POPIA Compliance Policy

M.I.L. Mining Enterprises CC
Last Updated: 22nd August 2025

1. Purpose of this Policy

The Protection of Personal Information Act, 4 of 2013 (POPIA) promotes the constitutional right to privacy by protecting personal information from misuse, loss, or unlawful processing.
This policy sets out how M.I.L. Mining Enterprises CC (“the Company”) collects, uses, stores, shares, and safeguards personal information in compliance with POPIA and related legislation.

2. What is Personal Information?

Under POPIA, “Personal Information” means any information relating to an identifiable, living natural person or an identifiable juristic person, including but not limited to:

  • Basic identifying information: Name, email address, physical address, telephone number, location information.
  • Personal opinions or preferences.
  • Opinions of others about the individual.
  • Sensitive data:
    • Race, gender, sex, pregnancy, marital status, nationality, ethnic or social origin, color, sexual orientation, age.
    • Physical or mental health, well-being, disability.
    • Religion, culture, language.
    • Education history, employment history.
    • Financial, criminal, or credit information.
    • Biometric data and medical information.

3. Our Commitment

M.I.L. Mining Enterprises CC is committed to:

  • Protecting the personal information of employees, customers, suppliers, service providers, and all stakeholders.
  • Collecting and processing personal information lawfully and responsibly, in accordance with POPIA and other applicable laws.
  • Maintaining transparency regarding how we process personal information.
  • Implementing appropriate technical and organizational security measures to prevent unauthorized access, loss, or misuse of personal data.

4. Principles of Lawful Processing

The Company adheres to the Eight POPIA Conditions for Lawful Processing:

  1. Accountability – We accept responsibility for compliance with POPIA.
  2. Processing Limitation – We only process personal information when necessary, with consent, or as required by law.
  3. Purpose Specification – Personal information is collected for a specific, explicitly defined, and lawful purpose.
  4. Further Processing Limitation – Further processing will only occur if compatible with the original purpose.
  5. Information Quality – We take reasonable steps to ensure information is accurate, complete, and up to date.
  6. Openness – We maintain transparency in our data processing practices.
  7. Security Safeguards – Appropriate measures protect data from unauthorized access, alteration, or destruction.
  8. Data Subject Participation – Individuals have the right to access, correct, or delete their personal information.

5. Collection and Use of Personal Information

We collect personal information in the course of business for:

  • Providing goods and services.
  • Processing orders and accounts.
  • Credit applications and verification.
  • Marketing communications, only with consent.
  • Compliance with legal and regulatory obligations.

Information is collected through:

  • Direct interaction (e.g., forms, email, phone calls).
  • Our website, social media platforms, and mobile applications.
  • Third-party service providers (with lawful agreements in place).

6. How We Protect Your Information

  • Physical security measures for on-site records.
  • Electronic safeguards including encryption, firewalls, and secure access controls.
  • Restricted access to personal data on a need-to-know basis.
  • Employee training on POPIA compliance and data handling.

7. Sharing of Personal Information

We do not sell personal information.

We may share personal information only with:

  • Authorized employees and departments within the Company.
  • Third-party service providers under contractual obligation to maintain confidentiality.
  • Regulatory bodies, law enforcement, or legal entities, when required by law.

8. Data Subject Rights

Under POPIA, you have the right to:

  • Access your personal information held by us.
  • Request corrections or updates to inaccurate information.
  • Withdraw consent for optional marketing communications.
  • Request deletion of personal information, where legally permissible.

To exercise your rights, contact:

Email: admin2@milmining.co.za or stock@milmining.com

You may also lodge a complaint with the Information Regulator at:
Website: www.justice.gov.za/inforeg/

9. Retention of Personal Information

Personal information will be retained only as long as necessary for:

  • The purposes for which it was collected.
  • Compliance with legal, contractual, or regulatory obligations.
  • 10. Non-Compliance & Breach

Any data breach or suspected breach will be addressed immediately in line with POPIA requirements, including notifying the Information Regulator and affected data subjects where required.

11. Changes to This Policy

This POPIA Policy may be updated from time to time. Updates will be published on our website with the revised date displayed at the top.