VHD THEME 3 UNIT 1
Study objectives:
1. explain how SA payment system works
2. differentiate between national payment system (NPS) and electronic funds
transfer (EFT)
South Africa Payment System (SAPS) facilitates exchange of money and
transfer of value through electronic system of debits & credits
Consumer may use cash or issue payment instruction to bank/financial
institution when they wish to make payment/have funds released
Paper based payment instructions = instructions will be on paper and
authenticate by signature – authenticated document = transferred between
parties and or financial institutions to obtain payment
Electronic payment instructions means instruction to transfer/release funds
takes place by way of electronic means and authentication takes effect by
way of electronic inputs (passwords, accounting numbers – internet banking
payments / stop orders)
Payment instruction can be in:
o paper-based form : bills, cheques
o or electronic form: eft
Transfer of Value
Payment can be initiated by debtor or creditor
Party initiating gives payment instruction to financial institution
Financial institution will transfer funds to beneficiary’s account at same or
other financial institution
When debtor initiates transfer of funds to creditor = CREDIT TRANSFER
(stop orders or internet banking)
Funds = PUSHED through payment system from debtor to creditor
Debit transfer
Creditor initiates process upon giving financial institution instruction to collect
payment from debtor
Funds = PULLED through system into creditor’s account (collection of a
cheque or debit order)
Debit and stop orders all affect debtor – debit order whereby debtor instructs
bank to allow third party to debit account whereas stop order = debtor gives
instructions to bank to stop debit order from being processed
Payment instructions
1. Paper based instructions = instruction is completed on paper in words and
figures and authenticated by signature
2. Document = physically transferred between parties and their financial
institutions to obtain payment
3. Electronic payment instructions = electronically + authentication by electronic
inputs such as passwords & account numbers
National Payment System
Payment instructions = received and then given effect by respective financial
institutions through mandated system of electronic debits and credits resulting in
multilateral set off claims
Multilateral set-off
o Amongst banks for batch of instructions – helps banks electronically
set off their payment obligations against each other
Bilateral set off
o Between banks (inter-bank agreement) e.g. ABSA and FNB
Batch of transactions = routed through clearing house for multi-lateral set-off
between banks e.g. all the banks
Interbank agreements and the SA clearing house agreements are confidential – not
accessible by public.
Nature of bank-customer relationship
Complex multi-dimensional relationship – includes deposit taking ( bank becomes
debtor and customer creditor) roles = exchanged when a customer takes a loan for
use, handles payments, manages investments
Nature of relationship in credit transfers = based on contract of mandate – each
service having specific terms and conditions – eg for using internet banking
Under general contract of mandate – common law requires bank to:
A. Exercise reasonable care and skill when carrying out their mandate
B. Do so within reasonable time
C. In good faith
D. Without negligence
Bank will be measured against standard of a reasonable bank in similar
circumstances
Bank which doesn’t comply with stated duties will be held strictly liable for
its reach
Duties include installing/maintaining security systems that comply with
prevailing business practice and technology – includes matching account
numbers with names of beneficiaries
Customers have corresponding common law duty to draw up payment
instructions with reasonable care – confirmed in SA Code of Banking
Practice – customers = required to take precautionary measures when
using cards, internet, cellphone banking and ATMs to take due care when
transacting
Banks subscribe to code of banking practice – accept jurisdiction of
banking adjudicator and agree to be bound by adjudicator’s decision at
resolving bank and customer issues however ito the code – decision = not
enforceable in a court of law and may not be used to interpret legal
relationship between bank and customer
Provides various safeguards for customer
Codes principles = often incorporated into standard form contract for
various services
EFT Legal framework
SA has no definitive dealing with EFTs
Legal relationship between parties involved = regulated by general principles
of contract law
SA code of banking practice
NCA
CPA
ECTA
Eft = exchange or transfer of value from one account to another
Where one or more of steps in transfer process = completed electronically
Transfer of funds = initiated with an accepted access device
Through electronic terminal, phone, computer, magnetic tape or similar device
For purpose of ordering, instructing or authorising a bank to debit/credit an
account
EFT payments
EFT payment complete when funds = unconditionally credited to a
beneficiary’s account – resulting in discharge of underlying obligation
Bank account credited with payment amount = prima facie evidence of
completed transaction
Standard bank v Oneanate Investments – does not mean in a particular case
one is precluded from looking behind such entries to discover true state of
affairs
Vereins-und westbank v Veren investments – payee must acquire unrestricted
right to immediate use of the funds otherwise payment is incomplete
Accepted access device
Access device refers to a card, code or other means of access to an account /
any combination thereof that initiates the EFT
Access devices become accepted device when device = used by consumer to
request and receive, sign or uses it to transfer money or obtain money,
property, services
Internet banking
Point of sale (POS) transfer (eg. retail stores)
ATM
Transfer initiated by telephone / mobile phone
Direct deposit or withdrawal of funds using any of the above
EFTPOS
Technology allows suppliers of goods/services to accept access devices eg.
cards, debit or credit to facilitate payment
Funds = directly debited and credited from customers account and credited to
beneficiary’s account
Transaction =
Supplier swipes or waves card or other access device through
or over an EFTPOS electronic terminal
Cardholder/payer chooses account from which payment is to be
made
Puts pin
EFTPOS electronic terminal encrypts the pin (secure) and
allocates transaction number
Terminal connects to network and sends details of transaction
electronically thus submitting it to relevant financial institution for
verification
Financial institution then accepts or declines – insufficient funds,
wrong pin and sends back info to EFTPOS
If accepted – direct debit occurs from cardholders account –
confirmation received on receipt and bank statement
Some are online systems where money = electronically transferred from
cardholders acc to suppliers account
Others = offline systems – payment instruction = stored on magnetic tape or
disk for processing at later stage
EFTPOS network holds all collected funds and deposit them to suppliers
account in lumpsum when terminal is settled
Significant difference between EFTPOS credit card transaction and EFTPOS
debit card transaction = credit transaction cardholder can elect to pay
outstanding balance on card in full or in instalments to the issuer, whereas
debit card transaction = full and immediate payment to supplier
Credit card offers client credit and can be used outside EFT system whereas
debit is connected to specific bank account and can only be used with EFT
systems – no manual transactions can be processed
Rules: erroneous EFT reversal
Banks may try assist but inconsistent results from litigation
Number of unresolved issues
Incorrect payment (wrong beneficiary or incorrect amount) = payer can only claim
amount directly from recipient on grounds of unjustified enrichment
Payments association of SA (PASA) – has rules in place regarding reversal of
payments, for reversal to be present:
1. Full amount of funds paid must still be available in beneficiary account
and
2. Consent to reverse funds/debit accounts must be given by the
beneficiary account holder
3. Preferred approach – court interdict to preserve funds (freeze account)
= claim for unjustified enrichment
Legal nature of EFT payment
Some authors = view that it is a conditional payment
Subject to the condition the recipient is entitled to the amount
Banks should be able to reverse transactions
Others argue when request is given to a bank to transfer an amount and bank
gives effect to that instruction
It is unconditional payment and bank cannot reverse transaction
Bank not liable where client knowingly made payment erroneously
VHD THEME 3 UNIT 2
EFT reversals
Malan: payment cannot be reversed or cancelled once complete
Standard form agreements:
One authorization for EFT has been given by client and a payment, EFT
cannot be reversed without first seeking consent of recipient
Erroneous EFT Reversal
Banks may try assist but inconsistent rules from litigation
Incorrect payment (wrong beneficiary or incorrect amount) – payer can only
claim amount directly from recipient on grounds of unjustified enrichment
Payments association of SA (PASA) – has rules in place regarding reversal of
payments – for reversal request to be successful:
Full amount of funds paid must still be
available in beneficiary account, and ‘
Consent to reverse funds / debit account
must be given by beneficiary account holder
Preferred approach = court intended to preserve funds (freeze account) +
claim for unjustified enrichment
Legal nature of EFT payment
Some authors are of view that it is conditional payment
Subject to condition that recipient is entitled to the amount
Therefore banks should be able to reverse transactions
Others argue when request is given to bank to transfer amount and bank
gives effect to that instruction, it = unconditional payment and bank cannot
reverse transaction
Bank not liable where client knowingly made payment erroneously
Unauthorised use
Para. 7.7 and 7.8 of Code of Banking Practice
Responsibility for losses =
Customers if acted:
Fraudulently liable to all losses
Negligently or without reasonable care (this caused/contributed
to loss)
Did not inform bank as soon as reasonably practicable after
discovering or believing secret codes / devices for accessing e-
banking services had been compromised, lost or stolen or that
unauthorized transactions had been conducted on your
accounts
Otherwise will be refunded if:
Not received card or misused
Transactions not authorised by customers after reporting theft or
loss
System malfunction occurred in ATM or associated system
Electronic banking
Internet banking, cell phone banking
Bank services accessible virtually in any part of global community
Access statements, check balances, transfer funds between accounts, pay
accounts etc. although there are risks
Consumer = granted electronic access to banking services by agreement to
standard form contracts
Client pays relevant fees and then issued with set of access codes, security
procedures and security data – access info sent to client for authorisation
Legal nature of electronic banking
Bank will act on instructions that appear to be from customer
Customer cannot cancel or withdraw any instruction given
Customer must look after all access codes, make sure they’re secure and
inform bank if compromised
Avoid using public device such as computer at internet café to access account
Disputes be referred to Banking Ombudsman for determination as per Code
of Banking Practice
Phishing Scams
Fraudulent email sent to unsuspecting bank customers
Retrieve customer confidential internet banking credentials from them
Emails appear genuine
Lure reader into providing confidential info by either replying to email or
clicking on hyperlink to fraudulent website
Once at website, customer enticed to disclose PIN, password, account
number, OTPs or random verification number
Fraudster can view info entered on false website and use to gain access to
unsuspecting persons account / banking profile
Usually sender does not know customers bank
Send bulk emails randomly to lure unsuspecting victims
Roestoff v Cliffe Dekker Hofmeyer
Held that money paid into bank account becomes the property of the bank
and the account holder usually becomes creditor of the bank for the amount
so deposited into his account
Held that stolen money paid into bank account of bona fide third party and
which cannot be claimed from third party using rei vindicatio
Key logging
Key logging makes use of either software or hardware to record all the
keystrokes entered on particular computer keyboard
Details of keystrokes are saved and retrieved by fraudster
Software is installed by hacking into computer and installing software or by
encouraging victim to open an email attachment that triggers download and
installation of key-logger software
Collected info = then used to access victims banking profile
The banks approach
Para 9.3 Code of banking practice:
Banks undertake to provide reliable banking and payment systems
And take reasonable care to make these services safe and secure
Para 9.3 Code of banking Practice requires internet banking to take
precautions such as:
Checking bank statements and reconciling accounts regularly
Keeping personal info secret
Checking website security certificate before accessing site
Changing passwords and PINs
Obtain anti-virus
Entering numbers correctly
Ensuring payments = made to correct beneficiary
Do not store passwords in browser
Different banks use different banking security systems – fraud detection
systems = bonus loss mitigating tool
Banks cannot prevent phishing emails
Bank has no duty to perform forensic analysis on customers PC to establish
phishing
Banks have no control over sim swaps
Banks may face challenges ito sec 48 – 52 of CPA in respect of unfair / unjust
terms
Electronic communications and Transactions Act
ECTA applies to any electronic transaction or data message
Took effect 2002
Data message = data generated, sent, received, stored by electronic
means and includes voice where used in automated transaction and a
stored record
Electronic transaction = not defined in ECTA
Includes transactions where use of data or electronic representations of
info = intrinsic to or an element of commercial or non-commercial
transactions
Sec. 11
Gives legal recognition to data messages – data message = not without legal force
and effect merely on grounds that it = wholly or partly in data message form
Sec. 22(1)
Working in tandem with sec. 11, this sec confirms that legal effect will be given to a
contract concluded by means of data messages
All electronic transactions, debit and credit transfers or EFTs are given full
recognition in ECTA.
Automated transaction
Definition in sec 1
Elec transactions = conducted/performed in whole or in part by means of data
messages (elec representations of info in any form) which are generated,
sent, received or stored by electronic means and include voice (where used in
automated transaction and a stored record)
In which conduct or data messages of 1 or both parties = not reviewed by a
natural person in the ordinary course of such a natural persons business or
employment.
Sec. 20
Provisions on automated transactions, particularly NB in most EFTs & other
electronically concluded financial transactions as they are automated transactions
20( e ) – no agreement = formed where natural person interacts directly with
electronic agent of another person and has made a material error during creation of
data message and:
(i) Elec agent did not provide that person with opportunity to prevent or
correct error
(ii) Person notifies other person of the error as soon as practicable after that
person has learned of it
(iii) Person takes reasonable steps incl to conform to other persons
instructions to return any performance received or if instructed to destroy
the performance &;
(iv) Person has not used or received any material benefit or value from
performance received from other person
Sec. 20 provides elec transaction will be void due to mistake despite meeting
reqs of (i) – (iv) – onus lies on customer to prove reqs.
Sec. 42(1) + chapter VII
Sec. 42(1) - Consumer protection provisions only apply to electronic transactions
where one party is a consumer – application hinges on interpretations/definition of
“consumer” and “electronic transaction”.
Chapter VII – any natural person who enters or intends entering into an electronic
transaction with supplier as the end-user of the goods or services offered by that
supplier
Excludes operation of the consumer protection provisions in following
electronic transactions:
a. All business-to-business (B2B) transactions where services are
supplied to juristic persons
b. Certain business-to-consumer (B2C) transactions where consumer
= natural person but not end-user of services required
Person browsing
Consumer = also person who intends entering electronic transaction in other
words consumers who merely browse a website with intention of possibly
entering a transaction = also entitled to protection offered by Chapter VII of
ECTA
This is NB to supplier because it dictates how & where info has to be
displayed is placed on website.
Consumer Protection Act
Aim and focus – regulates marketing of goods and services to consumers
Specific focus placed on relationships, transactions and agreements between
suppliers, retailers, service providers & other intermediaries and the consumer
Main commercial activities affected are transactions & marketing
Sec. 5(1)
Act applies to every transaction occurring in SA
Natural persons & small to medium juristic persons who do not exceed R2
million threshold (monetary asset value or annual turnover)
act on services
Services like the provision of debit or credit cards and electronic banking will
be affected by comprehensive provisions of the Act
Act excludes: banking services, related or similar financial services that
constitute advice or intermediary services – regulated by Financial Advisory &
Intermediary Services Act
Sec. 48
Supplier may not make use of unfair, unreasonable or unjust contract terms
Protection of Personal Information Act
Aim: aims to protect personal info processed by public and private individuals
so as to ensure that:
19-22: Processing takes place according to internationally accepted data
protection principles
105-106: There is adequate enforcement to ensure compliance
Sec. 19
Security measures on integrity and confidentiality of personal information
1) A responsible party must secure integrity and confidentiality of personal info in
its possession or under its control by taking appropriate, reasonable technical
and organisational measures to prevent –
a. Loss of, damage to or unauthorised destruction of personal info; &
b. Unlawful access to or processing of personal info
2) In order to give effect to subsection (1) the responsible party must take
reasonable measures to –
a. Identify all reasonably foreseeable internal & external risks to personal
info in its possession or under its control
b. Est and maintain appropriate safeguards against risks identified,
c. Regularly verify that safeguards = effectively implemented &
d. Ensure safeguards = continually updated in response to new risks or
deficiencies in previously implemented safeguards
3) Responsible party must have due regard to generally accepted info security
practices & procedures which may apply to it generally or be required ito
specific industry or professional rules & regulations
Sec. 20
Info processed by operator or person acting under authority
1) An operator or anyone processing personal info on behalf of a responsible
party or operator, must –
a. Process such info only with the knowledge or authorisation of the
responsible party; and
b. Treat personal info which comes to their knowledge as confidential and
must not disclose it, unless required by law or in the course of proper
performance of their duties
Sec. 21
Security measures regarding info processed by operator:
1. Responsible party must, ito a written contract btwn responsible party and
operator, ensure operator which processes personal info for responsible party
establishes & maintains security measures referred to in s19.
2. Operator must notify responsible party immediately where reasonable
grounds to believe personal info of data subject was accessed/acquired by an
unauthorised person
Sec. 22
Notification of security compromises