It’s almost time for a well-deserved break – just a few more days! With various religious and public holidays coming up, we hope you take the opportunity to regather some energy. Stay safe and healthy if you’re attending any events.
We’ve gathered some light reading for the long weekends coming up.
The Financial Sector Conduct Authority (the FSCA)
Continuous Professional Development (CPD)
An important reminder that there are two months left for Key Individuals and applicable Representatives to complete their CPD requirements.
Here’s a basic breakdown of the CPD hours required.
| 2021 CPD Requirements | CPD hours | Deadline | |
| One category | One sub-category | 4.5 | 31 May 2021 |
| Multiple sub-categories | 9 | 31 May 2021 | |
| Multiple categories | One sub-category | 13.5 | 31 May 2021 |
| Multiple sub-categories | 13.5 | 31 May 2021 | |
Should you urgently need to complete hours, we recommend you contact Charmaine Koch at our CPD partner, AC Develop via charmaine@acdevelop.co.za.
Exemptions from solvency conditions
Just in time for most financial service providers’ (FSPs’) annual year end, the FSCA has once again updated the exemptions for FSPs that don’t collect premium or hold funds, as well as for Juristic Representatives of insurers that do collect premium or hold funds. The expiration dates of Notices 123 and 124 of 2017 have been extended until 31 December 2023.
Essentially, it’s business as usual.
The notices are available here, here, and here (the last corrects the date error).
Prudential Authority (PA)
Solvency Capital Requirement
On 3 March 2021, the PA released Guidance Note 1 of 2021 to provide guidance on the Iterative Approach for determining the Solvency Capital Requirement (SCR).
It’s a technical document to explain the method to be employed by insurers when determining their SCR. This was deemed necessary to avoid a circularity issue in the previous method.
Make sure you’ve had your omega oil before you read this.
The PA’s “flavour-of-the-year”
On 12 March, the PA released Communication 2 of 2021 which explains its focus for the year. The focus is the implementation of International Financial Reporting Standard 17: Insurance Contracts (IFRS 17).
It does means that the ‘new technologies’ focus from 2020 which was suspended due to the COVID-19 restrictions will no longer remain a major focus. However, the PA is likely to request further information on this topic.
Insurers are required to acknowledge the Communication via a letter to the PA team dealing with the insurer. The letter must be signed by the chief executive officer and external auditors.
Read the full Communication here
National Treasury
National Treasury is continuing with its plans to amend Regulation 28 of the Pension Funds Act (Act No. 24 of 1956) and requested comments during March.
The intention of the amendment is to allow pension funds to invest in “infrastructure” which they were previously prohibited from doing. The draft aims to define the term and create suitable limits for investment in such avenues.
Importantly, hedge and private equity funds will be delinked from the category, but limitations on the percentage investment in them will apply.
Read the full draft amendment here.
South African Reserve Bank (SARB)
Discussion document
On 18 February 2021, the SARB invited comments on a discussion document on the data definition and reporting requirements for deposit insurance in South Africa.
The intention is to describe the data requirements and operational proposals for the Corporation for Deposit Insurance (CoDI).
Comments are due by 16 April 2021, and the discussion document is available here.
Registration of R+V Versicherung AG
The SARB announced that it has approved the registration of R+V Versicherung AG to operate in South Africa as a branch of a foreign reinsurer. The registration was approved from 14 January 2021, and includes all non-life insurance classes and sub-classes.
Read the full notice here.
Financial Intelligence Centre (FIC)
Financial Action Task Force (FATF) meeting
South Africa participated in the meeting of the FATF in February 2021. The FATF aims to promote and guide effective implementation of measures against money laundering and the financing of terrorism. As such, it has taken a number of steps to increase the effectiveness of the applicable legislation in the various jurisdictions it is involved in.
Of note was the increase in monitoring requirements for transactions with Burkina Faso, the Cayman Islands, Morocco, and Senegal which will require Risk Management and Compliance Plans for South African Accountable Institutions (AIs) to be updated once again.
Read the FIC’s summary here.
Draft Public Compliance Communication 113 (draft PCC 113)
On 4 March 2021, the FIC issued draft PCC 113 for consideration by all AIs. The draft PCC aims to provide guidance on the compliance measures relating to foreign prominent influential persons (FPPOs), domestic prominent influential persons (DPIPs), their family members, and known close associates.
The FIC stated that it felt this was necessary as it had identified inconsistencies in AIs’ understanding of how and when they determine whether clients are DPIPs or FPPOs, the implications of family members or known associates of the client are DPIPs or FPPOs, and when a legal entity client has a beneficial owner or an appointed person who is a DPIP or FPPO.
If approved, the PCC will provide more clarity and assist AIs to better manage this aspect of their client due diligence.
Read the draft PCC here.
Information Regulator – POPIA (Protection of Personal Information Act)
On 24 March 2021, it was 100 days until 1 July 2021 where public and private bodies need to be POPIA compliant.
Prior Authorisation Guidance
On 11 March 2011, the Information Regulator published detailed guidance on “Prior Authorisation.” This guidance was highly anticipated, but unexpected. We thought that this would be available from July 2021 or even sometime thereafter. The reason it has been released sooner than expected is to allow applications to be submitted as soon as possible, and give the Information Regulator time to process prior authorisation applications on or before 30 June 2021. The application process can take between four and 13 weeks depending on whether the Information Regulator wishes to conduct a more detailed investigation into the lawfulness of the processing of unique identifiers.
Chapter 6 and sections 57 to 59 of POPIA deal with prior authorisation.
- Section 57(1)(a) requires responsible parties to apply for authorisation to process unique identifiers of data subjects where the purpose for processing the unique identifier changes from the original purpose for the objective of linking the information with information processed by other responsible parties.
- Examples of unique identifiers are: bank account number (or any account number), policy number, identity number, employee number, student number, location data, an online identifier, personal tax number, telephone or cell phone number, or reference number. A practical scenario could be as follows: a person’s name and surname might not be enough to uniquely identify that person, but when you combine that person’s telephone number or home address with their name and surname, they may become uniquely identifiable.
- Section 57(1)(b) requires all persons contracted to conduct criminal record verification and background checks for third parties, for example service provider conducting background checks for employers relating to any potential employees to obtain prior authorisation.
- Section 57(1)(c) refers to credit reporting by credit bureaux registered with the National Credit regulator, or any person processing personal information for credit reporting purposes. Such processing includes personal payment history, lending, and credit worthiness of a data subject by creating a credit report on that information, and lender or credit providers using credit reports along with other personal information to determine a data subject’s creditworthiness.
- Section 57(3) states that sections 57 and 58 are not applicable where a Code of Conduct has been issued (for example, the Credit Bureau Association published the final version of its “Code of Conduct: Lawful Processing of Personal Information in the Credit Sector”) which has been approved by the Information Regulator. (We’re not sure how the section grants exemption from itself, but let’s go with it – Ed.)
- Section 57(1)(d) deals with the transfer of the special personal information or personal information of children to a third party in a foreign country that does not provide an adequate level of protection for the processing of personal information. Special personal information includes personal information relating to religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, the criminal behaviour of a data subject in respect of the alleged commission of any offence, processing in respect of any offence allegedly committed by a data subject, or disposal of such proceedings.
The Information Regulator has further clarified the position relating to transborder flows of personal information. If the flow of special personal information or personal information of children to a third party who is subject to:
- adequate laws in the foreign jurisdiction (adequate jurisdiction, akin to the concept under the European Union’s GDPR [General Data Protection Regulation]);
- binding corporate rules; or
- a binding agreement (data transfer agreement), which provides an adequate level of protection that effectively upholds principles for processing the information that are substantially similar to the conditions for the lawful processing in terms of POPIA, then prior authorisation would not be required.
In all other circumstances, prior authorisation will be required for transfers of special personal information or personal information of the children to a third party in a foreign country that does not provide an adequate level of protection.
- Section 57(2) deals with other types of information if such processing carries a particular risk to the legitimate interests of the data subject.
- Section 58 – Application form for prior authorisation
The Information Regulator has provided a prescribed application form, which is to be completed and submitted by responsible parties, prior to the responsible party conducting any activity which is subject to prior authorisation.
The application form provides for the disclosure of information such as: the relevant details of the responsible party and the registered information officer of the responsible party, the relevant category of personal information processed, a description of the processing activity, the reasons why the processing of information is necessary, the number of data subjects the information relates to, and the security measures and other operational measures to be implemented.
The application form must be signed by the registered information officer of the organisation.
It is important to note that the requirements of prior authorisation are not applicable to the processing of personal information which took place prior to 1 July 2021, however any further or continued processing of such personal information (which was initially processed before 1 July 2021) will be subject to prior authorisation requirements in terms of section 57 and 58 of POPIA.
Registration of information officers
The Information Regulator tweeted on 18 March 2021 that the registration of information officers will commence from 1 May 2021.
The Information Regulator further states that the guidelines (registration of information officers) will be published once all public comments have been considered. We were advised last month that we should expect the guidelines by the end of April.
We will keep you informed of developments regarding the online registration and/or the forms should the format have changed.
Read the tweet here.
A-Proofed
Is text speak ruining business English writing?
On 3 December 1992, a 22-year-old Canadian test engineer typed out a very simple message, “Merry Christmas.” It flew over the Vodafone network to the phone of one Richard Jarvis, and since then, we just haven’t been able to stop texting.
Today, almost 30 years later, statistics provided by https://fortunly.com/statistics/ show that WhatsApp has more than two billion active monthly users who are sending 100 billion messages every day. That’s almost 1.4 million messages a minute!
Text messaging is so convenient because we’re able to “access our peeps in a flash”. Think about it – imagine not being able to send a message to your wife while you’re in Woolies about missing items from the shopping list. How about “I’m having a drink with the guys. See you later.” Very important!
With the “convenience” aspect, comes the “in a hurry, can’t type too many letters or words” aspect. “What’s for dinner?” becomes “Wot’s 4 dnr?” and “See you later” becomes “C U L8r”. There’s also the historical aspect of the days prior to smartphones, when each button on the cell phone keypad had three letters, and it was just so much easier to use what has become known as txtspk. And you won’t be surprised to know that many people still use that format, even though it’s just as easy to type the full word on today’s phones. In addition, there was the cost aspect – txt msgs were limited to 160 characters, so people found creative ways to reduce the number of characters, without losing the context of the message.
This type of quick communication has now filtered through into our business lives and has impacted on our general communication, and on business communication in particular. Txtspk leads to deficiencies in basic language skills. Shortcuts with spelling, punctuation, and emoticons aren’t helping children, and teenagers aren’t learning the necessary writing and communication skills they need to take into their working life.
Some experts say that casual communication such as text message lingo, instant message abbreviations, emoticons, or even a quickly dashed off (and often misspelled) message from your smartphone can shatter your chances of landing a new customer, making a potential sale, or getting a certain job. In addition, there’s potential for a recipient to misinterpret your message.
Let’s look at a couple of examples:
Client: How are you progressing with my proposal?
Employee: NP Jack. Im wrkin it this wknd.
Client: How are you progressing with my proposal?
Employee: Hello Jack. I’ll be working on it this weekend, and you’ll have it by midday on Monday.
I’m sure you’ll agree that the second response is much more professional, despite the fact that you have to type a few more words.
An email sent on your company address is a business record and, as such, represents your brand and image. How would you feel as the chief executive if your staff sent emails which don’t properly reflect your brand and company values? While some of your clients may forgive the occasional typo, spelling mistake, or casual communication, for others it could indicate that you’re sloppy and not to be taken seriously. Those types of misunderstandings can be costly when it comes to business.
Remember, there is a time and place for casual chatter. After the close of business, customers aren’t your friends, so save the LOLs for non-work acquaintances. You don’t know what might annoy someone, so the best plan is to keep it formal and professional. Put together thoughtful sentences and support your written communications with a polished verbal or personal presentation.
Business emails need to be properly structured, grammatically correct, and spell-checked*. After all, it wouldn’t be good to tell board members that “there’s a mistake in the board pack. LOL!”
If all else fails, you can always call on me for assistance with compiling that important email.
ps. U can thnk me 4 this advice l8tr.
* Remember to set your spell-checker to the appropriate language. I can help with that, too.
Kim Hatchuel
083 657 3377 | kim@a-proofed.co.za
www.a-proofed.co.za



