GIB

TERMS OF WEBSITE USE

PRIVACY NOTICE

 

-    First Publication date: 27 December 2022
-    Last updated on: 27 May 2024

 

Dear Customer,

 

Gulf International Bank - Saudi Arabia (“GIB”, “GIB KSA”, “Bank”, "We”, “Us”, or “Our”) seeks to protect the privacy of your information. This privacy notice (“Privacy Notice” and/or “Notice’) (together with our Terms and Conditions of Use and any other documents referred to on it) explains the basis on which any Personal Data (as defined below) which We collect from you, or that you provide to Us, will be processed by Us. 

 

Please read the following provisions carefully to understand our views and practices regarding your Personal Data (as defined below) and how we will treat it.

1. OVERVIEW AND PURPOSE

Gulf International Bank - Saudi Arabia , a Saudi Closed Joint Stock Company registered in the Kingdom of Saudi Arabia with Unified Number 7001399042 and Commercial Registration Number 2052001920, licensed by the Saudi Central Bank (“SAMA”) to operate as a bank in the Kingdom of Saudi Arabia with banking license number 2007 whose principal address is at PO Box 93, Al Khobar 31952, national address number 5515 Kingdom of Saudi Arabia is committed to safeguarding your Personal Data We maintain physical, electronic and procedural safeguards that comply with applicable laws and regulations to secure your information from unauthorised access and use, accidental or unlawful alteration and destruction; and other unlawful or unauthorised forms of processing. We engage in the continuous training of Our employees in the proper management of Personal Data. 


At GIB, We take data privacy very seriously and we provide our customers with all necessary data security to protect such Personal Data from unauthorised access. We require any third parties who carry out any work on Our behalf to comply with appropriate compliance standards to protect your information.  Accordingly, this Privacy Notice reflects the requirements outlined by the Saudi Personal Data Protection Law (“KSA PDPL” or “Law”).

 

The purpose of this Notice aims to help you understand the nature of the personal data we collect, use, store, share or process during and after your interaction with us to offer you more personalised products and services, and the legal bases on which we do so in the Kingdom of Saudi Arabia. Further, this Notice explains the various measures we have in place to protect the security of your personal data and minimise the potential for its unauthorised use, disclosure or destruction.

2. DEFENITIONS

 

PERSONAL DATA:

means any data – of whatever source or form – that would lead to the identification of the individual specifically or make it possible to identify him or her directly or indirectly, including name, personal identification number, addresses, contact numbers, license numbers, records, personal property, location data, bank account and credit card numbers, fixed or moving pictures of the individual, and other data of personal nature.

 

SENSITIVE DATA:

means any personal data that includes a reference to an individual's ethnic or tribal origin, or religious, intellectual, or political belief, or indicates his membership in nongovernmental associations or institutions, as well as criminal and security data, biometric data, genetic data, credit data, health data, and data that indicates that both parents of an individual or one of them is unknown.
 

3. THE INFORMATION WE COLLECT

We will limit the collection and use of customer information to the minimum We require to deliver Our services to Our customers, which includes advising Our customers about Our products, services and other opportunities, and to administer Our business. 

4. HOW DO WE COLLECT INFORMATION?

We may collect information from a range of sources and it may relate to any of Our products or services We currently provide or may have provided in the past.
We collect your Personal Data when:

•    you open an account or perform transactions such as make deposits or withdrawals from your account, payment history and transactions records
•    you apply for a loan or use your credit or debit card
•    you seek advice about your investments
•    you seek information from Our customer service provider, information concerning complaints and disputes
•    We seek information about your credit history from credit bureaus
•    you provide account information such as your personal details e.g., name, gender, date and place of birth; contact information such as address, email address, and mobile numbers, provide your employment information
•    you provide information concerning your identity e.g., photo ID, passport information, national ID card and nationality
•    you use your login credentials for online banking and mobile banking apps and We collect information about your computer (or mobile device), including collecting your IP address, operating system and browser type. We use this information for system administration or for Our own commercial purposes.
•    We conduct necessary investigations i.e., due diligence checks, and anti-money laundering/counter fraud and terrorism checks and obtain information that We need to support Our regulatory obligations, e.g., information about transaction details, detection of any suspicious and unusual activities.

5. HOW WE USE YOUR INFORMATION

•    We will only use your information when you have provided your consent or when we are required by the law to do so. If you do refuse to provide us with your consent (where applicable) to use and / or share your personal data, due to regulatory restrictions, We may not be able to provide you with the products or services for which your consent is being requested.
•    We use the information We collect to provide customers with excellent products and services, to manage Our business and to offer an enriched and enhanced customer experience.
•    We make appropriate use of your data to manage transactions, respond to your requests, and to provide you with more relevant products and services.
•    We use your information to deliver Our products and services, carry out your instructions, and provide online banking, mobile banking and other online product and services.
•    We use this information to detect and prevent financial crimes including fraud, financing for terrorism and money laundering, this is to ensure security and business continuity.
•    We will use your information to meet Our compliance obligations, to comply with laws and regulations and to share with regulators when absolutely necessary.
•    Where We have your consent, we may use Personal Data We have about you such as your email address, mobile number, mailing address to deliver advertising to you directly or on Our websites, provide updates on special deals and offers that might interest you.
•    We may send you general announcements or important news about your account.
•    We may need to record conversations you have with Us including phone calls, face-to-face meetings, letters, emails and any other kinds of communication. These recordings may be used to check your instructions to Us and improve on Our product and service delivery.
•    We may collect information about your computer (or mobile device), including where available your IP address, operating system and browser type, for system administration or for Our own commercial purposes. This is statistical data about Our users' browsing actions and patterns, and does not identify any individual.

 

6. WHO WE SHARE YOUR INFORMATION WITH?

At GIB, We, in efforts to provide you with excellent products and services, may need to outsource our product delivery, this will be done in line with relevant regulations and laws. We may share your personal data with internal parties (e.g., GIB entities and/or affiliates) and external parties (e.g., regulatory authority, service providers, third parties, etc.) for processing to the extent necessary to fulfil the purposes described in this Notice
We may also share your information where We have a public or legal duty to do so, when We need it to conclude regulatory reporting and when We have requested and received your permission to share it. In some circumstances where the law permits, this will involve us transferring your personal data outside the Kingdom of Saudi Arabia (KSA). Such transfers will be performed in compliance with the law. When we transfer your personal information outside the region, we will take the necessary steps to ensure appropriate safeguards are applied to maintain the same levels of protection as required under the law.

7. COOKIES

We use 'cookies' to monitor how people use our website 'www.gib.com'. A cookie is a piece of information that is stored on your computer's hard drive and it records how you have used a website. This helps us to understand how our customers use our website so we can develop and improve it. 

8. APPLICABILITY

This Privacy Notice is applicable to Personal Data and Sensitive Data or information collected by us or our affiliates directly from the customer or through our online portals, mobile apps and electronic communications as also any information collected by our servers from the customer’s browser.

9. SECURITY PRACTICES & PROCEDURES

The security of Personal Data is a priority and is protected by maintaining physical, electronic, and procedural safeguards that meet applicable laws. We shall take reasonable steps and measures to protect the security of the customer’s Personal Data from misuse, loss, unauthorised access, modification or disclosure. We maintain Our security systems to ensure that the Personal Data of the customer is appropriately protected and follows standard encryption norms for the transmission of information. We ensure that Our employees and affiliates respect the confidentiality of any Personal Data held by Us.

 

10. RETENTION OF PERSONAL DATA

At GIB, We retain your Personal Data only for as long as mandated by the regulators for the purposes set out in this Privacy Notice. We will retain and use your information to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies which is subject to Electronic Banking Services instructions and other applicable rules and regulations within the designated jurisdiction.

11.COLLECTION OF DATA FROM MINORS

If you are a resident in KSA and under 18 or, alternatively, are resident elsewhere and are not yet the relevant age of majority in the jurisdiction in which you reside, We are not permitted to contract with you directly. Where necessary by local legislation, by agreeing to this Privacy Notice, your guardian acknowledges and consents to the terms of this Privacy Notice on your behalf. If we seek your consent to process your Personal Data for a specific purpose in accordance with this Privacy Notice, such consent must be granted on your behalf by your guardian.

12. PRIVACY NOTICE CHANGES

The effective date of this Notice is provided above. Any updates or changes to the Notice will be posted on this website with the new revision date, which is the effective date of changes. Your continued use of this website constitutes your acceptance of any changes to this Notice. Therefore, we recommend you check the Notice periodically to be aware of the most updated version of this Notice.

13. DATA SUBJECT RIGHTS QUERIES

You may have certain rights relating to your Personal Data depending on the country in which you access our KSA website. In some cases, depending on applicable legislation, such as Kingdom Saudi Arabia – Personal Data Protection Law (“KSA PDPL”), these rights may include: the right to be informed – this right allows you to receive information from Us about what Personal Data We collect and what do We do with it. The purpose of this notice is to fulfil this right.

14. YOUR RIGHTS - LEGAL RIGHTS AVAILABLE TO HELP MANAGE YOUR PRIVACY

Right to Know / Information

You have the right to know about Our contact details, the exact reason the data is being collected, the methods being used for data collection, and whether this collected data will be shared or sold.

Right to Request Access or Copy

You have the right to access your Personal Data from us and obtain a copy of it in a clear and readable format, in conformity with the content of the records, at no cost.

Right to Request Correction

You have the right to request correction of any data collected on them if it is incomplete, inaccurate, or obsolete.

Right to Request Destruction

You have the right to request the destruction of data collected on them. The reasons can range from the user rescinding their consent for data collection to the data no longer serving the purpose for which it was collected. 

Right to Limit/Restriction of Processing

You have the right to limit or refuse the processing of their Personal Data by the organization for special cases and for a limited period of time. This right is not explicitly provided under the KSA PDPL; however, the regulatory authority has released a set of FAQs that provides details of this right.
We are required to ensure that you are appropriately informed about these rights and establish dedicated channels for you to exercise these rights. We must fulfill these requests within 30 days and record all data subject requests received.

 

15. DISCLAIMER

This Privacy Notice is not intended to, nor does it, create any contractual rights whatsoever or any other legal rights, nor does it create any obligations on us in respect of any other party or on behalf of any party. When you log in to third parties’ websites, you will not be subject or under this Privacy Notice. Moreover, we are not responsible for their websites’ content, and we do not represent third parties. Therefore, we recommend you review the privacy and security policy of each link you log in to.

 

CONTACT US

If you have any questions, concerns or complaints regarding our compliance with this Privacy Notice and the KSA PDPL, or if you wish to exercise your rights, please contact us. We will investigate and will attempt to resolve complaints and disputes and make every reasonable effort to honor your wish to exercise your rights as quickly as possible, in any event, within the timescales provided by applicable data protection laws or regulations.


If you have any questions or comments regarding the processing of your Personal Data, our privacy practices or if you would like us to update information or preferences you provided to us, please contact the Data Privacy / Protection Team (Data Management Office) through the following email:  or 

Gulf International Bank - Saudi Arabia, a Saudi Closed Joint Stock company with a capital of SAR (7,500,000,000), Commercial Registration No. (2052001920), Unified Number (7001399042), P.O. Box 93, Al Khobar 31952, Kingdom of Saudi Arabia, Telephone +966 13 866 4000, National Address: 5515 Cooperative Council Road - Al Khuzama Area, Unit No. 54, Al Khobar 34721-8208, Website: www.gib.com, Licensed with number: (2007) and it is under the supervision and control of The Saudi Central Bank.