Compliance & Cyber Intelligence for Insurance
Menu
Log in ↗
PROVANTIS / RULE LIBRARY
← BACK TO LIBRARY
← Conduct rule engine

Category 06

Digital Trust and UX

POPIA, FAIS, and TCF obligations applied to digital channels — consent design, cookie compliance, digital disclosures, and UX integrity.

Applicability gate

A rule's presence does not establish a direct legal duty

Confirm the entity's licensed capacity, actual services, agreement, data-processing role and Schedule 1 status. The audience-qualified publication rows below travel with this library and its public API.

Fais Conduct
  • Insurance Broker: FAIS and the applicable conduct code govern authorised FSPs and representatives rendering covered financial services. State the firm's licensed capacity and service; do not convert a readiness scan into a legal compliance conclusion.
  • Uma Binder Holder: FAIS duties apply where the UMA is an authorised FSP or acts through representatives in a covered capacity. Do not infer the licence category or every conduct duty from the UMA label alone.
  • Insurer: FAIS duties apply to an insurer when it also acts in a capacity requiring FAIS authorisation or through covered representatives. Insurance conduct duties also arise under insurance legislation and policyholder-protection rules; do not collapse those regimes into FAIS.
Popia
  • Insurance Broker: POPIA duties follow the entity's role as responsible party or operator and the personal information it processes. Do not state that consent is always the lawful basis, or that a public scan proves POPIA compliance.
  • Uma Binder Holder: POPIA duties follow whether the UMA is a responsible party or operator for the processing in question. The insurer relationship does not by itself settle POPIA role allocation; check the processing purpose, means and operator agreement.
  • Insurer: POPIA duties follow the insurer's responsible-party or operator role for each processing activity. Allocate duties for outsourced processing explicitly; the insurer cannot treat outsourcing as eliminating its own responsible-party obligations.

Key legislation

  • POPIA 4 of 2013
  • ECTA 25 of 2002
  • FAIS Act 37 of 2002
  • FIC GN 7

Readiness guidance

Conduct a digital audit of the primary website and mobile application. Test cookie consent, privacy notice linkage, and consent mechanism design. Use browser developer tools to confirm HTTPS is enforced. Verify FSP licence information is displayed. Test the unsubscribe mechanism in marketing communications.

Rules in this category

12 rules

DIG-01

Cookie consent mechanism — POPIA-compliant opt-in banner for non-essential cookies

High
Trigger
No consent mechanism or consent assumed/pre-granted for analytics/marketing cookies
Section
POPIA s.11 / s.69
Evidence
['Cookie consent banner screenshot', 'CMP configuration', 'Cookie audit report']
Remediation
Implement a compliant cookie consent management platform. Default to deny for non-essential cookies.

DIG-02

Privacy Notice — accessible on all digital channels; meets POPIA s.18 requirements

High
Trigger
Privacy Notice absent from website/app or missing prescribed s.18 content
Section
POPIA s.18
Evidence
['Privacy Notice document', 'Page link audit', 's.18 content checklist']
Remediation
Update Privacy Notice. Link from footer of all pages and from each data collection form.

DIG-03

Consent flow design — no dark patterns; consent freely given and granular

Critical
Trigger
Dark pattern identified in consent design (pre-ticked boxes, bundled consent, deceptive language)
Section
POPIA s.11(1)(a) / s.69
Evidence
['Consent flow wireframes/screenshots', 'UX audit report', 'User testing results']
Remediation
Redesign consent flows. Remove all dark patterns. Test with independent UX reviewer.

DIG-04

Digital FAIS disclosure — FSP name, licence number, and category displayed

High
Trigger
FSP licensing information absent or incorrect on website or application
Section
FAIS General Code of Conduct s.4
Evidence
['Website screenshot showing FSP disclosure', 'FSCA Register verification']
Remediation
Add FSP disclosure to website footer and all digital touchpoints. Verify against FSCA Register.

DIG-05

PAIA Manual — publicly accessible on website with current contact details

Medium
Trigger
PAIA Manual not linked from website or document version > 12 months old without review
Section
PAIA s.51
Evidence
['Website URL of PAIA Manual', 'Last review date', 'IO contact details']
Remediation
Publish PAIA Manual on website. Add to footer navigation. Review annually.

DIG-06

Digital ROA — electronically generated and delivered after digital advice interaction

High
Trigger
Digital advice interactions conducted without electronic ROA delivery
Section
FAIS General Code of Conduct s.9
Evidence
['Digital ROA template', 'Email delivery logs', 'Timestamp audit trail']
Remediation
Implement digital ROA generation in online advice journey. Deliver via email with timestamp.

DIG-07

Electronic contract validity — ECTA compliance for digital policy issuance

High
Trigger
Electronic contracts not compliant with ECTA Chapter 3 requirements
Section
ECTA 25 of 2002 Ch.3
Evidence
['ECTA compliance review', 'E-signature system documentation', 'Policy issuance workflow']
Remediation
Review digital contracting process against ECTA requirements. Implement compliant e-signature.

DIG-08

Digital onboarding — biometric/electronic verification meets FIC GN 7 standards

High
Trigger
Remote onboarding verification process not compliant with FIC guidance
Section
FIC Guidance Note 7
Evidence
['GN 7 compliance checklist', 'Verification system documentation', 'Fail rate monitoring data']
Remediation
Review verification methods against GN 7. Implement liveness detection for biometric verification.

DIG-09

Unsubscribe mechanism — functional opt-out from marketing communications

High
Trigger
Unsubscribe mechanism absent or non-functional in electronic marketing
Section
POPIA s.69 / ECTA s.45
Evidence
['Email unsubscribe test', 'Suppression list records', 'Opt-out processing log']
Remediation
Implement and test one-click unsubscribe. Process opt-outs within 3 business days.

DIG-10

Data minimisation — digital channels collect only personal information necessary for purpose

Medium
Trigger
Excessive data fields collected on digital forms without justification
Section
POPIA s.10 (Processing Limitation)
Evidence
['Form audit report', 'Field justification mapping', 'Before/after form screenshots']
Remediation
Audit all digital data collection forms. Remove fields not required for stated purpose.

DIG-11

Security — HTTPS, encryption at rest and in transit for all personal information

Critical
Trigger
Digital channels not using HTTPS or personal data transmitted unencrypted
Section
POPIA s.19 (Security Safeguards)
Evidence
['SSL certificate details', 'Security scan results', 'Encryption policy']
Remediation
Enforce HTTPS across all digital properties. Implement TLS 1.2 minimum. Encrypt data at rest.

DIG-12

UX accessibility — basic WCAG 2.1 AA compliance for key digital journeys

Low
Trigger
Material accessibility failures identified in critical user journeys
Section
FSCA TCF / general consumer protection
Evidence
['Accessibility audit report', 'WCAG AA checklist', 'Remediation plan']
Remediation
Commission accessibility audit. Remediate critical failures. Include accessibility in design standards.