Privacy statement


About this statement

This External Privacy Statement explains how Rio Tinto collects, uses, stores and shares personal data about people who interact with us outside an employment, contractor or recruitment relationship.

It also explains the choices and rights you may have in relation to your personal data, and how to contact us if you have questions or concerns.
In this statement, “Rio Tinto”, “we”, “us” and “our” means the Rio Tinto Group company that you interact with, and other Rio Tinto Group companies where they are involved in handling your personal data.

For the purposes of applicable privacy laws, the Rio Tinto Group company that you interact with is usually the controller of your personal data. Other Rio Tinto Group companies may also be controllers where they decide why and how your personal data is used, either independently or together with the Rio Tinto company you interact with.

Where Rio Tinto uses service providers to process personal data on our behalf, those service providers act as processors or service providers, depending on the laws that apply.

We describe the types of service providers we use in the section “Who we share your data with”.

Who this statement applies to

This statement applies to people who interact with Rio Tinto outside an employment, contractor or recruitment relationship.

This may include:

  • visitors to Rio Tinto websites, microsites, online platforms, offices, sites, accommodation, operations or events;
  • customers, suppliers, business partners, professional advisers, investors, shareholders, analysts, media contacts, government or public officials, civil society organisations and other external stakeholders;
  • members of communities where Rio Tinto operates, seeks to operate, or has business or community relationships;
  • people who participate in community engagement, consultation, complaints, grievance, agreement, social performance, cultural heritage, land access, impact assessment, grant, sponsorship or community investment processes;
  • people who contact us, make enquiries, provide feedback, raise concerns or complaints, or otherwise communicate with Rio Tinto;
  • alumni, former employees, former contractors and other people who have a previous relationship with Rio Tinto, where they interact with us outside their former employment or contractor relationship;
  • people who live in, visit or use Rio Tinto-owned, managed or provided accommodation;
  • work experience students and their parents or guardians; and
  • children who attend Rio Tinto-organised events or activities with a parent or guardian.

When we refer to “you” or “your”, we mean the person whose personal data we collect and use.

This statement does not apply to personal data collected and used in connection with your employment, contractor engagement or application for a role at Rio Tinto. If you are a current or former employee or contractor, personal data collected and used in connection with your employment or engagement is covered by the Rio Tinto Employee Privacy Statement. 

If you are a candidate or applicant, including if you need to access or correct application information or submitted questionnaire responses, you should read the Rio Tinto Candidate Privacy Statement. If you are a former employee or contractor and need information about how your employment-related personal data is handled, or wish to exercise rights in relation to that data, you may contact AskE&C@riotinto.com or another contact point notified to you.

How this statement fits with other notices and policies

This statement applies alongside any other privacy notice, collection notice, consent notice, website terms, cookies notice, event notice, site access notice, supplier notice, community notice or local privacy notice that applies to your interaction with Rio Tinto.

If you are a current or former employee or contractor, the Rio Tinto Employee Privacy Statement applies to personal data collected and used in connection with your employment or engagement. This External Privacy Statement may apply to separate interactions you have with Rio Tinto outside that employment or contractor relationship, such as alumni activities, shareholder or investor interactions, community engagement, site visits, complaints, enquiries or other external interactions.

Depending on where you live, where you interact with Rio Tinto, or the services, websites, events, sites or platforms you use, additional privacy notices, local notices or addenda may also apply. These notices or addenda may provide extra information about how your personal data is collected, used, stored or shared in a particular location or context. They may also explain country-specific or region-specific requirements, including local legal bases, consent requirements, local identifiers, cross-border transfer requirements, service provider or delegate disclosures, retention rules, and rights available under local privacy laws.

For example:

  • if Rio Tinto provides you with electricity supply services, you should also read the Supplementary Privacy Notice for Electricity Supply Services;
  • if you are a California resident, you should also read the section “Additional information for California residents”; and
  • if you live in Mainland China, Mongolia, South Korea or another country where a local privacy notice or addendum applies, you should also read that local notice or addendum.

If there is any inconsistency between this statement and an additional privacy notice, local notice or addendum that applies to you, that additional notice, local notice or addendum will apply to the extent of the inconsistency.

You can contact aske&c@riotinto.com for information about any additional privacy notice, local notice or addendum that applies to you.

Key terms used in this statement

In this statement, “personal data” means information about an identified or identifiable person. In some countries, this is called “personal information” or “personally identifiable information”. We use “personal data” to include these terms.

In South Africa, personal data may also include information about companies or other legal entities where applicable law treats that information as protected.

Some types of personal data receive extra protection under privacy laws. We call this “sensitive data”. Sensitive data may include information about health, race or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, biometric data, sexual orientation, criminal convictions, and other information that receives special protection under applicable law.

“Applicable laws” means the privacy and data protection laws that apply to the way we collect and use your personal data.

“Privacy regulator” means the authority responsible for supervising or enforcing privacy or data protection laws in a particular country or region.

What personal data we collect

We collect personal data that we need to manage our interactions with you, operate our websites and sites, communicate with stakeholders, support community engagement, meet our legal obligations, keep people and sites safe, protect our rights and interests, and operate our business.

The types of personal data we collect will depend on who you are, how you interact with Rio Tinto, where you are located, the Rio Tinto site, event, service or platform involved, and the legal requirements that apply. We do not collect every type of personal data about every person.

The personal data we may collect includes:

  • contact and identity information, such as your name, address, email address, phone number, organisation, job title, signature, government-issued identifiers, passport details, vehicle registration details and other information used to identify or contact you;
  • business, stakeholder and relationship information, such as your role, organisation, business contact details, interactions with Rio Tinto, meeting records, correspondence, feedback, complaints, interests, preferences, public statements or positions relevant to your interaction with Rio Tinto, stakeholder mapping information, relationship-management records, and information relevant to managing our relationship with you;
  • community and social performance information, such as information about community membership, connection to land or location, cultural heritage matters, community interests, community concerns, engagement preferences, participation in community programs, grants, agreements, events or consultations, and information needed to understand and respond to community impacts;
  • site, event and access information, such as access logs, visitor records, registration records, attendance status, access alerts, restrictions or security flags, CCTV footage, photographs, audio or video recordings, dietary requirements, health and safety information, emergency contact details, drug and alcohol screening results where required, medical or fitness information where required, personal protective equipment requirements, and information needed to manage site access or event participation;
  • safety, security, complaints and incident information, such as information relating to safety events, security incidents, complaints, grievances, protests, campaigns, disputes, suspected misconduct, suspicious activity, fraud, criminal activity, threats, risk assessments, security assessments, publicly available online or social media information relevant to safety, security or risk management, or other activity that may affect the safety, security, rights, interests, operations, sites, assets, information or reputation of Rio Tinto, our people, communities or others;
  • digital and website information, such as IP address, device information, browser information, pages viewed, links clicked, forms completed, dates and times of visits, cookie information, online identifiers and information about your interaction with Rio Tinto websites, microsites, platforms or electronic communications;
  • financial, commercial and transaction information, such as payment details, banking information, shareholder or investor information, supplier or customer information, transaction records, contract information and due diligence information;
  • compliance and due diligence information, such as anti-bribery and corruption checks, sanctions screening, anti-money laundering checks, conflict of interest information, politically exposed person information, regulatory checks, beneficial ownership information and information needed to comply with legal, regulatory, governance or responsible business requirements; and
  • other information you provide to us, or that we collect where required or permitted by applicable law.

Sensitive data

Some personal data receives extra protection under privacy laws. We call this “sensitive data”.

Depending on who you are, how you interact with Rio Tinto, and the purpose of the interaction, we may collect sensitive data such as:

  • health or medical information, including information needed for site access, event participation, accommodation, emergency response, workplace or site safety, drug and alcohol screening, medical treatment, fitness assessments, or reasonable adjustments;
  • race, ethnicity, Indigenous status, language group, community membership, cultural heritage information, connection to land or location, religious or philosophical beliefs, or similar information, where this is voluntarily provided by you, relevant to community engagement, social performance, cultural heritage, agreement, consultation, legal, reporting or responsible business purposes, or otherwise permitted or required by law;
  • political opinions, political affiliations, public positions, campaign activity or similar information, where relevant and permitted by applicable law, including in connection with stakeholder engagement, public policy, government relations, community matters, legal obligations, security, risk management, complaints, disputes or investigations;
  • criminal convictions, offence information, allegations of unlawful conduct, suspected misconduct, fraud, suspicious activity, threats, security incidents or similar information, where relevant and permitted by applicable law;
  • biometric information, such as facial recognition information, fingerprints, voice information, photographs, video footage or biometric templates, where required or permitted for site access, identity verification, safety, security, emergency, investigation or legal purposes; and
  • other information that receives special protection under applicable law.

We only collect and use sensitive data where we have a lawful basis to do so. This may include your consent, where consent is appropriate and required, or another lawful basis such as meeting legal obligations, protecting health and safety, supporting community engagement, managing cultural heritage or agreement obligations, responding to emergencies, establishing or defending legal claims, preventing or detecting misconduct, fraud or crime, or protecting Rio Tinto’s legitimate interests.

We do not collect every type of sensitive data about every person. The sensitive data we collect will depend on the circumstances, the nature of your interaction with Rio Tinto, and the laws that apply.

Children and young people

We may collect personal data about children or young people in limited circumstances, such as where they participate in a Rio Tinto-organised event, community program, education program, work experience program, site visit or similar activity.

The personal data we collect may include contact details, parent or guardian details, school or organisation details, attendance information, photographs or video footage, emergency contact details, health or medical information, dietary requirements, accessibility requirements, permissions, consent forms, and information needed to support safety, participation or supervision.

Where required by applicable law, we will seek consent from a parent, guardian or another authorised person before collecting or using personal data about a child or young person.
We will only collect and use personal data about children and young people where it is appropriate for the relevant activity and in accordance with applicable law.

Why we use your data

We use your personal data to manage our interactions with you, operate our websites, sites and services, communicate with stakeholders, support community engagement, meet our legal obligations, keep people and sites safe, protect our rights and interests, and operate our business.

This may include information relating to site access, registration and attendance, safety events, security incidents, complaints, grievances, protests, campaigns, disputes, suspected misconduct, suspicious activity, threats, fraud, criminal activity, publicly available online or social media information, stakeholder or security risk assessments, or other activity that may affect Rio Tinto, our people, communities, sites, assets, operations, information, rights or interests.

The purposes for which we may use your personal data include the following:

Websites, communications and enquiries

We use personal data to operate Rio Tinto websites, microsites, online platforms and electronic communications, respond to enquiries, provide information you request, manage subscriptions, send updates, administer forms, understand how our websites and communications are used, and improve our online services.

Events, site access and accommodation

We use personal data to arrange and manage visits to Rio Tinto offices, sites, operations, accommodation and events. This may include managing registration, access, identity checks, travel, accommodation, health and safety requirements, emergency response, photographs or recordings, dietary or accessibility requirements, and site or event security.

Community engagement, social performance and cultural heritage

We use personal data to support community engagement, social performance, cultural heritage, land access, consultation, agreement-making, complaints and grievance processes, community programs, grants, sponsorships, impact assessments, and activities designed to avoid, reduce or manage impacts on communities.

This may include understanding community views, interests and concerns, managing relationships with community members and representatives, recording engagement activities, responding to questions, feedback, complaints or grievances, and meeting legal, regulatory, agreement, permit, licence, cultural heritage or responsible business requirements.

Stakeholder, investor, media and business relationships

We use personal data to manage relationships with shareholders, investors, analysts, customers, suppliers, business partners, professional advisers, media contacts, civil society organisations, government or public officials, regulators and other external stakeholders.

This may include communicating with you, managing meetings and events, responding to enquiries, providing updates, conducting due diligence, managing contracts or transactions, maintaining business records, and supporting investor relations, media relations, government relations, public policy, procurement, commercial, corporate affairs and external affairs activities.

Safety, security, complaints, incidents and risk management

We use personal data to identify, assess, manage and respond to health, safety, security, legal, regulatory, reputational, operational or business risks.

This may include information relating to site access, safety events, security incidents, complaints, grievances, protests, campaigns, disputes, suspected misconduct, suspicious activity, threats, fraud, criminal activity, or other activity that may affect Rio Tinto, our people, communities, sites, assets, operations, information, rights or interests.

We may use this information to protect people, communities, sites, assets, operations and information, prevent or respond to harm, manage incidents, conduct investigations, seek advice, make reports, and take steps to protect Rio Tinto’s rights, property and interests or the rights, property and interests of others.

Legal, regulatory, governance and compliance purposes

We use personal data to comply with laws, regulatory obligations, court orders, search warrants, subpoenas, government or regulator requests, sanctions, anti-bribery and corruption, anti-money laundering, tax, corporate governance, reporting, health and safety, environmental, cultural heritage, land access, community, procurement, contract and record-keeping obligations.

We may also use personal data to obtain professional advice, respond to legal claims, enforce agreements, manage disputes, support audits, conduct investigations, and prevent or respond to dishonesty, misconduct, fraud, crime, malpractice or serious improper conduct.

Business planning, reporting and improvement

We use personal data for business administration, management reporting, analytics, business improvement, stakeholder analysis, stakeholder mapping, community and social performance planning, website improvement, systems administration, risk management, audit, assurance, historical and archival purposes, and actual or proposed business transfers, acquisitions, divestments, investments, reorganisations or other changes to the Rio Tinto Group.

Where possible and appropriate, reporting and analytics will use aggregated or de-identified information.

We do not use every type of personal data for every purpose. The personal data we use will depend on who you are, how you interact with Rio Tinto, the relevant site, service, event, platform or relationship, and the laws that apply.

Our legal reasons for using your data

Privacy laws require us to have a legal reason for collecting, using and sharing personal data. The legal reason we rely on will depend on the purpose, the type of data, your location, the nature of your interaction with Rio Tinto, and the laws that apply.

Where applicable, we may rely on one or more of the following legal reasons:

Consent

We may rely on your consent where we ask for your clear agreement to use your personal data for a specific purpose.

When we ask for consent, we will explain what we are asking you to agree to. Depending on the circumstances, consent may be given by signing a consent form, clicking an opt-in button or link, selecting a yes/no option, choosing settings in a system or preference dashboard, responding to a request, answering yes to an oral request where permitted, or voluntarily providing information for a specific purpose.

Where we rely on consent, you may withdraw your consent. Withdrawing consent may affect our ability to provide a service, manage your participation in an event or program, respond to an enquiry, include you in communications, or carry out another activity that depends on your consent.

Contract or steps before entering into a contract

We may use your personal data where this is needed to enter into, perform or manage a contract with you or an organisation you represent.

This may include managing supplier, customer, commercial, shareholder, investor, accommodation, event, sponsorship, grant, community, land access, cultural heritage, consultation, agreement or other business relationships.

Where we use sensitive data in connection with a contract or relationship, we will also identify and rely on an additional legal reason where required by applicable law.

Legal obligations

We may use your personal data where this is needed to comply with laws, regulations, court orders, regulator requests or other legal processes.

This may include obligations relating to corporate governance, shareholder and investor relations, procurement, sanctions, anti-bribery and corruption, anti-money laundering, tax, health and safety, environment, cultural heritage, land access, communities, human rights, modern slavery, reporting, audit and record-keeping.

We may also use your personal data to meet legal and regulatory obligations, respond to legal claims, enforce agreements, conduct investigations, obtain professional advice, or protect our rights, property, people, communities, systems, sites, operations or assets.

Vital interests

We may use your personal data where this is needed to protect someone’s life or respond to an emergency.

This may include contacting you or your emergency contact, providing or arranging urgent medical care, responding to a site, event, accommodation, community or workplace incident, or managing an emergency affecting health, safety, security or wellbeing.

Legitimate interests

We may use your personal data where Rio Tinto, or a third party, has a legitimate business, operational, community, safety, security, legal or stakeholder-related reason to do so, and we have assessed that this is not overridden by your interests, rights or freedoms.

Our legitimate interests may include managing our business, operating our websites and sites, communicating with stakeholders, managing investor and shareholder relations, managing supplier and customer relationships, supporting community engagement and social performance, protecting our people, communities, premises, systems, sites, operations, information and assets, preventing and detecting misconduct, fraud or crime, maintaining network and information security, conducting investigations, responding to complaints or grievances, managing disputes or incidents, carrying out due diligence, preparing management reporting, conducting analytics, supporting audit and assurance, and managing business changes such as acquisitions, divestments or reorganisations.

When we rely on legitimate interests, we consider the purpose of the processing, whether the processing is necessary for that purpose, and whether your interests, rights or freedoms override our interests.

Sensitive data and specially protected data

Where we use sensitive data, criminal records information, biometric information, health information, political opinion information, cultural heritage information, Indigenous status information, or other specially protected data, we will only do so where permitted by applicable law and where any additional legal requirements are met.

Site access, monitoring, biometrics and location data

We may use monitoring, access control, identity verification, biometric, location or security tools where this is required or appropriate for safety, security, site access, emergency response, compliance, investigations, network and information security, or to protect Rio Tinto people, communities, visitors, sites, systems, information, assets and operations.

This may include visitor management systems, access logs, ID checks, badges, CCTV or other security camera footage, photographs, audio or video recordings, vehicle or accommodation access records, incident records, system logs, and location information where this is enabled, required for the interaction, or needed for safety, security, emergency, compliance or investigation purposes.

In some circumstances, we may use biometric information, such as facial recognition information, fingerprints, voice information, photographs, video footage or biometric templates. This may be used for purposes such as site access, identity verification, safety, security, emergency response, investigation, legal compliance, or protecting Rio Tinto people, communities, sites, systems, information, assets or operations.

We may also use monitoring information when investigating complaints, grievances, suspected misconduct, suspicious activity, fraud, criminal activity, security incidents, threats, protests, campaigns, disputes or other activity that may cause harm or affect Rio Tinto, our people, communities, sites, assets, operations, information, rights or interests.
Where required by applicable law, we will provide additional notice, seek consent, complete required assessments, or take other steps before using particular monitoring, biometric or location tools.

AI-assisted tools, profiling and automated decision-making

We may use AI-assisted tools, automated processes, data analytics or profiling to support some of the purposes described in this statement.

These tools may help us review information more efficiently, identify patterns or risks, support due diligence, manage safety and security, improve websites and services, understand stakeholder interactions, prioritise work, support workflow management, and support decision-making. They may generate scores, ratings, risk indicators, match indicators, rankings, recommendations, alerts or similar outputs.

The personal data used by these tools will depend on the purpose. It may include contact and identity information, website and device information, stakeholder and relationship information, community engagement information, site access information, safety and security information, complaints or incident information, due diligence information, compliance information, and other information described in this statement.

AI-assisted tools, automated processes, data analytics or profiling may be used to support activities such as:

  • website analytics, cookie analytics, audience measurement and service improvement;
  • stakeholder engagement, relationship management and communication planning;
  • community engagement, social performance, complaints and grievance management;
  • safety, security, incident response, risk assessment and site access management;
  • sanctions screening, anti-bribery and corruption checks, anti-money laundering checks, supplier due diligence, conflict checks and other compliance activities;
  • fraud prevention, misconduct detection, investigation support and legal or regulatory risk management; and
  • business reporting, analytics, audit, assurance, operational planning and business improvement.

Automated tools may help inform decisions or actions. Where an AI-assisted tool, automated process, data analytics process or profiling materially influences a decision or action that may significantly affect you, Rio Tinto will assess the process by reference to its practical effect, including whether human review and override are available in practice.

Where automated decision-making laws apply, we will provide information about the kinds of personal data used in automated decision-making and the kinds of decisions made or substantially assisted by automated decision-making.

Where required by applicable law, we will explain how the relevant tool or process works, how its output may be used, and any consent, opt-out, withdrawal, objection or review options available to you.

We will use human review where required by applicable law or where appropriate having regard to the nature and impact of the decision or action.

AI-assisted tools or automated processes used in connection with recruitment or candidate applications are addressed in the Rio Tinto Candidate Privacy Statement.

Cookies and similar technologies

Rio Tinto websites, microsites, online platforms and electronic communications may use cookies and similar technologies.

Cookies and similar technologies may help us operate our websites and platforms, remember your preferences, support security, understand how people use our websites and communications, measure the effectiveness of content, improve user experience, and support analytics and reporting.

These technologies may collect information such as IP address, device information, browser information, online identifiers, pages viewed, links clicked, forms completed, referring pages, approximate location derived from your IP address, and dates and times of visits.

Where required by applicable law, we will ask for your consent before using non-essential cookies or similar technologies.

You can manage cookies through your browser settings or through any cookie preference tool made available on the relevant website. More information may be provided in the applicable cookies notice, cookie preference tool or website privacy information.

How we collect your data

We collect most personal data directly from you. This may happen when you visit or use a Rio Tinto website, microsite or online platform, contact us, make an enquiry, attend a meeting or event, visit a Rio Tinto office, site, operation or accommodation, complete a form, participate in a community program or consultation, provide feedback, raise a complaint or grievance, enter into a contract or other arrangement with us, or otherwise interact with Rio Tinto.

We may also collect personal data from the systems, sites and services you use when interacting with Rio Tinto. This may include websites, online platforms, electronic communications, access systems, visitor management systems, security systems, accommodation systems, event systems, CCTV, site access tools, and other tools used to manage safety, security, compliance, engagement or business operations.

In some circumstances, we may infer or generate personal data about you from other information we hold. For example, we may generate information through stakeholder engagement records, relationship-management records, community engagement records, complaints or grievance processes, due diligence checks, incident reports, risk assessments, security assessments, investigations, reporting, analytics, system logs, website analytics, publicly available online or social media information, or other business records.

We may also collect personal data from other people or organisations where permitted by applicable law. Examples may include Rio Tinto Group companies, joint venture partners, suppliers, customers, business partners, community representatives, event organisers, professional advisers, regulators, public authorities, law enforcement bodies, courts, security providers, public databases, media sources, social media platforms, publicly available websites, or other third parties.

If a local Rio Tinto entity, local privacy notice or addendum applies to your interaction with Rio Tinto, we will provide additional information where required by applicable law.

If you do not provide data or withdraw consent

We do not collect or use every type of personal data or sensitive data about every person. The information we need will depend on who you are, how you interact with Rio Tinto, the relevant site, service, event, platform or relationship, and the laws that apply.

In some cases, we need certain personal data to respond to your enquiry, manage your participation in an event or program, give you access to a site, office, accommodation or platform, manage a contract or relationship, meet our legal obligations, support community engagement, protect health, safety and security, or operate our business.

You do not have to provide personal data unless you choose to do so or are required to do so by law, by a contract or arrangement, or by requirements that apply to the site, event, platform, program or relationship. However, if you choose not to provide information that we need, this may affect our ability to interact with you, provide a service, respond to an enquiry, allow you to access a site or platform, manage a relationship, include you in a program or event, meet legal or regulatory requirements, or protect health, safety and security.

Where we rely on your consent to collect, use or share personal data, including sensitive data, you may withdraw your consent at any time. You can do this by contacting aske&c@riotinto.com, using a button or preference setting where one is provided, or using another method we tell you about.

Withdrawing consent will not affect the lawfulness of any processing that occurred before the withdrawal. However, it may affect what we can do after you withdraw consent. For example, it may affect our ability to send you communications, include you in an event or program, provide a service, process a request, or continue an activity where consent is required.

If you give us someone else’s data

Sometimes you may give us personal data about another person. For example, you may provide details for an emergency contact, family member, representative, colleague, employee, contractor, community member, event attendee, visitor, beneficiary, referee, complainant, witness, or someone else connected with your interaction with Rio Tinto.

Before you give us another person’s personal data, you should make them aware that:

  • you are providing their personal data to Rio Tinto;
  • Rio Tinto will collect, use, store and share their personal data as described in this statement and any other privacy notice that applies; and
  • they can contact us if they have questions about how we handle their personal data.

Where required by applicable law, you should also obtain their consent before providing their personal data to us.

When we collect your data from others

Most of the personal data we collect comes directly from you. Sometimes, however, we may collect personal data about you from other people or organisations where this is permitted by applicable law.

For example, we may collect personal data from Rio Tinto Group companies, joint venture partners, service providers, event organisers, community representatives, business partners, suppliers, customers, professional advisers, regulators, government agencies, public authorities, law enforcement bodies, courts, health and medical professionals, security providers, media sources, public databases, publicly available websites, social media platforms, or other third parties.

We may do this where it is not reasonably practical to collect the information directly from you, where we need the information for engagement, verification, safety, security, legal, compliance, investigation, community, operational or business purposes, or where we consider it necessary to protect your interests, Rio Tinto’s interests, or the interests of another person.

Who we share your data with

We may share your personal data, including sensitive data where permitted, for the purposes described in this statement and where we have a legal reason to do so.

We may share your personal data with:

  • Rio Tinto Group companies and related entities, including other Rio Tinto companies, affiliates and, where relevant, managed or non-managed joint venture partners;
  • people who need the information for business, operational, engagement, safety, security, legal, compliance, community or stakeholder-related purposes, such as Rio Tinto employees, managers, agents, contractors, site personnel, security personnel, community engagement personnel, corporate affairs personnel, investor relations personnel and other people who need access to perform their role or provide services to us;
  • service providers who support our websites, sites, events, accommodation, stakeholder engagement, community engagement, complaints and grievance processes, shareholder and investor relations, supplier and customer management, due diligence, security, investigations, communications, analytics, audit, assurance and business administration;
  • technology, systems and security providers, such as providers of network services, cloud storage, hosting, IT support, website platforms, analytics tools, access systems, visitor management systems, CCTV, security and monitoring equipment;
  • professional advisers and insurers, such as legal advisers, auditors, financial advisers, consultants, brokers, insurers, health and medical advisers, community advisers, cultural heritage advisers, environmental advisers, security advisers and other business or specialist advisers;
  • operational partners and business service providers, such as facilities providers, maintenance providers, transport providers, accommodation providers, event providers, travel providers, medical providers, emergency response providers and other parties that help our sites, events, services and operations function;
  • community representatives, agreement parties, traditional owner groups, landholders, cultural heritage bodies or other community-related parties, where relevant and permitted by applicable law;
  • regulators, government agencies, courts, law enforcement bodies and other public authorities, where required or permitted by law, court order, regulatory process or legal obligation;
  • shareholders, investors, purchasers, lenders or other parties involved in corporate transactions, reporting, governance or business change, such as a proposed or actual acquisition, divestment, investment, debt or loan sale, business transfer, restructuring or change in ownership; and
  • other recipients with your permission or where required or permitted by applicable law.

In some jurisdictions, we may disclose information to law enforcement or regulatory bodies without a formal notice where we are legally permitted to do so, for example in connection with suspected serious crimes or offences.

We will only share personal data where it is appropriate for the relevant purpose and subject to applicable legal requirements.

International transfers

Rio Tinto operates globally, so your personal data may be transferred to, stored in, or accessed from countries outside your home jurisdiction.

For example, your personal data may be accessed by Rio Tinto Group companies, affiliates, joint venture partners, service providers, advisers or other recipients involved in business administration, website operation, stakeholder engagement, community engagement, site access, safety, security, compliance, legal, technology support, reporting, audit, assurance or other purposes described in this statement.

Where we transfer personal data internationally, we will do so in accordance with applicable law. Depending on the circumstances and the laws that apply, this may include transferring personal data where:

  • you have given consent, where consent is required;
  • the transfer is subject to appropriate safeguards, such as standard contractual clauses or other contractual, technical and organisational protections;
  • the transfer is to a country recognised by the relevant privacy regulator as providing adequate protection for personal data; or
  • the transfer is otherwise permitted under applicable law.

Where required, we put in place safeguards designed to protect personal data transferred internationally. These may include contractual obligations requiring recipients to protect personal data, and technical and organisational security measures designed to keep personal data secure.

How we protect your data

We use technical, organisational and physical measures designed to protect personal data from unauthorised access, use, disclosure, alteration, loss or destruction.

These measures may include access controls, system security controls, monitoring, encryption or other protective technologies where appropriate, confidentiality obligations, staff training, internal policies, vendor due diligence, contractual protections, and physical security measures.

We limit access to personal data to people who need it for their role or to provide services to us, and we require service providers to protect personal data they handle on our behalf.

No system or method of transmission is completely secure. However, we take steps designed to protect personal data in accordance with applicable laws and Rio Tinto security requirements.

How long we keep your data

We keep personal data only for as long as we need it for the purposes described in this statement, or for as long as we are required or permitted to keep it by law.

How long we keep particular records will depend on the type of information, the reason we collected it, who you are, how you interact with Rio Tinto, the relevant site, service, event, platform or relationship, applicable legal or regulatory requirements, and whether the information is needed for engagement, community, safety, security, legal, audit, investigation, dispute, insurance, reporting, compliance, corporate governance or business purposes.

We may keep personal data after our interaction with you ends where this is required or permitted by law, including to comply with record-keeping obligations, respond to queries, manage legal claims, manage complaints or grievances, support community or stakeholder engagement, protect health, safety or security, maintain business records, or protect Rio Tinto’s rights, property and interests or the rights, property and interests of others.

Where we no longer need personal data, we will delete it, de-identify it, or securely archive it where retention is required or permitted by applicable law and Rio Tinto retention requirements.

If you are a former employee or contractor, employment-related records will be retained in accordance with the Rio Tinto Employee Privacy Statement, applicable law and Rio Tinto retention requirements.

Your rights and how to exercise them

Depending on where you live, where you interact with Rio Tinto, and subject to applicable laws, you may have rights in relation to your personal data. These rights are not absolute, and exceptions may apply.

Your rights may include the right to:

  • be informed about how we collect and use your personal data;
  • request access to, or a copy of, personal data we hold about you;
  • ask us to correct personal data that is inaccurate, incomplete or out of date;
  • ask us to delete personal data in certain circumstances;
  • ask us to restrict how we use personal data in certain circumstances;
  • object to certain uses of your personal data, including certain automated decision-making or profiling where applicable;
  • receive personal data you have provided to us in a reasonable format, where applicable;
  • withdraw consent where we rely on consent, without affecting the lawfulness of processing before consent was withdrawn;
  • ask for information about safeguards used for international transfers, where applicable;
  • ask for human review or further information about automated decision-making, where applicable; and
  • nominate another person to exercise your rights in the event of your death or incapacity, where applicable.

To make a request, contact AskE&C@riotinto.com or use another contact point or process we tell you about.

If your request relates to a job application, candidate profile or submitted recruitment questionnaire response, please use the contact point in the Rio Tinto Candidate Privacy Statement. If your request relates to employment-related personal data held about you as a current or former employee or contractor, you may contact AskE&C@riotinto.com or another contact point notified to you.

We may need to verify your identity before responding to a request. This helps us protect personal data and prevent unauthorised access or fraudulent requests.

We will respond to your request within a reasonable period and in accordance with applicable law. Where possible, we aim to respond to access and correction requests within 30 calendar days. If we cannot comply with your request, or can only comply in part, we will explain why, unless we are legally prevented from doing so.

Where local law requires additional information about your rights, including access, correction or automated decision-making transparency rights, we will provide that information in this statement, a local privacy notice, an addendum, or another notice made available to you.

Complaints

If you have a question, concern or complaint about how we handle your personal data, please contact aske&c@riotinto.com or the data protection officer responsible for your country or region, if applicable.

We will review your concern and respond in accordance with applicable law.

If you are not satisfied with our response, you may have the right to make a complaint to the privacy regulator or data protection authority in your country or region.

UK data protection complaints

If UK data protection law applies to the way we handle your personal data, you may make a data protection complaint to us if you think we have not complied with applicable data protection law. You can do this by contacting AskE&C@riotinto.com or another contact point notified to you.

We will acknowledge receipt of your complaint within 30 days of receiving it. We will take appropriate steps to consider and respond to your complaint, including making enquiries where needed, keeping you informed, and telling you the outcome without undue delay.

You also have the right to complain to the UK Information Commissioner’s Office. Where applicable, you may be asked to raise your complaint with us first so that we have an opportunity to consider and respond to it.

Additional information for California residents

If you are a California resident, additional privacy rights and disclosures may apply to the personal data we collect and use about you.

Where applicable, these rights and disclosures may include information about:

  • the categories of personal data we collect;
  • the categories of sources from which we collect personal data;
  • the purposes for which we collect, use, disclose or otherwise process personal data;
  • the categories of third parties or other recipients to whom we disclose personal data;
  • how long we keep personal data;
  • whether we sell or share personal data as those terms are defined under California law;
  • how we use or disclose sensitive personal data;
  • your rights to know, access, correct, delete, opt out, limit certain uses of sensitive personal data, and not be discriminated against for exercising your rights; and
  • how you or your authorised representative may submit a privacy request.

We will provide any California-specific information required by applicable law in this statement, a California privacy notice, a local notice, an addendum, or another notice made available to you.

Additional information for Mainland China, Mongolia, South Korea and other local requirements

If you live in Mainland China, Mongolia, South Korea or another country where local privacy requirements apply, additional privacy notices, local notices or addenda may also apply to your personal data.

These notices or addenda may provide additional information about:

  • the Rio Tinto entity or entities responsible for handling your personal data;
  • the categories of personal data or sensitive data collected;
  • the purposes and legal reasons for using personal data;
  • local consent requirements;
  • local identifiers or registration details;
  • service providers, delegates, entrusted parties or other recipients;
  • international transfers;
  • retention requirements;
  • local rights and how to exercise them; and
  • local privacy regulator or complaint routes.

Where required by applicable law, we will provide this information in this statement, a local privacy notice, an addendum, or another notice made available to you.

If there is any inconsistency between this statement and a local notice or addendum that applies to you, the local notice or addendum will apply to the extent of the inconsistency.

Changes to this statement

We may update this statement and any additional or local privacy notices from time to time.

The current version of this statement will be made available online. Where we publish an updated version, the updated version will replace the previous version from the effective date stated in the updated statement.

You should review this statement periodically to understand how we collect, use, store and share personal data.

Where required by applicable law, we may also take additional steps to notify you of material changes or provide you with a new or updated notice.

If we want to use personal data we have already collected for a new purpose that is not compatible with the purpose we originally told you about, we will provide additional information in accordance with applicable law and, where required, seek your consent before using the personal data for that new purpose.

Translations

Translations of this statement may be available on request.

If there is any inconsistency between a translated version of this statement and the English version, the English version will apply, unless applicable law requires otherwise.

Rio Tinto Group

In this statement, “Rio Tinto Group” means all companies or businesses wholly or majority owned or managed by Rio Tinto plc or Rio Tinto Limited, whether directly or indirectly.

Date and version

Version 2.0

Effective date: 17 July 2026

Note: this privacy statement was prepared with the assistance of enterprise AI tools, subject to human review, oversight and approval by Rio Tinto personnel. Rio Tinto remains responsible for the content of the statements and the decisions reflected in them.

Cookies 

We may use Cookies and similar technologies that aim to collect and store information when you visit our Websites or microsites. You can control and manage your Cookie preferences by changing the settings on your browser. However, if you disable Cookies and similar technologies, some features may not work as intended. For more detailed information about the specific Cookies and similar technologies we use and your choices, please see below. For a list of the different types of Cookies and similar technologies used on our Websites, visit the preference/settings in the Cookie banner of the Website you are viewing. 

Cookies are a standard feature of websites that allow us to store small amounts of data on your computer about your visit to and use of the Services. Cookies help us learn which areas of the Services are useful and which areas need improvement. For this purpose, we also use technologies similar to Cookies, such as Flash Local Shared Objects (also known as Flash Cookies) or pixel tags, as further detailed below.

Strictly Necessary Cookies: These enable you to navigate our Websites. Without these absolutely necessary Cookies, our Websites will not perform as smoothly for you as we would like it to.

Functional Cookies: These collect information about your choices and preferences, and allow us to remember language or other local settings and customize for you accordingly.

Performance Cookies: These are analytics Cookies which collect information about your use of our Website and enable us to improve the way it works. They can show us which are the most frequently visited pages on our Websites. 

Targeting and Social Media Cookies: These Cookies collect information about your activities on our Websites (or other Sites) to provide you with targeted advertising. Social media Cookies collect information about social media usage.

Google Analytics: Some of our Websites, may use Google Analytics services, as provided by Google, Inc. (“Google”), which uses Cookies and similar technologies to collect and analyse information and report on activities and trends. This service may also collect information regarding the use of other Websites, applications and online resources. You can learn about Google’s practices by going to google.com/technologies/partner-sites, and you can opt out by downloading the Google Analytics opt-out browser add-on, available at tools.google.com/dlpage/gaoptout.

Your Choices About Our Use of Cookies and Similar Technologies: Depending on the applicable law of your jurisdiction (such as the EU/EEA, or the UK), we may ask for your Consent for placing Cookies on your device, with the exception of strictly necessary Cookies. You can change your settings for Cookies and similar technologies by visiting the preference/settings in the Cookie banner of the Website you are viewing.

In addition, you can also avoid Cookies being placed on your device, by configuring your browser settings. Please refer to allaboutcookies.org for information on commonly used browsers. Please note, however, if some Cookies are disabled, not all features of our Websites function as intended.

Contact information and complaints

If you have any questions or concerns regarding our use of your Personal Data, or if you wish to exercise any of your rights described in this Privacy Statement, please contact us by emailing aske&c@riotinto.com, or by contacting the data protection officer responsible for your country or region, if applicable. You also have the right to lodge any complaints you may have regarding Rio Tinto’s processing of your Personal Data to us or the privacy regulator for your country or region.

California residents

If you have any questions or concerns regarding our use of your Personal Information, or if you wish to exercise any of your rights under CCPA, please contact us by emailing aske&c@riotinto.com, or by phoning our free toll number +18008726729.  

Other important information

This Privacy Statement may be changed over time. Please visit this page regularly for possible changes. 

Our Websites and microsites may contain links to Websites or applications we do not own or control. Our Privacy Statement does not apply to those. Please read the privacy statements on those Websites or applications if you would like to find out how they collect, use, process, and disclose your Personal Data. 

Any translation is for reference only, and in the event of any conflict, the English version will prevail.