A serious breach of a representative’s duty to protect confidential client information can demonstrate a lack of integrity, and justify debarment, even without proof of dishonesty, misuse of the information, or actual client harm, the Financial Services Tribunal has ruled.
In a decision dated 11 September 2026, the Tribunal found that the representative’s unauthorised transfer of sensitive client information to her personal Gmail account was sufficiently serious to impugn the integrity required of a representative under the Financial Advisory and Intermediary Services Act.
The applicant joined Affinity Life as a representative in February 2024 and became a senior sales adviser in January 2025. She had about 10 years’ experience in the insurance industry, and her responsibilities included coaching junior agents.
According to the Tribunal’s decision, the applicant emailed an Excel spreadsheet from her work account to her personal Gmail account without authorisation on 4 March 2026. It contained client names, identity numbers, policy numbers, and premium details.
Although the applicant had lawful access to client information for her work, she knew the information could be handled only on company equipment connected to a secure virtual private network, and clients could be contacted only through Affinity Life’s dialler.
The applicant described the spreadsheet as her “stats” sheet and maintained that it contained her own working data. She said she intended to analyse the information after hours to identify clients whose policies had lapsed and improve her sales performance. She said she adopted this approach on the advice of a colleague who had improved her own results by re-engaging clients whose policies had lapsed.
Her sales performance had declined, and she was receiving performance coaching at the time. She contended that sending the spreadsheet to herself was an error of judgement under performance pressure, rather than conduct demonstrating dishonesty or a fundamental defect in her character.
The applicant submitted that she had sent the information only to herself and had neither disclosed nor exploited it, and she relied on the absence of proven client harm. She also said she co-operated with Affinity Life, including by complying with a cease-and-desist demand. She had no previous disciplinary record.
After the transmission was detected, Affinity Life took possession of the applicant’s laptop and suspended her on full pay on 19 March. The applicant said she deleted the spreadsheet from her personal account that day, 15 days after sending it and only after the transfer had been detected.
However, a screenshot of the workbook showed worksheets bearing the names of other representatives and records dating from 2023, before the applicant joined Affinity Life. The Tribunal found that this contradicted her assertion that the workbook contained only her own data compiled since joining the company. She did not credibly explain why her stated purpose required information associated with other representatives or records predating her employment.
Following a disciplinary hearing on 1 April 2026, the applicant was found guilty of charges concerning a conflict of interest, misappropriation or theft, misuse of company property, and breaches of policy and data protection obligations.
Affinity Life notified the applicant of potential debarment on 27 March, alleging a lack of honesty and integrity arising from the misappropriation and unauthorised use of client information. The FSP debarred her on 11 May.
Dishonesty and integrity are distinct
Under section 14(1)(a) of the FAIS Act, a financial services provider must debar a representative or former representative where the available facts establish that the person no longer complies with the applicable fit and proper requirements or has materially contravened the Act.
The applicable fit and proper requirements concerned honesty and integrity, but the Tribunal’s finding against the applicant was confined to integrity. It expressly made no finding that she had acted dishonestly.
The Tribunal said the applicant’s contention that debarment required proof of dishonesty, misuse, or harm was too broad.
Section 6A(2)(a) of the FAIS Act identifies honesty and integrity as personal character qualities. The Tribunal said they are related but distinct: integrity extends beyond the absence of deceit and may be impaired by a serious, conscious, or reckless breach of a fundamental professional obligation.
But the Tribunal qualified this principle carefully. A deliberate policy breach does not automatically establish dishonesty or a lack of integrity, and not every unauthorised transfer of confidential information warrants debarment. The question is whether the particular conduct, assessed in context, is sufficiently serious to impugn the representative’s integrity.
An isolated act of dishonesty, negligence, or incompetence does not automatically establish unfitness, although a sufficiently serious single act may do so. Nor does misconduct confined to the employment relationship, or a breach of an employer’s code, necessarily establish a statutory ground for debarment.
The Tribunal held that the obligation to safeguard client information formed part of rendering financial services and was owed to clients and to Affinity Life. Its breach therefore engaged the protective purpose of section 14 of the FAIS Act.
Why the conduct crossed the threshold
The Tribunal considered the circumstances cumulatively in deciding that the applicant’s conduct was more than an administrative lapse.
It took account of the applicant’s experience and the training she had received on protecting client information, including under the Protection of Personal Information Act. She had also signed confidentiality and non-disclosure undertakings.
She did not seek permission to transfer the spreadsheet or raise her proposed strategy during coaching sessions addressing her performance.
The Tribunal acknowledged that the applicant’s inability to contact clients outside Affinity Life’s dialler did not exclude an intention to analyse the information after hours.
However, a company laptop was available, and the applicant had not tested her assumption that its battery would not last through loadshedding.
The Tribunal also considered evidence that the applicant was pursuing alternative employment. Nine days after sending the spreadsheet to her personal account, she requested the urgent correction of her regulatory records. She said the existing records prevented her from taking up work as a financial adviser at Sanlam, where she had succeeded in an interview.
The Tribunal found that this established she was pursuing other employment, but not that she had secured another position or intended to benefit a competitor or solicit Affinity Life’s clients. The debarment had to be assessed on the conduct that had been established.
The Tribunal concluded that an experienced and trained representative had knowingly removed extensive confidential information from its protected environment without credibly explaining why her stated purpose required other representatives’ records.
It found that this serious breach of client trust established a lack of the integrity required of a representative.
No proof of misuse or client harm
The Tribunal accepted that there was no direct evidence that the applicant disclosed the spreadsheet to anyone else, exploited the information, or caused client loss. Her compliance with the cease-and-desist demand and subsequent co-operation weighed in her favour but were not decisive.
Proof of misuse or loss was not essential. Transferring confidential information to a personal account removed it from Affinity Life’s control and exposed it to storage and access outside the company’s security measures. This created risks of loss, unauthorised access, and further disclosure.
The clients were neither consulted nor informed about the transfer, while Affinity Life remained responsible for safeguarding their information.
Debarment separate from disciplinary action
The applicant was dismissed on 10 April 2026 following a disciplinary hearing. She challenged the dismissal in separate proceedings before the Commission for Conciliation, Mediation and Arbitration.
Her reconsideration application included complaints about the disciplinary process. She contended that requests for particulars had not been adequately answered, legal representation had been refused, relevant correspondence had been withheld, and colleagues had been unwilling to testify.
The Tribunal said it was not responsible for deciding whether the disciplinary hearing or dismissal was fair. Debarment is a protective regulatory measure, not punishment for employment misconduct. A defect in the disciplinary process was relevant only if it affected the fairness of the debarment enquiry or the reliability of the material on which the decision was based.
The Tribunal rejected her contention that the matter had been predetermined because Affinity Life issued the notice of potential debarment before the disciplinary hearing. A provider did not have to await the outcome of disciplinary proceedings before initiating a debarment process.
The determination was made after the applicant’s representations had been considered, and the chronology and reasons did not indicate that the decision-maker had a closed mind.
Affinity Life’s key individual and debarment decision-maker was not bound by the disciplinary chairperson’s characterisation of the misconduct. She was required to assess independently whether the underlying conduct established non-compliance with the fit and proper requirements, and the Tribunal found that her determination reflected such an assessment.
The pending CCMA proceedings did not automatically suspend or prevent the debarment. Neither a dismissal nor an award setting it aside necessarily determines whether a representative meets the statutory fit and proper requirements.
Supervision could not replace integrity
The applicant argued that debarment was disproportionate and indicated that she was willing to continue working under supervision.
The Tribunal found that supervision could not replace integrity, and no arrangement had been identified that would adequately address the risk demonstrated by her conduct.
Her service history, clean disciplinary record, personal circumstances, and subsequent co-operation did not outweigh the seriousness of the breach. Although debarment had substantial consequences, those consequences did not displace the provider’s statutory duty where the requirements for debarment had been established.
The Tribunal found the determination that the applicant no longer met the integrity requirement was substantiated and dismissed her application for reconsideration.



