Skip to content

PAIA Manual

In terms of section 51 of the Promotion of Access to

Information Act 2 of 2000 (as amended)

1. List of Acronyms, Abbreviations and Definitions

  • “Company” Hereford Financial Services (Pty) Ltd, Registration 1998/020101/07
  • “DIO” Deputy Information Officer
  • “Data Subject” means the person to whom personal information relates
  • “IO” Information Officer
  • “PAIA” Promotion of Access to Information Act 2 of 2000 (as amended)
  • “POPIA” Protection of Personal Information Act 4 of 2013
  • “HFS” Hereford Financial Services (Pty) Ltd, Registration 1998/020101/07
  • “Regulator” Information Regulator
  • “Republic” Republic of South Africa

2. Introduction

  • PAIA was enacted to give effect to, among other things, section 32 of the Constitution of the Republic of South Africa, 1996, namely the right to access to information. Specifically, information held by the State and information held by any other person when that information is required for the exercise or protection of any right.
  • In terms of section 51 of PAIA, private institutions are obliged to compile a manual to facilitate the foregoing objective (“PAIA Manual”).

3. Purpose of PAIA Manual

This PAIA Manual is for use by the public to:

  • check the categories of records held by the Company which are available without a person having to submit a formal PAIA request;
  • have a sufficient understanding of how to make a request for access to a record of the Company, by providing a description of the subjects on which the Company holds records and the categories of records held on each subject;
  • know the description of the records of the Company which are available in accordance with any other legislation;
  • access all the relevant contact details of the IO and the DIO(s) who will assist the public with the records they intend to access;
  • know the description of the guide on how to use PAIA, as updated by the Regulator, and how to obtain access to it;
  • know if the Company will process personal information, the purpose of processing of personal information and the description of the categories of Data Subjects and of the information or categories of information relating thereto;
  • know the description of the categories of Data Subjects and of the information or categories of information relating thereto;
  • know the recipients or categories of recipients to whom the personal information may be supplied;
  • know if the Company has planned to transfer or process personal information outside the Republic and the recipients or categories of recipients to whom the personal information may be supplied; and
  • know whether the Company has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.

4. Key Contact Details for Access to Information of the Company

4.1. Information Officer

Name: ____________________________

Designation: Head: Group Legal and Compliance

Tel:

Email: janinen@herefordgroup.co.za

4.2. Deputy Information Officers

Name: ____________________________

Designation: Chief Operations Officer – HFS

Tel:

Email: _______________@herefordgroup.co.za

4.3. Head Office

Physical Address:

Hereford Group Building
Ground Floor, Building 2
Central Park, 2 West Park
Century City, Cape Town, 7441

Telephone: 021 552 7136

Email: info@herefordgroup.co.za

Website: www.herefordgroup.co.za

5. Guide on How to Use PAIA and How to Obtain Access to the Guide

  • The South African Human Rights Commission has compiled a guide on how to use PAIA (“Guide”). The Regulator has, in terms of section 10(1) of PAIA, updated and made available a revised version of the Guide in a comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
  • The Guide is available in each of the official languages.
  • The aforesaid Guide contains the description of:
    • the objects of PAIA and POPIA;
    • the postal and street address, phone and fax number and, if available, electronic mail address of the Information Officer of every public company, and every Deputy Information Officer of every public and private company designated in terms of section 17(1) of PAIA and section 56 of POPIA;
    • the manner and form of a request for access to a record of a public company contemplated in section 11 of PAIA, and access to a record of a private company contemplated in section 50 of PAIA;
    • the assistance available from the Information Officer of a public company in terms of PAIA and POPIA;
    • the assistance available from the Regulator in terms of PAIA and POPIA;
    • all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, and an application with a court against a decision by the information officer of a public company, a decision on internal appeal or a decision by the Regulator or a decision of the head of a private company;
    • the provisions of sections 14 and 51 of PAIA requiring a public company and a private company, respectively, to compile a manual, and how to obtain access to a manual;
    • the provisions of sections 15 and 52 of PAIA providing for the voluntary disclosure of categories of records by a public company and a private company, respectively;
    • the notices issued in terms of sections 22 and 54 of PAIA regarding fees to be paid in relation to requests for access; and
    • the regulations made in terms of section 92 of PAIA.
  • Members of the public can inspect or make copies of the Guide from the office of the Regulator, during normal working hours.
  • The Guide can also be obtained upon request to the Information Officer via e-mail with a form that corresponds substantially with form 1 of Annexure A to the PAIA Regulations, or from the website of the Regulator (inforegulator.org.za).

6. Information Requests

  • In terms of Chapter 1 of Part 3, Section 50 of PAIA, any person may request access to information from the Company, and must be given access to same, provided that:
    • the record is required for the exercise or protection of any rights;
    • the requester complies with the procedural requirements as defined in PAIA for a request to access a record; and
    • access to a record is not refused on any ground for refusal as contemplated in Chapter 4 of Part 3 of PAIA.
  • In terms of Section 23 of POPIA, a Data Subject, having provided adequate proof of identity, has the right to:
    • request confirmation, free of charge, of whether or not the Company holds personal information about the Data Subject;
    • request the record, or a description of the personal information, held by the Company, including information about the identity of all third parties, or categories of third parties, who have, or have had, access to the information – within a reasonable time, at a prescribed fee (if any), in a reasonable manner and format, and in a form that is generally understandable.

7. How to Request Information

  • Complete the relevant form that can be acquired from the revised Guide referred to in paragraph 5 above.
  • If a request is made on behalf of another person, then the requester must submit proof of the capacity in which the requester is making the request to the reasonable satisfaction of the IO.
  • Submit the form to the IO or the DIO at the physical address or electronic mail address, as stated above.
  • The requester must pay the prescribed fee (as explained in paragraph 8 below) before any further processing can take place.
  • The Company will process the request within 30 days, unless the requester has stated special reasons which would satisfy the IO that circumstances dictate that the above time periods will not be complied with.
  • Records held by the Company may be accessed by requesters only once the prerequisite requirements for access have been met. A requester is any person making a request for access to a record of the institution. There are two types of requesters:
    • a Personal Requester: being a person seeking access to a record containing personal information about him/her/itself; and
    • an Other Requester: this person is entitled to request access to information on third parties. However, the Company is not obliged to voluntarily grant access.

8. Fees

  • PAIA provides for two types of fees which can be established by reference to the Guide referred to above:
    • a request fee, which will be a standard fee; and
    • an access fee, which must be calculated by taking into account reproduction costs, search and preparation time and cost, as well as postal costs.
  • When the IO receives the request, he/she shall notify the requester to pay the prescribed request fee (if any), before any further processing of the request. The IO may withhold a record until the requester has paid the fees. If a deposit has been paid in respect of a request for access which is refused, then the IO concerned must repay the deposit to the requester.
  • The prescribed fees can be found in the Guide referred to in paragraph 5.

9. Refusal to Grant Access to Records

  • The Company will, within 30 days of receipt of the request, decide whether to grant or decline the request and give notice with reasons (if required) to that effect.
  • The 30-day period within which the Company has to decide whether to grant or refuse the request may be extended for a further period of not more than 30 days if the request is voluminous, or the request requires a search for information held at another office of the Company and the information cannot reasonably be obtained within the original 30-day period. The Company will notify the requester in writing should an extension be required.
  • The main grounds to refuse a request for information are:
    • mandatory protection of the privacy of a third party who is a natural person, which would involve unreasonable disclosure of personal information of that natural person;
    • mandatory protection of the commercial information of a third party, if the record contains trade secrets of that third party; financial, commercial, scientific or technical information, other than trade secrets, disclosure of which could likely cause harm to the financial or commercial interest of that third party; or information disclosed in confidence by a third party to the Company, if the disclosure could put that third party at a disadvantage in contractual, or other, negotiations or prejudice that third party in commercial competition;
    • mandatory protection of confidential information of a third party if its disclosure would constitute an action for breach of a duty of confidence owed to a third party in terms of any agreement;
    • mandatory protection of the life or physical safety of individuals and the protection of property;
    • mandatory protection of records which would be regarded as privileged from production in legal proceedings;
    • the protection of the commercial information of the institution, which may include trade secrets; financial, commercial, scientific or technical information, other than trade secrets, disclosure of which would likely cause harm to the financial or commercial interests of the institution; information which, if disclosed, could reasonably be expected to put the institution at a disadvantage in contractual or other negotiations or prejudice the institution in commercial competition; or a computer program owned by the institution and protected by copyright;
    • mandatory protection of the research information of the institution or a third party, if its disclosure would be likely to expose the institution, the third party, the researcher or the subject matter of the research to serious harm; and
    • requests for information that are clearly frivolous or vexatious, or which involve an unreasonable diversion of resources, shall be refused.

10. Notice in Terms of Section 52(2) of PAIA

As at the date of publishing of this version of the PAIA Manual, no notice has been published in terms of section 52(2) of PAIA.

11. Records of the Company Which are Available Without a Person Having to Request Access

The records of the Company which are available without a person having to request access are available at www.herefordgroup.co.za and include:

  • Access to Information Manual
  • Career Vacancy Advertisements
  • Executive Officer Details: name, employment history, qualifications and date of appointment
  • Financial Adviser Details: name, address, contact details, qualifications and specialisation
  • FSP Licence(s) and ancillary information
  • Fund Performance Notices
  • Group Corporate Structure and Information
  • Group Privacy Policy(ies) and Procedure
  • Information pertaining to the Company’s products and services published on the Company website and generally available within the public domain
  • Listing Information and updates
  • Newsletters
  • Promotional and marketing material published on the Company website and generally available within the public domain
  • Trading and Investment Forms: Local and Global, and ancillary information

12. Records of the Company Which are Available in Accordance with Legislation

All records kept and/or information processed in terms of relevant legislation are available in accordance with said legislation and apply, but are not limited, to the following:

Applicable LegislationCategory of Record
Basic Conditions of Employment Act 75 of 1997
  • Employee details
  • Labour relations reports
  • Information regarding dismissals
  • Information on disability, race and religion
  • Employee next of kin or emergency contact details
  • Conflict-of-interest declarations
  • Education information
  • Health and safety records
  • Pension and provident fund records
  • Leave records
  • Internal evaluations and performance records
  • Disciplinary records
  • Training records
  • Background checks
Companies Act 71 of 2008
  • Memorandum of incorporation
  • Annual financial statements
  • Share register
  • CIPC company registration document
  • Registration certificate
  • Certificate of incorporation
  • Details of all share trades by employees, directors and officers
  • Own-organisational title deeds
  • Company rules
  • Records of directors
  • Copies of reports presented at annual general meetings
  • Notices and minutes of shareholder meetings
  • Resolutions and their supporting documents
  • Copies of written communications sent to securityholders
  • Minutes of meetings of directors, directors’ committees, audit committees, shareholders
  • Securities registers
  • Record of company secretaries and auditors
Compensation of Occupational Injuries and Diseases Act 130 of 1993
  • Record of earnings and other prescribed particulars of all employees
  • Auction-related records
  • Promotional-competition-related records
Consumer Protection Act 68 of 2008
  • Promotion and marketing material
  • Terms and conditions
  • Direct marketing consent
  • Complaints process document
Copyright Act 98 of 1978 (as amended by Act 2 of 2002)
  • Software licences
Disaster Management Act 57 of 2002
  • Covid-19 registers
  • Business continuity management plans
  • Business impact assessment
Electronic Communications and Transaction Act 25 of 2002
  • Digital signatures
  • Transactional record
  • Electronic terms and conditions
Employment Equity Act 55 of 1998
  • Employment equity plans and targets
Employment Services Act 4 of 2014
  • Job advertisements
Exchange Control Amnesty and Amendment Taxation Laws Act 12 of 2003
  • Reports on foreign spend greater than R10 million to SARS (quarterly)
  • Cross-border transfer-of-funds applications and transactions
Financial Advisory and Intermediary Services Act 37 of 2002
  • Learning history reports
  • Registers of representatives, key individuals, qualifications and competences
  • Records evidencing representatives’ compliance with section 13(1)–(2) of FAIS
  • Continued professional development (CPD) programme and activity records
  • Records of financial and system procedures
  • Records evidencing supervision actions, methods and frequency
  • Records evidencing deployment of technological resources for client records/data integrity
  • Records relating to compliance conclusions and supporting discussions
  • Records relating to advice given, call recordings and product agreements
  • Records relating to debarments of FAIS representatives and key individuals
  • Records relating to business continuity plans
  • Records relating to competency requirements (Grade 12, FSCA-recognised qualifications, COB training, CPD, product-specific training)
  • Signed supervision agreements
  • Representative letters of authority
  • Key-individual authorisation letters
  • Compliance reports
  • FSP licence and addendum with conditions
  • Complaints management (compliance officer contact details)
Financial Intelligence Centre Act 38 of 2001
  • Identification and verification records
  • Client due-diligence records
  • Applications for credit or credit agreements
Income Tax Act 58 of 1991
  • IT3
  • IRP5
  • IT3a
  • Monthly IRP5 files
  • Unemployment Insurance Fund (UIF) files
  • PAYE information
  • SDL information
  • VAT records
  • Ledgers
  • Cash books
  • Journals
  • Bank statements
  • Deposit slips
  • Invoices
  • Other books of accounts
  • Electronic representations of information
Labour Relations Act 66 of 1995
  • Disciplinary records, including outcomes
  • Labour relations reports
  • Arbitration awards
Long-term Insurance Act 52 of 1998
  • Retrenchment claim documents (letter, claim form, ID copy, etc.)
  • Disability claim documents (claim form, medical report, ID copy, etc.)
  • Death claim documents (death certificate, claim form, etc.)
National Credit Act 34 of 2005
  • Loan or credit agreements
  • Applications for credit
  • Occupation information
  • Credit bureau demographic, financial and consumer credit information
  • Pre-agreement statement and quote transactions and transactional history
  • Bank details, contact details and location information
  • Documentation supporting steps taken after consumer default
Occupational Health and Safety Act 85 of 1993
  • Learning history report
  • OHS agreement
  • OHS appointment letters
  • Data centre procedure documents
  • Incident reports
  • Personal information for workmen’s compensation
  • Personal information of visitors to premises and branches
  • CCTV footage
Prevention of Organised Crime Act 121 of 1998
  • Corrupt or fraudulent employee, client or merchant activities
  • Reports on corrupt and fraudulent activities to law enforcement agencies
Protection of Personal Information Act 4 of 2013
  • POPIA Policy
  • Data transfer agreement
  • Privacy Notice
Short-term Insurance Act 53 of 1998
  • Original NaTIS documents
  • Settlement letters
  • Agreements of loss
  • Proof of payment
  • Rejection letters
Skills Development Act 97 of 1998
  • SETA reports (no unique identifiers)
  • Learning history reports
  • Skills development levies
  • Certificates of completion
Value-added Tax Act 89 of 1991
  • Invoices
  • Tax invoices
  • Credit notes
  • Debit notes
  • Bank statements
  • Deposit slips

13. Categories of Data Subjects on Which the Company Holds Records and Type of Records Held on Each Data Subject by the Company

The categories of Data Subjects on which the Company holds records and the type of records held on each Data Subject by the Company may include, but are not limited to:

Categories of Data SubjectsPersonal Information that may be Processed
Customers / ClientsName, address, registration numbers or identity numbers, employment status, information relating to the education and/or the medical, financial, criminal or employment history of the person
Service ProvidersEmail address, name, contact number
Employees / Prospective EmployeesName, address, identity number, date of birth, employment status, tax reference number, residential address, email address, contact number(s), remuneration, race, gender, medical aid applications, CVs, language, qualifications, work history, pregnancy information, marital status, tax certificate, bank statement, medical aid membership number
DirectorsName, address, identity number, employment status, residential address, date of birth, gender, marital status, race
VAT-registered Entities / Juristic RepresentativesName, address, identity number, employment status, tax reference number, business/residential address, email address, contact number, remuneration, bank account statement
Financial AdvisersName, address, contact details, loan agreement. Refer below for information normally included as part of a loan agreement.

14. Categories of Subjects That the Company Holds Records of and the Type of Records That the Company Holds in Respect of These Subjects

The categories of subjects that the Company holds records of and the type of records that the Company holds in respect of these subjects may include, but are not limited to:

CategoryInformation that may be Requested
Personnel recordsPersonal staff records, salary records, conditions of employment and other personnel-related contractual and quasi-legal records, UIF records, tax records, leave records, training schedules and material
Customer-related documentsRecords pertaining to customers / clients, records pertaining to transactions
Financial recordsAnnual and interim reports, management reports, VAT returns, income tax returns and assessments, invoices, receipts, brokerage notes on transactions in listed shares, Regional Services Council returns, SETA returns
Company recordsOperational records, databases, information technology, marketing records, internal correspondence, product records, statutory records, internal policies and procedures, compliance records, treasury-related records, securities and equities, records held by officials, shareholder records, board members, incorporation documents, minutes of meetings, share allotment register, fund prospectus, company resolutions and statutory company documentation, shareholding in subsidiaries and other companies
Other partiesContractors, suppliers, auditors, attorneys, joint ventures, administrators, related companies
Products and servicesAsset management funds, collective investment schemes, investment products, structured products, stockbroking, mandates and application forms, performance histories

15. Processing of Personal Information

15.1. Purpose of Processing Personal Information

HFS processes the personal information of its clients only for the purposes for which said information was collected and as agreed, for example:

  • to provide our products or services to our clients;
  • to execute transactions for and on behalf of our clients;
  • to maintain and nurture our client relationships;
  • to conduct credit reference searches and/or verification processes with third parties;
  • to confirm and verify our client’s identity or to verify that our clients are authorised users for security purposes, as the case may be;
  • for the detection and prevention of fraud, crime, money laundering or other malpractice;
  • for debt tracing and/or debt recovery;
  • to conduct market or customer satisfaction research and for statistical analysis;
  • for audit and record-keeping purposes;
  • to liaise with third parties to offer services to our clients that form part of the products our clients have with us; and
  • in connection with legal proceedings.

For more information on the processing of personal information, please refer to the HFS privacy policy that can be found on the HFS website.

15.2. The Recipients to Whom Personal Information may be Supplied by Law

Category of Personal InformationRecipients or Categories of Recipients to Whom the Personal Information may be Supplied
Identity number and names, for criminal checksSouth African Police Services
Identity number, registration number, name, transaction detailsFinancial Intelligence Centre
Qualifications, for qualification verificationsSouth African Qualifications Authority
Credit and payment history, for credit informationCredit Bureaus

15.3. Planned Transborder Flows of Personal Information

The transfer of personal information from the Republic to foreign countries is prohibited unless:

  • the person receiving the information is subject to a law, binding corporate rules and/or binding agreement that provides an adequate level of protection that effectively upholds principles for reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information relating to a Data Subject who is a natural person and, where applicable, a juristic person, and includes provisions that are substantially similar to the provisions of POPIA relating to the further transfer of personal information from the recipient to third parties who are in a foreign country;
  • the Data Subject has agreed to the transfer of information; or
  • such transfer is necessary for the performance of a contract between the Data Subject and the responsible party, or for the implementation of pre-contractual measures taken in response to the Data Subject’s request;
  • such transfer is necessary for the conclusion or performance of a contract concluded in the interest of the Data Subject between the responsible party and a third party; or
  • the transfer is for the benefit of the Data Subject and it is not reasonably practicable to obtain their consent, and such consent, if it were reasonably practicable to obtain, would likely have been given.

HFS, during the ordinary course and scope of its business operations, transfers personal information to foreign jurisdictions. No processing of data outside of standard operational requirements will be done in regions that are not POPIA compliant. All data processing falls within the South African region. Any data sharing agreements are explicit and transparent. No other sharing or processing of data will be performed outside of standard operational or existing data sharing agreements in place with service providers.

15.4. General Description of Information Security Measures Implemented to Ensure the Confidentiality, Integrity and Availability of the Information

HFS has implemented various IT security initiatives, such as, but not limited to:

  • firewall and network endpoint protection;
  • antivirus and multifactor authentication;
  • cybersecurity professionals;
  • encryption of data at rest (inclusive of backups);
  • application security priority;
  • data security matrices;
  • disaster recovery and business continuity management; and
  • driven by policy (Information Security Policy).

Data quality and integrity is governed through data governance standards and represented in the Data Quality Standards document, where controls are defined and monitored. All access controls are managed through the group data governance council to ensure that defined data owners approve access requests through a standard approval process. Stewardship processes are implemented to ensure data integrity for personal information.

Special personal information is masked, and access is managed through approval processes and monitored and logged when accessed.

16. Availability of the PAIA Manual

  • A copy of the PAIA Manual is available:
    • on the Company’s website;
    • to any person upon request and upon the payment of a reasonable prescribed fee; and
    • to the Information Regulator upon request.
  • A fee for a copy of the PAIA Manual, as contemplated in Annexure B of the PAIA Regulations, shall be payable per each A4-size photocopy made.

17. Updating of the PAIA Manual

This PAIA Manual will be updated from time to time as may be necessary by the IO of the Company.

Issued by: Shan Nissiotis

Head: Group Legal and Compliance, Information Officer

HEREFORD GROUP FINANCIAL SERVICES