Privacy Policy

Protection of Personal Information Act 4 of 2013 (South Africa)  ·  UK GDPR and Data Protection Act 2018  ·  EU General Data Protection Regulation (EU) 2016/679  ·  Personal Data Protection Act 2012 (Singapore)

Document control

Document title

Global Tax Recovery Privacy Notice (external)

Version

2.0

Status

Published

Supersedes

Protection of Personal Information (POPI) & Privacy Policy, last modified 19 June 2025

Effective date

19/07/2016

Owner

Nalinee Du Plessis, Information Officer

Approved by

Nalinee Du Plessis, 02/06/2026

Next review

02/06/2027

1.  About this notice

1.1  What this notice does

Global Tax Recovery (“GTR”, “we”, “us”, “our”) recovers over-withheld tax on cross-border dividends, interest and royalties on behalf of institutional and individual investors. Doing that work necessarily involves handling personal information, and this notice explains, in plain terms, what we collect, why we collect it, what we do with it, who we share it with, how long we keep it and what rights you have.

We have written this notice to meet the requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”) in South Africa, the UK General Data Protection Regulation and Data Protection Act 2018 in the United Kingdom, the EU General Data Protection Regulation (EU) 2016/679 in the European Economic Area, and the Personal Data Protection Act 2012 in Singapore. Where those laws differ, we apply the standard most protective of you.

In this notice, “personal information” and “personal data” mean the same thing: information relating to an identified or identifiable living person, and, where South African law applies, information relating to an existing juristic person. “Processing” means anything we do with that information, including collecting, recording, storing, using, sharing, transferring, correcting, restricting, erasing or destroying it.

1.2  Who we are

Global Tax Recovery is a group of companies operating from the United Kingdom, the United States, South Africa and Singapore. The entity responsible for your personal information depends on where you are and how you deal with us.

Entity

Registered address

Registration / VAT
number

Acts as controller for

Global Tax Recovery Ltd

(United Kingdom)

25 Cabot Square, Canary Wharf,
London, E14 4QZ

12580957

434425313

Clients and contacts in the United Kingdom, the EEA and the rest of the world other than those below; visitors to globaltaxrecovery.com

Global Tax Recovery (Pty) Ltd

(South Africa)

78 Corlett Drive, Melrose North,
Johannesburg,

2196

2016/404751/07

4110284405

Clients and contacts in South Africa and the wider African region; South African employees, candidates and suppliers

Global Tax Recovery Pte Ltd (Singapore)

Centennial Tower, 21st
Floor, 3 Temasek Avenue, Singapore, 039190

202419252D

Clients and contacts in Singapore and the Asia-Pacific region

Where two or more GTR entities determine jointly why and how your personal information is processed, they act as joint controllers. The essence of that arrangement is available on request, and you may exercise your rights against any of them.

1.3  Our role: when we are a controller and when we are a processor

This distinction matters, because it determines who you should approach about your information.

    We act as a controller – deciding why and how information is processed — for our own client relationships and prospective client relationships, for visitors to our website, for our marketing, for our suppliers and professional advisers, for job applicants, and for our own staff.

    We act as a processor – acting on documented instructions — where a bank, custodian, asset manager, pension fund or other institution engages us to recover withholding tax and passes us personal information about its own underlying clients, members or beneficial owners. In those cases the institution is the controller. Our processing is governed by the data processing terms in our client agreement, entered into under Article 28 of the UK and EU GDPR and sections 20 and 21 of POPIA. If you are an underlying investor and want to exercise your rights over that information, please contact your institution in the first instance; if you contact us, we will pass your request to them promptly and support them in answering it.

1.4  How to contact us about privacy

Role

Contact

Privacy enquiries and data subject requests

[email protected]

Information Officer (POPIA section 55)

Mark Berger 

+27 10 141 5588

Registered with the Information Regulator (South Africa) on 20/02/2019

Deputy Information Officer(s)

Nalinee Du Plessis

[email protected]

Data Protection Officer (UK/EU GDPR Article 37)

Mark Berger

markb@globaltaxrecovery

EU representative (GDPR Article 27)

Mark Berger

markb@globaltaxrecovery

UK representative (UK GDPR Article 27)

Nalinee Du Plessis

[email protected]

General enquiries

[email protected]

UK +44 208 264 8777  ·  US +1 646 755 9744  ·  ZA +27 10 141 5588  ·  SG +65 6829 7047

2.  Who this notice applies to

This notice applies to you if you are:

    a visitor to globaltaxrecovery.com or a user of any GTR online platform or portal;

    a contact at a current, former or prospective institutional client, or someone who enquires about our services;

    an individual investor who engages us directly to recover withholding tax;

    an individual whose details appear in reclaim documentation – for example a beneficial owner, a trustee, a fund member, an authorised signatory or a named representative;

    a contact at a supplier, custodian, paying agent, professional adviser or other counterparty; or

    a candidate applying for a role with us.

This notice does not cover our processing of employee information, which is dealt with in our separate Employee Privacy Notice, or our internal data protection procedures, which are set out in our internal Data Protection Policy. It also does not apply to third-party websites we link to; those sites have their own notices.

3.  The personal information we collect

We collect only what we need for the purposes described in section 5. We do not collect information speculatively, and we do not collect categories of information that have nothing to do with withholding tax recovery.

Category

What it includes

Who it relates to

Identity and contact data

Full name, title, job title and
employer, business email address, business telephone number, business postal address, and where you deal with us as an individual, your personal contact details.

Client contacts, individual clients,
supplier contacts, enquirers, candidates

Verification data

Identity number or passport number,
date of birth, nationality, tax residency, taxpayer identification number,
proof of address, specimen signature, and the identity of beneficial owners
and controlling persons.

Individual clients, beneficial
owners, authorised signatories, persons subject to onboarding checks

Tax and holdings data

Securities held, holding periods,
dividend, interest and royalty entitlements, amounts withheld, applicable treaty rates, tax residency certificates, tax vouchers, dividend credit advices, powers of attorney and reclaim forms.

Individual clients, beneficial
owners, underlying investors

Financial data

Bank account and payment details
used to remit recovered amounts, invoicing and fee data, and contingency fee calculations.

Clients and individual claimants

Correspondence data

Emails, letters, portal messages,
call notes, meeting notes, enquiry and contact form submissions, and
complaint records.

Anyone who communicates with us

Technical and usage data

IP address, approximate location
derived from IP address, browser type and version, device type, operating
system, referring URL, pages viewed, time on page, and cookie and similar
identifiers.

Website and platform users

Marketing data

Your marketing preferences,
subscription status, event and conference attendance, and whether you have opened or clicked our communications.

Client and prospective client
contacts

Recruitment data

CV, cover letter, employment and
education history, references, right-to-work documentation and interview
notes.

Candidates

We do not collect information about your marital status, pregnancy, religion, culture, social origin, language, education, personal opinions, or another person’s opinions about you, other than where such information happens to appear on a document you provide to us (for example an identity document or a CV) and is incidental to the purpose for which we hold it. We do not operate a payroll, an employee self-service platform, an insurance or lending business, or a customer loyalty programme, and we do not process personal information for any of those purposes.

3.1  Special categories of personal information

“Special personal information” under POPIA section 26 and “special category data” under Article 9 of the UK and EU GDPR includes information about race, ethnic origin, health, biometrics, religious or philosophical beliefs, trade union membership, political opinions, sex life or sexual orientation, and, under POPIA, criminal behaviour.

We do not seek out special category information and it is not needed to recover withholding tax. It may nonetheless reach us in three limited situations:

    Identity documents. A passport or identity card supplied for verification may show your photograph, which can constitute biometric data if used for identification, and may reveal ethnic origin. We use these documents only to confirm identity, and we do not run facial recognition or any other automated biometric matching against them.

    Screening. Anti-money-laundering, sanctions and politically exposed person screening may return information about alleged or actual criminal conduct.

    Information you volunteer. For example, an accessibility or dietary requirement you tell us about for an event, or health information you disclose in a recruitment context so that we can make reasonable adjustments.

Where we do process this information, we rely on the following conditions:

    UK and EU GDPR Article 9(2)(a) — your explicit consent; Article 9(2)(b) — employment and related obligations; Article 9(2)(f) — the establishment, exercise or defence of legal claims; and Article 9(2)(g) — substantial public interest, read with Schedule 1 Part 2 paragraphs 10, 11 and 12 of the Data Protection Act 2018 for the prevention and detection of unlawful acts, regulatory compliance and money laundering. We maintain an Appropriate Policy Document as required by Schedule 1 Part 4.

    POPIA section 27(1)(a) — your consent; section 27(1)(b) — the establishment, exercise or defence of a right or obligation in law; and section 27(1)(c) — compliance with an obligation of international public law. Criminal behaviour information is processed under section 33 where it relates to obligations imposed on us by law.

4.  Where we obtain your personal information

    Directly from you – when you contact us, complete a form on our website, subscribe to our insights, meet us at a conference, engage our services, or apply for a role.

    From the institution that engaged us – where a bank, custodian, asset manager, pension fund, family office or other client provides information about its underlying clients, members or beneficial owners so that we can file reclaims on their behalf.

    From custodians, sub-custodians, paying agents and withholding agents – holdings, entitlement and withholding data needed to substantiate a claim.

    From tax authorities and their agents – correspondence, determinations, queries and refund confirmations relating to claims we have filed.

    From publicly available and commercial sources – company registers, regulatory registers, professional networking sites, sanctions and PEP screening providers, and business information databases, where we need to verify a party or assess a prospective client relationship.

    From your device – through cookies and similar technologies, as described in section 9.

    From recruiters and referees – in a recruitment context, and with your knowledge.

Where we obtain your information from someone other than you and POPIA section 18 or Articles 13 and 14 of the UK and EU GDPR require us to tell you, we will do so within a reasonable period and in any event within one month, unless an exemption applies.

5.  Why we process your information, and our lawful basis

We must have a lawful basis for every purpose for which we process your personal information. The table below sets out each purpose, the basis we rely on under the UK and EU GDPR, and the corresponding justification under section 11 of POPIA. We do not rely on a general catch-all such as “any other related purposes”.

Purpose

Information used

UK / EU GDPR lawful
basis

POPIA section 11
justification

Providing withholding tax recovery services: preparing, filing and pursuing reclaims, and corresponding with tax authorities

Identity, verification, tax and holdings, financial, correspondence

Article 6(1)(b) performance of a
contract, where our contract is with you; Article 6(1)(f) legitimate
interests, where our contract is with the institution acting for you

s11(1)(b) necessary to conclude or perform a contract; s11(1)(f) legitimate interests of GTR or a third party

Client onboarding, identity verification, anti-money-laundering, sanctions and PEP screening

Identity, verification, screening results

Article 6(1)(c) legal obligation; Article 9(2)(g) and DPA 2018 Sch 1 para 12 for related special category data

s11(1)(c) compliance with an obligation imposed by law; FIC Act 38 of 2001 where applicable

Managing the client relationship: instructions, queries, reporting, invoicing and contingency fee calculation

Identity, contact, financial, correspondence

Article 6(1)(b) performance of a
contract; Article 6(1)(f) legitimate interests

s11(1)(b); s11(1)(f)

Responding to enquiries, complaints and requests received through our website, email or telephone

Identity, contact, correspondence

Article 6(1)(f) legitimate interests in responding to those who contact us; Article 6(1)(b) where you are taking steps towards a contract

s11(1)(f); s11(1)(b)

Direct marketing of our services to business contacts, including our insights mailing list and conference follow-up

Identity, contact, marketing

Article 6(1)(a) consent where required by PECR or equivalent; otherwise Article 6(1)(f) legitimate
interests in promoting our services to relevant professionals

s11(1)(a) consent, as required by s69 for electronic direct marketing to persons who are not customers;
s11(1)(f) otherwise

Operating, securing and maintaining our website, platform and IT systems, including fraud and intrusion prevention

Technical and usage, correspondence

Article 6(1)(f) legitimate interests in keeping our systems secure and available

s11(1)(f)

Analytics and advertising cookies and similar technologies

Technical and usage

Article 6(1)(a) consent

s11(1)(a) consent

Improving our services, analysing demand across markets and producing aggregate and anonymised statistics and research

Technical and usage, aggregated claim data

Article 6(1)(f) legitimate interests in understanding and improving our services

s11(1)(f); s15 processing for
statistical and research purposes

Complying with legal, tax,
accounting, audit and regulatory obligations, and responding to lawful
requests from authorities

Any category, as required

Article 6(1)(c) legal obligation

s11(1)(c)

Establishing, exercising or defending legal claims, and managing disputes and professional indemnity
matters

Any category, as relevant

Article 6(1)(f) legitimate interests in protecting our legal position

s11(1)(f)

Recruitment: assessing applications, interviewing, checking references and right to work

Recruitment, identity, verification

Article 6(1)(b) steps prior to entering a contract; Article 6(1)(c) for right-to-work checks; Article
6(1)(f) for reference checking

s11(1)(b); s11(1)(c); s11(1)(f)

Corporate transactions, including a sale, merger, restructuring or due diligence exercise

Identity, contact, contractual and
financial records

Article 6(1)(f) legitimate interests in managing our business

s11(1)(f)

5.1  What we mean by legitimate interests

Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interest in the processing against your interests, rights and freedoms, and we proceed only where our interest is not overridden. You can ask us for a summary of the relevant assessment by writing to [email protected], and you have the right to object to processing based on this ground, as explained in section 14.

5.2  If we want to use your information for a new purpose

If we intend to process your personal information for a purpose that is not described in this notice, we will tell you beforehand, explain the lawful basis, and where consent is required, ask for it. We do not treat your continued use of our website or services as consent to a new purpose.

6.  Marketing and your choices

We market our services to professionals at institutions that invest across borders. Our marketing is business-to-business, and we keep it relevant and infrequent.

    Every marketing email we send contains a one-click unsubscribe link, and we act on unsubscribe requests promptly and at no cost to you.

    You can also opt out at any time by writing to [email protected]. Opting out of marketing does not affect communications we send you about a service we are providing.

    Where the law requires prior consent for electronic direct marketing – including POPIA section 69 for persons who are not our customers, and the Privacy and Electronic Communications Regulations 2003 in the United Kingdom – we obtain that consent before sending, and we keep a record of it.

    We do not sell, rent or trade your personal information, and we do not share it with third parties for their own marketing purposes.

    We do not send marketing to individuals who have asked us to stop, and we maintain a suppression list for that purpose. That list holds the minimum data needed to honour your request.

7.  Automated decision-making and profiling

We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing.

Our platform automates parts of the reclaim workflow, such as matching holdings to entitlements, calculating recoverable amounts and identifying claims that are approaching a filing deadline. Those outputs are reviewed by our specialists before any claim is filed or any decision is taken about a client relationship.
Anti-money-laundering and sanctions screening produces automated alerts, but a person reviews every alert before we act on it.

We use limited profiling for marketing purposes — for example, segmenting our insights list by market or institution type. You can object to this at any time, and where profiling is for direct marketing, we will stop.

If this position changes, we will update this notice and, where required, tell you about the logic involved and the significance and likely consequences of the processing, and give you the right to obtain human intervention, express your point of view and contest the decision.

8.  Who we share your information with

We share personal information only where there is a lawful basis and a genuine need. Every service provider that processes personal information on our behalf does so under a written contract that meets the requirements of Article 28 of the UK and EU GDPR and sections 20 and 21 of POPIA, is bound by confidentiality, may act only on our documented instructions, and must return or delete the information when the engagement ends. We carry out due diligence before appointing them.

Recipient

Why

Role

Other Global Tax Recovery group
entities

To deliver a single managed service across jurisdictions, and for group administration, oversight and IT support

Controller or processor, depending on the activity

Tax authorities and their appointed agents

To file, substantiate and pursue
reclaims. This is the core of the service and cannot be avoided if a claim is to succeed

Independent controller

Custodians, sub-custodians, paying agents, withholding agents and depositories

To obtain and verify holdings,
entitlement and withholding data

Independent controller

Local tax agents, correspondent
firms and legal counsel in claim jurisdictions

To file or pursue claims where local representation is required

Processor or independent controller depending on the engagement

IT, cloud hosting, document
management, email, security and support providers

To operate the systems on which our services and website run

Processor

Professional advisers: auditors,
lawyers, accountants, insurers and consultants

To obtain professional advice,
conduct audits and manage risk

Independent controller or processor

Banks and payment providers

To remit recovered amounts and
process fees

Independent controller

Screening and identity verification
providers

To meet anti-money-laundering,
sanctions and know-your-client obligations

Processor or independent controller

Marketing, analytics and event
platform providers

To send our insights, run our
website and manage conference attendance, subject to your cookie and marketing choices

Processor

Regulators, courts, law enforcement and government bodies

Where we are required to disclose by law or court order, or to establish, exercise or defend legal claims

Independent controller

Purchasers, investors and their
advisers in a corporate transaction

Where GTR or part of it is sold,
restructured or merged. Personal information disclosed for this purpose is limited to what is necessary and is shared under confidentiality undertakings

Independent controller

We do not share your information with your spouse, dependants, employer, medical practitioners, insurers, tracing agents or debt collectors, and we do not participate in loyalty reward programmes. Those disclosures appeared in our previous policy and have no application to our business.

A current list of the categories of processors we use, and the countries in which they operate, is available on request.

9.  Cookies and similar technologies

Cookies are small files placed on your device when you visit a website. We also use similar technologies such as pixels, tags and local storage. Together they let the site function, help us understand how it is used, and support our advertising.

We do not set any non-essential cookie or tag until you have given consent. When you first visit globaltaxrecovery.com you will see a consent banner. Strictly necessary cookies are set automatically because the site cannot work without them; everything else stays blocked until you choose to accept it. You can accept all, reject all, or choose by category, and you can change your choice at any time using the “Cookie preferences” link in the footer of every page. Rejecting non-essential cookies will not restrict your access to any part of the site.

We honour the Global Privacy Control signal where your browser sends one.

Category

What it does

Examples

Consent

Strictly necessary

Enables core functions such as page
navigation, security, load balancing and remembering your cookie choice. The
site cannot function without these

Session duration, search queries, security and CMP cookies

Not required

Performance and analytics

Tells us which pages are visited and
how visitors move through the site, so we can improve it

Google Analytics, deployed through
Google Tag Manager 

Required

Advertising and targeting

Measures the performance of our
campaigns and allows us to show relevant advertising on third-party platforms

LinkedIn Insight Tag

Google Ads

Microsoft Bing Ads

Required

Functional

Remembers preferences such as
language or previously submitted form details

Name, Surname, Organisation, Email, Message

Required

A full, current list of the individual cookies we use, their providers, their purposes and their lifespans is available in the cookie preferences panel on our website. Third-party cookies are set by the providers named above, who are independent controllers for their own processing; their own privacy notices govern that processing.

You can also block or delete cookies through your browser settings. Doing so may affect how parts of our site behave.

10. International transfers

Recovering withholding tax is inherently cross-border. To pursue a claim in France, Japan or Norway, we must send documentation to the tax authority in that country. Our group also operates from four countries and uses service providers in others. Your personal information will therefore be transferred outside the country in which it was collected.

We only make those transfers where one of the following applies.

Transfers from the United Kingdom and the EEA

     The destination is covered by an adequacy decision or adequacy regulations, meaning the receiving country has been formally recognised as offering an adequate level of protection.

    The transfer is made under appropriate safeguards – for us, the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Agreement or the UK Addendum to the SCCs — supported by a transfer risk assessment and, where required, supplementary technical and organisational measures.

    A derogation in Article 49 applies. In practice, the most relevant is that the transfer is necessary for the performance of a contract with you, or for the conclusion or performance of a contract concluded in your interest, or is necessary for the establishment, exercise or defence of legal claims. Filing a reclaim with a foreign tax authority ordinarily falls within these.

Transfers from South Africa

We transfer personal information out of South Africa only where section 72 of POPIA permits it, namely where the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection and includes principles for onward transfer; or where you have consented; or where the transfer is necessary for the performance of a contract between you and us, or for the conclusion or performance of a contract concluded in your interest; or where the transfer is for your benefit and it is not reasonably practicable to obtain your consent.

Transfers from Singapore

We comply with the Transfer Limitation Obligation under the Personal Data Protection Act 2012 and take reasonable steps to ensure the recipient is bound to a comparable standard of protection.

Typical destinations include the United Kingdom, the European Economic Area, South Africa, the United States, Singapore, and any jurisdiction in which we are filing a claim on your behalf.

You may request a copy of the safeguards we rely on by writing to [email protected]. We may redact commercially sensitive terms.

11.  How long we keep your information

We keep personal information only for as long as we need it for the purpose we collected it for, or for as long as the law requires. We review our records periodically and securely delete or anonymise information that has passed its retention period. The periods below are our standard positions; a longer period applies where a specific legal obligation, a live dispute, a regulatory investigation or a tax authority limitation period requires it.

Record

Retention period

Reason

Reclaim files and supporting tax
documentation

7 years from the date the claim is finally determined, or longer where the limitation or audit period of the relevant tax authority requires

Tax authorities may reopen or query
a claim after payment; evidence must remain available

Client contracts, engagement letters
and correspondence

7 years from the end of the relationship

Statutory record-keeping and the
limitation period for contractual claims

Accounting, invoicing and fee
records

7 years from the end of the relevant tax year

Companies Act 71 of 2008 and Tax Administration Act 28 of 2011 in South Africa; Companies Act 2006 in the United Kingdom

Identity verification and
anti-money-laundering records

5 years from the end of the business
relationship or the date of the transaction

Financial Intelligence Centre Act 38 of 2001; Money Laundering Regulations 2017 in the United Kingdom

General enquiries and correspondence
that do not lead to an engagement

24 months from the last contact

Allows us to respond to follow-up
and to evidence what was said

Marketing contact data and
preferences

Until you opt out, or  24 months after your last engagement with our communications, whichever
is earlier

Keeps our list accurate and limits
retention of data no longer in active use

Opt-out and suppression records

Indefinitely, limited to the minimum data needed

We must be able to honour your
opt-out permanently

Website analytics data

26 months

Standard analytics retention; allows
year-on-year comparison

Cookie consent records

12 months, after which we ask again

Demonstrates consent was obtained and keeps it current

Unsuccessful job applications

6 months after the outcome, or 12 months where you agree to be kept on file

Allows us to respond to queries
about the decision

Complaint records

 6 years from resolution

Limitation period and regulatory
accountability

Where we anonymise information so that it can no longer be linked to you, we may keep and use it indefinitely for statistical and research purposes without further notice.

We do not keep information simply because it might one day be useful. Where a retention period expires but we still hold the record because it is embedded in a system backup, that record remains isolated and is deleted on the normal backup cycle.

12.  How we protect your information

We take appropriate technical and organisational measures to protect personal information against loss, unauthorised access, alteration, disclosure and destruction.
These include:

    encryption of personal information in transit and at rest;

    role-based access control on the principle of least privilege, with multi-factor authentication on systems holding personal information;

    network security controls, logging and monitoring of access and unusual activity;

    secure development practices and regular vulnerability scanning and penetration testing;

    physical access controls at our premises;

    secure destruction of physical and electronic records at the end of their retention period;

    due diligence on service providers before appointment, and contractual security obligations on them thereafter;

    mandatory data protection and information security training for all staff, refreshed annually; and

    documented incident response and business continuity procedures, which are tested.

Our information security management system is certified to ISO/IEC 27001, certificate number IS 715435, issued by BSI, with a scope covering Information Security Management System

No system can be guaranteed completely secure. Email in particular is not a secure medium, and we ask that you do not send identity documents, bank details or other sensitive information to us by ordinary email. We will provide a secure channel on request.

13.  Personal information breaches

If a breach occurs that compromises your personal information, we will act quickly to contain it, assess the risk and put things right.

    Where the breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority — the Information Commissioner’s Office, an EEA supervisory authority, or both — without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 of the UK and EU GDPR.

    Under section 22 of POPIA we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after becoming aware of the breach, unless the identity of the affected person cannot be established. Notification to data subjects will describe the possible consequences, the measures we intend to take, what you can do to mitigate the effects, and the identity of the person who accessed the information if we know it.

    Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly under Article 34 of the UK and EU GDPR.

    Where we act as a processor for an institutional client, we will notify that client without undue delay so that they can meet their own obligations.

    We maintain an internal register of all personal information breaches, whether or not they are notifiable.

14.  Your rights

You have the following rights in relation to your personal information. Some apply only under particular laws, and some are qualified — we will always tell you if we cannot give effect to a request and why.

Right

What it means

Access

To be told whether we hold personal information about you, and to receive a copy of it together with information about how and why we process it, who we share it with, how long we keep it, and the identity or categories of third parties who have had access to it.

Correction

To have inaccurate or incomplete personal information corrected or completed.

Erasure

To have your personal information deleted where it is no longer necessary for the purpose it was collected for, where you withdraw consent and there is no other basis, where you successfully object, where it has been processed unlawfully, or where the law requires deletion. Under POPIA you may also require deletion of information that is irrelevant, excessive, out of date, misleading or obtained unlawfully.

Restriction

To require us to pause processing – for example while we check the accuracy of information you have challenged, or while we consider an objection. We will keep the information but not otherwise use it.

Portability

To receive the personal information you have given us in a structured, commonly used, machine-readable format, and to have it sent directly to another organisation where that is technically feasible. This applies where processing is based on consent or on a contract and is carried out by automated means.

Objection

To object, on grounds relating to your particular situation, to processing based on legitimate interests or on public interest. We will stop unless we can show compelling legitimate grounds that override your interests, or that the processing is for the establishment, exercise or defence of legal claims. Under POPIA you may object on reasonable grounds to processing under sections 11(1)(d), (e) and (f).

Objection to direct marketing

To object to direct marketing at any time. This right is absolute — we will stop immediately and without question.

Withdrawal of consent

Where we rely on your consent, to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it, and it does not affect processing we carry out on another lawful basis.

Rights concerning automated
decisions

Not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, and to obtain human intervention, express your view and contest such a decision. Section 71 of POPIA and Article 22 of the UK and EU GDPR apply.

Complaint

To complain to us, and to the relevant supervisory authority. See section 16.

14.1 How to exercise your rights

Write to [email protected]. Please tell us which right you wish to exercise and give us enough detail to locate the information. You do not need to use a particular form, although POPIA Form 2 (objection) and Form 3 (correction or deletion) are available on request and through our PAIA manual.

We will ask you to verify your identity before we act, so that we do not disclose your information to someone else. We will request only what is needed for that purpose.

Our commitment

Timeframe

We will respond within one month of receiving your request. If the request is complex or you have made several requests, we may extend this by up to two further months, and we will tell you within the first month if we need to, together with the reason.

Cost

There is no charge. We may charge a reasonable administrative fee, or refuse to act, only where a request is manifestly unfounded or excessive, in particular because it is repetitive. If we do, we will explain why and tell you how to challenge that decision. A prescribed fee may apply to a request made formally under the Promotion of Access to Information Act 2 of 2000, and we will tell you the amount before proceeding.

If we cannot comply

We will tell you which exemption or limitation applies, why, and how to complain.

Third parties

Where we have shared your information with others, we will tell them about a correction, erasure or restriction, unless that proves impossible or involves disproportionate effort. We will tell you who those recipients are if you ask.

Systems updates

Changes to your information will usually be reflected across our systems within 15 business days.

15. Children

Our services are directed at institutions and adult investors. We do not knowingly market to children and we do not offer online services directly to them.

Under POPIA, a child is a person under the age of 18, and we may not process a child’s personal information unless one of the grounds in section 35 applies — most relevantly, the prior consent of a competent person, or where processing is necessary to establish, exercise or defend a right or obligation in law. Under the UK GDPR the age at which a child can consent to an online service is 13; under the EU GDPR it is 16 unless a member state has set a lower age. Where these differ, we apply the higher threshold.

Personal information about a person under 18 may reach us where that person is a beneficiary, a fund member or a beneficial owner named in reclaim documentation. In those cases we process the information under the authority of the competent person or the institution acting for them, and we apply the same protections as for any other data subject.

If you believe we hold information about a child without a proper basis, please write to [email protected] and we will investigate and, where appropriate, delete it.

16. Complaints

If you are unhappy with how we have handled your personal information or your request, please tell us first at [email protected]. We take complaints seriously, we will acknowledge yours promptly, and we will aim to resolve it within one month.

You also have the right to complain to a supervisory authority, and you may do so without contacting us first.

Authority

When to approach them

Contact

Information Regulator 

(South Africa)

Where the South African entity is the controller, or where the processing has a South African connection

Woodmead North Office Park, 54
Maxwell Drive, Woodmead, Johannesburg, 2191

[email protected]
(POPIA)

[email protected]
(PAIA)

inforegulator.org.za — complaints
are lodged through the eServices portal

Information Commissioner’s Office (United Kingdom)

Where the UK entity is the
controller, or where you are in the United Kingdom

Wycliffe House, Water Lane,
Wilmslow, Cheshire, SK9 5AF

Helpline 0303 123 1113

ico.org.uk

Your national data protection
authority (EEA)

Where you are in the European
Economic Area

You may complain to the authority in
the country where you live, where you work, or where the alleged infringement
occurred. A directory is maintained at edpb.europa.eu

Personal Data Protection Commission (Singapore)

Where the Singapore entity is the controller, or where you are in Singapore

pdpc.gov.sg

17.  Access to information under PAIA

The Promotion of Access to Information Act 2 of 2000 gives you the right to request access to records held by us. Our PAIA manual explains what records we hold, how to make a request, the prescribed forms and fees, and how to appeal a refusal.

Our PAIA manual is available at https://globaltaxrecovery.com/wp-content/uploads/2026/08/GTR-PAIA-Manual-2026-Section-51.pdf and on request from
our Information Officer, whose details appear in section 1.4. A copy has been submitted to the Information Regulator as required.

18.  Changes to this notice

We review this notice at least annually and whenever our processing changes materially. The version number and effective date appear on the cover page and at the foot of the published web page.

Where a change is material – for example a new purpose, a new category of recipient, or a change to the basis on which we process your information – we will bring it to your attention before it takes effect, by email where we hold your address and by a prominent notice on our website. We will not rely on your continued use of our website as agreement to a material change.

Version

Date

Summary of changes

1.0

2016

Original POPI and Privacy Policy

1.1

19 June 2025

Minor amendments

2.0

02/06/2026

Full rewrite. Controller identity and contact details added; lawful bases mapped to purposes; controller and processor roles distinguished; full rights schedule including restriction, portability and automated decision-making; transfer mechanisms specified; retention periods stated; breach notification added; cookie consent standard corrected; children’s age threshold corrected to align with POPIA; internal staff policy content removed; processing descriptions unrelated to GTR’s business removed

19.  Related documents

Website Terms of Use 

Cookie preferences – available on every page on globaltaxrecovery.com

PAIA Manual

Email Disclaimer

Employee and Candidate Privacy Notice – available internally

Data Protection Policy (internal) – available internally