Privacy, PAIA & Data Protection Notice
At The National Employees Benefit Umbrella Fund (NEBUF) (“we”, “our”, “us”), we are committed to protecting your personal information in compliance with all required laws and regulations, such as the Protection of Personal Information Act 4 of 2013 (POPIA). This privacy notice applies to all of our members and any other users of our website, apps, or other services.
“Personal Information” has the same meaning as defined in POPIA, meaning any information relating to an identifiable, living, natural person, and where applicable, an identifiable, existing juristic person.
1. Collection and Purpose of Information
To provide our services, we collect and process personal information from both our corporate clients (juristic entities) and non-corporate clients (natural persons). The information we may collect includes, but is not limited to:
- Personal Information: Details such as your name, contact information, date of birth, employment information and any other information that allows us to identify you.
- Contact Information: Your email address, telephone number, and residential or postal address, which allows us to communicate with you.
- Beneficiary and Dependant Information: Details regarding your nominated beneficiaries and legal dependants, including their names, contact details, Identity Numbers, and relationship to you.
- Financial Information: Details such as your bank account information and pensionable salary to facilitate the collection of monthly contributions, the payment of retirement or withdrawal benefits, and to ensure compliance with Section 13A of the Pension Funds Act 24 of 1956 regarding the reconciliation of the fund assets.
- Employer and Entity Identification: For participating employers, we collect the registered company name, registration number, physical address, alongside the Identity and contact details of the authorised signatories responsible for the administration of the fund and the submission of contribution schedules.
- User Experience: We analyse data on how users interact with the app and website to improve their experience, troubleshoot issues, and enhance customer support.
The collection of this information is strictly for the purposes of providing, managing, and improving our services, ensuring legal and regulatory compliance, and managing our financial obligations as outlined in the Service Level Agreements, or Terms of Use.
2. Protection of Your Information
We take all reasonable steps to protect your personal information from unauthorised access, loss, or misuse by implementing appropriate technical measures and appropriate cybersecurity controls. We comply with the Cybercrimes Act 19 of 2020, and continuously update our cybersecurity measures to protect our systems and your data from cyber threats.
3. Your Rights and Access to Information
You have the following rights regarding your personal information, as governed by the Promotion of Access to Information Act 2 of 2020 (PAIA):
- Access: You can request access to the personal information we hold about you.
- Rectification: You have the right to request the correction or update of any inaccurate or incomplete personal information.
- Erasure: You may request the deletion of your personal information, including your account information, where the information is not legally required to be retained.
- Objection: You may object to the processing of your personal information.
- Consent Withdrawal: You have the right to withdraw that consent at any time. If we rely on your consent as a legal basis for processing your personal information, you have the right to withdraw your consent at any time. You may at any time request that your data, which includes your personal information and account information, be permanently deleted. If you wish to have your data deleted, please click here.
4. Disclaimer
While we strive to provide accurate and secure services, your use of our website and services is at your own risk. We do not guarantee that the information on our website is suitable for any particular purpose or that it is free of viruses or other harmful code. We are not legally responsible for any damages you may experience from using our website. Any information provided does not constitute financial or credit advice.
5. Electronic Communications
Our website and electronic communications are governed by the Electronic Communications and Transactions Act (ECTA) 25 of 2002. By using our website, you consent to electronic communication and transactions with us, including receiving marketing communications, unless you opt out.
6. Member Protection and Fair Outcomes
NEBUF is committed to the principles of Treating Customers Fairly (TCF) as mandated by the Financial Sector Regulation Act 9 of 2017. This ensures that we provide clear, fair, and transparent terms while protecting your rights to full disclosure and effective complaint handling. We adhere to the conduct standards set out by the Financial Sector Conduct Authority (FSCA) and the governance requirements of the Pension Funds Act 24 of 1956, to ensure that the fund is managed in the best interests of its members at all times.
7. Sharing of Information
Your personal information will not be sold or shared with third parties except where necessary to deliver our services, comply with legal requirements, or with your consent.
8. Data Retention and Destruction
We will keep your personal information only for as long as it is necessary to fulfil the purpose for which it was collected, or as required by law. Once the information is no longer needed, we will take all reasonable steps to destroy or delete it in a secure manner. This includes:
- Financial Records: Financial information is retained for the period mandated by tax and financial regulations.
- Account Information: Your account data will be retained for a reasonable period after you close your account to handle any outstanding queries or legal obligations.
- Secure Disposal: When information is no longer needed, it is permanently deleted from our servers and any physical records are shredded or otherwise securely destroyed.
9. Security Breach
We are committed to the highest standards of data protection. However, in the unlikely event of a security breach, we have a clear incident management plan. A security breach means any unauthorised access to, or loss, disclosure, or destruction of, personal information.
Should a breach occur, we will take immediate and reasonable steps to mitigate any harm, which may include:
- Containing the Breach: We will work to stop the unauthorised activity and secure all affected systems and information.
- Assessing the Risk: We will investigate the breach to understand the cause, the extent of the harm, and which individuals and types of data have been affected.
- Notification: We will notify you and the Information Regulator as required by POPIA. This notification will include a description of the breach, the potential consequences, and the measures we have taken to address it. We will communicate with affected data subjects as soon as reasonably possible.
10. Lodging a Complaint with the Information Regulator
If you believe that NEBUF has interfered with the protection of your personal information, you have the right to lodge a complaint with the Information Officer of the Fund or the Information Regulator.
The Fund’s Information Officer can be contacted by lodging a complaint addressed to [email protected]
The Regulator’s contact information is provided below. You will be required to complete a prescribed form (POPIA Form 5 or PAIA Form 5), which is available on their website.
The Information Regulator (South Africa)
- Complaints Email (POPIA): [email protected]
- Complaints Email (PAIA): [email protected]
- General Enquiries: [email protected]
- Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- Contact Number: 010 023 5200
- Toll-Free Number: 0800 017 160
By using our website, you acknowledge that you have read and understood this Privacy, PAIA & Data Protection Notice and consent to the collection, use, and processing of your personal information as described.
If you have any questions, requests for access, or concerns about your personal information, please contact the Information Officer at [email protected]