Privacy Policy

Your privacy is important to us

1. INTRODUCTION AND PURPOSE

1.1 PURPOSE

Pilbara Minerals Limited and its subsidiaries (together, PLS or we/us) are committed to protecting the privacy of individuals’ personal information in accordance with applicable law.

This Privacy Policy (Policy) sets out the principles that PLS will follow in collecting, using, holding, disclosing, and otherwise managing, personal information. It sets out rights in relation to personal information and how you can contact us.

1.2 WHO DOES THIS POLICY APPLY TO?

PLS and its directors, officers and employees must comply with this Policy.

2. COLLECTION OF PERSONAL INFORMATION

2.1 WHAT IS PERSONAL INFORMATION?

Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable, whether true or not and whether the information or opinion is recorded in a material form or not.

2.2 HOW WE COLLECT PERSONAL INFORMATION

PLS may collect personal information from you in a variety of ways, including when you work with us, apply for a position, attend our operational sites, use our website, invest in us, or have business dealings with us (e.g., customers, suppliers, contractors, investors and the like), and/or when you attend a company presentation (e.g., annual investor presentation).

Where possible, we collect personal information directly from you. This may occur when you interact with PLS in person, over the telephone or electronically (e.g. via websites, apps, social media posts, chats, telephone, emails and or SMS) or as otherwise permitted by law.

From time to time, we may also collect personal information about you from other sources. For example, we may collect information:

  • from your employer, where your employer is a contractor engaged by us and you may be mobilised to our mine site;
  • from your former employer or other nominated reference as part of pre-employment checks;
  • from publicly available sources; or
  • from credit reporting agencies or other third parties.

If we collect personal information about you from someone else, we will take reasonable steps to ensure that you are made aware that we have collected the information.

2.3 UNSOLICITED INFORMATION

From time to time, we may receive personal information that we have not requested (unsolicited personal information).

If we receive unsolicited personal information, we will consider if we could have collected that information directly from the relevant individual.

If we determine that:

  • we could have collected the personal information had it been requested, we may store, use, and disclose that information in accordance with this Policy; or
  • we could not have collected the personal information had it been requested; we will take reasonable steps to destroy or de-identify it as soon as practicable if it is lawful and reasonable to do so.
2.4 EXAMPLES OF INFORMATION WE MAY COLLECT

Examples of the kinds of personal information that PLS may collect, and hold could include:

  • name;
  • gender;
  • date of birth;
  • contact details (such as phone number, fax number, home address or email address);
  • photographic identification (e.g., drivers’ licence or passport);
  • employment history and academic qualifications;
  • licences and permits;
  • payroll information including banking, superannuation, and tax details;
  • credit card information;
  • health information; and
  • any other information (including background checks) to verify your identity or right to work.

We may collect information about you when you access our website. This can include (but may not be limited to) the following:

  • website usage information (server logs, your IP address etc);
  • date and time of your visit;
  • pages accessed and information downloaded;
  • name, email address and contact details.

PLS uses cookies and IP address tracking to administer its website and generally improve its content and service offering. You may set your browser to refuse cookies if you wish, although this may affect your browsing experience.

2.5 ANONYMITY AND PSEUDONYMITY

In most circumstances, it is impractical for people to communicate with us anonymously. However, where possible and practical, we will provide you with the option of not identifying yourself or using a pseudonym when communicating with us.

2.6 SENSITIVE INFORMATION

Sensitive information is a subset of personal information and includes:

  • information or an opinion (that is also personal information) about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, or criminal record;
  • health information about an individual;
  • genetic information (that is not otherwise health information);
  • biometric information that is to be used for the purpose of automated biometric verification or biometric identification; or
  • biometric templates.

We only collect sensitive information where you have consented to the collection, and it is reasonably necessary for one or more of our functions or activities.

3. USE OR DISCLOSURE OF PERSONAL INFORMATION

3.1 HOW WE USE YOUR PERSONAL INFORMATION

PLS uses personal information to carry out its business functions and activities, to comply with regulatory obligations and in connection with investigations or claims.

If required by law, we will ask for your express consent to use certain types of personal information and, where we do so, you may have the right to withdraw that consent.

We may collect, use, and store personal information for the legitimate business interests of PLS, including:

  • facilitating our internal business and mining operations, work management and maintenance of proper business records;
  • authenticating your identification to protect and maintain the security and safety of PLS-owned or operated premises, sites, systems, assets, and people;
  • maintaining our relationships with our employees, contractors, customers, and suppliers;
  • managing safety and security risks (including using CCTV), and our IT systems (including monitoring of electronic communications);
  • managing shareholder relationships inclusive of the purposes of undertaking share transactions, dividend payments and maintaining ongoing communications with our shareholders;
  • engaging in business sales or, acquisitions or joint ventures;
  • investigating or responding to any incidents, complaints, or grievances; or
  • to the extent that we are required, authorised, or permitted to do so by law.
3.2 DISCLOSURE OF PERSONAL INFORMATION

PLS will only disclose your personal information for:

  • the primary purpose for which it was collected;
  • any related purpose for which it would reasonably be expected to be used or disclosed;
  • a purpose required or permitted by law; or
  • a purpose for which you have provided consent.

Examples of instances where we may disclose personal information about you to third parties include disclosure to providers of services to PLS, government agencies, regulatory authorities, and our professional advisers.

3.3 INTERNATIONAL DISCLOSURE

Personal information collected by PLS may be transferred within its group of companies who require the information for the purposes in this Policy. An overview of PLS’ global corporate group and the countries in which PLS group companies operate can be found in PLS’ annual report.

In addition, some of our service providers, including data storage and technology service providers, may be located or use locations in a different country to where personal information was collected.

Where we are required to disclose information to a third party in a country which does not have substantially similar legal protections for personal information to the privacy laws applicable to PLS (each a privacy law), we will take reasonable steps to ensure that:

  • the recipient does not do anything that would breach the applicable privacy law; and
  • that information is protected in a similar manner to which it would otherwise have been under the applicable privacy law.
3.4 GOVERNMENT IDENTIFIERS

A government identifier of an individual is one that has been assigned by the government (e.g. an Australian tax file number). Subject to certain exemptions under applicable privacy law, PLS will not disclose identifiers assigned by government agencies or use those identifiers to identify your personal information.

4. STORAGE, SECURITY AND DESTRUCTION OF PERSONAL INFORMATION

4.1 STORAGE AND SECURITY

We will take reasonable steps to ensure the security of the personal information that is collected such that the personal information that we hold is protected from misuse, interference, loss, and from unauthorised access, modification, and/or disclosure.

As a company we store and retain information both in electronic and hard copy format.

We have implemented strict controls within our IT systems that restrict access to information databases, maintain our security firewalls and intrusion detection systems, and where applicable, encrypt our data.

No information that is transmitted over the internet can be guaranteed to be 100% secure. We will strive to protect users’ personal information however we cannot guarantee or warrant the security of information transmitted over the internet and users do so at their own risk.

If you have concerns about transmitting information over the internet, you should contact our Privacy Office to arrange a suitable alternative.

4.2 RETENTION

We will retain your data in line with good record-keeping practices. The relevant time period for retention of your information is determined in accordance with relevant legal and regulatory requirements, the purpose for which your personal information was collected, limitation periods for any claims that might arise and industry practice guidelines.

PLS will take reasonable steps to ensure that personal information it holds that is no longer necessary for the disclosed purpose is destroyed or permanently de-identified, subject to any legal obligation to keep the personal information for any required period.

4.3 DESTRUCTION OR DE-IDENTIFICATION

Personal information held in hard copy is shredded or disposed of through secured access recycling bin collection services.

Where possible, personal information held in electronic form will be ‘sanitised’ from the relevant hardware to completely remove the stored personal information. Where hardware cannot be sanitised, reasonable steps will be taken to destroy the personal information in another way.

Where it is not possible to irretrievably destroy personal information held in electronic format, we take reasonable steps to de-identify the personal information or put it beyond use.

5. ACCESS TO AND CORRECTION OF PERSONAL INFORMATION

At the request of an individual, PLS will, in most circumstances, provide access to any personal information that is being held by PLS about that individual. We will endeavour to do this within 30 days of the request.

There are certain circumstances where PLS will not provide an individual access to such personal information in accordance with applicable privacy law. These circumstances include where providing access would have an unreasonable impact to the privacy of others, where providing access would reveal commercially sensitive information about the organisation or where providing access would be unlawful.

We take reasonable steps to ensure that the information is up to date and complete. However, if you believe the information we hold about you is inaccurate or incomplete, you may request that we correct it.

An individual can seek access to, and update or correct, any personal information that is being held by us about that individual by contacting the Privacy Office directly in writing.

6. BREACH

Any breach of this Policy will be regarded as a serious matter and may result in, for employees, contractors and consultants, disciplinary action, including termination, or for third parties, appropriate legal action in accordance with applicable privacy law.

In certain circumstances, PLS will be required to notify affected individuals and relevant regulators about a data breach.

7. QUESTIONS OR COMPLAINTS

7.1 PROCEDURE

Should you have any questions or complaints relating to this Policy, you should direct them in writing to our Privacy Office, who can be contacted at privacy@pls.com.

If you are not satisfied with our handling of your complaint, you may lodge a complaint with your applicable privacy regulator.

7.2 INVESTIGATION AND OUTCOME

All complaints will be investigated by an appropriately qualified representative of PLS. We will endeavour to resolve your complaint as quickly as possible. We will notify you of the outcome of the investigation, including how we propose to resolve your complaint and what, if any, corrective measures we will implement.

8. COUNTRY SPECIFIC PROVISIONS

Additional privacy rules and restrictions relating to our management of your personal information may apply in some countries where we operate.

8.1 AUSTRALIA

This additional provision applies to all individuals that work for PLS and are based in Australia.

This Policy does not apply to information collected or otherwise obtained by PLS in relation to current and former employees and which relates directly to the employment relationship that exists, or existed, between us and our current and former employees.

8.2 BRAZIL

The additional provisions in this section apply to all individuals that work for PLS in Brazil and anyone whose personal data is collected in Brazil.

We may only collect sensitive data if we have express consent for a specific purpose or to comply with laws, exercise our legal rights, protect the physical safety of a person or for fraud prevention or for electronic system security and authentication processes.

You may exercise your legal rights by contacting our Brazilian Personal Data Protection Officer at privacy@pls.com to:

  • request confirmation of whether your personal information is being processed;
  • request the correction of your personal information;
  • request restrictions on the use of your personal information;
  • express opposition to or withdraw consent for the use of your personal information; or
  • request the anonymization, blocking, or deletion of your personal information.
8.3 SINGAPORE

The additional provisions in this section apply to all individuals that work for PLS and whose personal information is collected, used, or disclosed in Singapore.

References in this Policy to “personal information” means any data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which PLS has or is likely to have access.

PLS will collect, use, or disclose your personal information where necessary for the purposes of managing and administering your employment or appointment with PLS. These purposes may continue to apply for a reasonable period after the termination of your employment or appointment.

You may exercise your legal rights to the following by emailing our Privacy Office to:

  • withdraw your consent for us to process personal information by giving us reasonable notice;
  • receive or access your personal information as well as information about how your personal information was used or disclosed within a year before your request; and
  • correct any error or omission in your personal information.

9. PORTUGUESE TRANSLATION

A Portuguese version of this Policy will be made available on PLS’ website for convenience purposes only. In the event of any conflict, the English version of this Policy will prevail.

10. POLICY REVIEW

This Policy will be reviewed by the Board every two years and amended as required. The current version of this Policy will be made available on PLS’ website.