Prepared in terms of section 51 of the Promotion of Access to Information Act, 2 of 2000, as amended
Private body: Cofi Compliance [insert legal entity name]
Website: https://coficompliance.com/
Effective date: [insert date]
Version: 1.0
1. Acronyms and abbreviations
- CEO: Chief Executive Officer.
- DIO: Deputy Information Officer.
- IO: Information Officer.
- PAIA: Promotion of Access to Information Act, 2 of 2000.
- POPIA: Protection of Personal Information Act, 4 of 2013.
- Regulator: Information Regulator (South Africa).
- FSP: Financial Services Provider.
- FSCA: Financial Sector Conduct Authority.
2. Purpose of this Manual
This Manual assists members of the public to understand the categories of records held by Cofi Compliance and the process for requesting access to records under PAIA. It also provides information relating to the processing of personal information under POPIA.
3. Details of the private body
Name: Cofi Compliance [insert legal entity name]
Registration number: [insert registration number]
Trading name: Cofi Compliance
Website: https://coficompliance.com/
Email: hello@coficompliance.com
Telephone: [insert telephone number]
Physical address: [insert physical address]
Postal address: [insert postal address, if different]
4. Information Officer
Information Officer: [insert name]
Email: hello@coficompliance.com
Telephone: [insert telephone number]
Deputy Information Officer: [insert name, if applicable]
5. Guide on how to use PAIA
The Information Regulator has published a Guide on how to use PAIA. The Guide assists persons who wish to exercise rights under PAIA and POPIA. It is available from the Information Regulator's website and in the official languages identified by the Regulator.
6. Records automatically available
The following records may be available without a formal PAIA request:
- Public website content, service descriptions, regulatory notices, and contact details.
- Public marketing material, newsletters, brochures, and public regulatory-update summaries.
- Published privacy, PAIA, terms, disclaimer, cookie, and data-subject request notices.
- Public job or vacancy information, where published.
- Publicly available company and regulatory information, where applicable.
7. Records available in accordance with legislation
Cofi Compliance may hold records required under applicable legislation, including where relevant:
- Companies Act, 71 of 2008.
- Income Tax Act, 58 of 1962.
- Value-Added Tax Act, 89 of 1991.
- Tax Administration Act, 28 of 2011.
- Basic Conditions of Employment Act, 75 of 1997.
- Labour Relations Act, 66 of 1995.
- Employment Equity Act, 55 of 1998, where applicable.
- Skills Development Act, 97 of 1998, where applicable.
- Unemployment Insurance Act, 63 of 2001.
- Compensation for Occupational Injuries and Diseases Act, 130 of 1993.
- Financial Advisory and Intermediary Services Act, 37 of 2002, where applicable.
- Financial Intelligence Centre Act, 38 of 2001, where applicable.
- Protection of Personal Information Act, 4 of 2013.
- Promotion of Access to Information Act, 2 of 2000.
- Electronic Communications and Transactions Act, 25 of 2002.
- Consumer Protection Act, 68 of 2008, where applicable.
8. Categories of records held
Cofi Compliance may hold the following categories of records:
8.1 Company and governance records
Registration documents, resolutions, ownership records, governance documents, policies, procedures, business plans, insurance records, internal approvals, and statutory records.
8.2 Financial and tax records
Accounting records, invoices, statements, payment records, banking records, tax records, payroll records, audit information, and supplier records.
8.3 Client and service records
Client onboarding records, engagement letters, proposals, service records, FSP licence information, compliance calendars, regulatory correspondence, evidence files, monitoring notes, implementation plans, training records, fit and proper records, website review records, and client communications.
8.4 Human resources and recruitment records
Employee records, contractor records, CVs, applications, interview notes, references, contracts, training records, leave records, disciplinary records, and payroll information.
8.5 Supplier and operator records
Supplier due diligence, contracts, confidentiality undertakings, operator agreements, service levels, invoices, security information, and correspondence.
8.6 Information technology and security records
System access records, security policies, incident logs, backup records, hosting records, email records, domain records, and website analytics or technical logs.
8.7 PAIA, POPIA and complaint records
PAIA requests, POPIA data subject requests, consent records, complaints, breach or incident records, Information Officer records, training records, and privacy assessments.
9. Request procedure
A requester who wishes to access a record must submit a request using the prescribed PAIA request form, substantially corresponding to Form 2 under the PAIA Regulations. The request must be submitted to the Information Officer using the contact details in this Manual.
The request should provide enough detail to identify:
- The requester and proof of identity.
- The record requested.
- The right the requester seeks to exercise or protect.
- Why the requested record is required for the exercise or protection of that right.
- The preferred form of access.
- Contact details for correspondence.
If a request is made on behalf of another person, proof of authority must be provided.
10. Fees
Request fees and access fees may be payable as prescribed under PAIA. Where applicable, Cofi Compliance may provide an estimate of fees and may require payment before access is granted.
11. Grounds for refusal
Access to records may be refused where PAIA requires or permits refusal, including where disclosure would involve unreasonable disclosure of personal information, breach confidentiality, reveal trade secrets or commercial information, endanger safety, prejudice legal privilege, prejudice law enforcement, or otherwise fall within a statutory ground for refusal.
12. Decision and remedies
Cofi Compliance will respond to a PAIA request within the period prescribed by law, subject to any lawful extension. If a request is refused or no response is received within the prescribed period, the requester may lodge a complaint with the Information Regulator or approach a court, as provided under PAIA.
13. POPIA processing information
Cofi Compliance processes personal information relating to clients, prospective clients, employees, contractors, job applicants, suppliers, website visitors, service providers, representatives of FSPs, key individuals, directors, and other persons involved in compliance matters.
The purposes of processing include service delivery, regulatory support, consultation, licensing, compliance monitoring, training, recruitment, administration, billing, security, marketing where permitted, legal compliance, dispute resolution, and business operations.
Categories of personal information may include identity, contact, employment, qualifications, fit and proper, FSP, financial, communication, website, technical, and service-related information.
Personal information may be shared with authorised personnel, service providers, operators, regulators, public bodies, professional advisers, and other parties where required or permitted by law or necessary for service delivery.
14. Security measures
Cofi Compliance implements reasonable safeguards appropriate to the nature of the information and processing activities. These may include access controls, secure storage, confidentiality undertakings, technical security controls, operator due diligence, backup controls, and incident response measures.
15. Availability of this Manual
This Manual is available on the Cofi Compliance website and may be requested from the Information Officer.
16. Review
This Manual will be reviewed periodically and updated when required by law, regulatory guidance, or changes to Cofi Compliance's operations.