons Attorneys is a South African law firm based in Johannesburg.
We provide legal services to corporate and individual clients, including in relation to commercial disputes, litigation, insolvency, business rescue, financial restructuring, commercial advisory work, arbitration, mediation, white-collar defence and related matters.
5. Contact details
Mendelson Attorneys Inc trading as Mendelsons Attorneys
Telephone: +27 10 446 5750
Email: jeff@mattorneys.net
Information Officer: Jeff Mendelson
Email: jeff@mattorneys.net
Mobile: +27 83 634 4003
All requests under PAIA must be addressed to the Information Officer.
6. The Information Regulator’s PAIA Guide
The Information Regulator has published a guide explaining how to use PAIA and POPIA.
The guide is intended to assist members of the public who wish to exercise rights under PAIA or POPIA, including the right to request access to records.
The guide is available from the Information Regulator.
Information Regulator South Africa
Website: www.inforegulator.org.za
Email: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Toll-free: 0800 017 160
Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
7. Automatically available information
Certain information may be available without a formal PAIA request.
This may include:
information published on our website;
attorney profiles;
service descriptions;
insights, articles, updates and publications;
contact details;
website terms, disclaimers and policies;
our Privacy Policy;
this Access to Information Manual; and
other information that we make publicly available from time to time.
Information that is publicly available on our website need not be requested through the formal PAIA process.
8. Records held by Mendelsons Attorneys
Mendelsons Attorneys may hold records in the categories listed below.
The inclusion of a category in this manual does not mean that access to records in that category will automatically be granted. Each request will be considered on its own facts in accordance with PAIA, POPIA, legal professional privilege, confidentiality obligations and applicable law.
8.1 Corporate, statutory and governance records
We may hold records relating to our own business and statutory affairs, including:
company registration documents;
company secretarial records;
resolutions;
statutory records;
tax records;
accounting records;
financial records;
insurance records;
professional indemnity records;
internal policies and procedures;
operational records;
correspondence;
supplier agreements;
service-provider agreements;
technology and software records; and
records relating to compliance with applicable laws.
8.2 Client-related records
We may hold records relating to clients and matters, including:
client-onboarding records;
FICA and identity-verification records;
mandate and fee agreements;
engagement letters;
correspondence;
consultation notes;
instructions;
pleadings;
affidavits;
notices;
court documents;
arbitration, mediation and dispute-resolution documents;
settlement agreements;
opinions and memoranda;
contracts and commercial documents;
business rescue records;
insolvency records;
liquidation and sequestration records;
enquiry records;
company records;
financial records;
transaction documents;
evidentiary material;
expert reports;
counsel’s opinions and advices;
briefs to counsel;
attorney-client privileged communications;
documents received from clients, counterparties, courts, regulators or third parties; and
other records relating to legal services provided by us.
8.3 Supplier and service-provider records
We may hold records relating to suppliers and service providers, including:
contracts;
proposals and quotations;
invoices;
payment records;
tax information;
contact details;
correspondence;
service records;
information technology records;
confidentiality undertakings; and
due-diligence or verification information.
8.4 Personnel and employment-related records
We may hold personnel-related records, including:
employment contracts;
candidate attorney records;
contractor records;
consultant records;
payroll records;
leave records;
performance records;
disciplinary records;
training records;
statutory employment records;
emergency contact information;
tax and UIF records; and
internal correspondence.
Access to personnel-related records may be restricted in order to protect privacy, confidentiality and the rights of employees or other persons.
8.5 Financial and accounting records
We may hold financial records, including:
invoices;
statements;
receipts;
banking records;
trust-account records, where applicable;
accounting records;
tax records;
VAT records;
audit records;
ledgers;
payment records;
debtor records; and
creditor records.
8.6 Marketing, website and communication records
We may hold marketing and communication records, including:
website content;
insights, articles and publications;
newsletters;
mailing-list records;
subscription records;
event records;
marketing preferences;
social media content;
media material;
business-development records; and
general communications.
8.7 Information technology and security records
We may hold information technology and security records, including:
software records;
system administration records;
access-control records;
cybersecurity records;
backup records;
data-storage records;
website analytics records;
device and system records;
email and communication records; and
records relating to information-security measures.
9. Records available in terms of other legislation
Where applicable to our operations, we may hold records in terms of legislation including:
the Companies Act 71 of 2008;
the Promotion of Access to Information Act 2 of 2000;
the Protection of Personal Information Act 4 of 2013;
the Financial Intelligence Centre Act 38 of 2001;
the Income Tax Act 58 of 1962;
the Value-Added Tax Act 89 of 1991;
the Basic Conditions of Employment Act 75 of 1997;
the Labour Relations Act 66 of 1995;
the Employment Equity Act 55 of 1998;
the Occupational Health and Safety Act 85 of 1993;
the Compensation for Occupational Injuries and Diseases Act 130 of 1993;
the Broad-Based Black Economic Empowerment Act 53 of 2003;
the Prevention and Combating of Corrupt Activities Act 12 of 2004;
the Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002;
the Legal Practice Act 28 of 2014;
the Superior Courts Act 10 of 2013;
the Magistrates’ Courts Act 32 of 1944;
the Insolvency Act 24 of 1936;
the Companies Act 61 of 1973, to the extent that it remains applicable to liquidation and winding-up matters;
the National Credit Act 34 of 2005, where applicable; and
any other legislation applicable to our professional services or business operations.
The fact that a record is held under any legislation does not mean that access will automatically be granted. Access remains subject to PAIA, POPIA, legal professional privilege, confidentiality, applicable court rules and any other applicable law.
10. POPIA information
10.1 Categories of data subjects
We may process personal information relating to the following categories of data subjects:
clients;
prospective clients;
former clients;
directors, shareholders, members, trustees, partners and beneficial owners of clients or counterparties;
witnesses;
debtors and creditors;
business rescue practitioners;
liquidators, trustees, curators and other office-holders;
counsel, experts, correspondent attorneys and professional advisers;
counterparties and opposing parties;
suppliers and service providers;
employees, candidate attorneys, contractors, consultants and job applicants;
website users;
newsletter subscribers;
event attendees;
representatives of courts, tribunals, regulators and public bodies; and
any other person whose personal information may be processed in connection with our legal services or business operations.
10.2 Categories of personal information
We may process categories of personal information including:
identifying information;
contact information;
company and juristic-person information;
FICA and verification information;
beneficial-ownership information;
financial information;
bank-account and payment information;
tax information;
employment information;
family and relationship information where relevant to a matter;
litigation and dispute information;
criminal, regulatory or investigation-related information where relevant;
health or medical information where relevant;
special personal information where lawful and necessary;
correspondence and communication records;
website-use and analytics information; and
any other information necessary for the provision of legal services or the operation of our firm.
10.3 Purposes of processing personal information
We process personal information for purposes including:
client onboarding;
identity verification;
FICA, anti-money-laundering, sanctions and risk checks;
conflict checks;
providing legal services;
carrying out instructions;
representing clients in legal proceedings and negotiations;
drafting, reviewing and implementing legal documents;
managing accounts, billing and payments;
complying with legal, regulatory, tax and professional obligations;
preventing and detecting fraud, corruption, money laundering and unlawful conduct;
maintaining professional records and internal know-how;
managing our business operations;
communicating with clients, service providers and other parties;
managing marketing, newsletters and events;
improving our website, systems and services;
protecting legal rights; and
any other lawful purpose connected with our business or professional obligations.
10.4 Recipients of personal information
Depending on the matter and the purpose of processing, personal information may be shared with:
our directors, attorneys, candidate attorneys, employees, consultants and authorised representatives;
counsel;
correspondent attorneys;
experts and consultants;
courts, tribunals, arbitrators, mediators, commissioners and regulators;
sheriffs, liquidators, trustees, business rescue practitioners, curators and office-holders;
banks, auditors, accountants, insurers and tax advisers;
information-technology, cloud, data-storage, cybersecurity and document-management service providers;
tracing agents, search providers, verification providers and compliance service providers;
counterparties and their representatives, where necessary for a matter;
law-enforcement agencies, tax authorities and public bodies where required or permitted by law; and
any person authorised by you or by law to receive the information.
10.5 Transborder transfers
We may transfer personal information outside South Africa where necessary and lawful, including where:
a matter has a cross-border element;
foreign counsel, attorneys, experts or service providers are involved;
cloud, software, email or data-storage services are hosted outside South Africa;
international verification, compliance or search providers are used; or
we are required or permitted by law or by a client’s instruction to do so.
Where personal information is transferred outside South Africa, we will take reasonable steps to ensure that the transfer complies with applicable data-protection laws.
10.6 Information-security measures
We take reasonable technical and organisational measures to protect personal information.
These measures may include:
access controls;
password protection and authentication controls;
firewalls;
anti-virus and anti-malware tools;
secure backups;
confidentiality obligations;
secure document management;
restricted access to matter files;
physical security measures;
staff awareness and internal controls; and
procedures for dealing with suspected or actual security compromises.
11. Request procedure under PAIA
A requester who wishes to obtain access to a record held by Mendelsons Attorneys must submit a request to the Information Officer.
The request must be made on the prescribed PAIA form, currently Form 2: Request for Access to Record, or on a form that substantially corresponds with it.
The request should:
provide sufficient detail to identify the requester;
provide sufficient detail to identify the record requested;
identify the right that the requester seeks to exercise or protect;
explain why the requested record is required for the exercise or protection of that right;
identify the form of access required;
provide contact details for correspondence;
indicate whether the requester is acting on behalf of another person; and
include proof of authority, if the requester acts on behalf of another person.
Requests must be sent to:
Information Officer: Jeff Mendelson
Email: jeff@mattorneys.net
Mobile: +27 83 634 4003
We may require proof of identity before processing any request.
12. Requests relating to personal information under POPIA
A data subject may request confirmation of whether we hold personal information about them.
A data subject may also request access to personal information held by us, or request correction, deletion or destruction of personal information where permitted by law.
A data subject may object to the processing of personal information on reasonable grounds where POPIA permits such objection.
Requests relating to personal information must be submitted to the Information Officer and may require use of the forms prescribed by the Information Regulator.
We may refuse, limit or defer a request where permitted or required by law, including where the request would affect legal privilege, confidentiality, the rights of another person, litigation, investigations, regulatory obligations or professional duties.
13. Fees
The prescribed PAIA fees may be payable.
For private bodies, the current prescribed request fee is R140.00, subject to amendment by law or regulation.
Access fees may also be payable for:
photocopying;
printing;
electronic copies;
transcription;
search and preparation time;
postage;
electronic transmission; and
any other prescribed item.
If a search for records is likely to exceed the prescribed period, we may require payment of a deposit before continuing with the request.
Where a request is granted, access to the record may be withheld until the applicable fees have been paid.
14. Time periods
We will consider a PAIA request within the period prescribed by PAIA.
The ordinary period is 30 days from receipt of a valid request.
This period may be extended where PAIA permits an extension, including where the request is complex, involves a large volume of records, requires a search through records held at more than one location, or requires consultation with a third party.
If an extension is required, we will notify the requester in accordance with PAIA.
15. Grounds on which access may be refused
Access to records may be refused where PAIA permits or requires refusal.
Grounds for refusal may include:
protection of the privacy of a third party;
protection of commercial information of a third party;
protection of confidential information of a third party;
protection of safety or property;
protection of records privileged from production in legal proceedings;
protection of legally privileged attorney-client communications;
protection of confidential client information;
protection of our commercial information;
protection of research information;
protection of information supplied in confidence;
protection of records relating to legal proceedings, investigations or dispute resolution;
where disclosure would breach a legal, professional, contractual or ethical duty;
where the request is frivolous, vexatious or an abuse of process; or
where any other ground of refusal recognised by PAIA or applicable law applies.
Many records held by Mendelsons Attorneys are confidential client records or legally privileged records. Requests for access to those records will be considered with particular care.
16. Third-party records and consultation
If a requested record relates to, or contains information about, a third party, we may be required to notify that third party and provide an opportunity for representations before deciding whether access should be granted.
Where third-party notification is required, the time periods and procedures in PAIA will apply.
17. Public-interest override
PAIA contains a public-interest override in certain circumstances.
Where the requirements of the public-interest override are met, disclosure may be required despite a ground of refusal. This will be assessed strictly in accordance with PAIA.
18. Decision on request
After considering a valid request, we will notify the requester whether access is granted or refused.
If access is granted, we will advise:
the form in which access will be given;
any fees payable;
when access will be provided; and
any other relevant conditions.
If access is refused, we will provide reasons for refusal as required by PAIA and advise the requester of available remedies.
19. Remedies if access is refused
If a requester is dissatisfied with our decision, the requester may use the remedies available under PAIA.
As Mendelsons Attorneys is a private body, there is no internal appeal procedure under PAIA.
A requester may, where applicable:
lodge a complaint with the Information Regulator; or
apply to a court with jurisdiction for appropriate relief.
The Information Regulator’s contact details are:
Information Regulator South Africa
Website: www.inforegulator.org.za
Email: enquiries@inforegulator.org.za
Telephone: 010 023 5200
Toll-free: 0800 017 160
Address: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
20. Availability of this manual
This manual is available:
on our website;
for inspection at our offices during normal business hours, by prior arrangement; and
on request from the Information Officer.
A copy may also be submitted to, or made available through, the Information Regulator where required.
21. Updates to this manual
We may update this manual from time to time.
The latest version will be the version published on our website or otherwise made available by us.