PAIA Manual

1. INTRODUCTION

Credit Bar (Pty) Ltd (“Credit Bar”, “we”, “us”, or “our”) understands the importance of transparency and the Constitutional right of access to information and will do our utmost best to ensure that anyone who requires access to any record to fully exercise and protect their rights has access to the PAIA Guide prepared by the Regulator as well as assistance from us in undertaking the request process. Credit Bar takes extreme care to ensure all the records we hold are protected from unlawful access and are processed in accordance with South African law. To this end, we have prepared this PAIA manual in accordance with the requirements of section 51 of PAIA to assist anyone where they seek to request access to information held by us under PAIA.

2. DEFINITIONS AND INTERPRETATION

In this Agreement, unless otherwise indicated by context, the following words and expressions bear the meanings assigned to them and cognate expressions bear corresponding meanings:

2.1.  “CEO” means the Chief Executive Officer;

2.2.  “DIO” means the Deputy Information Officer;

2.3.  “IO” means Information Officer;

2.4.  “PAIA” means the Promotion of Access to Information Act, 2 of 2000, as amended;

2.5.  “POPI” means the Protection of Personal Information Act, 4 of 2013, as amended;

2.6.  “Regulator” means the Information Regulator established in terms of section 39 of POPI;

2.7.  “Regulations” means the regulations published in terms of section 92 of PAIA;

2.8.  “South Africa” means the Republic of South Africa.

3. PURPOSE OF PAIA MANUAL

The purpose of this PAIA manual is to assist anyone to:

3.1.  review the categories of records we hold which are available without having to submit a formal PAIA request;

3.2.  understand how to make a request for access to a record of ours, by providing a description of the subjects on which we hold records and the categories of records held under each subject;

3.3.  review the types of records which are available in accordance with any other legislation;

3.4.  access all the relevant contact details of the IO and DIO of CreditBar who will assist with the records anyone intends to access;

3.5.  understand how to access the guide on how to use PAIA, as updated by the Regulator;

3.6.  understand whether we will process personal information, the purposes for which we process personal information and the description of the categories of data subjects and of the information or categories of information relating thereto;

3.7.  distinguish the categories of data subjects and of the information or categories of information relating thereto;

3.8.  identify the third parties to whom personal information may be supplied by us;

3.9.  identify if we have planned to transfer or process personal information outside of South Africa and the parties to whom the personal information may be transferred;

3.10.  understand the appropriate security measures we employ to ensure the confidentiality, integrity, and availability of the personal information we process.

4. GUIDE ON HOW TO USE PAIA AND HOW TO OBTAIN ACCESS TO THE GUIDE

4.1.  The Regulator has, in terms of section 10(1) of PAIA, updated and made available the revised Guide on how to use PAIA (“PAIA Guide”), in an easily comprehensible form and manner, as may reasonably be required by a person who wishes to exercise any right contemplated in PAIA and POPI.

4.2.  The Regulator has made the PAIA Guide available in each of the official languages of South Africa and in braille.

4.3.  The PAIA Guide contains the following:

4.3.1.  The objects of PAIA as well as POPI;

4.3.2.  How to access the postal address, telephone number and email address of every registered IO and DIO (for both public and private bodies);

4.3.3.  The manner and form of request for:

4.3.3.1.  access to a record of a public body contemplated in section 11 of PAIA

4.3.3.2.  access to a record of a private body contemplated in section 50 of PAIA.

4.3.4.  the assistance available from the IO of a body in terms of PAIA and POPI;

4.3.5.  the assistance available from the Regulator in terms of PAIA and POPI;

4.3.6.  all remedies in law available regarding an act or failure to act in respect of a right or duty conferred or imposed by PAIA and POPI, including the manner of lodging –

4.3.6.1.  an internal appeal;

4.3.6.2.  a complaint to the Regulator;

4.3.6.3.  an application with a court against a decision by the IO of a public body, a decision on internal appeal or a decision by the Regulator or a decision of the head of a private body;

4.3.7.  the provisions of sections 14 and 51 of PAIA requiring a public body and private body, respectively, to compile a manual, and how to obtain access to a manual;

4.3.8.  the provisions of sections 15 and 52 of PAIA providing for the voluntary disclosure of categories of records by a public body and private body, respectively;

4.3.9.  the notices issued in terms of sections 22 and 54 of PAIA regarding fees to be paid in relation to requests for access;

4.3.10.  the Regulations.

4.4.  Anyone can inspect or make copies of the PAIA Guide from the office of the Regulator, during normal working hours.

4.5.  The PAIA Guide can also be obtained

4.5.1.  upon request to CreditBar’s IO or DIO;

4.5.2.  from the website of the Regulator (https://inforegulator.org.za).

4.6.  A copy of the PAIA Guide is also available in the following two official languages, for public inspection during normal office hours –

4.6.1.  English; and

4.6.2.  Zulu.

5. CONTACT DETAILS FOR ACCESS TO INFORMATION

5.1.  INFORMATION OFFICER

Name: Anastasiia Vasylieva

Email: contact@creditbar.co.za

5.2.  GENERAL CONTACT

Email: contact@creditbar.co.za

5.3.  HEAD OFFICE

Hyde Park, House 11, Century Way, Milnerton, Cape Town, Western Cape, 7441

5.4.  Website: https://creditbar.co.za 

6. PROCEDURE TO REQUEST ACCESS TO INFORMATION

6.1.  A request for access to information for a record held by the company must be made on a form which corresponds substantially to Form 2 along with proof of payment of the prescribed fee to CreditBar’s IO or DIO at the details listed in section 5.

6.2.  When completing Form 2 or a form substantially similar, a requester must provide clear and accurate information and clearly state the right which the requester seeks to exercise or protect, the record which they are seeking to access and an explanation as to how such record will assist them to exercise or protect their rights.

6.3.  CreditBar has 30 (thirty) days within which to respond to any request received. Once a decision has been made, the company’s IO or DIO will inform a requester of their decision whether to grant or refuse a request and any fees payable on a form that corresponds substantially to that of Form 3 of the Regulations.

6.4.  CreditBar may refuse a request for access to a record on any of the grounds listed in Chapter 4 of PAIA (which are listed in the PAIA Guide).

6.5.  A requester is required to pay the request fee before a request will be processed. The request fee is listed in Annexure B to the Regulations. The current request fee payable is R140.00 (one hundred and forty Rand) per request.

6.6.  The request fee must be paid into CreditBar’s nominated bank account, which details are available from our IO or DIO on request.

6.7. Prior to granting access to any record containing personal information, CreditBar reserves the right to verify the identity and authority of the requester to ensure that personal information is disclosed only to authorised persons and in accordance with POPIA.

6.8. Where requested records contain personal information relating to third parties, CreditBar shall consider the provisions of PAIA and POPIA before granting access and may refuse, partially grant, or redact records where disclosure would unreasonably infringe the privacy rights of another person.

7. REMEDIES

7.1.  If a requester is unhappy with a decision made, they may submit a complaint to the Regulator.

7.2.  A complaint to the Regulator must be made on a form which corresponds substantially to that of Form 5 of the Regulations. A complaint to the Regulator must be lodged within 180 (one hundred and eighty) days of receipt of the decision from CreditBar.

7.3.  The complaint will then follow the dispute resolution process described in the Regulations as well as the PAIA Guide.

8. RECORDS WHICH ARE AVAILABLE WITHOUT REQUEST

The following records are made freely available by CreditBar and do not require any request to access:

Category of Records Types of the Record Where Available
CreditBar Policies Terms of Use On Website
CreditBar Policies Privacy policy On Website

9. RECORDS WHICH ARE AVAILABLE IN ACCORDANCE WITH OTHER LEGISLATION

The following records are freely available to the public in accordance with legislation:

Category of Records Applicable Legislation
Memorandum of Incorporation Companies Act 71 of 2008
PAIA Manual Promotion of Access to Information Act 2 of 2000
Privacy Policy Protection of Personal Information Act 4 of 2013

10. SUBJECTS AND CATEGORIES OF RECORDS HELD

CreditBar holds records on the following subjects:

Subject of Records Categories of Records
Company Secretarial Memorandum of Incorporation; share certificates, resolutions, director registrations, minutes of meetings, share register
Human Resources HR policies and procedures; available employment opportunities; employee records
Finance Banking/bank account records; contractual agreements, accounting records, financial statements and reports, invoices
Insurance Insurance policy documents
Intellectual Property Trademarks, copyright, know-how, and contractual agreements; original designs
Tax Income tax records, contractual agreements
Property Lease agreements
Commercial Agreements Service level agreements; employee agreements, contractor agreements
Information Technology Software licenses, data protection measures, data retention formulae, breach recovery processes
Compliance POPIA compliance records, PAIA requests, complaints, Information Officer records, breach registers
Credit Administration Loan applications, affordability assessments, credit reports, repayment records, customer correspondence
FICA Compliance Customer identification records, risk assessments, source of funds documentation, transaction monitoring
Risk Management Risk registers, internal audit reports, compliance monitoring reports
Information Security Access logs, incident reports, backup records, disaster recovery documentation

11. PROCESSING OF PERSONAL INFORMATION

11.1.  Purpose of Processing

11.1.1.  CreditBar processes personal information for legitimate business purposes and as a necessary function of a client’s engagement with our services with such client’s express consent. We therefore process personal information in the following circumstances:

11.1.1.1.  to provide our credit services to clients;

11.1.1.2.  to receive and accept services from independent contractors;

11.1.1.3.  to provide it to authorised third party service providers who need personal information to provide services to us;

11.1.1.4.  to provide it to mandated government authorities when instructed to do so for legal compliance only (such as the Income Tax Act, FICA);

11.1.1.5.  to improve experiences on our website through analytical data.

11.1.1.6. to comply with applicable legislation including the National Credit Act, Financial Intelligence Centre Act, Companies Act, Income Tax Act, Labour legislation and other statutory obligations.

11.1.1.7. to detect, investigate and prevent fraud, money laundering, identity theft and other unlawful activities.

11.1.1.8. to establish, exercise or defend legal rights and legal proceedings.

11.1.1.9. to maintain internal governance, risk management and compliance processes.

11.2.  Data Subjects and Information Processed

As a responsible party, we process the following information from the following list of data subjects:

Data Subjects Personal Information that may be processed
Clients Information from on-boarding which includes personal information;
contact details; company information; support enquiries.
Service Providers Service Providers Company information such as name, registration number, VAT information,
registered address, Information obtained from service level agreements such as,
trade secrets confidential information and banking information.
Employees / Possible Employees / Directors / Shareholders Full name, identity documentation, address, contact information, educational qualifications (including curriculum vitae),
gender, race, banking information, and tax information.
Independent Contractors / Sub-Contractors Company information such as name, registration number, VAT information, registered address, and/or personal information such as full name,
address, identity number, contact information, and information obtained from contractual agreements
such as confidential information, banking information and/or tax information.
Prospective Customers Loan applications, affordability information, identity verification, contact details
Guarantors Identity documents, financial information, contact details
Website Visitors IP addresses, cookies, browser information, analytics data
Regulators Correspondence, investigations, compliance submissions

 

11.3.  Third Party Recipients to Whom We Share Personal Information

In accordance with our operational requirements, we share personal information with the following third parties:

Category of personal
information
Recipients or Categories of Recipientsts
whom the personal information may be supplied
Identity, Contact, Marketing, Financial, Transactional,
Contractual, Technical and Usage data.
Cloud storage and database hosting software service provider
Identity, Contact, Marketing, Financial, Transactional,
Contractual, Technical and Usage data.
Accountants and Legal Advisors
Identity, Contact, Financial, Transactional,
Contractual, Technical and Usage data.
Customer Relationship Management software
Identity, Contact, Financial, Transactional,
Contractual, Technical and Usage data.
Credit Bureaux
Identity information, credit application information, affordability assessment data, credit agreements, payment history, repayment performance, defaults, adverse information and other information permitted under the National Credit Act. Credit Bureaux
Customer identification information, loan application information, affordability assessment records, credit agreements, complaint records, regulatory returns, compliance documentation, audit information and any records required under the National Credit Act. National Credit Regulator
Identity verification records, FICA customer due diligence documentation, source of funds information, beneficial ownership information, risk assessments, suspicious transaction reports (where applicable), transaction records and other information required under FICA. Financial Intelligence Centre
Tax reference numbers, financial records, invoices, payment records, payroll information, employee tax information, VAT records and any other information required under applicable tax legislation. South African Revenue Service
Financial records, accounting records, payroll information, company records, contracts, compliance records and any information reasonably required to perform professional services. External Auditors
User account information, system logs, access logs, device information, technical identifiers, backup data and limited personal information necessary for maintaining and securing CreditBar’s systems. IT Security Providers
Customer names, banking details, account numbers, payment amounts, transaction references, payment histories and payment instructions necessary to facilitate transactions. Payment Service Providers
Customer banking information, payment instructions, account verification information, settlement information and transaction records necessary for processing payments and collections. Banks
Identity numbers, names, dates of birth, contact information, identity documents, biometric verification information (where applicable), fraud screening information and verification results. Identity Verification Service Providers

CreditBar only shares personal information with third parties where there is a lawful basis to do so, including where disclosure is required by law, necessary for the performance of a contract, required to protect the legitimate interests of CreditBar or the data subject, made with the consent of the data subject where required, or where the recipient is acting as an authorised operator on behalf of CreditBar. All operators and service providers are required to implement appropriate technical and organisational security measures to protect personal information in accordance with POPIA.

11.4.  International Transfers

11.4.1.  CreditBar may transfer personal information outside of South Africa in the following circumstances:

11.4.1.1.  Personal information which is stored using secure cloud servers hosted outside of South Africa.

11.4.1.2.  Service providers including software for business operation, based outside of South Africa.

11.4.1.3.  Personal information may be shared within the CreditBar group of companies.

11.4.2. Whenever we transfer any personal information outside of South Africa, we always ensure a similar degree of protection is afforded to it by ensuring there are contracts in place with all such third parties, providing warranties that they will process the personal information at standards equal to or better than those applied by us.

11.5.  Data Security

CreditBar maintains appropriate, reasonable technical and organisational measures designed to prevent loss of, damage to, unauthorised destruction of, unlawful access to or unlawful processing of personal information. Such measures include:

  • encryption of sensitive information;
  • multi-factor authentication;
  • role-based access controls;
  • password management standards;
  • anti-virus and endpoint protection;
  • firewall protection;
  • secure backups;
  • disaster recovery procedures;
  • logging and monitoring of access;
  • periodic security reviews;
  • secure destruction of records; and
  • confidentiality obligations applicable to employees, contractors and service providers.

11.6.  Data Collection Practices

CreditBar shall take reasonably practicable steps to ensure that personal information processed is complete, accurate, not misleading and updated where necessary, having regard to the purpose for which it is processed.

11.7.  Data Subjects Rights

Include:

  • right of access
  • right to correction
  • right to deletion
  • right to object
  • right to withdraw consent
  • right to lodge complaints
  • right to submit PAIA requests

11.8.  Record Retention

CreditBar retains personal information only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, resolve disputes and enforce agreements. Records are securely destroyed once retention periods have expired unless legislation requires otherwise.

11.9.  Special Personal Information

  • race
  • health
  • criminal records
  • biometrics (if applicable)

are processed only where permitted by POPIA or required by law.

11.10.  Direct Marketing

CreditBar only conducts direct marketing in accordance with POPIA and provides data subjects with an opportunity to opt out of receiving marketing communications.

11.11.  Personal Information Breach

CreditBar maintains procedures for identifying, reporting, investigating and responding to actual or suspected personal information security compromises. Where required by law, CreditBar will notify affected data subjects and the Information Regulator as soon as reasonably possible following discovery of a security compromise.

11.11.  Operator Management

CreditBar requires all operators processing personal information on its behalf to implement appropriate security safeguards and to process personal information only on documented instructions from CreditBar in accordance with section 20 and section 21 of POPIA.

12. AVAILABILITY OF PAIA MANUAL

12.1.  A copy of this PAIA Manual is available

12.1.1.  on our website, at https://creditbar.co.za;

12.1.2.  to any person upon request and upon the payment of a reasonable prescribed fee

12.1.3.  to the Information Regulator upon request.

12.2.  The fee for a copy of this PAIA Manual, as contemplated in Annexure B of the Regulations, shall be payable per each A4-size photocopy made.

13. UPDATE TO THIS PAIA MANUAL

13.1.  This PAIA Manual will be regularly updated by CreditBar’s IO and/or DIO.

13.2.  This PAIA Manual was last updated on 27 May 2025.

If you have any questions, please direct them to the IO or Deputy Information Officer.

13.3. This Manual shall also be reviewed whenever there are material changes to applicable legislation, regulatory guidance, business operations, information processing activities or information security practices.