C Cofi Compliance coficompliance.com
Services FSP compliance What's new Regulatory Brief Newsletter Fit & Proper Vacancies Contact

Legal hygiene

PAIA Manual

Cofi Compliance - Compliance, Implemented.

Company identity: Cofi Compliance (Pty) Ltd, registration number 2025/665787/07. Identity details last updated from the CIPC record on 19 August 2026.

Prepared in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000, as amended

Private body: Cofi Compliance (Pty) Ltd

Website: https://coficompliance.com/

Date compiled: 19 August 2026

Date revised: 19 August 2026

Version: 2.0

1. Acronyms and abbreviations

  • CEO: Chief Executive Officer.
  • DIO: Deputy Information Officer.
  • IO: Information Officer.
  • PAIA: Promotion of Access to Information Act, 2 of 2000.
  • POPIA: Protection of Personal Information Act, 4 of 2013.
  • Regulator: Information Regulator (South Africa).
  • FSP: Financial Services Provider.
  • FSCA: Financial Sector Conduct Authority.

2. Purpose of this Manual

This Manual assists members of the public to understand the categories of records held by Cofi Compliance and the process for requesting access to records under PAIA. It also provides information relating to the processing of personal information under POPIA.

3. Details of the private body

Name: Cofi Compliance (Pty) Ltd

Registration number: 2025/665787/07

Trading name: Cofi Compliance

Website: https://coficompliance.com/

Email: info@coficompliance.com

Telephone: +27 81 479 1292

Physical delivery and inspection: By prior appointment arranged through info@coficompliance.com. The applicable service address will be confirmed before delivery or inspection.

Postal service: Arrange service through info@coficompliance.com so that the current postal or physical service address can be confirmed.

4. Information Officer

Information Officer: The head of Cofi Compliance (Pty) Ltd, acting in that statutory capacity.

Email: info@coficompliance.com

Telephone: +27 81 479 1292

Deputy Information Officer: No separate deputy contact is published. Requests should be directed to the Information Officer channel above.

5. Guide on how to use PAIA

The Information Regulator has published a Guide on how to use PAIA. The Guide assists persons who wish to exercise rights under PAIA and POPIA. The English PAIA Guide and other official-language versions are available from the Regulator.

6. Records automatically available

The following records may be available without a formal PAIA request:

  • Public website content, service descriptions, regulatory notices, and contact details.
  • Public marketing material, newsletters, brochures, and public regulatory-update summaries.
  • Published privacy, PAIA, terms, disclaimer, cookie, and data-subject request notices.
  • Public job or vacancy information, where published.
  • Publicly available company and regulatory information, where applicable.

7. Records available in accordance with legislation

Cofi Compliance may hold records required under applicable legislation, including where relevant:

  • Companies Act, 71 of 2008.
  • Income Tax Act, 58 of 1962.
  • Value-Added Tax Act, 89 of 1991.
  • Tax Administration Act, 28 of 2011.
  • Basic Conditions of Employment Act, 75 of 1997.
  • Labour Relations Act, 66 of 1995.
  • Employment Equity Act, 55 of 1998, where applicable.
  • Skills Development Act, 97 of 1998, where applicable.
  • Unemployment Insurance Act, 63 of 2001.
  • Compensation for Occupational Injuries and Diseases Act, 130 of 1993.
  • Financial Advisory and Intermediary Services Act, 37 of 2002, where applicable.
  • Financial Intelligence Centre Act, 38 of 2001, where applicable.
  • Protection of Personal Information Act, 4 of 2013.
  • Promotion of Access to Information Act, 2 of 2000.
  • Electronic Communications and Transactions Act, 25 of 2002.
  • Consumer Protection Act, 68 of 2008, where applicable.

8. Categories of records held

Cofi Compliance may hold the following categories of records:

8.1 Company and governance records

Registration documents, resolutions, ownership records, governance documents, policies, procedures, business plans, insurance records, internal approvals, and statutory records.

8.2 Financial and tax records

Accounting records, invoices, statements, payment records, banking records, tax records, payroll records, audit information, and supplier records.

8.3 Client and service records

Client onboarding records, engagement letters, proposals, service records, FSP licence information, compliance calendars, regulatory correspondence, evidence files, monitoring notes, implementation plans, training records, fit and proper records, website review records, and client communications.

8.4 Human resources and recruitment records

Employee records, contractor records, CVs, applications, interview notes, references, contracts, training records, leave records, disciplinary records, and payroll information.

8.5 Supplier and operator records

Supplier due diligence, contracts, confidentiality undertakings, operator agreements, service levels, invoices, security information, and correspondence.

8.6 Information technology and security records

System access records, security policies, incident logs, backup records, hosting records, email records, domain records, and website analytics or technical logs.

8.7 PAIA, POPIA and complaint records

PAIA requests, POPIA data subject requests, consent records, complaints, breach or incident records, Information Officer records, training records, and privacy assessments.

9. Request procedure

A requester who wishes to access a record must submit the prescribed PAIA Form 2: Request for Access to Record to the Information Officer using the contact details in this Manual.

The request should provide enough detail to identify:

  • The requester and proof of identity.
  • The record requested.
  • The right the requester seeks to exercise or protect.
  • Why the requested record is required for the exercise or protection of that right.
  • The preferred form of access.
  • Contact details for correspondence.

If a request is made on behalf of another person, proof of authority must be provided.

10. Fees

Request fees and access fees may be payable as prescribed under PAIA. Where applicable, Cofi Compliance may provide an estimate of fees and may require payment before access is granted.

11. Grounds for refusal

Access to records may be refused where PAIA requires or permits refusal, including where disclosure would involve unreasonable disclosure of personal information, breach confidentiality, reveal trade secrets or commercial information, endanger safety, prejudice legal privilege, prejudice law enforcement, or otherwise fall within a statutory ground for refusal.

12. Decision and remedies

Cofi Compliance will decide a PAIA request within 30 calendar days after receipt, subject to any lawful extension. If a request is refused or no response is received within the prescribed period, the requester may use the Regulator's PAIA Form 5 complaint process or approach a court as provided under PAIA.

13. POPIA processing information

Cofi Compliance processes personal information relating to clients, prospective clients, employees, contractors, job applicants, suppliers, website visitors, service providers, representatives of FSPs, key individuals, directors, and other persons involved in compliance matters.

The purposes of processing include service delivery, regulatory support, consultation, licensing, compliance monitoring, training, recruitment, administration, billing, security, marketing where permitted, legal compliance, dispute resolution, and business operations.

Categories of personal information may include identity, contact, employment, qualifications, fit and proper, FSP, financial, communication, website, technical, and service-related information.

Personal information may be shared with authorised personnel, service providers, operators, regulators, public bodies, professional advisers, and other parties where required or permitted by law or necessary for service delivery.

13.1 Planned transborder flows

Personal information may be processed or stored outside South Africa by website-hosting, email, document-storage, security, or other contracted technology operators. The public website is delivered using Cloudflare infrastructure. The country or region may vary by operator and service. Cofi Compliance applies the safeguards required by section 72 of POPIA and will provide information about a material operator or transfer relevant to a requester where required by law.

14. Security measures

Cofi Compliance implements reasonable safeguards appropriate to the nature of the information and processing activities. These may include access controls, secure storage, confidentiality undertakings, technical security controls, operator due diligence, backup controls, and incident response measures.

15. Availability of this Manual

This Manual is available on the Cofi Compliance website, for inspection at the physical address stated above during normal business hours, from the Information Officer on request, and to the Information Regulator on request. A copy may be subject to a lawful prescribed reproduction fee.

16. Review

This Manual will be reviewed periodically and updated when required by law, regulatory guidance, or changes to Cofi Compliance's operations.

Issued by: The Information Officer of Cofi Compliance (Pty) Ltd

Privacy Notice PAIA Manual Data Subject Requests
Cofi Compliance Compliance, Implemented. info@coficompliance.com
Privacy Notice PAIA Manual Terms of Use Website Disclaimer Cookie Notice Data Subject Requests Email Disclaimer