C Cofi Compliance coficompliance.com
Services What's new Regulatory Brief Fit & Proper Vacancies Contact

Legal hygiene

PAIA Manual

Cofi Compliance - Compliance, Implemented.

Publication placeholder: Final legal/entity details are still required where bracketed placeholders appear, including legal entity name, registration number, addresses, telephone number, Information Officer details, and any approved FSCA compliance-practice wording.

Prepared in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000, as amended

Private body: Cofi Compliance [insert legal entity name]

Website: https://coficompliance.com/

Effective date: [insert date]

Version: 1.0

1. Acronyms and abbreviations

  • CEO: Chief Executive Officer.
  • DIO: Deputy Information Officer.
  • IO: Information Officer.
  • PAIA: Promotion of Access to Information Act, 2 of 2000.
  • POPIA: Protection of Personal Information Act, 4 of 2013.
  • Regulator: Information Regulator (South Africa).
  • FSP: Financial Services Provider.
  • FSCA: Financial Sector Conduct Authority.

2. Purpose of this Manual

This Manual assists members of the public to understand the categories of records held by Cofi Compliance and the process for requesting access to records under PAIA. It also provides information relating to the processing of personal information under POPIA.

3. Details of the private body

Name: Cofi Compliance [insert legal entity name]

Registration number: [insert registration number]

Trading name: Cofi Compliance

Website: https://coficompliance.com/

Email: hello@coficompliance.com

Telephone: [insert telephone number]

Physical address: [insert physical address]

Postal address: [insert postal address, if different]

4. Information Officer

Information Officer: [insert name]

Email: hello@coficompliance.com

Telephone: [insert telephone number]

Deputy Information Officer: [insert name, if applicable]

5. Guide on how to use PAIA

The Information Regulator has published a Guide on how to use PAIA. The Guide assists persons who wish to exercise rights under PAIA and POPIA. It is available from the Information Regulator's website and in the official languages identified by the Regulator.

6. Records automatically available

The following records may be available without a formal PAIA request:

  • Public website content, service descriptions, regulatory notices, and contact details.
  • Public marketing material, newsletters, brochures, and public regulatory-update summaries.
  • Published privacy, PAIA, terms, disclaimer, cookie, and data-subject request notices.
  • Public job or vacancy information, where published.
  • Publicly available company and regulatory information, where applicable.

7. Records available in accordance with legislation

Cofi Compliance may hold records required under applicable legislation, including where relevant:

  • Companies Act, 71 of 2008.
  • Income Tax Act, 58 of 1962.
  • Value-Added Tax Act, 89 of 1991.
  • Tax Administration Act, 28 of 2011.
  • Basic Conditions of Employment Act, 75 of 1997.
  • Labour Relations Act, 66 of 1995.
  • Employment Equity Act, 55 of 1998, where applicable.
  • Skills Development Act, 97 of 1998, where applicable.
  • Unemployment Insurance Act, 63 of 2001.
  • Compensation for Occupational Injuries and Diseases Act, 130 of 1993.
  • Financial Advisory and Intermediary Services Act, 37 of 2002, where applicable.
  • Financial Intelligence Centre Act, 38 of 2001, where applicable.
  • Protection of Personal Information Act, 4 of 2013.
  • Promotion of Access to Information Act, 2 of 2000.
  • Electronic Communications and Transactions Act, 25 of 2002.
  • Consumer Protection Act, 68 of 2008, where applicable.

8. Categories of records held

Cofi Compliance may hold the following categories of records:

8.1 Company and governance records

Registration documents, resolutions, ownership records, governance documents, policies, procedures, business plans, insurance records, internal approvals, and statutory records.

8.2 Financial and tax records

Accounting records, invoices, statements, payment records, banking records, tax records, payroll records, audit information, and supplier records.

8.3 Client and service records

Client onboarding records, engagement letters, proposals, service records, FSP licence information, compliance calendars, regulatory correspondence, evidence files, monitoring notes, implementation plans, training records, fit and proper records, website review records, and client communications.

8.4 Human resources and recruitment records

Employee records, contractor records, CVs, applications, interview notes, references, contracts, training records, leave records, disciplinary records, and payroll information.

8.5 Supplier and operator records

Supplier due diligence, contracts, confidentiality undertakings, operator agreements, service levels, invoices, security information, and correspondence.

8.6 Information technology and security records

System access records, security policies, incident logs, backup records, hosting records, email records, domain records, and website analytics or technical logs.

8.7 PAIA, POPIA and complaint records

PAIA requests, POPIA data subject requests, consent records, complaints, breach or incident records, Information Officer records, training records, and privacy assessments.

9. Request procedure

A requester who wishes to access a record must submit a request using the prescribed PAIA request form, substantially corresponding to Form 2 under the PAIA Regulations. The request must be submitted to the Information Officer using the contact details in this Manual.

The request should provide enough detail to identify:

  • The requester and proof of identity.
  • The record requested.
  • The right the requester seeks to exercise or protect.
  • Why the requested record is required for the exercise or protection of that right.
  • The preferred form of access.
  • Contact details for correspondence.

If a request is made on behalf of another person, proof of authority must be provided.

10. Fees

Request fees and access fees may be payable as prescribed under PAIA. Where applicable, Cofi Compliance may provide an estimate of fees and may require payment before access is granted.

11. Grounds for refusal

Access to records may be refused where PAIA requires or permits refusal, including where disclosure would involve unreasonable disclosure of personal information, breach confidentiality, reveal trade secrets or commercial information, endanger safety, prejudice legal privilege, prejudice law enforcement, or otherwise fall within a statutory ground for refusal.

12. Decision and remedies

Cofi Compliance will respond to a PAIA request within the period prescribed by law, subject to any lawful extension. If a request is refused or no response is received within the prescribed period, the requester may lodge a complaint with the Information Regulator or approach a court, as provided under PAIA.

13. POPIA processing information

Cofi Compliance processes personal information relating to clients, prospective clients, employees, contractors, job applicants, suppliers, website visitors, service providers, representatives of FSPs, key individuals, directors, and other persons involved in compliance matters.

The purposes of processing include service delivery, regulatory support, consultation, licensing, compliance monitoring, training, recruitment, administration, billing, security, marketing where permitted, legal compliance, dispute resolution, and business operations.

Categories of personal information may include identity, contact, employment, qualifications, fit and proper, FSP, financial, communication, website, technical, and service-related information.

Personal information may be shared with authorised personnel, service providers, operators, regulators, public bodies, professional advisers, and other parties where required or permitted by law or necessary for service delivery.

14. Security measures

Cofi Compliance implements reasonable safeguards appropriate to the nature of the information and processing activities. These may include access controls, secure storage, confidentiality undertakings, technical security controls, operator due diligence, backup controls, and incident response measures.

15. Availability of this Manual

This Manual is available on the Cofi Compliance website and may be requested from the Information Officer.

16. Review

This Manual will be reviewed periodically and updated when required by law, regulatory guidance, or changes to Cofi Compliance's operations.

Privacy Notice PAIA Manual Data Subject Requests
Cofi Compliance Compliance, Implemented. hello@coficompliance.com
Privacy Notice PAIA Manual Terms of Use Website Disclaimer Cookie Notice Data Subject Requests Email Disclaimer