PAIA Manual
In terms of section 51 of the Promotion of Access to
Information Act 2 of 2000 (as amended)
1. List of Acronyms, Abbreviations and Definitions
- “Company” Hereford Financial Services (Pty) Ltd, Registration 1998/020101/07
- “DIO” Deputy Information Officer
- “Data Subject” means the person to whom personal information relates
- “IO” Information Officer
- “PAIA” Promotion of Access to Information Act 2 of 2000 (as amended)
- “POPIA” Protection of Personal Information Act 4 of 2013
- “HFS” Hereford Financial Services (Pty) Ltd, Registration 1998/020101/07
- “Regulator” Information Regulator
- “Republic” Republic of South Africa
2. Introduction
- PAIA was enacted to give effect to, among other things, section 32 of the Constitution of the Republic of South Africa, 1996, namely the right to access to information. Specifically, information held by the State and information held by any other person when that information is required for the exercise or protection of any right.
- In terms of section 51 of PAIA, private institutions are obliged to compile a manual to facilitate the foregoing objective (“PAIA Manual”).
3. Purpose of PAIA Manual
This PAIA Manual is for use by the public to:
- check the categories of records held by the Company which are available without a person having to submit a formal PAIA request;
- have a sufficient understanding of how to make a request for access to a record of the Company, by providing a description of the subjects on which the Company holds records and the categories of records held on each subject;
- know the description of the records of the Company which are available in accordance with any other legislation;
- access all the relevant contact details of the IO and the DIO(s) who will assist the public with the records they intend to access;
- know the description of the guide on how to use PAIA, as updated by the Regulator, and how to obtain access to it;
- know if the Company will process personal information, the purpose of processing of personal information and the description of the categories of Data Subjects and of the information or categories of information relating thereto;
- know the description of the categories of Data Subjects and of the information or categories of information relating thereto;
- know the recipients or categories of recipients to whom the personal information may be supplied;
- know if the Company has planned to transfer or process personal information outside the Republic and the recipients or categories of recipients to whom the personal information may be supplied; and
- know whether the Company has appropriate security measures to ensure the confidentiality, integrity and availability of the personal information which is to be processed.
4. Key Contact Details for Access to Information of the Company
4.1. Information Officer
Name: ____________________________
Designation: Head: Group Legal and Compliance
Tel:
Email: janinen@herefordgroup.co.za
4.2. Deputy Information Officers
Name: ____________________________
Designation: Chief Operations Officer – HFS
Tel:
Email: _______________@herefordgroup.co.za
4.3. Head Office
Physical Address:
Hereford Group Building
Ground Floor, Building 2
Central Park, 2 West Park
Century City, Cape Town, 7441
Telephone: 021 552 7136
Email: info@herefordgroup.co.za
Website: www.herefordgroup.co.za
5. Guide on How to Use PAIA and How to Obtain Access to the Guide
- The South African Human Rights Commission has compiled a guide on how to use PAIA (“Guide”). The Regulator has, in terms of section 10(1) of PAIA, updated and made available a revised version of the Guide in a comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPIA.
- The Guide is available in each of the official languages.
- The aforesaid Guide contains the description of:
- the objects of PAIA and POPIA;
- the postal and street address, phone and fax number and, if available, electronic mail address of the Information Officer of every public company, and every Deputy Information Officer of every public and private company designated in terms of section 17(1) of PAIA and section 56 of POPIA;
- the manner and form of a request for access to a record of a public company contemplated in section 11 of PAIA, and access to a record of a private company contemplated in section 50 of PAIA;
- the assistance available from the Information Officer of a public company in terms of PAIA and POPIA;
- the assistance available from the Regulator in terms of PAIA and POPIA;
- all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPIA, including the manner of lodging an internal appeal, a complaint to the Regulator, and an application with a court against a decision by the information officer of a public company, a decision on internal appeal or a decision by the Regulator or a decision of the head of a private company;
- the provisions of sections 14 and 51 of PAIA requiring a public company and a private company, respectively, to compile a manual, and how to obtain access to a manual;
- the provisions of sections 15 and 52 of PAIA providing for the voluntary disclosure of categories of records by a public company and a private company, respectively;
- the notices issued in terms of sections 22 and 54 of PAIA regarding fees to be paid in relation to requests for access; and
- the regulations made in terms of section 92 of PAIA.
- Members of the public can inspect or make copies of the Guide from the office of the Regulator, during normal working hours.
- The Guide can also be obtained upon request to the Information Officer via e-mail with a form that corresponds substantially with form 1 of Annexure A to the PAIA Regulations, or from the website of the Regulator (inforegulator.org.za).
6. Information Requests
- In terms of Chapter 1 of Part 3, Section 50 of PAIA, any person may request access to information from the Company, and must be given access to same, provided that:
- the record is required for the exercise or protection of any rights;
- the requester complies with the procedural requirements as defined in PAIA for a request to access a record; and
- access to a record is not refused on any ground for refusal as contemplated in Chapter 4 of Part 3 of PAIA.
- In terms of Section 23 of POPIA, a Data Subject, having provided adequate proof of identity, has the right to:
- request confirmation, free of charge, of whether or not the Company holds personal information about the Data Subject;
- request the record, or a description of the personal information, held by the Company, including information about the identity of all third parties, or categories of third parties, who have, or have had, access to the information – within a reasonable time, at a prescribed fee (if any), in a reasonable manner and format, and in a form that is generally understandable.
7. How to Request Information
- Complete the relevant form that can be acquired from the revised Guide referred to in paragraph 5 above.
- If a request is made on behalf of another person, then the requester must submit proof of the capacity in which the requester is making the request to the reasonable satisfaction of the IO.
- Submit the form to the IO or the DIO at the physical address or electronic mail address, as stated above.
- The requester must pay the prescribed fee (as explained in paragraph 8 below) before any further processing can take place.
- The Company will process the request within 30 days, unless the requester has stated special reasons which would satisfy the IO that circumstances dictate that the above time periods will not be complied with.
- Records held by the Company may be accessed by requesters only once the prerequisite requirements for access have been met. A requester is any person making a request for access to a record of the institution. There are two types of requesters:
- a Personal Requester: being a person seeking access to a record containing personal information about him/her/itself; and
- an Other Requester: this person is entitled to request access to information on third parties. However, the Company is not obliged to voluntarily grant access.
8. Fees
- PAIA provides for two types of fees which can be established by reference to the Guide referred to above:
- a request fee, which will be a standard fee; and
- an access fee, which must be calculated by taking into account reproduction costs, search and preparation time and cost, as well as postal costs.
- When the IO receives the request, he/she shall notify the requester to pay the prescribed request fee (if any), before any further processing of the request. The IO may withhold a record until the requester has paid the fees. If a deposit has been paid in respect of a request for access which is refused, then the IO concerned must repay the deposit to the requester.
- The prescribed fees can be found in the Guide referred to in paragraph 5.
9. Refusal to Grant Access to Records
- The Company will, within 30 days of receipt of the request, decide whether to grant or decline the request and give notice with reasons (if required) to that effect.
- The 30-day period within which the Company has to decide whether to grant or refuse the request may be extended for a further period of not more than 30 days if the request is voluminous, or the request requires a search for information held at another office of the Company and the information cannot reasonably be obtained within the original 30-day period. The Company will notify the requester in writing should an extension be required.
- The main grounds to refuse a request for information are:
- mandatory protection of the privacy of a third party who is a natural person, which would involve unreasonable disclosure of personal information of that natural person;
- mandatory protection of the commercial information of a third party, if the record contains trade secrets of that third party; financial, commercial, scientific or technical information, other than trade secrets, disclosure of which could likely cause harm to the financial or commercial interest of that third party; or information disclosed in confidence by a third party to the Company, if the disclosure could put that third party at a disadvantage in contractual, or other, negotiations or prejudice that third party in commercial competition;
- mandatory protection of confidential information of a third party if its disclosure would constitute an action for breach of a duty of confidence owed to a third party in terms of any agreement;
- mandatory protection of the life or physical safety of individuals and the protection of property;
- mandatory protection of records which would be regarded as privileged from production in legal proceedings;
- the protection of the commercial information of the institution, which may include trade secrets; financial, commercial, scientific or technical information, other than trade secrets, disclosure of which would likely cause harm to the financial or commercial interests of the institution; information which, if disclosed, could reasonably be expected to put the institution at a disadvantage in contractual or other negotiations or prejudice the institution in commercial competition; or a computer program owned by the institution and protected by copyright;
- mandatory protection of the research information of the institution or a third party, if its disclosure would be likely to expose the institution, the third party, the researcher or the subject matter of the research to serious harm; and
- requests for information that are clearly frivolous or vexatious, or which involve an unreasonable diversion of resources, shall be refused.
10. Notice in Terms of Section 52(2) of PAIA
As at the date of publishing of this version of the PAIA Manual, no notice has been published in terms of section 52(2) of PAIA.
11. Records of the Company Which are Available Without a Person Having to Request Access
The records of the Company which are available without a person having to request access are available at www.herefordgroup.co.za and include:
- Access to Information Manual
- Career Vacancy Advertisements
- Executive Officer Details: name, employment history, qualifications and date of appointment
- Financial Adviser Details: name, address, contact details, qualifications and specialisation
- FSP Licence(s) and ancillary information
- Fund Performance Notices
- Group Corporate Structure and Information
- Group Privacy Policy(ies) and Procedure
- Information pertaining to the Company’s products and services published on the Company website and generally available within the public domain
- Listing Information and updates
- Newsletters
- Promotional and marketing material published on the Company website and generally available within the public domain
- Trading and Investment Forms: Local and Global, and ancillary information
12. Records of the Company Which are Available in Accordance with Legislation
All records kept and/or information processed in terms of relevant legislation are available in accordance with said legislation and apply, but are not limited, to the following:
| Applicable Legislation | Category of Record |
|---|---|
| Basic Conditions of Employment Act 75 of 1997 |
|
| Companies Act 71 of 2008 |
|
| Compensation of Occupational Injuries and Diseases Act 130 of 1993 |
|
| Consumer Protection Act 68 of 2008 |
|
| Copyright Act 98 of 1978 (as amended by Act 2 of 2002) |
|
| Disaster Management Act 57 of 2002 |
|
| Electronic Communications and Transaction Act 25 of 2002 |
|
| Employment Equity Act 55 of 1998 |
|
| Employment Services Act 4 of 2014 |
|
| Exchange Control Amnesty and Amendment Taxation Laws Act 12 of 2003 |
|
| Financial Advisory and Intermediary Services Act 37 of 2002 |
|
| Financial Intelligence Centre Act 38 of 2001 |
|
| Income Tax Act 58 of 1991 |
|
| Labour Relations Act 66 of 1995 |
|
| Long-term Insurance Act 52 of 1998 |
|
| National Credit Act 34 of 2005 |
|
| Occupational Health and Safety Act 85 of 1993 |
|
| Prevention of Organised Crime Act 121 of 1998 |
|
| Protection of Personal Information Act 4 of 2013 |
|
| Short-term Insurance Act 53 of 1998 |
|
| Skills Development Act 97 of 1998 |
|
| Value-added Tax Act 89 of 1991 |
|
13. Categories of Data Subjects on Which the Company Holds Records and Type of Records Held on Each Data Subject by the Company
The categories of Data Subjects on which the Company holds records and the type of records held on each Data Subject by the Company may include, but are not limited to:
| Categories of Data Subjects | Personal Information that may be Processed |
|---|---|
| Customers / Clients | Name, address, registration numbers or identity numbers, employment status, information relating to the education and/or the medical, financial, criminal or employment history of the person |
| Service Providers | Email address, name, contact number |
| Employees / Prospective Employees | Name, address, identity number, date of birth, employment status, tax reference number, residential address, email address, contact number(s), remuneration, race, gender, medical aid applications, CVs, language, qualifications, work history, pregnancy information, marital status, tax certificate, bank statement, medical aid membership number |
| Directors | Name, address, identity number, employment status, residential address, date of birth, gender, marital status, race |
| VAT-registered Entities / Juristic Representatives | Name, address, identity number, employment status, tax reference number, business/residential address, email address, contact number, remuneration, bank account statement |
| Financial Advisers | Name, address, contact details, loan agreement. Refer below for information normally included as part of a loan agreement. |
14. Categories of Subjects That the Company Holds Records of and the Type of Records That the Company Holds in Respect of These Subjects
The categories of subjects that the Company holds records of and the type of records that the Company holds in respect of these subjects may include, but are not limited to:
| Category | Information that may be Requested |
|---|---|
| Personnel records | Personal staff records, salary records, conditions of employment and other personnel-related contractual and quasi-legal records, UIF records, tax records, leave records, training schedules and material |
| Customer-related documents | Records pertaining to customers / clients, records pertaining to transactions |
| Financial records | Annual and interim reports, management reports, VAT returns, income tax returns and assessments, invoices, receipts, brokerage notes on transactions in listed shares, Regional Services Council returns, SETA returns |
| Company records | Operational records, databases, information technology, marketing records, internal correspondence, product records, statutory records, internal policies and procedures, compliance records, treasury-related records, securities and equities, records held by officials, shareholder records, board members, incorporation documents, minutes of meetings, share allotment register, fund prospectus, company resolutions and statutory company documentation, shareholding in subsidiaries and other companies |
| Other parties | Contractors, suppliers, auditors, attorneys, joint ventures, administrators, related companies |
| Products and services | Asset management funds, collective investment schemes, investment products, structured products, stockbroking, mandates and application forms, performance histories |
15. Processing of Personal Information
15.1. Purpose of Processing Personal Information
HFS processes the personal information of its clients only for the purposes for which said information was collected and as agreed, for example:
- to provide our products or services to our clients;
- to execute transactions for and on behalf of our clients;
- to maintain and nurture our client relationships;
- to conduct credit reference searches and/or verification processes with third parties;
- to confirm and verify our client’s identity or to verify that our clients are authorised users for security purposes, as the case may be;
- for the detection and prevention of fraud, crime, money laundering or other malpractice;
- for debt tracing and/or debt recovery;
- to conduct market or customer satisfaction research and for statistical analysis;
- for audit and record-keeping purposes;
- to liaise with third parties to offer services to our clients that form part of the products our clients have with us; and
- in connection with legal proceedings.
For more information on the processing of personal information, please refer to the HFS privacy policy that can be found on the HFS website.
15.2. The Recipients to Whom Personal Information may be Supplied by Law
| Category of Personal Information | Recipients or Categories of Recipients to Whom the Personal Information may be Supplied |
|---|---|
| Identity number and names, for criminal checks | South African Police Services |
| Identity number, registration number, name, transaction details | Financial Intelligence Centre |
| Qualifications, for qualification verifications | South African Qualifications Authority |
| Credit and payment history, for credit information | Credit Bureaus |
15.3. Planned Transborder Flows of Personal Information
The transfer of personal information from the Republic to foreign countries is prohibited unless:
- the person receiving the information is subject to a law, binding corporate rules and/or binding agreement that provides an adequate level of protection that effectively upholds principles for reasonable processing of the information that are substantially similar to the conditions for the lawful processing of personal information relating to a Data Subject who is a natural person and, where applicable, a juristic person, and includes provisions that are substantially similar to the provisions of POPIA relating to the further transfer of personal information from the recipient to third parties who are in a foreign country;
- the Data Subject has agreed to the transfer of information; or
- such transfer is necessary for the performance of a contract between the Data Subject and the responsible party, or for the implementation of pre-contractual measures taken in response to the Data Subject’s request;
- such transfer is necessary for the conclusion or performance of a contract concluded in the interest of the Data Subject between the responsible party and a third party; or
- the transfer is for the benefit of the Data Subject and it is not reasonably practicable to obtain their consent, and such consent, if it were reasonably practicable to obtain, would likely have been given.
HFS, during the ordinary course and scope of its business operations, transfers personal information to foreign jurisdictions. No processing of data outside of standard operational requirements will be done in regions that are not POPIA compliant. All data processing falls within the South African region. Any data sharing agreements are explicit and transparent. No other sharing or processing of data will be performed outside of standard operational or existing data sharing agreements in place with service providers.
15.4. General Description of Information Security Measures Implemented to Ensure the Confidentiality, Integrity and Availability of the Information
HFS has implemented various IT security initiatives, such as, but not limited to:
- firewall and network endpoint protection;
- antivirus and multifactor authentication;
- cybersecurity professionals;
- encryption of data at rest (inclusive of backups);
- application security priority;
- data security matrices;
- disaster recovery and business continuity management; and
- driven by policy (Information Security Policy).
Data quality and integrity is governed through data governance standards and represented in the Data Quality Standards document, where controls are defined and monitored. All access controls are managed through the group data governance council to ensure that defined data owners approve access requests through a standard approval process. Stewardship processes are implemented to ensure data integrity for personal information.
Special personal information is masked, and access is managed through approval processes and monitored and logged when accessed.
16. Availability of the PAIA Manual
- A copy of the PAIA Manual is available:
- on the Company’s website;
- to any person upon request and upon the payment of a reasonable prescribed fee; and
- to the Information Regulator upon request.
- A fee for a copy of the PAIA Manual, as contemplated in Annexure B of the PAIA Regulations, shall be payable per each A4-size photocopy made.
17. Updating of the PAIA Manual
This PAIA Manual will be updated from time to time as may be necessary by the IO of the Company.
Issued by: Shan Nissiotis
Head: Group Legal and Compliance, Information Officer
HEREFORD GROUP FINANCIAL SERVICES