1. Introduction
Welcome to ABC Bank Plc ("the Bank", "we", "us", or "our"). We are committed to protecting and respecting your privacy in accordance with the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy explains what personal information we collect about you, why we collect it, how we use it, and your rights in relation to that information.
As a responsible financial institution, we recognise that the personal information you entrust to us is one of our most valuable assets. We maintain strict security standards and procedures to prevent unauthorised access to your information. When we say "personal data", we mean any information relating to an identified or identifiable living individual, whether it relates to your private, professional, or public life.
This policy applies to all personal data that we process in the course of providing our financial products and services, including through our website, mobile banking applications, telephone banking, branch services, and any other channels through which you interact with us. It also applies to prospective customers, job applicants, suppliers, contractors, and any other individuals whose personal data we may process in the course of our business activities.
We encourage you to read this policy carefully, along with any additional privacy notices we may provide on specific occasions when we are collecting or processing your personal data, so that you are fully informed about how and why we are using your information. Please contact us if you have any questions about our privacy practices.
2. Controller & Contact
For the purposes of data protection legislation, ABC Bank Plc is the data controller responsible for your personal data. As data controller, we are responsible for deciding how your personal data is held and used. We are registered with the Information Commissioner's Office (ICO) and maintain appropriate records of our processing activities in accordance with our legal obligations.
Contact Details
- ABC Bank Plc
- 100 King Street, London EC2V 8AH, United Kingdom
- support@abcintplc.com
Our Data Protection Officer (DPO) is responsible for overseeing questions in relation to this Privacy Policy and our compliance with data protection legislation. If you have any concerns or questions about how we handle your personal data, or if you wish to exercise your legal rights, you may contact our DPO directly using the contact details above, marking your correspondence for the attention of the Data Protection Officer.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues, if you are unhappy with how we have handled your personal data. We would, however, appreciate the chance to deal with your concerns before you approach the ICO and encourage you to contact us in the first instance.
3. Personal Data We Collect
We collect different types of personal data depending on the nature of our relationship with you and the products or services you use. This data is collected either directly from you when you provide it to us, or automatically through your interactions with our systems and services, or from third parties where permitted by law.
When you apply for, open, or use an account or service with us, you may provide us with the following categories of personal data:
- Identity and contact information: Full name, date of birth, gender, nationality, residential and postal addresses, email addresses, telephone numbers, and emergency contact details.
- Verification and identification documents: Passport details, driving licence, national identity card, biometric data, proof of address documents, signatures, and photographic identification required for anti-money laundering and know-your-customer checks.
- Financial information: Income, expenditure, credit history, assets, liabilities, tax residency status, tax identification numbers, national insurance numbers, and employment details including employer name and occupation.
- Product and service preferences: The specific products and services you apply for, use, or express an interest in, your communication preferences, and any additional information you choose to provide in application forms, correspondence, or surveys.
When you use our digital channels, we automatically collect certain information about your device, browsing actions, and patterns, including:
- Technical data: Internet protocol (IP) address, device type, operating system and platform, browser type and version, browser plug-in types and versions, time zone setting and location, unique device identifiers, and mobile network information.
- Usage data: Pages of our website that you visit, what you clicked on, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
- Location data: Information about your location based on your IP address or, where you have enabled location services on your mobile device, your precise geo-location data.
- Transaction data: Details of payments, transfers, deposits, withdrawals, standing orders, direct debits, card transactions, and any other financial activities conducted through your accounts or services with us.
We may receive personal data about you from various third parties and public sources as permitted or required by law:
- Credit reference agencies and fraud prevention databases: Credit history, adverse markers, fraud prevention flags, public register information such as electoral roll data, County Court Judgments (CCJs), Individual Voluntary Arrangements (IVAs), and bankruptcy records.
- Regulators, law enforcement, and government agencies: Information from HM Revenue & Customs, the Department for Work and Pensions, law enforcement agencies, and sanctions screening databases as part of our legal and regulatory obligations.
- Payment service providers and financial institutions: Information relating to incoming and outgoing payments, account verification information, and transaction details from other banks and payment networks.
- Publicly available sources: Information from Companies House, Land Registry, the electoral roll, and published news media where this is relevant to our business relationship.
We also collect and process special categories of personal data in limited circumstances, such as information about your health where this is necessary to assess your ability to operate an account, or information about your racial or ethnic origin, religious or philosophical beliefs, or sexual orientation where you have explicitly provided this and consented to its processing, or where we are required to do so by law.
4. Legal Bases
Under the UK GDPR, we must have a valid legal basis for each processing activity we carry out involving your personal data. We rely on one or more of the following legal bases, depending on the specific purpose for which we are processing your information. In most cases, we will rely on more than one legal basis for a given processing activity, as set out below.
Contractual Necessity
Processing is necessary for the performance of a contract between you and us, or to take steps at your request prior to entering into a contract. Examples include opening and maintaining your account, processing transactions, providing statements, and delivering the financial services you have requested.
Legal Obligation
Processing is necessary for compliance with a legal or regulatory obligation to which we are subject. Examples include anti-money laundering and counter-terrorism financing checks, sanctions screening, tax reporting obligations, record-keeping requirements, and responding to lawful requests from regulators or law enforcement.
Consent
Where you have given us clear, specific, informed, and unambiguous consent to process your personal data for a particular purpose. Examples include marketing communications where you have opted in, processing of special category data where explicitly provided, and cookie preferences where required by law. You can withdraw your consent at any time.
Legitimate Interests
Processing is necessary for the purposes of our legitimate interests, provided that these interests are not overridden by your fundamental rights and freedoms. Examples include detecting and preventing fraud, ensuring network and information security, improving our products and services, carrying out corporate restructuring, and managing our legal affairs.
Where we rely on legitimate interests as our legal basis, we conduct a Legitimate Interests Assessment (LIA) to ensure that we have considered and balanced the impact of the processing activity on you and your rights. A record of these assessments is maintained by our Data Protection Officer and is available on request.
Where we process special categories of personal data (sensitive personal data), we rely on additional conditions as set out in Article 9 of the UK GDPR, such as explicit consent where you have provided it, substantial public interest, employment, social security and social protection law, the establishment, exercise or defence of legal claims, or where the processing relates to manifestly made public personal data.
5. How We Use Data
We use your personal data for a wide range of purposes in the course of our relationship with you. Each purpose is linked to one or more of the legal bases described in the previous section. We do not use your personal data in ways that are incompatible with the purposes for which it was originally collected, unless we are legally permitted to do so and have notified you accordingly.
| Purpose | Categories of data used | Legal basis |
|---|---|---|
| Setting up and administering your accounts and services | Identity, contact, financial, verification | Contract · Legal Obligation |
| Processing transactions, payments, and transfers | Identity, contact, financial, transaction | Contract · Legal Obligation |
| Assessing applications for credit, loans, mortgages, and other lending products | Identity, contact, financial, credit history, employment | Contract · Legitimate Interests |
| Anti-money laundering, know-your-customer, sanctions screening, and fraud prevention | Identity, contact, financial, verification, transaction, credit history | Legal Obligation · Legitimate Interests |
| Providing customer support, responding to queries and complaints | Identity, contact, financial, transaction, correspondence | Contract · Legitimate Interests |
| Sending service-related communications, statements, and notices | Identity, contact, account information | Contract · Legal Obligation |
| Marketing and promoting products and services (where consented or permitted) | Identity, contact, product preferences, usage data | Consent · Legitimate Interests |
| Personalising your experience and improving our services | Identity, contact, usage, transaction, product preferences | Legitimate Interests |
| Managing our legal and regulatory obligations | All categories as required | Legal Obligation · Legitimate Interests |
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason that is compatible with the original purpose and is permitted by law. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so.
We may anonymise or aggregate your personal data so that it can no longer be associated with you, and we may use such anonymised or aggregated data for any lawful purpose, including statistical analysis, product development, research, and business planning. Where data is truly anonymised, it falls outside the scope of data protection legislation.
6. Sharing & Disclosures
We may share your personal data with third parties in certain circumstances, as described in this section. We require all third parties with whom we share your personal data to respect its security and to treat it in accordance with the law and the contractual protections we put in place. We do not sell your personal data to any third party under any circumstances.
Categories of recipients:
- Other companies within our group: Parent undertakings, subsidiary undertakings, and associated companies for administrative, operational, risk management, and compliance purposes, where necessary as part of our corporate structure.
- Credit reference agencies (CRAs): Experian, Equifax, TransUnion, and similar agencies for the purposes of assessing applications for credit, verifying your identity, and preventing and detecting fraud. Information held by CRAs may be shared with other organisations.
- Fraud prevention agencies and databases: Organisations that maintain shared databases of known fraud indicators to help detect and prevent financial crime and identity theft.
- Payment service providers and payment networks: Payment scheme operators, card issuers, acquirers, and other financial institutions involved in processing transactions such as CHAPS, BACS, Faster Payments, and card networks.
- Regulators, law enforcement, and government bodies: The PRA, FCA, ICO, HMRC, NCA, police forces, courts, and other competent authorities to comply with legal obligations, combat financial crime, and where required or permitted by law.
- Professional advisers and service providers: Auditors, solicitors, barristers, accountants, actuaries, consultants, IT service providers, data processing partners, cloud providers, printing and mailing houses, and debt collection agencies acting on our instructions.
- Insurers and assurance providers: Where you have purchased financial protection products through us or where we are required to disclose information under the terms of our own insurance arrangements.
- Potential assignees or transferees: In connection with any proposed sale, transfer, securitisation, or assignment of any of our rights, obligations, or assets, or in the event of a corporate reorganisation, merger, or acquisition.
Where we share your personal data with service providers who process personal data on our behalf as data processors, we have in place written data processing agreements that set out their obligations to process your personal data only on our documented instructions, to implement appropriate security measures, to assist us in responding to your rights requests, and to delete or return your personal data at the end of our contractual relationship.
We may also be required to disclose your personal data to third parties under compulsion of law, such as in response to a court order, subpoena, search warrant, or lawful request from a government or law enforcement authority with appropriate jurisdiction. We will disclose only such information as is strictly necessary to comply with the specific legal requirement, and we will, where permitted, endeavour to notify you before making such disclosure.
In addition, we may share your personal data with your nominated representatives, such as attorneys under a registered Lasting Power of Attorney, deputies appointed by the Court of Protection, executors or administrators of deceased estates, trustees, or any other person who provides satisfactory evidence of their legal authority to act on your behalf.
7. International Transfers
The processing described in this Privacy Policy may involve the transfer of your personal data to countries outside the United Kingdom. Where this occurs, we will ensure that such transfers are carried out in compliance with the UK GDPR and the Data Protection Act 2018, and that your personal data receives an adequate level of protection wherever it is processed.
Where we transfer personal data to a country that has been designated by the UK Secretary of State as providing an adequate level of protection for personal data, the transfer may proceed without further safeguards being required. For transfers to countries that do not benefit from an adequacy decision, we will implement appropriate safeguards to ensure the protection of your personal data.
Appropriate Safeguards We Use
- UK International Data Transfer Agreements (UK IDTAs): We use the UK IDTA issued by the Information Commissioner's Office as the basis for transfers to third countries where no adequacy decision applies, ensuring that data importers are bound by enforceable data protection obligations.
- Binding Corporate Rules (BCRs): For intra-group transfers within our corporate group, we may rely on binding corporate rules that have been approved by the ICO as providing adequate protection for personal data transferred outside the UK.
- Standard Contractual Clauses: Where appropriate, we may use standard contractual clauses approved or issued by the ICO, supplemented by transfer impact assessments to address any residual risks identified.
- Transfer Impact Assessments (TIAs): Prior to any international transfer of personal data, we conduct a documented assessment of the laws and practices of the recipient country, the recipient's data protection policies and procedures, and any additional technical and organisational measures that may be required to mitigate identified risks.
Our primary service providers and data processors are located in the United Kingdom and the European Economic Area. However, some of our cloud infrastructure and technology providers may process or store personal data in other jurisdictions, including the United States, Canada, and other countries. Where such transfers occur, we ensure that the appropriate safeguards described above are in place before any transfer takes place.
You have the right to obtain further information about the safeguards we have put in place in relation to international transfers of your personal data, and to receive a copy of the relevant contractual clauses, by contacting our Data Protection Officer using the details provided in Section 2 of this policy.
8. Retention
We will only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements, and to establish, exercise, or defend legal claims. Our retention periods are reviewed regularly and take into account the nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process the data, applicable legal requirements, and applicable limitation periods.
Illustrative Retention Periods
The retention periods described above are indicative minimums, and we may retain your personal data for longer periods where required or permitted by law, where we have an ongoing legitimate business need to do so, or where there is a reasonable expectation that litigation may be commenced. When determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, and the applicable statutory limitation periods.
At the end of the applicable retention period, your personal data will be securely disposed of by permanent deletion from our systems (including any back-ups) or by irreversible anonymisation, in accordance with our Information Security Policy and the ICO's guidance on secure disposal of personal information. Where it is not technically possible to delete your personal data, we will take all reasonable steps to prevent any further processing of the data other than for security or archiving purposes.
9. Your Rights
As a data subject, you have a number of legal rights in relation to the personal data that we hold about you under the UK GDPR. These rights are subject to certain exemptions and limitations, and not all rights apply in all circumstances. We will respond to all legitimate requests to exercise your rights within one calendar month of receipt, unless the request is particularly complex or numerous, in which case we may extend this period by a further two months. If we are unable to respond within the initial one-month period, we will notify you of the extension and the reason for the delay.
Right of Access
You have the right to obtain confirmation that we are processing your personal data and to request a copy of the personal data that we hold about you, together with supplementary information about our processing activities such as the purposes, categories of data, recipients, retention periods, and sources of the data.
Right to Rectification
You have the right to require us to correct any inaccurate personal data that we hold about you and to have incomplete personal data completed, taking into account the purposes of the processing, including by means of providing a supplementary statement.
Right to Erasure (Right to be Forgotten)
You have the right to request the deletion or removal of your personal data in certain circumstances, such as where the data is no longer necessary for the purposes for which it was collected, where we are processing unlawfully, or where you have successfully exercised your right to object to processing. This right is subject to exceptions where we need to retain the data for legal or regulatory purposes.
Right to Restriction of Processing
You have the right to request the suspension or restriction of our processing of your personal data in certain circumstances, such as where you contest the accuracy of the data, where the processing is unlawful, where we no longer need the data but you require it for legal claims, or where you have objected to processing pending our verification of our legitimate grounds.
Right to Data Portability
Where we are processing your personal data on the basis of your consent or for the performance of a contract, and the processing is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit that data directly to another controller, where technically feasible.
Right to Object
You have the right to object to our processing of your personal data where we are processing on the basis of legitimate interests or for the purposes of direct marketing. Where you object to processing based on legitimate interests, we will cease processing unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where we need the data for the establishment, exercise, or defence of legal claims.
Rights relating to automated decision-making and profiling
We may use automated decision-making processes, including profiling, in relation to creditworthiness assessments, anti-money laundering and fraud prevention checks, and certain pricing decisions. Where such processing produces legal effects concerning you or similarly significantly affects you, you have the right:
- Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless it is necessary for entering into or the performance of a contract, is authorised by law, or is based on your explicit consent.
- To obtain human intervention on our part, to express your point of view, and to contest the decision where such automated processing does take place.
- To be provided with meaningful information about the logic involved in the automated decision-making process, as well as the significance and the envisaged consequences of such processing for you.
How to exercise your rights
To exercise any of your rights under this section, please contact our Data Protection Officer in writing using the contact details provided in Section 2. We may require you to provide proof of your identity and sufficient information about your relationship with us to locate your records before we can respond to your request. We will not charge a fee for processing your request unless the request is clearly unfounded, repetitive, or excessive, in which case we may charge a reasonable administrative fee or refuse to respond to the request. If we refuse to respond to your request, we will provide you with reasons for our refusal in writing and inform you of your right to complain to the ICO.
Where we have based processing on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal. You can withdraw your marketing consent at any time by clicking the unsubscribe link in any marketing email, by updating your preferences through online banking, or by contacting us using the details in Section 2.
10. Cookies
Our website and mobile applications use cookies and similar technologies to distinguish you from other users, to provide you with the best possible experience when you visit our digital channels, and to improve our products and services. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your device if you agree. Cookies contain information that is transferred to your device's storage.
We use the following categories of cookies on our website: strictly necessary cookies, which are essential for the operation of our website and the provision of our services; functional and preference cookies, which enable us to remember choices you make and to provide enhanced, more personalised features; analytics and performance cookies, which help us to understand how visitors interact with our website and to measure and improve the performance of our services; and marketing and advertising cookies, which are used to deliver advertisements that are relevant to you and to measure the effectiveness of our marketing campaigns.
For full details of the cookies we use, their purposes, categories, and expiry periods, please refer to our dedicated Cookies Policy, which forms part of this Privacy Policy and is available at the Cookies Policy page of our website. You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our website may become inaccessible or may not function properly.
11. Children
Our products and services are not directed at children under the age of 13, and we do not knowingly collect or process personal data from children under 13 years of age. If you are under 13, please do not submit any personal data to us through our website, mobile applications, or any other channel. If we become aware that we have inadvertently collected personal data from a child under 13, we will take steps to delete that information from our systems as soon as reasonably practicable.
Where we offer products or services that are suitable for customers under the age of 18 (but who are at least 13 years of age), such as junior savings accounts, we will require the consent of the child's parent or legal guardian before we collect or process any personal data relating to the child. The parent or legal guardian will be required to provide appropriate evidence of their identity and their relationship to the child, and we will rely on the parent or guardian's consent as the legal basis for processing the child's personal data.
If you are a parent or legal guardian and you believe that your child has provided us with personal data without your knowledge or consent, please contact our Data Protection Officer using the details provided in Section 2 of this policy, and we will take prompt steps to investigate and, where appropriate, to delete any such information from our records. Parents and guardians should also be aware that where consent is withdrawn, this may affect the ability of the child to access or continue to use any products or services that are dependent on the processing of their personal data.
12. Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, to incorporate new or modified products or services, to address changes in technology or the regulatory environment, or to ensure the policy remains accurate and up-to-date. We reserve the right to make changes to this Privacy Policy at any time, without prior notice to you, provided that any such changes will be posted on this page and, where appropriate, notified to you by email, by a notice within our online and mobile banking services, or by such other means as we consider appropriate in the circumstances.
Any changes we make to our Privacy Policy in the future will be posted on this page, and where changes are material, we will take reasonable steps to bring the changes to your attention, such as by displaying a prominent notice on our website for a reasonable period, by sending you a secure message through online banking, or by writing to you at your last known address. The date of the latest version of this Privacy Policy will be displayed at the top of this page along with the date on which it was last updated.
We encourage you to review this Privacy Policy regularly and whenever you access our services, to ensure that you are aware of the most current version and any changes that may have been made. Your continued use of our products, services, website, or mobile applications after the posting of any changes to this Privacy Policy will constitute your acceptance of those changes. If you do not agree with the revised Privacy Policy, you should discontinue your use of our services and contact us to close any accounts you may hold with us, subject to the terms and conditions applicable to those accounts.
13. How to Contact Us
If you have any questions, comments, or concerns about this Privacy Policy or our processing of your personal data, if you wish to exercise any of your legal rights as set out in this policy, or if you would like to request further information about any aspect of our privacy practices, please do not hesitate to contact us. We are committed to resolving any privacy concerns you may have and will respond to all enquiries in a prompt and professional manner.
Contact Channels
Post
100 King Street, London EC2V 8AH, United Kingdom
Phone
Please refer to our contact page for telephone lines
Please mark correspondence for the attention of the Data Protection Officer. You may also be asked to provide proof of identity to verify your request.
If you are not satisfied with our response to your enquiry or complaint, or if you believe that our processing of your personal data has not been carried out in accordance with applicable law, you have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection. The ICO's contact details are:
Information Commissioner's Office (ICO)
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Telephone: 0303 123 1113
- Website: www.ico.org.uk
You can also use the ICO's website to report concerns directly and to obtain further information about your rights under data protection legislation. However, we kindly request that you allow us the opportunity to address your concerns first by contacting us directly before escalating the matter to the ICO, as we are committed to resolving any issues promptly and satisfactorily.