Privacy Policy
Protection of Personal Information Act 4 of 2013 (South Africa) · UK GDPR and Data Protection Act 2018 · EU General Data Protection Regulation (EU) 2016/679 · Personal Data Protection Act 2012 (Singapore)
Document control | |
Document title | Global Tax Recovery Privacy Notice (external) |
Version | 2.0 |
Status | Published |
Supersedes | Protection of Personal Information (POPI) & Privacy Policy, last modified 19 June 2025 |
Effective date | 19/07/2016 |
Owner | Nalinee Du Plessis, Information Officer |
Approved by | Nalinee Du Plessis, 02/06/2026 |
Next review | 02/06/2027 |
1. About this notice
1.1 What this notice does
Global Tax Recovery (“GTR”, “we”, “us”, “our”) recovers over-withheld tax on cross-border dividends, interest and royalties on behalf of institutional and individual investors. Doing that work necessarily involves handling personal information, and this notice explains, in plain terms, what we collect, why we collect it, what we do with it, who we share it with, how long we keep it and what rights you have.
We have written this notice to meet the requirements of the Protection of Personal Information Act 4 of 2013 (“POPIA”) in South Africa, the UK General Data Protection Regulation and Data Protection Act 2018 in the United Kingdom, the EU General Data Protection Regulation (EU) 2016/679 in the European Economic Area, and the Personal Data Protection Act 2012 in Singapore. Where those laws differ, we apply the standard most protective of you.
In this notice, “personal information” and “personal data” mean the same thing: information relating to an identified or identifiable living person, and, where South African law applies, information relating to an existing juristic person. “Processing” means anything we do with that information, including collecting, recording, storing, using, sharing, transferring, correcting, restricting, erasing or destroying it.
1.2 Who we are
Global Tax Recovery is a group of companies operating from the United Kingdom, the United States, South Africa and Singapore. The entity responsible for your personal information depends on where you are and how you deal with us.
Entity | Registered address | Registration / VAT | Acts as controller for |
Global Tax Recovery Ltd (United Kingdom) | 25 Cabot Square, Canary Wharf, | 12580957 434425313 | Clients and contacts in the United Kingdom, the EEA and the rest of the world other than those below; visitors to globaltaxrecovery.com |
Global Tax Recovery (Pty) Ltd (South Africa) | 78 Corlett Drive, Melrose North, 2196 | 2016/404751/07 4110284405 | Clients and contacts in South Africa and the wider African region; South African employees, candidates and suppliers |
Global Tax Recovery Pte Ltd (Singapore) | Centennial Tower, 21st | 202419252D | Clients and contacts in Singapore and the Asia-Pacific region |
Where two or more GTR entities determine jointly why and how your personal information is processed, they act as joint controllers. The essence of that arrangement is available on request, and you may exercise your rights against any of them.
1.3 Our role: when we are a controller and when we are a processor
This distinction matters, because it determines who you should approach about your information.
• We act as a controller – deciding why and how information is processed — for our own client relationships and prospective client relationships, for visitors to our website, for our marketing, for our suppliers and professional advisers, for job applicants, and for our own staff.
• We act as a processor – acting on documented instructions — where a bank, custodian, asset manager, pension fund or other institution engages us to recover withholding tax and passes us personal information about its own underlying clients, members or beneficial owners. In those cases the institution is the controller. Our processing is governed by the data processing terms in our client agreement, entered into under Article 28 of the UK and EU GDPR and sections 20 and 21 of POPIA. If you are an underlying investor and want to exercise your rights over that information, please contact your institution in the first instance; if you contact us, we will pass your request to them promptly and support them in answering it.
1.4 How to contact us about privacy
Role | Contact |
Privacy enquiries and data subject requests | |
Information Officer (POPIA section 55) | Mark Berger +27 10 141 5588 Registered with the Information Regulator (South Africa) on 20/02/2019 |
Deputy Information Officer(s) | Nalinee Du Plessis |
Data Protection Officer (UK/EU GDPR Article 37) | Mark Berger markb@globaltaxrecovery |
EU representative (GDPR Article 27) | Mark Berger markb@globaltaxrecovery |
UK representative (UK GDPR Article 27) | Nalinee Du Plessis |
General enquiries | UK +44 208 264 8777 · US +1 646 755 9744 · ZA +27 10 141 5588 · SG +65 6829 7047 |
2. Who this notice applies to
This notice applies to you if you are:
• a visitor to globaltaxrecovery.com or a user of any GTR online platform or portal;
• a contact at a current, former or prospective institutional client, or someone who enquires about our services;
• an individual investor who engages us directly to recover withholding tax;
• an individual whose details appear in reclaim documentation – for example a beneficial owner, a trustee, a fund member, an authorised signatory or a named representative;
• a contact at a supplier, custodian, paying agent, professional adviser or other counterparty; or
• a candidate applying for a role with us.
This notice does not cover our processing of employee information, which is dealt with in our separate Employee Privacy Notice, or our internal data protection procedures, which are set out in our internal Data Protection Policy. It also does not apply to third-party websites we link to; those sites have their own notices.
3. The personal information we collect
We collect only what we need for the purposes described in section 5. We do not collect information speculatively, and we do not collect categories of information that have nothing to do with withholding tax recovery.
Category | What it includes | Who it relates to |
Identity and contact data | Full name, title, job title and | Client contacts, individual clients, |
Verification data | Identity number or passport number, | Individual clients, beneficial |
Tax and holdings data | Securities held, holding periods, | Individual clients, beneficial |
Financial data | Bank account and payment details | Clients and individual claimants |
Correspondence data | Emails, letters, portal messages, | Anyone who communicates with us |
Technical and usage data | IP address, approximate location | Website and platform users |
Marketing data | Your marketing preferences, | Client and prospective client |
Recruitment data | CV, cover letter, employment and | Candidates |
We do not collect information about your marital status, pregnancy, religion, culture, social origin, language, education, personal opinions, or another person’s opinions about you, other than where such information happens to appear on a document you provide to us (for example an identity document or a CV) and is incidental to the purpose for which we hold it. We do not operate a payroll, an employee self-service platform, an insurance or lending business, or a customer loyalty programme, and we do not process personal information for any of those purposes.
3.1 Special categories of personal information
“Special personal information” under POPIA section 26 and “special category data” under Article 9 of the UK and EU GDPR includes information about race, ethnic origin, health, biometrics, religious or philosophical beliefs, trade union membership, political opinions, sex life or sexual orientation, and, under POPIA, criminal behaviour.
We do not seek out special category information and it is not needed to recover withholding tax. It may nonetheless reach us in three limited situations:
• Identity documents. A passport or identity card supplied for verification may show your photograph, which can constitute biometric data if used for identification, and may reveal ethnic origin. We use these documents only to confirm identity, and we do not run facial recognition or any other automated biometric matching against them.
• Screening. Anti-money-laundering, sanctions and politically exposed person screening may return information about alleged or actual criminal conduct.
• Information you volunteer. For example, an accessibility or dietary requirement you tell us about for an event, or health information you disclose in a recruitment context so that we can make reasonable adjustments.
Where we do process this information, we rely on the following conditions:
• UK and EU GDPR Article 9(2)(a) — your explicit consent; Article 9(2)(b) — employment and related obligations; Article 9(2)(f) — the establishment, exercise or defence of legal claims; and Article 9(2)(g) — substantial public interest, read with Schedule 1 Part 2 paragraphs 10, 11 and 12 of the Data Protection Act 2018 for the prevention and detection of unlawful acts, regulatory compliance and money laundering. We maintain an Appropriate Policy Document as required by Schedule 1 Part 4.
• POPIA section 27(1)(a) — your consent; section 27(1)(b) — the establishment, exercise or defence of a right or obligation in law; and section 27(1)(c) — compliance with an obligation of international public law. Criminal behaviour information is processed under section 33 where it relates to obligations imposed on us by law.
4. Where we obtain your personal information
• Directly from you – when you contact us, complete a form on our website, subscribe to our insights, meet us at a conference, engage our services, or apply for a role.
• From the institution that engaged us – where a bank, custodian, asset manager, pension fund, family office or other client provides information about its underlying clients, members or beneficial owners so that we can file reclaims on their behalf.
• From custodians, sub-custodians, paying agents and withholding agents – holdings, entitlement and withholding data needed to substantiate a claim.
• From tax authorities and their agents – correspondence, determinations, queries and refund confirmations relating to claims we have filed.
• From publicly available and commercial sources – company registers, regulatory registers, professional networking sites, sanctions and PEP screening providers, and business information databases, where we need to verify a party or assess a prospective client relationship.
• From your device – through cookies and similar technologies, as described in section 9.
• From recruiters and referees – in a recruitment context, and with your knowledge.
Where we obtain your information from someone other than you and POPIA section 18 or Articles 13 and 14 of the UK and EU GDPR require us to tell you, we will do so within a reasonable period and in any event within one month, unless an exemption applies.
5. Why we process your information, and our lawful basis
We must have a lawful basis for every purpose for which we process your personal information. The table below sets out each purpose, the basis we rely on under the UK and EU GDPR, and the corresponding justification under section 11 of POPIA. We do not rely on a general catch-all such as “any other related purposes”.
Purpose | Information used | UK / EU GDPR lawful | POPIA section 11 |
Providing withholding tax recovery services: preparing, filing and pursuing reclaims, and corresponding with tax authorities | Identity, verification, tax and holdings, financial, correspondence | Article 6(1)(b) performance of a | s11(1)(b) necessary to conclude or perform a contract; s11(1)(f) legitimate interests of GTR or a third party |
Client onboarding, identity verification, anti-money-laundering, sanctions and PEP screening | Identity, verification, screening results | Article 6(1)(c) legal obligation; Article 9(2)(g) and DPA 2018 Sch 1 para 12 for related special category data | s11(1)(c) compliance with an obligation imposed by law; FIC Act 38 of 2001 where applicable |
Managing the client relationship: instructions, queries, reporting, invoicing and contingency fee calculation | Identity, contact, financial, correspondence | Article 6(1)(b) performance of a | s11(1)(b); s11(1)(f) |
Responding to enquiries, complaints and requests received through our website, email or telephone | Identity, contact, correspondence | Article 6(1)(f) legitimate interests in responding to those who contact us; Article 6(1)(b) where you are taking steps towards a contract | s11(1)(f); s11(1)(b) |
Direct marketing of our services to business contacts, including our insights mailing list and conference follow-up | Identity, contact, marketing | Article 6(1)(a) consent where required by PECR or equivalent; otherwise Article 6(1)(f) legitimate | s11(1)(a) consent, as required by s69 for electronic direct marketing to persons who are not customers; |
Operating, securing and maintaining our website, platform and IT systems, including fraud and intrusion prevention | Technical and usage, correspondence | Article 6(1)(f) legitimate interests in keeping our systems secure and available | s11(1)(f) |
Analytics and advertising cookies and similar technologies | Technical and usage | Article 6(1)(a) consent | s11(1)(a) consent |
Improving our services, analysing demand across markets and producing aggregate and anonymised statistics and research | Technical and usage, aggregated claim data | Article 6(1)(f) legitimate interests in understanding and improving our services | s11(1)(f); s15 processing for |
Complying with legal, tax, | Any category, as required | Article 6(1)(c) legal obligation | s11(1)(c) |
Establishing, exercising or defending legal claims, and managing disputes and professional indemnity | Any category, as relevant | Article 6(1)(f) legitimate interests in protecting our legal position | s11(1)(f) |
Recruitment: assessing applications, interviewing, checking references and right to work | Recruitment, identity, verification | Article 6(1)(b) steps prior to entering a contract; Article 6(1)(c) for right-to-work checks; Article | s11(1)(b); s11(1)(c); s11(1)(f) |
Corporate transactions, including a sale, merger, restructuring or due diligence exercise | Identity, contact, contractual and | Article 6(1)(f) legitimate interests in managing our business | s11(1)(f) |
5.1 What we mean by legitimate interests
Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interest in the processing against your interests, rights and freedoms, and we proceed only where our interest is not overridden. You can ask us for a summary of the relevant assessment by writing to [email protected], and you have the right to object to processing based on this ground, as explained in section 14.
5.2 If we want to use your information for a new purpose
If we intend to process your personal information for a purpose that is not described in this notice, we will tell you beforehand, explain the lawful basis, and where consent is required, ask for it. We do not treat your continued use of our website or services as consent to a new purpose.
6. Marketing and your choices
We market our services to professionals at institutions that invest across borders. Our marketing is business-to-business, and we keep it relevant and infrequent.
• Every marketing email we send contains a one-click unsubscribe link, and we act on unsubscribe requests promptly and at no cost to you.
• You can also opt out at any time by writing to [email protected]. Opting out of marketing does not affect communications we send you about a service we are providing.
• Where the law requires prior consent for electronic direct marketing – including POPIA section 69 for persons who are not our customers, and the Privacy and Electronic Communications Regulations 2003 in the United Kingdom – we obtain that consent before sending, and we keep a record of it.
• We do not sell, rent or trade your personal information, and we do not share it with third parties for their own marketing purposes.
• We do not send marketing to individuals who have asked us to stop, and we maintain a suppression list for that purpose. That list holds the minimum data needed to honour your request.
7. Automated decision-making and profiling
We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing.
Our platform automates parts of the reclaim workflow, such as matching holdings to entitlements, calculating recoverable amounts and identifying claims that are approaching a filing deadline. Those outputs are reviewed by our specialists before any claim is filed or any decision is taken about a client relationship.
Anti-money-laundering and sanctions screening produces automated alerts, but a person reviews every alert before we act on it.
We use limited profiling for marketing purposes — for example, segmenting our insights list by market or institution type. You can object to this at any time, and where profiling is for direct marketing, we will stop.
If this position changes, we will update this notice and, where required, tell you about the logic involved and the significance and likely consequences of the processing, and give you the right to obtain human intervention, express your point of view and contest the decision.
8. Who we share your information with
We share personal information only where there is a lawful basis and a genuine need. Every service provider that processes personal information on our behalf does so under a written contract that meets the requirements of Article 28 of the UK and EU GDPR and sections 20 and 21 of POPIA, is bound by confidentiality, may act only on our documented instructions, and must return or delete the information when the engagement ends. We carry out due diligence before appointing them.
Recipient | Why | Role |
Other Global Tax Recovery group | To deliver a single managed service across jurisdictions, and for group administration, oversight and IT support | Controller or processor, depending on the activity |
Tax authorities and their appointed agents | To file, substantiate and pursue | Independent controller |
Custodians, sub-custodians, paying agents, withholding agents and depositories | To obtain and verify holdings, | Independent controller |
Local tax agents, correspondent | To file or pursue claims where local representation is required | Processor or independent controller depending on the engagement |
IT, cloud hosting, document | To operate the systems on which our services and website run | Processor |
Professional advisers: auditors, | To obtain professional advice, | Independent controller or processor |
Banks and payment providers | To remit recovered amounts and | Independent controller |
Screening and identity verification | To meet anti-money-laundering, | Processor or independent controller |
Marketing, analytics and event | To send our insights, run our | Processor |
Regulators, courts, law enforcement and government bodies | Where we are required to disclose by law or court order, or to establish, exercise or defend legal claims | Independent controller |
Purchasers, investors and their | Where GTR or part of it is sold, | Independent controller |
We do not share your information with your spouse, dependants, employer, medical practitioners, insurers, tracing agents or debt collectors, and we do not participate in loyalty reward programmes. Those disclosures appeared in our previous policy and have no application to our business.
A current list of the categories of processors we use, and the countries in which they operate, is available on request.
9. Cookies and similar technologies
Cookies are small files placed on your device when you visit a website. We also use similar technologies such as pixels, tags and local storage. Together they let the site function, help us understand how it is used, and support our advertising.
We do not set any non-essential cookie or tag until you have given consent. When you first visit globaltaxrecovery.com you will see a consent banner. Strictly necessary cookies are set automatically because the site cannot work without them; everything else stays blocked until you choose to accept it. You can accept all, reject all, or choose by category, and you can change your choice at any time using the “Cookie preferences” link in the footer of every page. Rejecting non-essential cookies will not restrict your access to any part of the site.
We honour the Global Privacy Control signal where your browser sends one.
Category | What it does | Examples | Consent |
Strictly necessary | Enables core functions such as page | Session duration, search queries, security and CMP cookies | Not required |
Performance and analytics | Tells us which pages are visited and | Google Analytics, deployed through | Required |
Advertising and targeting | Measures the performance of our | LinkedIn Insight Tag Google Ads Microsoft Bing Ads | Required |
Functional | Remembers preferences such as | Name, Surname, Organisation, Email, Message | Required |
A full, current list of the individual cookies we use, their providers, their purposes and their lifespans is available in the cookie preferences panel on our website. Third-party cookies are set by the providers named above, who are independent controllers for their own processing; their own privacy notices govern that processing.
You can also block or delete cookies through your browser settings. Doing so may affect how parts of our site behave.
10. International transfers
Recovering withholding tax is inherently cross-border. To pursue a claim in France, Japan or Norway, we must send documentation to the tax authority in that country. Our group also operates from four countries and uses service providers in others. Your personal information will therefore be transferred outside the country in which it was collected.
We only make those transfers where one of the following applies.
Transfers from the United Kingdom and the EEA
• The destination is covered by an adequacy decision or adequacy regulations, meaning the receiving country has been formally recognised as offering an adequate level of protection.
• The transfer is made under appropriate safeguards – for us, the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Agreement or the UK Addendum to the SCCs — supported by a transfer risk assessment and, where required, supplementary technical and organisational measures.
• A derogation in Article 49 applies. In practice, the most relevant is that the transfer is necessary for the performance of a contract with you, or for the conclusion or performance of a contract concluded in your interest, or is necessary for the establishment, exercise or defence of legal claims. Filing a reclaim with a foreign tax authority ordinarily falls within these.
Transfers from South Africa
We transfer personal information out of South Africa only where section 72 of POPIA permits it, namely where the recipient is subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection and includes principles for onward transfer; or where you have consented; or where the transfer is necessary for the performance of a contract between you and us, or for the conclusion or performance of a contract concluded in your interest; or where the transfer is for your benefit and it is not reasonably practicable to obtain your consent.
Transfers from Singapore
We comply with the Transfer Limitation Obligation under the Personal Data Protection Act 2012 and take reasonable steps to ensure the recipient is bound to a comparable standard of protection.
Typical destinations include the United Kingdom, the European Economic Area, South Africa, the United States, Singapore, and any jurisdiction in which we are filing a claim on your behalf.
You may request a copy of the safeguards we rely on by writing to [email protected]. We may redact commercially sensitive terms.
11. How long we keep your information
We keep personal information only for as long as we need it for the purpose we collected it for, or for as long as the law requires. We review our records periodically and securely delete or anonymise information that has passed its retention period. The periods below are our standard positions; a longer period applies where a specific legal obligation, a live dispute, a regulatory investigation or a tax authority limitation period requires it.
Record | Retention period | Reason |
Reclaim files and supporting tax | 7 years from the date the claim is finally determined, or longer where the limitation or audit period of the relevant tax authority requires | Tax authorities may reopen or query |
Client contracts, engagement letters | 7 years from the end of the relationship | Statutory record-keeping and the |
Accounting, invoicing and fee | 7 years from the end of the relevant tax year | Companies Act 71 of 2008 and Tax Administration Act 28 of 2011 in South Africa; Companies Act 2006 in the United Kingdom |
Identity verification and | 5 years from the end of the business | Financial Intelligence Centre Act 38 of 2001; Money Laundering Regulations 2017 in the United Kingdom |
General enquiries and correspondence | 24 months from the last contact | Allows us to respond to follow-up |
Marketing contact data and | Until you opt out, or 24 months after your last engagement with our communications, whichever | Keeps our list accurate and limits |
Opt-out and suppression records | Indefinitely, limited to the minimum data needed | We must be able to honour your |
Website analytics data | 26 months | Standard analytics retention; allows |
Cookie consent records | 12 months, after which we ask again | Demonstrates consent was obtained and keeps it current |
Unsuccessful job applications | 6 months after the outcome, or 12 months where you agree to be kept on file | Allows us to respond to queries |
Complaint records | 6 years from resolution | Limitation period and regulatory |
Where we anonymise information so that it can no longer be linked to you, we may keep and use it indefinitely for statistical and research purposes without further notice.
We do not keep information simply because it might one day be useful. Where a retention period expires but we still hold the record because it is embedded in a system backup, that record remains isolated and is deleted on the normal backup cycle.
12. How we protect your information
We take appropriate technical and organisational measures to protect personal information against loss, unauthorised access, alteration, disclosure and destruction.
These include:
• encryption of personal information in transit and at rest;
• role-based access control on the principle of least privilege, with multi-factor authentication on systems holding personal information;
• network security controls, logging and monitoring of access and unusual activity;
• secure development practices and regular vulnerability scanning and penetration testing;
• physical access controls at our premises;
• secure destruction of physical and electronic records at the end of their retention period;
• due diligence on service providers before appointment, and contractual security obligations on them thereafter;
• mandatory data protection and information security training for all staff, refreshed annually; and
• documented incident response and business continuity procedures, which are tested.
Our information security management system is certified to ISO/IEC 27001, certificate number IS 715435, issued by BSI, with a scope covering Information Security Management System.
No system can be guaranteed completely secure. Email in particular is not a secure medium, and we ask that you do not send identity documents, bank details or other sensitive information to us by ordinary email. We will provide a secure channel on request.
13. Personal information breaches
If a breach occurs that compromises your personal information, we will act quickly to contain it, assess the risk and put things right.
• Where the breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority — the Information Commissioner’s Office, an EEA supervisory authority, or both — without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 of the UK and EU GDPR.
• Under section 22 of POPIA we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after becoming aware of the breach, unless the identity of the affected person cannot be established. Notification to data subjects will describe the possible consequences, the measures we intend to take, what you can do to mitigate the effects, and the identity of the person who accessed the information if we know it.
• Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly under Article 34 of the UK and EU GDPR.
• Where we act as a processor for an institutional client, we will notify that client without undue delay so that they can meet their own obligations.
• We maintain an internal register of all personal information breaches, whether or not they are notifiable.
14. Your rights
You have the following rights in relation to your personal information. Some apply only under particular laws, and some are qualified — we will always tell you if we cannot give effect to a request and why.
Right | What it means |
Access | To be told whether we hold personal information about you, and to receive a copy of it together with information about how and why we process it, who we share it with, how long we keep it, and the identity or categories of third parties who have had access to it. |
Correction | To have inaccurate or incomplete personal information corrected or completed. |
Erasure | To have your personal information deleted where it is no longer necessary for the purpose it was collected for, where you withdraw consent and there is no other basis, where you successfully object, where it has been processed unlawfully, or where the law requires deletion. Under POPIA you may also require deletion of information that is irrelevant, excessive, out of date, misleading or obtained unlawfully. |
Restriction | To require us to pause processing – for example while we check the accuracy of information you have challenged, or while we consider an objection. We will keep the information but not otherwise use it. |
Portability | To receive the personal information you have given us in a structured, commonly used, machine-readable format, and to have it sent directly to another organisation where that is technically feasible. This applies where processing is based on consent or on a contract and is carried out by automated means. |
Objection | To object, on grounds relating to your particular situation, to processing based on legitimate interests or on public interest. We will stop unless we can show compelling legitimate grounds that override your interests, or that the processing is for the establishment, exercise or defence of legal claims. Under POPIA you may object on reasonable grounds to processing under sections 11(1)(d), (e) and (f). |
Objection to direct marketing | To object to direct marketing at any time. This right is absolute — we will stop immediately and without question. |
Withdrawal of consent | Where we rely on your consent, to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it, and it does not affect processing we carry out on another lawful basis. |
Rights concerning automated | Not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, and to obtain human intervention, express your view and contest such a decision. Section 71 of POPIA and Article 22 of the UK and EU GDPR apply. |
Complaint | To complain to us, and to the relevant supervisory authority. See section 16. |
14.1 How to exercise your rights
Write to [email protected]. Please tell us which right you wish to exercise and give us enough detail to locate the information. You do not need to use a particular form, although POPIA Form 2 (objection) and Form 3 (correction or deletion) are available on request and through our PAIA manual.
We will ask you to verify your identity before we act, so that we do not disclose your information to someone else. We will request only what is needed for that purpose.
Our commitment | |
Timeframe | We will respond within one month of receiving your request. If the request is complex or you have made several requests, we may extend this by up to two further months, and we will tell you within the first month if we need to, together with the reason. |
Cost | There is no charge. We may charge a reasonable administrative fee, or refuse to act, only where a request is manifestly unfounded or excessive, in particular because it is repetitive. If we do, we will explain why and tell you how to challenge that decision. A prescribed fee may apply to a request made formally under the Promotion of Access to Information Act 2 of 2000, and we will tell you the amount before proceeding. |
If we cannot comply | We will tell you which exemption or limitation applies, why, and how to complain. |
Third parties | Where we have shared your information with others, we will tell them about a correction, erasure or restriction, unless that proves impossible or involves disproportionate effort. We will tell you who those recipients are if you ask. |
Systems updates | Changes to your information will usually be reflected across our systems within 15 business days. |
15. Children
Our services are directed at institutions and adult investors. We do not knowingly market to children and we do not offer online services directly to them.
Under POPIA, a child is a person under the age of 18, and we may not process a child’s personal information unless one of the grounds in section 35 applies — most relevantly, the prior consent of a competent person, or where processing is necessary to establish, exercise or defend a right or obligation in law. Under the UK GDPR the age at which a child can consent to an online service is 13; under the EU GDPR it is 16 unless a member state has set a lower age. Where these differ, we apply the higher threshold.
Personal information about a person under 18 may reach us where that person is a beneficiary, a fund member or a beneficial owner named in reclaim documentation. In those cases we process the information under the authority of the competent person or the institution acting for them, and we apply the same protections as for any other data subject.
If you believe we hold information about a child without a proper basis, please write to [email protected] and we will investigate and, where appropriate, delete it.
16. Complaints
If you are unhappy with how we have handled your personal information or your request, please tell us first at [email protected]. We take complaints seriously, we will acknowledge yours promptly, and we will aim to resolve it within one month.
You also have the right to complain to a supervisory authority, and you may do so without contacting us first.
Authority | When to approach them | Contact |
Information Regulator (South Africa) | Where the South African entity is the controller, or where the processing has a South African connection | Woodmead North Office Park, 54 [email protected] [email protected] inforegulator.org.za — complaints |
Information Commissioner’s Office (United Kingdom) | Where the UK entity is the | Wycliffe House, Water Lane, Helpline 0303 123 1113 ico.org.uk |
Your national data protection | Where you are in the European | You may complain to the authority in |
Personal Data Protection Commission (Singapore) | Where the Singapore entity is the controller, or where you are in Singapore | pdpc.gov.sg |
17. Access to information under PAIA
The Promotion of Access to Information Act 2 of 2000 gives you the right to request access to records held by us. Our PAIA manual explains what records we hold, how to make a request, the prescribed forms and fees, and how to appeal a refusal.
Our PAIA manual is available at https://globaltaxrecovery.com/wp-content/uploads/2026/08/GTR-PAIA-Manual-2026-Section-51.pdf and on request from
our Information Officer, whose details appear in section 1.4. A copy has been submitted to the Information Regulator as required.
18. Changes to this notice
We review this notice at least annually and whenever our processing changes materially. The version number and effective date appear on the cover page and at the foot of the published web page.
Where a change is material – for example a new purpose, a new category of recipient, or a change to the basis on which we process your information – we will bring it to your attention before it takes effect, by email where we hold your address and by a prominent notice on our website. We will not rely on your continued use of our website as agreement to a material change.
Version | Date | Summary of changes |
1.0 | 2016 | Original POPI and Privacy Policy |
1.1 | 19 June 2025 | Minor amendments |
2.0 | 02/06/2026 | Full rewrite. Controller identity and contact details added; lawful bases mapped to purposes; controller and processor roles distinguished; full rights schedule including restriction, portability and automated decision-making; transfer mechanisms specified; retention periods stated; breach notification added; cookie consent standard corrected; children’s age threshold corrected to align with POPIA; internal staff policy content removed; processing descriptions unrelated to GTR’s business removed |
19. Related documents
Cookie preferences – available on every page on globaltaxrecovery.com
Employee and Candidate Privacy Notice – available internally
Data Protection Policy (internal) – available internally