POPI POLICY

22 June 2021

INTRODUCTION

The Protection of Personal Information (POPI) Act is the comprehensive data protection legislation that obliges organisations to deal with the processing of personal information appropriately by applying specific principles and conditions. Millenium Star Capital (“MSC”) is an authorised financial services provider of 

  • financial advice and non-discretionary intermediary services (Category I FSP), and discretionary intermediary services (Category II) in terms of the Financial Advisory and Intermediary Services Act 37 of 2002 (the “FAIS Act”); and 
  • an accountable institution (AI) in terms of the Financial Intelligence Centre Act (the “FICA”). 

Through the provision of these services and as part of our integral service offering, MSC is required to collect, use, and disclose certain aspects of the personal information of our data subjects, employees, and other stakeholders. Respecting and protecting personal information is not only important to MSC but also a constitutional right, as well as both a legal and good business practice requirement. A person’s right to privacy entails having control over their personal information and being able to conduct their affairs relatively free from unwanted intrusions. Given the importance of privacy, the MSC is committed to protecting the privacy of our data subjects as well as ensuring that personal information is used appropriately, transparently, securely, and in accordance with applicable laws. This policy and our compliance framework establishes measures and standards for the protection and lawful processing of personal information within our organisation provides principles regarding the right of individuals to privacy and to reasonable safeguarding of their personal information. 

LEGISTLATIVE AND GOVERNANACE FRAMEWORK

MSC operates under the following framework: 

  • Financial Sector Regulation Act 9 of 2017 (“FSRA”)
  • Conduct of Financial Institutions Bill (“COFI Bill”)
  • Protection of Personal Information Act 4 of 2014 (“POPI Act”)
  • Promotion of Access to Information Act 2 of 2000 (“PAIA”)
  • Financial Intelligence Centre Act 38 of 2001 (“FICA”)
  • Financial Advisory and Intermediary Services Act 37 of 2002 (“FAIS”)
  • Companies Act 71 of 2008
  • Income Tax Act 58 of 1962
  • Exchange Control Regulations, as published by the South African Reserve Bank
  • Constitution of the Republic of South Africa, 1996 (“Constitution”). 

PURPOSE AND SCOPE

The purpose of this policy is to: 

  • protect MSC from the compliance risks associated with the protection of personal information, which includes breaches of confidentiality and reputational damage 
  • demonstrate our commitment to protecting the privacy rights of data subjects through documenting desired behaviour and directing compliance with the provisions of the POPI Act and best practice.
  • cultivate a culture that recognises privacy as a valuable human right; 
  • develop and implement internal controls for the purpose of managing the compliance risk associated with the protection of personal information; 
  • create business practices that will provide reasonable assurance that the rights of data subjects are protected and balanced with the legitimate business needs of MSC; 
  • assigning specific duties and responsibilities to control owners, including the appointment of an information officer to protect the interests of MSC and data subjects; 
  • raise awareness through training and providing guidance to individuals who process personal information so that they can act confidently and consistently. 

WHAT IS PERSONAL INFORMATION?

Personal information is defined by the Protection of Personal information Act (the Act) as: 

“means information relating to an identifiable, living, natural person, and where it is applicable, an identifiable, existing juristic person, including, but not limited to – 

  • information relating to the race, gender, sex, pregnancy, marital status, national, ethnic or social origin, colour, sexual orientation, age, physical or mental health, well-being, disability, religion, conscience, belief, culture, language and birth of the person; 
  • information relating to the education or the medical, financial, criminal or employment history of the person; 
  • any identifying number, symbol, e-mail address, physical address, telephone number, location information, online identifier or other particular assignment to the person; 
  • the biometric information of the person; 
  • the personal opinions, views or preferences of the person; 
  • correspondence sent by the person that is implicitly or explicitly of a private or confidential nature or further correspondence that would reveal the contents of the original correspondence; 
  • the views or opinions of another individual about the person; and 
  • the name of the person if it appears with other personal information relating to the person or if the disclosure of the name itself would reveal information about the person”. 

OTHER DEFINITIONS IN THE POPI ACT

Child 

A natural person under the age of 18 years who is not legally competent, without the assistance of a competent
person, to take any action or decision in respect of any matter concerning himself or herself. 

Competent person 

Any person who is legally competent to consent to any action or decision being taken in respect of any matter
concerning a child (i.e. a child’s legal guardian). 

Consent 

Any voluntary, specific and informed expression of will in terms of which permission is given for the processing
of personal information. 

Data subject 

The person to whom personal information relates – can be a client or an employee. 

De-identify and
de-identified 

In relation to personal information of a data subject, means to delete any information that: 

  • identifies the data subject; 
  • can be used or manipulated by a reasonably foreseeable method to identify the data subject; 
  • can be linked by a reasonably foreseeable method to other information that identifies the data subject. 

Electronic
communication 

Any text, voice, sound, image or message, sent over an electronic communications network, which is stored in the
network or in the recipient’s terminal equipment, until it is collected by the recipient. 

Information
officer 

The head of a business is the Information Officer who can delegate the IO responsibilities to any other duly authorised
individual although the head remains ultimately responsible for the processing of personal information. 

Operator 

A person who processes personal information for a responsible party in terms of a contract or mandate, without coming
under the direct authority of that party. 

Person 

A natural person or a juristic person. 

Processing 

Processing means, if effect, doing something with the data. Any operation or activity or any set of operations, whether
or not by automatic means, pertaining to personal information, including: 

  • the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation, or use; 
  • dissemination by means of transmission, distribution, or making available in any other form; 
  • merging, linking, restriction, degradation, erasure, or destruction of information. 

Public record 

A record that is accessible in the public domain and which is in the possession of, or under the control of, a public body,
whether or not it was created by that public body. 

Record 

Any recorded information, regardless of form or medium, including: 

  • writing on any material 
  • information produced, recorded or stored by means of any tape-recorder, computer equipment, whether hardware, or software or both, or other device, and any material subsequently derived from information produced, recorded or stored; 
  • label, marking or other writing that identifies or describes anything of which it forms part or to which it is attached, by any means; 
  • book, map, plan, graph or drawing; 
  • photograph, film, negative, tape or other device, in which one (1) or more visual images are embodied to be capable, with or without the aid of some other equipment, of being reproduced; 
  • in the possession or under the control of a responsible party; whether or not it was created by a responsible party and regardless of when it came into existence; 

Regulator 

The Information Regulator, established in terms of section 39 of the POPI Act 

Re-identify and
re-identified 

In relation to personal information of a data subject, means to resurrect any information that has been de-identified that: 

  • identifies the data subject; 
  • can be used or manipulated by a reasonably foreseeable method to identify the data subject; 
  • can be linked by a reasonably foreseeable method to other information that identifies the data subject; 

Responsible party 

A public or private body, or any other person which, alone or in conjunction with others, determines the purpose of and means for processing personal information. 

Restriction 

To withhold or restrict from circulation, use or publication, any personal information that forms part of a filing system but not to delete or destroy the information. 

Special personal information 

Personal information, as referred to in section 26 of the POPI Act: 

  • religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health, sex life or biometric information of a data subject; 
  • criminal behaviour of a data subject, to the extent that the information relates to alleged commission by a data subject of any offence; 
  • proceedings about any offence allegedly committed by a data subject or the disposal of those proceedings. 

Unique identifier 

Any identifier that is assigned to a data subject and is used by a responsible party for the purposes of the operations of that responsible party and that uniquely identifies that data subject for that responsible party. 

RIGHTS OF A DATA SUBJECT

The data protection laws give certain rights in relation to the personal information held on you. These are: 

  • The right to be notified: This means that we must tell you how we use your personal information; 
  • The right of access: You have the right to access the personal information that we hold on you. To do so, you should make a subject access request; 
  • The right for any inaccuracies to be corrected: If any personal information that we hold about you is incomplete or inaccurate, you can request us to make any necessary amendments to correct it; 
  • The right to have information deleted: If you would like us to stop processing your personal information, you have the right to ask us to delete it from our systems where you believe there is no reason for us to continue processing it; 
  • The right to restrict the processing of the personal information: For example, if you believe the personal information we hold is incorrect, we will stop processing it (whilst still holding it) until we have ensured that it is correct; 
  • The right to portability: You may transfer the personal information that we hold on you for your own purposes; 
  • The right to object to the inclusion of any information: You have the right to object to the way we use your Personal information where we are using it for our legitimate interests; 
  • The right to regulate any automated decision-making and profiling of Personal information: You have a right not to be subject to automated decision making in way that adversely affects your legal rights. 

HOW IS PERSONAL INFORMATION OBTAINED

  • Directly from data subjects and their ongoing dealings with MSC; 
  • Through information contained in a public record or has deliberately been made public by the data subject; 
  • Through the course of ongoing correspondence; 
  • Through MSC’s due diligence procedures, which may include information from third parties through publicly available sources; 
  • Through recording any communications with data subjects including, electronic, telephonic, in person or otherwise, which will constitute evidence of the communications. This information is collected in compliance with MSC’s regulatory record keeping obligations. Telephone conversations may be recorded without the use of a warning tone or any other further notice. 
  • Any of our offices or premises may have CCTV cameras which may record a data subject’s image. 

WHAT PERSONAL INFORMATION DOES MSC PROCESS?

  • Identifiers such as name, ID number, passport number, contact information
  • Age
  • Martial status and dependants 
  • Nationality 
  • Educational history 
  • Financial position 
  • Employment history 
  • Personal views 
  • Medical conditions (if relevant) 
  • Private correspondence 

WHO DOES MSC SHARE DATA SUBJECT’S PERSONAL INFORMATION WITH?

MSC needs to share data subject’s personal information with contracted service providers and partners to implement proposed solutions. MSC may also share personal information when specialised or additional guidance is required. 

A data subject’s personal information can be sent from South Africa to a third party in a foreign country provided that country: 

  • has a law that is similar to and consistent with the POPI Act, which the recipient in the foreign country is subject to; 
  • if there is a binding agreement between recipient and sender that ensures full compliance the POPI Act; or 
  • if the recipient and sender, are part of the same corporate structure, and are bound by binding corporate rules that ensure full compliance with the POPI 

MSC may also share personal information when required by any regulatory authority or any legislation or legal process as well as when we have been given express permission by a data subject to do so. 

MSC does not sell your personal information or share it with other parties for marketing use. 

INFORMATION OFFICER

MSC must appoint an Information Officer who will be responsible for ensuring that the information protection principles within the POPI Act and the controls that are in place to enforce them are complied with. 

Lisa Rodel is the appointed and registered Information Officer for MSC.
E-mail: lisa@mscapitalgroup.co.za
Tel: (011) 784 4730
Cell: 083 556 8414 

The Information Officer is responsible for: 

  • Conducting a preliminary assessment; 
  • The development, implementation and monitoring of this policy and compliance framework; 
  • Ensuring that this policy is supported by appropriate documentation; 
  • Ensuring that documentation is relevant and kept up to date; 
  • Ensuring this policy and subsequent updates are communicated to relevant managers, representatives and staff, where applicable. 

All employees and individuals directly associated with MSC are responsible for adhering to this policy and for reporting any security breaches or incidents to the Information Officer.