The EU s General Data Protection Regulation enters into force on 25 May 2018

Similar documents
Data Privacy Notice of Sumitomo Mitsui Banking Corporation, Brussels Branch ( SMBC )

Vanguard Group (Ireland) Limited Vanguard Funds plc Vanguard Investment Series plc Privacy policy. May 2018

Data Privacy Notice. Who are we and why do we register and use personal data?

PRIVACY NOTICE LAST UPDATED: SEPT. 2018

privacy notice who is responsible for processing your personal data and who you can contact in this regard reasons for processing your data

2. FROM WHICH SOURCES THE BANK COLLECTS YOUR PERSONAL DATA?

Capital Dynamics Privacy Policy

ANNEXURE. Privacy Notice

1.5 If your personal details change, please contact us at Jonathan Tait & co, 9 Crown Street, Aberdeen, AB11 6HA.

LAMP Services Limited Privacy Notice v1.2 4 th March Controller

We protect your data and privacy by taking all relevant measures in accordance with applicable legislation.

Privacy Policy. For the purposes of Data Protection Legislation the data controller is the Company.

Information about Danica Pension s processing of personal data

DATA PROTECTION NOTICE

TRAVELTOKENS SALE PRIVACY POLICY Last updated:

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ).

Data Privacy Statement

Institutional Investment Advisors Limited

DATA PROTECTION NOTICE. The protection of your personal data is important to the BNP Paribas Group 1.

CP is licenced and supervised by the Commission de Surveillance du Secteur Financier (hereinafter CSSF ).

DATA PROTECTION POLICY. AtonLine Limited

DATA PROTECTION NOTICE

Privacy notice. What personal data do we register and use?

PRIVACY POLICY FOR CUSTOMER, PROSPECT AND PARTNER REGISTER

Data protection information under the EU General Data Protection Regulation in Italy

General Data Protection Regulation (GDPR) Data Protection Notice

You may also obtain further information at CNPD Comissão Nacional de Proteção de Dados at

Data Protection Privacy Notice for people not directly involved in the accident

Privacy Policy and Personal Data

1. Personal data processed by NOVO BANCO as the data controller

FINANCIAL SERVICES OPPORTUNITIES INVESTMENT FUND LIMITED Company Registration Number: PRIVACY NOTICE

JOSTENS EUROPEAN PRIVACY POLICY

Account agreement Disposal Account

Data protection. VTB Bank (Europe) SE Rüsterstraße 7-9 D Frankfurt am Main Tel: Fax:

Principles of Processing the Personal Data of Clients

LGIM Liquidity Funds plc Privacy Policy

Foreign Currency Account 1 (6) Special and general terms and conditions

SILCHESTER INTERNATIONAL INVESTORS DATA PROTECTION POLICY

General agreement terms and conditions 1 (9) governing services with access codes

We are the Sanne Group, a listed multinational provider of alternative asset and administration services.

General terms and conditions for corporate customers

PRIVACY NOTICE 1. WHAT IS A PRIVACY NOTICE & WHY IS IT IMPORTANT?

Privacy Policy. This privacy policy shall be valid even if you have reserved your transfers through the other sales partners of Plus Group Kft.

FUNDS MANAGED BY GOLDMAN SACHS ASSET MANAGEMENT - FAIR PROCESSING NOTICE EFFECTIVE DATE: 25 MAY 2018

Data Protection Notice pursuant to the General Data Protection Regulation (GDPR)

GENERAL DATA PROTECTION REGULATIONS PRIVACY NOTICE

General terms and conditions for 1 (5) SEPA Core Direct Debit for debtor January 2018

General terms and conditions of Aktsiaselts (Public Limited Company) Tallink Grupp Finnish share depositary receipts

Privacy Statement v 1.1

PERSONAL DATA PROCESSING BY GOLDMAN SACHS FAIR PROCESSING NOTICE FOR REPRESENTATIVES OF CLIENTS AND PROSPECTIVE CLIENTS EFFECTIVE DATE: 25 MAY 2018

We take privacy and security of your information seriously and will only use such personal information as set out in this Privacy Notice.

Mortgages and Loans Privacy policy

PRIVACY NOTICE issued by DALE Accounting and Tax Services Ltd

Lazard Investment Funds (the Company )

DATA PROCESSING AGREEMENT/ADDENDUM

PRIVACY NOTICE. I. Indication of the data controller

Citi Canada. Privacy of Personal Information Statement

PRIVACY NOTICE Use of Information Data Controller and Data Processor

Nordea's general terms and conditions for 1 (6) outgoing and incoming currency payments

Quotation/Inception. Renewal. Policy administration. Claims processing PRIVACY POLICY

EU General Data Protection Regulation vs. Swiss Data Protection Act (in the Private Sector 1 )

BDML Connect Ltd Privacy Policy_v1.0_March updated Markerstudy Group 2018 Page 1 of 11

INFORMATION ON THE PROCESSING OF PERSONAL DATA

Data protection information under the EU General Data Protection Regulation in Germany

Standard 2.4. Customer due diligence - Prevention of money laundering and terrorist financing. Regulations and guidelines

Data Protection Information The following data protection information gives an overview of our collection and processing of your data.

General agreement terms and conditions 1 (9) governing services with access codes

ASTRAZENECA GLOBAL POLICY DATA PRIVACY

This Policy also explains how we collect information through the use of cookies and related technologies which are relevant if you visit our Site.

Data protection Your privacy is important to us

Power of Attorney Application to Appoint an Attorney to Operate an Account(s)

Nordea Bank AB (publ), Finnish branch 1 (10) terms and conditions applicable to cards

Fair Processing Notice

Data Processing Appendix

Nordea s general terms and conditions 1 (6) for euro-denominated payments transmitted within the Single Euro Payments Area

SECTION 1 IDENTITY AND CONTACT DETAILS OF THE DATA CONTROLLER

1. ENTITY & OWNERSHIP 1 Full Legal name

henriksen limited This document sets out how Henriksen processes data and your rights as the data subject.

DATA PROTECTION POLICY

The data controllers responsible for the personal information in this notice are:

Customer Privacy Notice Edition

WHO IS RESPONSIBLE FOR LOOKING AFTER YOUR PERSONAL DATA?

ERGO Versicherung AG UK Branch Data Privacy Notice

EMPLOYEE NOTICE OF DATA PRIVACY POLICIES AND PROCEDURES

All Sorts UK Limited Data Protection Policy 17 th May 2018

1 (9) Nordea Bank AB (publ), Finnish Branch terms and conditions applicable to cards

DATA PROTECTION NOTICE

first direct Travel Money

Privacy Policy Statement

FP CAF Investment Fund OEIC Application Form

JPMorgan recognises the importance of the personal information we hold about individuals and the trust they place in us.

The General terms and conditions for corporate customers

INFORMATION REPORT AND CONSENT TO THE PROCESSING OF PERSONAL DATA PURSUANT TO THE EU REGULATION 679/2016 ON PERSONAL DATA PROTECTION

Processing the customer s personal data at FINE

Nordea s general terms and conditions 1(6) for euro-denominated payments transmitted within the Single Euro Payments Area

PRIVACY POLICY: INSURANCE OPERATIONS

LEGAL PRIVACY NOTICE (EFFECTIVE MAY/2018) 12 Demostheni Severi Avenue 5th Floor 1080 Nicosia Cyprus

Privacy policy - contractors

Vhi and Intana Data Protection Statement Vhi Canada Cover

1.2 These General Terms and Conditions are applicable between the Broker and the Customer.

Transcription:

May 2018 The EU s General Data Protection Regulation enters into force on 25 May 2018 Keeping our customers data safe is nothing new to us. Protecting the information and the personal data that our customer share with us has always been at the centre of how we do banking. When you as a customer share information with Nordea Group, we are better able to offer customized financial advice and services. Over the past years, new technology has been playing an increasingly significant role in our lives, including how our personal data and online activities are stored and used by companies. This has created a need for updated rules to match the way personal data can be used today. The result is the General Data Protection Regulation, GDPR. The new regulation is expected to be implemented May 25, 2018 and will apply to all companies and organizations that handle personal data within the European Economic Area. The introduction of GDPR puts an increased focus on individuals having the right to be in charge of their own personal data. This includes individuals representing corporate or institutional customers. Nordea Bank AB (publ) Group s customer register, FI-00020 NORDEA NF003X_05.2018 As a corporate or institutional customer, you will disclose some of your employee s or other relevant party s personal data to us. As such, you are also responsible to inform these individuals of Nordea s privacy policy. Information about how Nordea handles personal data can be found in our Privacy Policy. The data protection policy is appended to this letter. Following the new regulation, we have also updated our terms and conditions and, where applicable, referred to our privacy policy. The following companies are the data controllers of Nordea Group s operations in Finland: Nordea Bank AB (publ), Nordea Funds Ltd, Nordea Life Assurance Finland Ltd, Nordea Investment Management AB, Nordea Mortgage Bank Plc, Nordea Finance Finland Ltd and Tukirahoitus Oy. Nordea Bank AB (publ), Finnish Branch, Satamaradankatu 5, Helsinki, FI-00020 NORDEA, Business Identity Code 1703218-0. Nordea Bank AB (publ), a public limited company, domicile Stockholm, reg. no. 516406-0120, registration authority Bolagsverket, Sweden.

Nordea Privacy Policy Nordea is fully committed to protecting your individual rights and keeping your personal data safe. In this Privacy Policy we describe the collection, usage, storage and sharing practices of personal data. Within the Nordea Group, the data controller will be Nordea Bank AB (publ) and/or the Nordea company(ies) you have your relationship with. Details of the controllers can be found on our webpages. We process individuals personal data for a number of reasons. When we write «you», we mean you as a customer, a potential customer, our customer s employee or other relevant parties, such as beneficial owners, authorised representatives, corporate cardholders and associated parties. This Privacy Policy covers the following areas: 1. What personal data we collect 2. How we may use your personal data and the lawful basis for doing so 3. Automated decision-making 4. Who we may disclose your personal data to 5. How we protect your personal data 6. Your privacy rights 7. Cookies 8. How long we keep your personal data 9. How changes to this Privacy Policy and the Cookies policy will be made 10. Contacting us or the data protection authority 1. What personal data we collect Personal data is in most cases collected directly from you or generated as part of the use of our services and products. Sometimes additional information is required to keep information up to date or to verify information we collect. The personal data we collect can be grouped into the following categories: Identification information: national identification number and name. We are obliged to collect documentation of such information, for instance in the form of copies of your passport, driver s license, or the like. Contact information: phone numbers and addresses, including postal address in the case of a foreign address, also the home country. Financial information: type of agreement, transactional data, credit history, insurance history. Information related to legal requirements: country of taxation or foreign tax payer reference, customer due diligence and anti-money laundering requirements. Special Categories of Data: for example information concerning health is needed for some insurance-specific products provided from the Nordea Life and Pension companies and information on trade-union membership related to certain loan products. Personal data we may collect from you: We collect information you provide directly to us. For example, when becoming a new customer, we collect personal data, such as name, national identification number, e-mail address and phone number, income and debt information to be able to provide you with the product or service in question.

Nordea also collects information which you provide us with such as messages you have sent us, e.g. feedback or a request in our digital channels. Calls and chat conversations with you may also be recorded and logged for verification of orders, documentation, and for quality and improvement purposes. For security purposes, we may have cameras in our branch offices and ATMs. Personal data that we may collect from third parties: Publicly available and other external sources; register held by governmental agencies (such as population registers and registers held by tax authorities, company registration offices, enforcement authorities, etc.), sanction lists (held by international organisations such as the EU and UN as well as national organisations such as Office of Foreign Assets Control (OFAC)), registers held by credit-rating agencies and other commercial information providers providing information on e.g. beneficial owners and politically exposed persons. In connection with payments, we collect information from remitters, shops, banks, payment service providers and others. Health data from health institution (for our Life and Pension companies). From other entities in the Nordea Group or other entities which we collaborate with. 2. How we may use your personal data and the lawful basis for doing so We use your personal data to comply with legal and contractual obligations as well as to provide you with offers, advice and services. Entering into and administration of service and product agreements (performance of a contract) The main purpose of our processing of personal data is to collect, verify, and process personal data prior to giving an offer and entering into a contract with you as well as documenting, administering and completing tasks for the performance of contracts. Examples of the performance of a contract: processes needed to e.g. open an account or online service or for granting a card or a credit customer service during the contract period possible establishment, exercise or defense of legal claims and collection procedure. Fulfilment of requirements and obligations for us stated in laws, regulations or decisions from authorities and supervisors (legal obligation) In addition to the performance of contract, processing of personal data also takes place for us to fulfil our obligations under law, other regulations or authority decisions. Examples of processing due to legal obligations: Know Your Customer requirements (KYC) Preventing, detecting, and investigating money laundering, terrorist financing, and fraud Sanctions screening

Bookkeeping regulations Reporting to tax authorities, police authorities, enforcements authorities, supervisory authorities Risk management obligations such as credit performance and quality, capital adequacy, and insurance risks Payment service requirements and obligations Other obligations related to service or product specific legislations, for example securities, funds, collateral, insurance or mortgage legislation. Marketing, product- and customer analysis (legitimate interest) Personal data is also processed in the context of marketing, product- and customer analyses. This processing forms the basis for marketing, process-, business- and system- development, including testing. This is to improve our product range and optimize our customer offerings. This may also involve profiling (see below). We have a legitimate interest to use profiling for example when conducting customer analysis for marketing purposes or monitoring transactions in order to detect frauds. Consent There are situations when we will ask for your consent to process your personal data. Examples of such situations are processing of payment transaction data for marketing purposes, or for some processing of special categories of data. The consent will contain information on that specific processing activity. If you have given consent to a processing of your personal data you can always withdraw the consent. 3. Automated decision-making We may in some cases use automated decision-making, if it is authorized by legislation, if you have provided an explicit consent or if it is necessary for the performance of a contract, for example automated credit approval process in the online channels. You can always request a manual decision-making process instead, express your opinion or contest decision based solely on automated processing, including profiling, if such a decision would produce legal effects or otherwise similarly significantly affect you. When using automated decision-making we will provide you with further information about the logic involved, as well as the significance and the envisaged consequences to you. 4. Who we may disclose your personal data to We may share your personal data with others such as authorities, Nordea Group companies, suppliers, payment service providers and business partners. Before sharing we will always ensure that we respect relevant financial industry secrecy obligations. To fulfill services and agreements we have to disclose information about you. If, for example you have asked us to transfer funds, we need to disclose certain information to fulfill that transfer. Third parties and Nordea Group companies To provide our services, for example credit transfer, we disclose data about you that is necessary to identify you and perform an assignment or agreement with companies that we cooperate with in order to perform our services. These services include, but not limited to, secure identification solutions in the

relevant country and between parties in the financial system such as central banks, transaction receivers and clearing houses. We also disclose personal data to authorities to the extent we are under statutory obligation to do so. Such authorities include tax authorities, police authorities, enforcements authorities and supervisory authorities in relevant countries. In addition, data are disclosed, with your consent or if this is permitted pursuant to legislation, internally in Nordea Group and to external business partners (including correspondent banks, other banks, vendor partners of finance object and re-insurers). In order to provide our services, we may also disclose data to other insurance companies, reinsurance companies and service companies within the field of collectively agreed occupational pensions. We have entered into agreements with selected suppliers, which include processing of personal data on behalf of us. Examples thereof are suppliers of IT development, maintenance, hosting and support. Third country transfers In some cases, we may also transfer personal data to organisations in socalled third countries (countries outside of the European Economic Area). Such transfers can be made if any of the following conditions apply; the EU Commission has decided that there is an adequate level of protection in the country in question other appropriate safeguards have been taken, for example the use of the standard contractual clauses (EU model-clauses) approved by the EU Commission or the data processor has valid Binding Corporate Rules (BCR) in place that there are exceptions in special situations, such as to fulfill a contract with you or your consent to the specific transfer. You can access a copy of the relevant EU model-clauses used by Nordea for transfers by going to www.eur-lex.europa.eu and search for 32010D0087. 5. How we protect your personal data Keeping your personal data safe and secure is at the centre of how we do business. We use appropriate technical, organizational and administrative security measures to protect any information we hold from loss, misuse, and unauthorized access, disclosure, alteration and destruction. 6. Your privacy rights You as a data subject have rights in respect of personal data we hold on you. You have the following rights; a) request access to your personal data. You have a right to access the personal data we are keeping about you. In many cases this information is already present to you in your online services from us. Your right to access may, however, be restricted by legislation, protection of other persons privacy and consideration for the Nordea Group s business concept and business practices. The Nordea Group s know-how, business secrets as well as internal assessments and material may restrict your right of access.

b) request correction of incorrect or incomplete data. If the data are incorrect or incomplete, you are entitled to have the data rectified, with the restrictions that follow from legislation. c) request erasure. You have the right request erasure of your data in case; you withdraw your consent to the processing and there is no other legitimate reason for processing you object to the processing and there is no justified reason for continuing the processing you object to processing for direct marketing processing is unlawful when processing personal data on minors, if the data was collected in connection with the provision of information society services. Due to the financial sector legislation we are in many cases obliged to retain personal data on you during your customer relationship, and even after that, e.g. to comply with a statutory obligation or where processing is carried out to manage legal claims. d) limitation of processing of personal data. If you contest the correctness of the data which we have registered about you or lawfulness of processing, or if you have objected to the processing of the data in accordance with your right to object, you may request us to restrict the processing of these data to only storage. The processing will only be restricted to storage, until the correctness of the data can be established, or it can be checked whether our legitimate interests override your interests. If you are not entitled to erasure of the data which we have registered about you, you may instead request that we restrict the processing of these data to only storage. If the processing of the data which we have registered about you is solely necessary to assert a legal claim, you may also demand that other processing of these data be restricted to storage. We may process your data for other purposes if this is necessary to assert a legal claim or if you have granted your consent to this. e) object to processing based on our legitimate interest. You can always object to the processing of personal data about you for direct marketing and profiling in connection to such marketing. f) data portability. You have a right to receive personal data that you have provided to us in a machine-readable format. This right applies to personal data processed only by automated means and on the basis consent or of fulfilling a contract. Where secure and technically feasible the data can also be transmitted to another data controller by us. Your request to exercise your rights as listed above will be assessed given the circumstances in the individual case. Please note that we may also retain and use your information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements.

7. Cookies We collect, process and analyse data regarding the use of our webpages. Traffic data is data connected to visitors on the webpage and data handled in communication fields for sending, distributing or making messages available. We use cookies and similar technologies to deliver products and services to you, provide a secure online environment, to manage our marketing and provide a better online experience, track our website performance and to make our website content more relevant to you. The data will not be used to identify individual visitors except for Nordea Netbank customers. You can set or amend your web browser controls to accept or reject cookies. If you choose to reject cookies, you may still use our websites and some services, however your access to some functionality and areas of our website or services may be restricted substantially. For more information, see cookies at the footer of our local website Nordea.fi. 8. How long we process your personal data We will keep your data for as long as they are needed for the purposes for which your data was collected and processed or required by laws and regulations. This means that we keep your data for as long as necessary for the performance of a contract and as required by retention requirements in laws and regulations. Where we keep your data for other purposes than those of the performance of a contract, such as for anti-money laundering, bookkeeping and regulatory capital adequacy requirements, we keep the data only if necessary and/or mandated by laws and regulations for the respective purpose. The data retention obligations will differ within the Nordea Group subject to local law. Specific examples are: Preventing, detecting and investigating money laundering, terrorist financing and fraud: minimum five years after termination of the business connection or the performance of the individual transaction Bookkeeping regulations: up to ten years Payment service requirements and obligations: five years Other service or product specific regulations such as securities, collateral, insurance or mortgage regulation: up to seven years Loan offers: Up to three months after the expiration of an offer Details on performance of an agreement: up to ten years after end of customer relationship to defend against possible claims. The above is only for explanatory purposes and the retention times may differ country to country.

9. How changes to this Privacy Policy and the Cookies policy will be made We are constantly working on improving and developing our services, products and websites, so we may change this privacy policy from time to time. We will not diminish your rights under this privacy policy or under applicable data protection laws in the jurisdictions we operate. If the changes are significant, we will provide a more prominent notice, when we are required to do so by applicable law. Please review this Privacy Policy from time to time to stay updated on any changes. 10. Contacting us or the data protection authority If you have any questions or concerns regarding our privacy policy, you can always contact Nordea s customer service 24/7 or your local branch office. Also, Nordea Group has appointed a Data Protection Officer that you can contact by sending a message to: dataprotectionoffice@nordea.com or by sending a letter to: Nordea, Group Data Protection Office, c/o Palveluasiamies, Satamaradankatu 5, FI-00020 Nordea, Finland. You can also lodge a complaint or contact the data protection authority in any of the countries where we provide services or products to you. Nordea Bank AB (publ) Group s customer register, FI-00020 NORDEA NF003C_05.2018 Nordea Bank AB (publ), Finnish Branch, Satamaradankatu 5, Helsinki, FI-00020 NORDEA, Business Identity Code 1703218-0. Nordea Bank AB (publ), a public limited company, domicile Stockholm, reg. no. 516406-0120, registration authority Bolagsverket, Sweden.