| 
   Abbreviation  | 
  
   Meaning   | 
 
| 
   CEO  | 
  
   Chief Executive Officer  | 
 
| 
   DIO  | 
  
   Deputy Information Officer   | 
 
| 
   IO  | 
  
   Information Officer   | 
 
| 
   PAIA  | 
  
   Promotion of Access to Information Act, 2 of 2002 (as amended)  | 
 
| 
   POPIA  | 
  
   Protection of Personal Information Act, 4 of 2013  | 
 
2.1       PAIA requires all public and private bodies in South Africa to have a
manual to explain to the public how they can get access to records that a body
holds. 
2.2       This manual will help you do the following: 
2.2.1        
Check the categories of
available records that a body holds without having to submit a formal PAIA
request.
2.2.2        
Request access to the records
that a body holds. 
2.2.3        
Obtain the contact
details of the IO and the DIO, who will help you gain access to the records that
you want.
2.3     The
manual will also give you information about the following: 
2.3.1        
The description of the
available records that the body holds, in line with other legislation.
2.2.4        
The description of the data
subject categories and the related information or categories of information.
2.2.5        
Whether and why a body
will process personal information, including sending or processing personal
information outside of South Africa. 
2.2.6        
The categories of data
subjects and the information or categories of information relating to the
personal information.
2.2.7        
The recipients or
categories of recipients to whom the personal information may be given. 
2.3.2        
Whether a body has
appropriate security measures to ensure the confidentiality, integrity and
availability of the personal information that will be processed.
2.3.3        
The PAIA guide and how
to access it.
Daleen du Toit
Physical address:             135 Rivonia Road
                                       Sandown
                                       Sandton
                                       Johannesburg
Postal address:               PO Box 653640 
                                       Benmore
Gardens 
                                       2196
Email:                             paia@nedbank.co.za 
Website:                          nedbank.co.za
Neelesh Mooljee
Physical address:             135
Rivonia Road
                                       Sandown
                                       Sandton
                                       Johannesburg
Postal address:               PO Box 653640 
                                       Benmore
Gardens 
                                       2196
Tel:                                 +27
(0)10 234 8858
Email:                             paia@nedbank.co.za 
Website:                          nedbank.co.za
Email:                             paia@nedbank.co.za 
Postal address:                PO Box 1144,
Johannesburg, 2000
Physical address:             135 Rivonia Road, Sandown, Sandton  
Telephone:                      0800
555 111
Website:                          nedbank.co.za
4      
How
to use PAIA and access the PAIA guide
4.1       In terms of section 10(1) of PAIA, the Information Regulator has updated and made available a revised guide on how to use PAIA to anyone
who wants to exercise a right as set out in
PAIA and POPIA.
4.2       The guide is easy to understand and available in all the official South
African languages, including braille.
4.3       The guide includes the following:
4.3.1        
Descriptions of the aims
of PAIA and POPIA.
4.3.2        
The postal and street
addresses, contact numbers and, if available, email addresses of - 
4.3.2.1           
the IO of every public
body; and
4.3.2.2           
the DIO of every public
and private body designated in terms of section 17(1) of PAIA[1]
and section 56 of POPIA[2].
4.3.3        
Request forms with
instructions on how to request access to records of -
4.3.3.1           
a public body as set
out in section 11[3] of
PAIA; and
4.3.3.2           
a private body as set
out in section 50[4] of
PAIA.
4.3.4        
A description of the help
available from the IO of a public body in terms of PAIA and POPIA.
4.3.5        
A description of the help
available from the Information Regulator in terms of PAIA and POPIA.
4.3.6        
A description of remedies
in law available regarding an act or failure to act in respect of a right or
duty that PAIA and POPIA confers or imposes, including how to lodge -
4.3.6.1           
an internal appeal; 
4.3.6.2           
a complaint with the
Information Regulator; and 
4.3.6.3           
a court application against
a decision of the IO of a public body, a decision about an internal appeal or a
decision of the Information Regulator or the head of a private body.
4.3.7        
The provisions of
sections 14[5]
and 51[6]
of PAIA, which require a public or private body to compile a manual and to
describe how to access the PAIA guide.
4.3.8        
The provisions of
sections 15[7]
and 52[8]
of PAIA providing for the voluntary disclosure of categories of records by a
public or private body.
4.3.9        
The notices issued in
terms of sections 22[9]
and 54[10]
of PAIA about the fees that must be paid for access requests.
4.3.10       The regulations made in terms of section 92[11]
of PAIA.
4.4       You can inspect or make copies of the guide from the offices of the
public and private bodies, including the office of the Information Regulator,
during normal working hours.
4.5       You can also get the guide:
4.5.1        
on request from the IO;
or
4.5.2        
from the Information Regulator’s
website at inforegulator.org.za.
4.6       A copy of the guide is also available in English and Afrikaans for
public inspection during normal office hours.
5   
General
information about disclosure following a request for access to records 
5.1  
We must or may refuse the
following requests for records:
5.1.1     
Records for the purpose
of criminal or civil proceedings (subject to section 7 of PAIA).
5.2.1     
a substantial
contravention of or failure to comply with the law; or
5.2.2     
an imminent and serious
public safety or environmental risk; and
if
6   
Nedbank
categories of records available without a request 
| 
    Record category   | 
   
    Record type   | 
   
    Available at our website at nedbank.co.za   | 
   
    Available on request   | 
  
| 
   Human resources  | 
  
   Statutory and other employee records 
 
  | 
  
   X  | 
  
   X  | 
 
| 
   External-candidate profiles and positions applied for  | 
  
   X  | 
  
   
  | 
 |
| 
   Company secretarial  | 
  
   Own portfolio or shareholdings, tax statements for share transactions
  (IT3), frequently asked questions (FAQs) and rules of the share scheme  | 
  
   
  | 
  
   X  | 
 
| 
   Own portfolio or shareholdings (transactions, dividends), tax
  statements for share transactions (IT3), FAQs and rules of the share scheme  | 
  
   
  | 
  
   X  | 
 |
| 
   Annual financial statements (audited), Stock Exchange News Service (SENS)
  announcements and share prices  | 
  
   X  | 
  
   
  | 
 |
| 
   Market conduct; financial advisory and intermediary services
  (FAIS)  | 
  
   Debarments and date-of-first-appointment (DOFA) documents  | 
  
   
  | 
  
   X  | 
 
| 
   Account statement for a specific period  | 
  
   X  | 
  
   X  | 
 |
| 
   Account statement for a specific period (Corporate Saver)  | 
  
   X  | 
  
   X  | 
 |
| 
   Copies of legal agreements (Corporate Saver)  | 
  
   
  | 
  
   X  | 
 |
| 
   Profile setup (Corporate Saver)  | 
  
   
  | 
  
   X  | 
 |
| 
   Confirmation of balances   | 
  
   X  | 
  
   X  | 
 |
| 
   Transaction listing  | 
  
   
  | 
  
   X  | 
 |
| 
   Needs analysis and disclosures  | 
  
   
  | 
  
   X  | 
 |
| 
   Available balance on account   | 
  
   
  | 
  
   X  | 
 |
| 
   Historic client receipts  | 
  
   
  | 
  
   X  | 
 |
| 
   Call recordings  | 
  
   
  | 
  
   X  | 
 |
| 
   Home loans  | 
  
   Account statement for a specific period  | 
  
   X  | 
  
   X  | 
 
| 
   Settlement letter  | 
  
   X  | 
  
   X  | 
 |
| 
   Quotation  | 
  
   X  | 
  
   X  | 
 |
| 
   Reconciliation  | 
  
   
  | 
  
   X  | 
 |
| 
   Decline letter   | 
  
   
  | 
  
   X  | 
 |
| 
   Approval letter  | 
  
   X  | 
  
   X  | 
 |
| 
   Personal loans and unsecured lending  | 
  
   Account statement for a specific period  | 
  
   X  | 
  
   X  | 
 
| 
   Application form for a personal loan, an overdraft or a student loan   | 
  
   
  | 
  
   X  | 
 |
| 
   FAIS
  acknowledgement for a personal loan, an overdraft or a student loan  | 
  
   
  | 
  
   X  | 
 |
| 
   Settlement
  letter for a personal loan or unsecured lending   | 
  
   
  | 
  
   X  | 
 |
| 
   Account
  closure letter for a personal loan or unsecured lending  | 
  
   
  | 
  
   X  | 
 |
| 
   Welcome
  letter for a personal loan or unsecured lending   | 
  
   
  | 
  
   X  | 
 |
| 
   Statement  | 
  
   X  | 
  
   X  | 
 |
| 
   Motor Finance
  Corporation (MFC)  | 
  
   Settlement
  quote  | 
  
   X  | 
  
   X  | 
 
| 
   Confirmation
  of client details changes   | 
  
      | 
  
   X  | 
 |
| 
   Tax
  certificate  | 
  
   X  | 
  
   X  | 
 |
| 
   Copy of
  registration papers   | 
  
   X  | 
  
   X  | 
 |
| 
   Cross-border
  letter  | 
  
   X  | 
  
   X  | 
 |
| 
   Transaction
  history  | 
  
   X  | 
  
   X  | 
 |
| 
   Banking
  details update  | 
  
   X  | 
  
   X  | 
 |
| 
   Addendum  | 
  
      | 
  
   X  | 
 |
| 
   Amortisation  | 
  
      | 
  
   X  | 
 |
| 
   Repayment
  schedule  | 
  
      | 
  
   X  | 
 |
| 
   Balloon
  quote  | 
  
      | 
  
   X  | 
 |
| 
   Balloon
  manual quote  | 
  
      | 
  
   X  | 
 |
| 
   Capital
  interest statement  | 
  
      | 
  
   X  | 
 |
| 
   Interest
  rate letter  | 
  
      | 
  
   X  | 
 |
| 
   Settlement
  letter  | 
  
      | 
  
   X  | 
 |
| 
   Change-of-owner
  settlement letter  | 
  
      | 
  
   X  | 
 |
| 
   Authorisation
  letter for police clearance  | 
  
      | 
  
   X  | 
 |
| 
   Relocation
  letter  | 
  
      | 
  
   X  | 
 |
| 
   Copy of
  the National Administration Traffic Information System (NaTIS) document  | 
  
   X  | 
 ||
| 
   Contract
  addendum relating to value-added product services   | 
  
      | 
  
   X  | 
 |
| 
   Cost of
  credit/Additional credit  | 
  
      | 
  
   X  | 
 |
| 
   Vehicle
  finance contract   | 
  
      | 
  
   X  | 
 |
| 
   Invoice  | 
  
      | 
  
   X  | 
 |
| 
   Remittance  | 
  
      | 
  
   X  | 
 |
| 
   Proof
  of payment  | 
  
      | 
  
   X  | 
 |
| 
   Copy of a NaTIS document  | 
  
   X  | 
 ||
| 
   Business
  banking  | 
  
   Original NaTIS document  | 
  
   
  | 
  
   X  | 
 
| 
   Own-entity product statement  | 
  
   X  | 
  
   
  | 
 |
| 
   Copy of facility letters, suretyships, title deeds, mortgage bond
  documents, etc  | 
  
   
  | 
  
   X  | 
 |
| 
   Original securities   | 
  
   
  | 
  
   X  | 
 |
| 
   NedFleet   | 
  
   X  | 
  
   
  | 
 |
| 
   Replacement cards   | 
  
   
  | 
  
   X  | 
 |
| 
   
  | 
  
   
  | 
  
   
  | 
 
7   
Nedbank
records available in line with other legislation
| 
   Applicable
  legislation  | 
  
   Category of record   | 
 
| 
   Banks Act, 94 of 1990 (guidance notes and
  directives)  | 
  
   ·    South African Reserve Bank (SARB) outsourcing list. ·    Materiality risk assessments.  ·    Letters or notifications to SARB.  | 
 
| 
   Basic Conditions of
  Employment Act, 75 of 1997 
  | 
  
   ·    Employee details. ·    Labour relations reports. ·    Information regarding dismissals for dishonesty-related behaviour. ·    Information on disability, trade union membership, race and religion.  ·    Employee next of kin or emergency contact details. ·    Conflict-of-interest declarations. ·    Education information. ·    Health and safety records. ·    Pension and provident fund records. ·    Leave records. ·    Internal evaluations and performance records. ·    Disciplinary records. ·    Training records. ·    Background checks.  | 
 
| 
   Broad-based Black Economic Empowerment Act, 53 of
  2003  | 
  
   ·    Skills development section on the Financial Services Council report
  (no unique identifiers). ·    BBBEE status (MTN ZF). ·    BBBEE status of suppliers. ·    Supplier employee information. ·    Contractor and supplier agreements. ·    List of suppliers, products, services and distributors.  | 
 
| 
   Code of Banking Practice  | 
  
   ·    Code of Banking Practice ·    Terms and conditions  | 
 
| 
   Companies Act, 71 of
  2008 
  | 
  
   ·    Memorandum of incorporation.  ·    Award letter. ·    Annual financial statements. ·    Share register (MTN ZF). ·    CIPC company registration document. ·    CoR 14.3 registration certificate. ·    COR123.1. ·    Business application form. ·    Certificate of incorporation. ·    Dealer application. ·    The details of all share trades by employees, directors and officers
  of the organisation.  ·    Own-organisational title deeds. ·    Register of disclosures in terms of section 140(1A) of the Companies
  Act, 71 of 2008. ·    Regulated-company (as defined in Chapter 5, Parts B and C, of the
  Companies Act, 71 of 2008) register of disclosures. ·    Company rules. ·    Records of directors. ·    Copies of reports presented at annual general meetings. ·    Notices and minutes of shareholder meetings. ·    Resolutions and their supporting documents. ·    Copies of written communications generally sent to securityholders. ·    Minutes of meetings of directors, directors’ committees, audit
  committees, shareholders. ·    Securities registers. ·    Record of company secretaries and auditors.  | 
 
| 
   Compensation for
  Occupational Injuries and Diseases Act, 130 of 1993  | 
  
   ·  
  Record of the
  earnings and other prescribed particulars of all employees. ·  
  Auction-related
  records. ·  
  Promotional-competition-related
  records.  | 
 
| 
   Consumer Protection
  Act, 68 of 2008  | 
  
   ·    Promotion and marketing material ·    Terms and conditions ·    Direct marketing consent  ·    Complaints process document  | 
 
| 
   Copyright Act, 98 of
  1978 (as amended by Act 2 of 2002)  | 
  
   Software licences  | 
 
| 
   Disaster Management
  Act, 57 of 2002  | 
  
   ·    Covid-19 registers ·    Business continuity management plans ·    Business impact assessment  | 
 
| 
   Electronic
  Communications and Transactions Act, 25 of 2002 
  | 
  
   ·    Digital signatures ·    Transactional record ·   
  Electronic terms and
  conditions  ·    Records of third parties to whom information is disclosed  | 
 
| 
   Employment Equity Act, 55 of 1998  | 
  
   Employment equity plans and targets  | 
 
| 
   Employment Services
  Act, 4 of 2014 
  | 
  
   ·   
  Employment work permits ·   
  Job advertisements  | 
 
| 
   Exchange Control
  Amnesty and Amendment Taxation Laws Act, 12 of 2003  | 
  
   ·   
  Reports on foreign
  spend greater than R10 million to the South African Revenue Service (quarterly). ·   
  Cross-border
  transfer-of-funds applications and transactions.  | 
 
| 
   Financial Advisory
  and Intermediary Services (FAIS) Act, 37 of 2002 
  | 
  
   ·   
  Learning history
  reports. ·   
  Registers of
  representatives, key individuals, qualifications completed by intermediaries
  and competences. ·   
  Records evidencing
  representatives’ compliance with section 13(1)–(2) of FAIS. ·   
  Continued professional
  development (CPD) programme and activity records. ·   
  Records of financial
  and system procedures. ·   
  Records evidencing
  supervision actions undertaken, including evidence regarding the rendering of
  services under supervision, the method followed and frequency thereof during
  the period under supervision. ·   
  Records evidencing
  the deployment of adequate technological resources to maintain client records
  and data integrity. ·   
  Records relating to
  conclusions regarding compliance with independent requirements, and the
  substance of relevant discussions that support those conclusions. ·   
  Records relating to giving
  advice, call recordings and product agreements. ·   
  Records relating to debarments
  of FAIS representatives and key individuals. ·   
  Records relating to business
  continuity plans. ·   
  Records relating to competency
  requirements (copies of Grade 12, FSCA-recognised qualifications, class of business
  training, CPD and product-specific training). ·   
  Signed supervision agreements. ·   
  Representative letters
  of authority. ·   
  Key-individual
  authorisation letters. ·   
  Compliance reports. ·   
  FSP licence and
  addendum with conditions. ·   
  Complaints management
  (contact details of the compliance officer).  | 
 
| 
   Financial
  Intelligence Centre Act (FICA), 38 of 2001  | 
  
   ·   
  Identification and
  verification records ·   
  Client due-diligence
  records ·   
  Applications for credit
  or credit agreements  | 
 
| 
   ·   
  Foreign Account Tax
  Compliance Act ·   
  Common Reporting
  Standard  | 
  
   ·   
  IRS W-8BEN-E; IRS
  W-8BEN; IRS W-9; IRS W-8ECI. ·   
  Self-certification
  forms.  | 
 
| 
   Income Tax Act, 58 of
  1962  | 
  
   ·   
  IT3. ·   
  IRP5. ·   
  IT3a. ·   
  Monthly IRP5 files. ·   
  Unemployment
  Insurance Fund (UIF) files. ·   
  PAYE information. ·   
  SDL information. ·   
  VAT records. ·   
  Ledgers. ·   
  Cash books. ·   
  Journals. ·   
  Cheque books. ·   
  Bank statements. ·   
  Deposit slips. ·   
  Paid cheques. ·   
  Invoices. ·   
  Stock lists. ·   
  Other books of
  accounts. ·   
  Electronic
  representations of information.  | 
 
| 
   Labour Relations Act,
  66 of 1995  | 
  
   ·   
  Disciplinary records,
  including  outcomes. ·   
  Labour relations
  reports. ·   
  Arbitration awards. ·   
  Records of strike
  action and protests.  | 
 
| 
   Long-term Insurance
  Act, 52 of 1998  | 
  
   ·    Retrenchment claim documents (retrenchment letter, retrenchment claim
  form, copy of the identity document, etc). ·    Disability claim documents (disability claim form, medical report, copy
  of the identity document, etc).  ·    Death claim documents (death certificate, claim form, etc).   | 
 
| 
   Lotteries
  Act, 57 of 1997  | 
  
   Personal information and LOTTO transactions of clients  | 
 
| 
   National Credit Act,
  34 of 2005  | 
  
   ·   
  Loan or credit
  agreements. ·   
  Applications for credit. ·   
  Occupation
  information. ·   
  Credit bureau demographic,
  financial and consumer credit information (credit bureau information). ·   
  Credit refusal letter. ·   
  Pre-agreement
  statement and quote transactions and transactional history. ·   
  Bank details, contact
  details and location information. ·   
  Documentation in
  support of steps taken after default by consumer.  | 
 
| 
   National
  Payment System Act, 78 of 1998  | 
  
   ·   
  Records obtained by
  so-called ‘system participants’ during the course of the operation and
  administration of the settlement system. ·   
  Records of payment
  instructions generated and/or obtained by it during the course of the
  operation and administration of the payment clearing house (PCH). ·   
  Records obtained
  during the course of operation and administration of a payment or SARB
  settlement system.  | 
 
| 
   Occupational Health
  and Safety Act, 85 of 1993  | 
  
   ·   
  Occupational health
  and safety (OHS) reports including the following: -          
  Learning history
  report -          
  OHS agreement -          
  OHS appointment
  letters -          
  Data centre procedure
  documents -          
  Incident reports -          
  Personal information
  for workmen’s compensation  -          
  Personal information
  of visitors to our premises and branches  -          
  CCTV footage  | 
 
| 
   Prevention and Combating of Corrupt Activities Act,
  12 of 2004  | 
  
   ·   
  Corrupt or fraudulent
  employee, client or merchant activities. ·   
  Reports on corrupt
  and fraudulent activities to law enforcement agencies. ·   
  Supplier Code of
  Ethics. ·   
  Business case. ·   
  Scorecards. ·   
  Tender awards.  | 
 
| 
   Promotion of Access
  to Information Act, 2 of 2000  | 
  
   The PAIA manual  | 
 
| 
   Promotion of Equality
  and Prevention of Unfair Discrimination Act, 4 of 2000 
  | 
  
   Grievance logged and
  outcome  | 
 
| 
   Protection of Personal Information Act, 4 of 2013 
  | 
  
   ·   
  POPIA operating
  contract ·   
  Data transfer
  agreement ·   
  Privacy Notice  | 
 
| 
   Regulation of
  Interception of Communications and Provision of Communication-related
  Information Act, 70 of 2002  | 
  
   ·   
  Mobile policy ·   
  Employee ID and proof
  of address ·   
  SIM card number ·   
  IME number ·   
  Cellphone number  | 
 
| 
   Short-term Insurance
  Act, 53 of 1998  | 
  
   ·    Original NaTIS documents  ·    Settlement letters  ·    Agreements of loss  ·    Proof of payment  ·    Rejection letters   | 
 
| 
   Skills Development
  Act, 97 of 1998  | 
  
   ·   
  Sector Education and
  Training Authority (SETA) reports (no unique identifiers). ·   
  Learning history
  reports. ·   
  Skills development levies. ·   
  Certificates of
  completion.  | 
 
| 
   UK Bribery Act  | 
  
   ·   
  Personal information
  of directors  ·   
  Financial statements ·   
  Tax returns  ·   
  Other documents
  relating to tax or invoices   ·   
  Accounting records  ·   
  Auditor reports  ·   
  Banking records  ·   
  Bank statements  ·   
  Electronic banking
  records  ·   
  Asset registers ·   
  Financial agreements   | 
 
| 
   Value-added Tax Act,
  89 of 1991  | 
  
   ·   
  Invoices. ·   
  Tax invoices. ·   
  Credit notes. ·   
  Debit notes. ·   
  Bank statements. ·   
  Deposit slips. ·   
  Stock lists. ·   
  Paid cheques relating
  thereto (no longer relevant since 30 December 2020).  | 
 
8   
Subjects
on which a body holds records and categories of records that Nedbank holds for
each subject
| 
    Subjects on which a body holds
   records  | 
   
    Categories of records  | 
  
| 
   Strategy, plans and proposals  | 
  
   Annual reports, strategic plans and annual performance
  plans.  | 
 
| 
   Human resources   | 
  
   ·   
  HR policies and
  procedures. ·   
  Employee records. ·   
  Advertised posts. ·   
  Updates to employee
  records. ·   
  Onboarding and
  offboarding of employees. ·   
  Internal- and
  external-candidate records. ·   
  Psychometric
  assessment information. ·   
  Leave records. ·   
  Tax. ·   
  Additional earnings. ·   
  Additional deductions. ·   
  Third-party
  deductions (retirement funds, etc). ·   
  Performance
  management. ·   
  Bursary information. ·   
  Educational
  assistance. ·   
  Labour relations
  information. ·   
  Training records.  | 
 
| 
   Shareholders  | 
  
   ·  
  Share registers ·  
  Cash and script
  holdings ·  
  Tax reporting ·  
  Shareholder
  statements  | 
 
| 
   Suppliers  | 
  
   ·  
  Supplier profile ·  
  Supplier invoices  | 
 
| 
   Occupational health
  and safety   | 
  
   ·  
  OHS policies,
  procedures and guidelines.  | 
 
| 
   
  | 
  
   
  | 
 
9     
Processing
of personal information
9.1  
Purpose of processing personal information
We process personal
information to do the following: 
9.1.1      Recruit new employees and, if the candidate is successful, to fulfil the
employee–employer relationship, including in respect of tax obligations,
employment equity reporting and skills development requirements.
9.1.2      Pay grants for medical bills.
9.1.3      Pay grants to employees for their children's primary and secondary
education.
9.1.4      Pay bursary claims to employees for their own tertiary education.
9.1.5      Enable employees to acquire recognised qualifications (eg FAIS and OHS
qualifications).
9.1.6      Facilitate travel for business purposes. 
9.1.7      Fulfil a contractual obligation to a shareholder (internal and external
trust schemes) or fulfil a contractual obligation to a third party (external
share scheme). 
9.1.8      Enable suppliers to provide goods or services to us and receive payment
for these good or services and collect information for BBBEE reporting and
accreditation purposes. 
9.1.9      Fulfil statutory obligations in terms of the Companies Act, 71 of 2008
(directors’ information).
9.1.10    Do creditworthiness assessments.         
9.1.11    Prevent fraud and for authentication purposes.   
9.1.12    Comply with anti-money-laundering regulations.  
9.1.13    Track clients for money collection purposes.       
9.1.14    Market our products and services (if we have consent).   
9.1.15    Assess applications and onboard new clients or service providers or
suppliers. 
9.1.16    Compile offer letters or expressions of interest (EOIs).
9.1.17    Use risk models to produce risk ratings or client risk profiles. 
9.1.18    Issue quotes (eg for vehicle and asset finance applications).
9.1.19    Open transactional accounts or provide other products or services (eg on
Ariba).
9.1.20    Validate client details, information or documents (eg signature card) to
provide a service and consider credit applications, as well as for know-your-customer
(KYC) and fraud prevention purposes.
9.1.21    Do social and environment screenings (SEMS).
9.1.22    Do due-diligence assessments (eg in terms of FICA).
9.1.23    Prepare fulfilment documentation [eg for debtor management, offer letters,
master agreements, extract of minutes, cession of debtors, fax indemnities and
extracts, banking of money letters, account verification letters, contract letters,
supplier forms, cessions of insurance (if applicable)].
9.1.24    Load and release payments or set facility limits.
9.1.25    Issue property guarantees.
9.1.26    Do periodic collateral valuations.
9.1.27    Do yearly or periodic reviews or due-diligence assessments of clients and
service providers or suppliers.  
9.1.28    Produce invoices, reconciliations, statements and remittances.    
9.1.29    Do routine client record maintenance (eg updating debit order details and
sending monthly statements).
9.1.30    Manage excesses and arrears.
9.1.31    Negotiate and conclude settlement agreements.  
9.1.32    Give instructions to bank panel third parties for credit- and credit-risk-related
activities (eg attorney instructions for collection actions).
9.1.33    Archive or destroy personal information in accordance with clients’
requests or regulatory requirements.
9.1.34    Do statutory reporting (eg for FICA and the Prevention and Combating of
corrupt Activities Act, 12 of 2004). 
9.1.35    Engage in general correspondence.
9.2  
Data subject categories and related information or categories of
information 
| 
    Data subject categories
     | 
   
    Personal information
   that may be processed  | 
  
| 
   Shareholders  | 
  
   Names, addresses, identity numbers, registration
  numbers, employment status, BBBEE information and banking details, income tax
  numbers, email addresses, telephone and cellphone numbers, physical addresses,
  postal addresses, disability, veteran status, and gender.  | 
 
| 
   Service providers   | 
  
   Names, registration numbers, VAT numbers, addresses,
  and banking details.  | 
 
| 
   Employees   | 
  
   Names, surnames, addresses and contact details,
  qualifications and professional registrations, CVs, tax information, marital
  status, gender, disability status, citizenship, race, banking details, identity
  numbers, next of kin, beneficiaries and benefit selections, training records,
  leave, and Covid-19 information.  | 
 
| 
   Pensioners   | 
  
   Names, surnames, identity numbers, accounting information
  and medical aid details.  | 
 
| 
   Names, addresses, company registration numbers, tax numbers, PAYE
  numbers, banking details, and contact details.  | 
  
 |
| 
   Clients   | 
  
  
   Names, surnames, addresses, registration or identity
  numbers, employment status, and banking details.  | 
  
 
9.3  
Recipients or categories of recipients to whom personal information may
be given
| 
    Category of personal information   | 
   
    Recipients or categories of recipients
   to whom personal information may be given  | 
  
| 
   Identity numbers, fingerprints and names for
  criminal checks.  | 
  
   South African Police Service  | 
 
| 
   Qualifications for qualification verifications   | 
  
   South African Qualifications Authority 
  | 
 
| 
   Credit and payment history for credit information  Shareholders contact details only  | 
  
   Credit bureaus  | 
 
| 
   Tracing shareholders  | 
  
   Tracing agent  | 
 
| 
   Shareholder information  | 
  
   Ince (to run virtual shareholder meetings)  | 
 
| 
   BBBEE (shareholders and suppliers)  | 
  
   BBBEE assessment or verification agency   | 
 
| 
   Employee names, identity numbers and demographics.  | 
  
   SETA (for programmes)  | 
 
| 
   Employee names and identity numbers   | 
  
   FAIS and OHS training providers  | 
 
| 
   ·   
  Suppliers ·   
  Credit checks ·   
  Media screening ·   
  Sanctions checks  | 
  
   ·   
  Experian   ·   
  Dow Jones ·   
  World check   | 
 
| 
   Identity number, names, psychometric test scores and
  reports, employee numbers, contact details, employment dates, performance
  history, industrial relations information, union membership fees, statutory
  requirements (including tax) and salary information.  | 
  
   ·   
  Old Mutual
  (retirement fund). ·   
  Medscheme (medical
  aid). ·   
  Safrican (funeral
  fund). ·   
  Alexander Forbes (Defined-benefit
  Pension Fund – closed scheme). ·   
  Department of Employment
  and Labour (UIF). ·   
  South African Revenue
  Service (PAYE, SDL, UIF). ·   
  Commission for
  Conciliation, Mediation and Arbitration (labour relations). ·   
  Psychometric-assessment
  suppliers. ·   
  Reference checks for former
  employees. ·   
  South African Society
  of Bank Officials (Sasbo union). ·   
  YES office and
  implementation partners. ·   
  Holsboer resorts and
  timeshare.  | 
 
| 
   Identity numbers, names and facial biometrics.  | 
  
   Department of Home Affairs  | 
 
| 
   Corporate Saver agent information  | 
  
   ·   
  Legal Practitioners
  Fidelity Fund  ·   
  Legal Practice
  Council  ·   
  Office of the Master
  of the High Court ·   
  FSCA ·   
  Estate Agencies
  Affairs Board  | 
 
| 
   Client information  | 
  
   SARB  | 
 
| 
   Identity numbers, names and surnames, physical and
  email addresses, payslips, medical records, and contact numbers.  | 
  
   ·   
  Corporate Industrial
  and Risk consultants. ·   
  Compensation
  Commissioner. ·   
  Department of
  Employment and Labour. ·   
  Department of Health. ·   
  ER24 and medical
  facilities. ·   
  Compliance Safety
  (Pty) Ltd (COMSAF).  | 
 
| 
   Identity numbers and names for criminal checks  | 
  
   South African Police Service  | 
 
| 
   Qualification verifications  | 
  
   South African Qualifications Authority  | 
 
| 
   Credit and payment history for credit information  | 
  
   Credit bureaus  | 
 
| 
   Names, identity numbers, and qualifications.  | 
  
   ·   
  Compliance Institute
  Southern Africa ·   
  Khulisane Academy  | 
 
9.4  
Planned transborder flows of personal information
9.4.1      Sub-Saharan Africa: Receive shareholders’
information from African countries and confirm payments in terms of dividends
and proceeds. The information is not moved offshore, and payments are made from
a South African scheme to a participant in another country.
9.4.2      Procurement: Cloud-based solution, with the necessary
contracts in place.
9.4.3      Employee services. 
9.5  
General description of information security measures that the
responsible party must implement to ensure the confidentiality, integrity and
availability of the information.
9.5.1     
We subscribe to and are a member of the Information Security Forum
(ISF) Standard of Good Practice and we align all our security principles to
this standard through:
9.5.1.1     
employee awareness and change management;
9.5.1.2     
regular system patching; and
9.5.1.3      secure system development lifecycle
management.
10.1.1   
A copy of the manual is available:
10.1.1.1               
at our website nedbank.co.za;
10.1.1.2               
at our head office for public inspection during normal business hours;
10.1.1.3               
to any person on request and payment of the fee in 10.2; and
10.1.1.4               
to the Information Regulator.
10.1.2   
A fee for a copy of this manual, as set out in Annexure B of the
regulations, is payable for each A4-size photocopy made.
The Information Officer, mandated by the Chief
Executive Officer of Nedbank, will update this manual regularly. 
Issued by:
Daleen du Toit
Group Chief Compliance Officer
For a better experience of the Nedgroup Investments website, please try the latest version of these browsers