Minco Projects

GDPR & POPIA Compliance

Last updated: 21 September 2026

Minco Projects, part of the EHL Engineering Group, is a South African mineral processing business. This page describes how we approach the Protection of Personal Information Act 4 of 2013 (POPIA) and, where it applies to a particular activity, the EU and UK General Data Protection Regulation (GDPR). It should be read with our Privacy Policy. It is a public compliance statement for clients, suppliers and website visitors — it is not legal advice.

How the two laws sit together

POPIA is the primary privacy law that applies to our processing of personal information in South Africa. It sets conditions for lawful processing, duties for responsible parties and operators, and rights for data subjects.

The GDPR applies when we process personal data of people in the European Economic Area or the United Kingdom, or when other GDPR territorial rules are triggered. In those cases we honour the additional GDPR standards that apply to that processing, including the relevant lawful basis, transparency and international-transfer rules.

In practice, most visitors to mincoprojects.com and most of our project counterparties are in South Africa and the wider African mining sector. We still design our practices so that a European or UK contact who enquires about our plants or services is treated lawfully.

Roles

For personal information processed in connection with this website and our own client and supplier relationships, Minco Projects acts as the responsible party under POPIA (and as controller under the GDPR, where the GDPR applies).

Companies in the EHL Engineering Group may process shared enquiry or project information as responsible parties in their own right or as operators acting on documented instructions, depending on the activity. Third-party hosts, analytics providers and professional advisers typically act as operators / processors.

Lawful processing

We process personal information only where a POPIA condition for lawful processing is met. Typical justifications for our B2B activities are that processing is necessary to conclude or perform a contract, required by law, or is in our or a third party's legitimate interests (for example, responding to a plant enquiry or securing this website) in a manner that does not override the data subject's rights.

Where the GDPR applies, we rely on the corresponding lawful bases: performance of a contract or steps at the request of the data subject prior to contract, compliance with a legal obligation, legitimate interests, and consent where we specifically request it (for example certain optional cookies or marketing).

We collect only information that is adequate, relevant and not excessive for the stated purpose, keep it accurate where we can, and do not keep it longer than needed.

Special personal information

We do not seek special personal information (such as health, biometric or religious data) through this website. If special information is required for a site access, occupational health or statutory reason, we process it only as POPIA allows and with additional care.

Data-subject rights

Under POPIA you may, subject to the Act's limits, request confirmation that we hold your personal information, request a copy or a description of it, ask us to correct or delete inaccurate or unlawfully held information, and object to processing in defined circumstances.

Where the GDPR applies you also have rights of access, rectification, erasure, restriction, objection, data portability, and the right not to be subject to certain automated decisions. We do not use automated decision-making or profiling that produces legal or similarly significant effects about website visitors.

Send requests to the contact details below. We will respond within the period required by the applicable law, after verifying your identity. We may refuse a request only on grounds permitted by law and will explain that decision.

Operators, processors and group companies

When we use an operator (processor) we remain responsible for ensuring that personal information is processed only for our instructions and with appropriate security. We expect operators to apply reasonable technical and organisational measures and to notify us of a security compromise where required.

Information may be shared within the EHL Engineering Group where that is necessary to respond to an enquiry or deliver a project. Group companies are expected to protect the information to an equivalent standard.

Security safeguards

POPIA requires responsible parties to secure the integrity and confidentiality of personal information. GDPR requires appropriate technical and organisational measures. We apply access controls, secure hosting, staff awareness and need-to-know sharing. Project and site information is handled according to the confidentiality terms of the relevant engagement.

Security compromises and breach notification

If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and affected data subjects as required by POPIA, and any other authority or individuals required under the GDPR where that law applies.

Cross-border transfers

Website hosting, email and analytics may involve processing outside South Africa. POPIA restricts transfers of personal information outside the Republic unless a listed justification applies — for example, the recipient is subject to a law, binding corporate rules or agreement that provides an adequate level of protection, or the transfer is necessary for a contract or with the data subject's consent.

Where the GDPR applies to a transfer from the EEA or UK, we use an approved transfer mechanism such as an adequacy decision or standard contractual clauses, together with a transfer assessment where required.

Records and accountability

We keep records of our processing activities to the extent appropriate for a business of our size and the nature of the information we handle. We review this page and our Privacy Policy when our practices or the law change.

Supervisory authorities

The lead authority for POPIA matters is the Information Regulator (South Africa): https://inforegulator.org.za. POPIA complaints may be sent to POPIAComplaints@inforegulator.org.za.

Where the GDPR applies, you may also lodge a complaint with the supervisory authority in your EU member state or, in the United Kingdom, the Information Commissioner's Office (https://ico.org.uk).

Contact

For GDPR or POPIA requests relating to Minco Projects and mincoprojects.com:

  • Minco Projects — EHL Engineering Group
  • The Woodlands Office Park, Building 32 First Floor, 20 Woodlands Drive, Sandton 2080
  • Telephone: +27 11 370 7400
  • Email: info@ehl.co.za
  • Website: https://mincoprojects.com