External Data Privacy Notice

The Saudi National Bank is committed to safeguarding your privacy and adhering to the highest standards of data protection

1. Overview

The Saudi National Bank (‘SNB’, ‘Us’, ‘We’, ‘Bank’) is committed to safeguarding your privacy and adhering to the highest standards of data protection, as prescribed by the Personal Data Protection Law of Saudi Arabia (‘KSA PDPL’, ‘Law’).

Personal Data encompasses any information relating to an identified or identifiable individual (‘Personal Data’), which may include but is not limited to, your name, address, photograph, and more. This Privacy Notice serves to inform you about how SNB collects, processes, and protects your Personal Data. The aim of this notice is to ensure transparency in our data handling practices and empower you to make informed decisions about your privacy.

 

2. Purpose

The purpose of this Notice is to provide you, our valued (‘Customer’), with clarity on how SNB collects, uses, stores, shares, and processes your Personal Data. This is integral to our commitment of delivering personalised products and services tailored to your specific needs. SNB ensures transparent and lawful processing of your Personal Data and implements comprehensive security measures to safeguard against unauthorised access, disclosure, or destruction.

 

3. Your personal data

We process your Personal Data to the extent required to deliver personalised products and services with high standards. This may encompass a range of information, including but not limited to: your name, birthdate, address, email, phone number, emergency contacts, banking details, photographs, videos, employee identification, passport information, visa or work permit details, national identification or residency permit, educational qualifications, salary particulars, CCTV footage, etc. Additionally, we may also process Sensitive Data, which could reveal aspects such as racial or ethnic origin, or religious, intellectual or political belief, data relating to security, criminal convictions and offences, biometric or genetic data, health data, or details indicating parental status (‘Sensitive Data’). Furthermore, we may handle Personal Data concerning minors or individuals lacking legal competence, in which case notification and consent will be sought from their parents or legal guardian.

 

Your Personal Data may be processed through various channels, including Third Parties, Government Institutions, websites, mobile applications, telephone conversations, emails, chats, IPs, Device IDs, and other means. The purposes for which this data may be used include but are not limited to:

 

  • Account Management: We may process Personal Data to manage accounts, including opening new accounts, closing accounts, and updating.
  • Transaction Processing: We may use Personal Data to process financial transactions such as deposits, withdrawals, transfers, collection and payments.
  • Risk Assessment and Fraud Prevention: We may analyse Personal Data to assess the risk associated with providing you with services and to prevent fraudulent activities.
  • Credit Assessment: We may use Personal Data to assess customers' creditworthiness when applying for loans, mortgages, or credit cards.
  • Customer Service: We may use your Personal Data to provide you with support, handle inquiries, and resolve issues related to accounts and transactions.
  • Marketing and Promotions: Given your consent, we may use your Personal Data for marketing purposes, such as offering new products or promotions tailored to customers' financial needs and preferences.
  • Compliance with Legal and Regulatory Requirement: We may possess your Personal Data to comply with various legal and regulatory requirements, including anti-money laundering (AML) and know your customer (KYC) regulations.
  • Account Reporting and Statements: We may use your Personal Data to generate account statements, reports, and other financial documents.
  • Security and Authentication: We may use your Personal Data for security purposes, including authentication of identities and protecting against unauthorized access to accounts.
  • Research and Analysis: We may use your Personal Data for research and analysis purposes to improve products and services, develop new offerings, and better understand customer behaviour and preferences.
  • Complaint Handling and Dispute Resolution: We may use Personal Data to handle complaints, disputes, and inquiries effectively and efficiently.

When we rely on consent as the legal basis for processing (refer to section 4), we will provide you with comprehensive details about the information required and its purpose. This empowers you to make informed decisions about consenting to the processing of your Personal Data.

You have certain rights regarding your processed Personal Data. For more information about your rights and how to exercise them, please (refer to section 9) of this Privacy Notice. This section provides comprehensive details on your rights and outlines the process for exercising them. Please be aware that processing your Personal Data is necessary to provide you the products or services. Not collecting Personal Data can expose us to a wide range of risks, including regulatory non-compliance, increased fraud, diminished customer insights, and /or reputational harm.

 

4. Purposes and Legal Basis for Processing

We will only collect and use your Personal Data in accordance with the requirements under the KSA PDPL. In most cases, our legal justification will be:

 

Your Consent, where Parents and legal guardian consent will be obtained for processing Personal Data related to children and incompetents’.

Processing achieves a definite interest for you, and it is impossible or difficult to contact you.

Processing is required by applicable Laws and is performed in accordance with them.

Processing is performed in order to perform an agreement to which you are a party.

Processing is necessary for the purpose of our legitimate interest.

 

5.Other Purposes

Our aim is to use your Personal Data in alignment with the legal basis (refer to section 4) above. However, it's important to note that in accordance with the Law, we reserve the right to process your Personal Data for other purposes (beyond those specified in section 4). This may occur in the following scenarios:

 

If you give your consent to such collection and processing.

If your Personal Data is publicly available, or if it was collected from a publicly available source.

If collection and processing is required for your vital interests.

If collection or processing of your Personal Data is necessary to protect public health or safety, or to protect the life or health of you or other individuals.

If your Personal Data is recorded or stored in a form that makes it impossible to identify you directly or indirectly.

Collection of your Personal Data is necessary to achieve our legitimate interests (in this case we will not process your Sensitive Data, e.g. health data).

 

6. Disclosure

As necessitated by the purposes listed (refer to section 4) above, we reserve the right to disclose your Personal Data, which is defined under the KSA PDPL as enabling any person other than us to access, collect, or use personal data by any means and for any purpose.  Disclosure may occur in the following cases:

 

Other subsidiaries and/or entities within the SNB Group.

Our contractors who provide us with professional or management services, such as IT companies, etc.

Insurance, health or legal services, etc.

Any applicable regulatory authorities (governmental and other public bodies, etc.) or other third parties as could be required by Law or in accordance with other regulatory obligations or policies applicable to us or to you.

 

We may disclose your Personal Data in accordance with KSA PDPL in the following cases:

 

You consent to the disclosure.

Your Personal Data has been collected from a publicly available source.

The entity requesting disclosure is a public entity, and the collection or processing of your Personal Data is required for public interest or security purposes, or to implement another Law, or to fulfil judicial requirements.

The disclosure is necessary to protect public health, public safety, or to protect the lives or health of specific individuals.

The disclosure will only involve subsequent processing in a form that makes it impossible to directly or indirectly identify you.

The disclosure is necessary to achieve our legitimate interests (in this case no Sensitive Data (e.g. Health Data, Credit Data) will be processed).

 

7.Transfer

We may share your Personal Data with internal parties (e.g. SNB entities) and external parties (e.g. regulatory authority, service providers, partners, etc.) including those of children and incompetents for processing to the extent necessary to fulfil the purposes listed above (refer to section 4). In some circumstances where the Law permits, this will involve us transferring your Personal Data outside KSA. Such transfers will adhere to the legal provisions concerning cross-border transfers of Personal Data, as stipulated by the KSA PDPL and the relevant laws and regulations.

 

8. Data Security

We have implemented suitable technical measures, administrative controls, and legal safeguards to:

 

●Safeguard your Personal Data and Sensitive Data, including data pertaining to children and incompetents from accidental loss, unauthorized access, misuse, alteration, or disclosure (such as access control, network security, and communication security protocols).

●Address any suspected Personal Data breaches promptly and thoroughly, in accordance with legal requirements. Should such a breach occur, we will notify you and the Competent Authority as mandated by the KSA PDPL.

 

9. Retention 

We will retain your Personal Data (including Personal Data related to children and incompetents) for the period required by KSA PDPL or any other period necessary for us to meet our operational obligations such as maintaining accounts, facilitating client relationship management, responding to legal claims or regulatory requests, etc.

 

10.Your right

In accordance with the KSA PDPL, you are entitled to exercise the following rights:

 

  1. Right of access: You may obtain access to your Personal/Sensitive Data which we hold about you.
  2. Right to be informed: You have the right to be informed about the legal basis and the purpose of the collection and processing.
  3. Right to request obtaining Personal Data: You are entitled to request a copy of your Personal/Sensitive Data (held by us) in a readable and clear format.
  4. Right to request correction/completing or updating: You have the right to request correction, completion or updating your Personal Data/Sensitive Data if you believe that any of the collected Personal/Sensitive Data we are holding is incorrect or incomplete.
  5. Right to request the destruction of Personal Data: The bank is entitled to retain your Personal/Sensitive Data in accordance with applicable laws, regulations, or judicial requirements, and for any legitimate interest as permitted by law.
  6. Right to withdraw consent: While you have the right to withdraw consent for processing your personal data, please be aware that there are situations where this right may be limited:
    1. If the bank is required to retain your Personal/Sensitive Data under applicable laws or regulations or by judicial requirement.
    2. If the processing of your Personal/Sensitive Data is essential to fulfil a contract or provide a service to you where your personal/sensitive data is necessary for the completion.
  7. Right to submit a complaint to the competent authority: You have the right to submit a complaint to the competent authority within (90) days from when incident occurred, or as soon as you are aware of it.

You may submit a request to exercise your rights by filling out the Data Subject Request Form and share it with DataSubjectRightRequest@alahli.com

 

11. Social media

SNB operates across multiple social media platforms to inform, assist, and engage with you, with the aim of enhancing our products and services. We kindly ask that you refrain from sharing Personal or Sensitive Data on our social media channels. It's important to note that SNB is not responsible for any information shared on these platforms, except for content posted by our authorised employees.

 

12. Marketing from us

We may use your Personal Data for marketing/advertising purposes to inform you about our products and services based on the consent provided. You may ask us to stop sending the marketing messages by contacting the SNB Customer Care department (+ 966 92000 1000 / contactus@alahli.com).

 

13.Your use of our website

We may use cookies solely for fraud prevention purposes. A cookie is a small piece of information stored on your computer's hard drive, tracking your interactions with a website (‘Cookies’). This enables us to detect and prevent fraudulent activities.

 

14. Review and updates

This Privacy Notice is subject to periodic updates. You can find the latest updates by referring to the last update date on our website.

 

15.Contact us

Maintaining the accuracy and currency of your Personal Data is very important for us. For inquiries about our Privacy Notice or further details, please contact (+ 966 92000 1000 / contactus@alahli.com / DataSubjectRightRequest@alahli.com)