Data Privacy Notice
On the Duties of Disclosure Upon the Collection and Processing of Personal Data in Accordance with the Swiss Data Protection Act and the EU General Data Protection Regulation (GDPR)
The following information provides an overview of how your data is processed by Habib Bank AG Zurich (“Habib Bank”) and your rights under data privacy laws. Although the GDPR is an EU regulation, it is applicable to Habib Bank AG Zurich. The details of data processing depend significantly on the services requested or agreed upon, so we ask you to familiarize yourself with this Data Privacy Notice.
Unfortunately, online fraud is on the rise, with criminal elements targeting consumers. One of the most common forms of fraud is “phishing,” where fraudulent emails appear to be sent from Habib Bank AG Zurich. These scam emails may contain links to fake websites resembling the Bank’s official page and request personal information. These emails are not legitimate, and the links they contain do not lead to any genuine Habib Bank AG Zurich webpage. You should never provide personal information by responding to such fraudulent emails, clicking on any links, or logging in.
1) Who is Responsible for Data Processing and How Can I Contact Them?
The legal entity responsible is:
- Habib Bank AG Zurich
Weinbergstrasse 59
CH-8006 Zurich
Switzerland
Our Privacy Officer can be reached at:
- Phone: +41 44 269 4528
Email: dataprivacy@habibbank.com
2) What Data is Used by Habib Bank AG Zurich?
Habib Bank AG Zurich processes data that it receives from its clients and generates as part of the business relationship. To facilitate, enable, and maintain business relationships, Habib Bank collects and processes personal data relating to clients and any other involved individuals (e.g., authorized representatives, individuals with power of attorney, and beneficial owners, if different from the client).
The personal data processed may include:
- Personal details (e.g., name, address, contact data, date and place of birth, nationality)
- Identification data (e.g., identification documents)
- Authentication data (e.g., specimen signature)
- Order data (e.g., payment orders)
- Data from fulfilling contractual obligations (e.g., payment transactions)
- Information regarding financial situations (e.g., credit reports, asset origins)
- Record-keeping data (e.g., consultation minutes)
- Publicly available data (e.g., social media, debtor directories, land registers)
3) For What Purpose and on What Legal Basis Does Habib Bank AG Zurich Use Your Data?
3.1 For the Fulfillment of Contractual Obligations
The processing of your data allows Habib Bank to provide you with the contractually agreed services or to carry out pre-contractual measures that occur as part of a request from an interested party. The purposes of data processing are primarily in compliance with specific banking products (e.g. accounts, loans, securities, deposits, brokerage services). Your data will be used, among other purposes, for the analysis of any potential needs, the provision of advice, wealth management, and to support the execution of transactions.
Further details can be found in your contract documents or in the General Terms & Conditions.
3.2 For the Safeguarding of Habib Bank AG Zurich’s and Third-Party Interests
Where required, we process your data beyond the actual fulfillment of the contract for the purposes of the legitimate interests pursued by us or a third-party. For example:
- Consulting with credit rating agencies to investigate creditworthiness and credit risks
- Reviewing and optimising procedures for needs assessment for the purpose of direct client discussions
- Obtaining personal data from publicly available sources for client acquisition
- Testing and optimising processes for requirement analysis or client contact
Measures for business management and further development of services and products:
- Risk control at Habib Bank and Habib Bank Group
- Asserting legal claims and defence in legal disputes
- Guarantee of Habib Bank Group’s IT security and IT operations
- Prevention and investigation of crimes
- Video surveillance and measures to protect the rights of an owner of premises to keep out trespassers and to provide security (e.g. access controls)
3.3 On the Basis of Your Consent
If you consent to specific data processing, such as for marketing purposes, we process your data based on your consent, which you can withdraw at any time.
This also applies to withdrawing your consent that was given to us before the GDPR came into force (25 May 2018). Withdrawal of consent does not affect the legality of data processed prior to withdrawal.
3.4 On the Basis of Statutory Requirements or in the Public Interest
We are subject to various legal obligations, meaning statutory requirements (e.g. Swiss Banking Act, Collective Investment Scheme Act, FINMA regulations and newsletters, tax laws, etc.), and Habib Bank has to fulfill requirements outlined by banking-specific regulations (e.g. the Swiss National Bank and FINMA). The processing of data is done, among others, for the verification of creditworthiness as well as identity and age, the prevention of fraud and money laundering, the fulfillment of tax-related monitoring and reporting obligations as well as the assessment and management of risks of Habib Bank and the Habib Bank Group.
4) Who Can Access Your Data?
4.1 Habib Bank Group
We may share your data with other entities in the Habib Bank Group where required to fulfill our contractual and legal obligations. We may transfer your personal data to other members of the Habib Bank Group for risk control purposes in connection with statutory/regulatory obligations. We may also share information with other members of the Habib Bank Group in connection with services that we believe may be of interest to you.
4.2 External Recipients of Data
We will transfer your personal data in the course of conducting our usual business or if legal, regulatory or market practice requirements demand it to be shared with the following external recipients, or if you have given consent (e.g. to process a financial transaction you have ordered us to fulfill) for the following purposes:
- to public entities and institutions (e.g. financial authorities, Swiss National Bank, law enforcement authorities)
- to other credit and financial services institutions or similar institutions to which Habib Bank transfers personal data within the context of its business relationships with you (e.g. correspondent banks, custodian banks, brokers, stock exchanges, information agencies)
- to third-parties (e.g. correspondent banks, brokers, exchanges, trade repositories, processing units and third-party custodian issuers, authorities, and their representatives) for the purpose of ensuring that we can meet the requirements of applicable law, contractual provisions, market practices, and compliance standards in connection with transactions you enter into and the services that we provide you with, or
- to a natural or legal person, public authority, agency or body for which you have given us your consent to transfer personal data to, or for which you have released us from banking confidentiality
4.3 Service Providers and Agents
We will transfer your personal data to service providers and agents appointed by us for the purposes given, subject to maintaining banking confidentiality. These are companies in the categories of banking services, IT services, logistics, printing services, telecommunications, collection, advice and consulting, and sales and marketing.
Habib Bank will implement appropriate organisational and technical safeguards to protect the personal data for which it acts as data controller at all times.
5) Does Habib Bank AG Zurich Transfer Data Across Borders?
Data transfer to legal entities in countries outside of Switzerland takes place so long as:
- it is necessary to administer the working relationships with you
- if we have a legitimate interest in doing so
- it is required by law (e.g. reporting obligations under financial regulation)
- if you have given your consent
We will also share your personal information with other entities in the Habib Bank Group as part of our regular reporting activities on Habib Bank AG Zurich’s performance, in the context of a business reorganisation or Group restructuring exercise, for system maintenance support, and for data hosting purposes.
These data transfers are secured through corresponding guarantees of the recipients to ensure an appropriate level of data protection.
6) For How Long Will Your Data be Stored?
We will process and store your information as long as it is necessary in order to fulfill our contractual, regulatory, and statutory obligations. It should be noted here that our business relationships are a long-term obligation, which is set up on the basis of an extended period.
We will assess and respond to requests to delete data. We will delete data provided that the data is no longer required to fulfill contractual, regulatory or statutory obligations, or the fulfillment of any obligations to preserve records according to commercial and tax law.
We will normally retain your records for a minimum of ten years to comply with regulatory and contractual requirements unless there is a particular reason to hold records for longer, including legal hold requirements, which require us to keep records for an undefined period of time.
7) What are Your Rights Under the GDPR?
The GDPR grants you the following rights:
- Right of access: requesting that your personal data (that Habib Bank AG Zurich holds on record) be shared with you
- Right to rectification: demanding that the information be rectified should it be incorrect
- Right to erasure: asking that your data be deleted if Habib Bank AG Zurich is not permitted or is not legally obliged to retain your data
- Right to restrict processing: demanding that the processing of your data be restricted if:
– you have disputed the accuracy of your data stored by Habib Bank AG Zurich and it has not yet completed its assessment
– you object to the deletion of your data although Habib Bank AG Zurich is obligated to delete it, or
– you have objected to the processing of your data but it has not yet been established whether this outweighs Habib Bank AG Zurich’s reasons for processing your data - Right to object: objecting to Habib Bank AG Zurich processing your data, if it processes your data on the basis of its legitimate interest (it will cease this processing unless it is outweighed by compelling and legitimate grounds)
- Right to data portability: demanding that your personal data that you have provided to Habib Bank AG Zurich be transferred in a generally useable, machine-readable, and standardised format.
You also have the right of appeal (as far as this affects you) to your respective Data Protection Supervisory Authority
8) What Data are you Asked to Supply?
In the context of your relationships with Habib Bank AG Zurich, you must provide all personal data that:
- is required for accepting and carrying out a business relationships and fulfilling the accompanying contractual obligations, and
- Habib Bank AG Zurich is legally required to collect
Without this data, Habib Bank AG Zurich will most likely be unable to enter into a contractual relationships with you.
Under the regulations on combatting money laundering and the financing of terrorism, Habib Bank AG Zurich is obligated to verify your identity on the basis of your identification documents and, in this context, to collect and store your address, nationality, name, date, and place of birth, and identification data prior to the commencement of a business relationships. For Habib Bank AG Zurich to comply with these regulations, you are required to supply it with the necessary information. If this information changes during the course of the business relationships, you are obliged to notify Habib Bank without delay. If you do not provide Habib Bank with the necessary information, it will not be able to commence or continue a business relationships with you.
9) Is The Decision-Making Automated?
No, Habib Bank AG Zurich does not use automated decision-making.
10) Will Cookies Be Collected?
Yes, Habib Bank AG Zurich does collect cookies.
10.1 What Are Cookies?
Cookies are information packages sent by a web server (in this case this website) to your internet browser, saved on your computer, and checked by the server on each subsequent visit to the website. To gain full benefit from this website, we recommend that you configure your browsers to accept cookies.
10.2 Why Do We Use Them?
Cookies are used to facilitate navigation within the website and its correct use. They also serve a statistical purpose, making it possible to establish which areas of the website have been visited, and to improve and update user procedures.
10.3 What Type of Cookies are Used?
For further information about the types of cookies used, please refer to the ‘Cookies Notice’ on our website.
10.4 How Should I Manage My Settings with Respect to Cookies?
To optimise your use of our website, we recommend that you accept the cookies. Most internet browsers are initially set to accept cookies. You can, at any time, set your browser to accept all cookies, just some cookies, or no cookies. In the latter case, you would disable use of part of the websites. Additionally, you can set your preferences in the browser so that you will be notified whenever a cookie is saved on your device. Please note that if you disable the cookies, you may not be able to enjoy optimal use of the website.
11) Will Your Data Be Automatically Processed?
We process some of your data automatically, with the goal of assessing certain personal aspects (profiling). For example, we may use profiling in the following ways:
- In order to combat money laundering, financing of terrorism, and criminal acts, Habib Bank also conducts data assessments (among others in payment transactions). The aim of these measures is to protect you.
- Habib Bank AG Zurich uses assessment tools to provide clients with relevant and appropriate information on its products and services. These allow communications and marketing to be tailored, as needed, including market and opinion research.
- Habib Bank AG Zurich uses assessment tools in order to be able to specifically notify you and advise you regarding products. These allow communications and marketing to be tailored as needed, including market and opinion research.
12) Will Biometric Data Be Used?
No, Habib Bank AG Zurich does not collect biometric data.
13) Where Can You Find The Current Privacy Notices?
This Data Privacy Notice can be adapted at any time in accordance with corresponding regulations. You can find the applicable version at: https://habibbank.com/ch/data-privacy-notice/
14) How Can You Contact Habib Bank AG Zurich?
Should you have any questions about the treatment of your data, please contact your Relationships Manager or Habib Bank AG Zurich’s Privacy Officer, who will be happy to assist you.