Privacy Policy Statement
UCO Bank Limited Hong Kong Branch — Personal Data (Privacy) Ordinance Compliance
1. Introduction
This Statement is adopted as the Privacy Policy Statement ("Statement") of UCO Bank Limited Hong Kong Branch (the "Bank"). The purpose of this Statement is to establish the policies and practices of the Bank's commitment to protect the privacy of personal data and to act in compliance with the provisions of the Personal Data (Privacy) Ordinance (the "Ordinance") and implementation of the guidelines thereon issued by the Hong Kong Association of Banks. The provisions of this Statement are supplement to Annexure 1 Personal Data (Privacy) Ordinance ("PDPO") Notice to General Terms and Conditions Governing Accounts and Secured Loan Facilities of the Bank.
As an overseas Branch in Hong Kong, the Bank is required to establish its own policies and practices to ensure full compliance with the applicable legal and regulatory requirements in their respective jurisdictions relating to personal data protection.
2. Kinds of Personal Data Held by The Bank
There are two broad categories of personal data held in the Bank. They are personal data related to customers and (potential) employees of the Bank.
2.2 Customer Personal Data may include:
- Name and address, occupation, contact details, date of birth and nationality, marital status, and identity card and/or passport numbers
- Current employer, nature of position and annual salary
- Information obtained in the ordinary course of the business relationship (cheques, deposits, verbal or written communications, telephone recordings)
2.3 Employment-related Personal Data may include:
- Name, address, contact details, date of birth and nationality of employees and their spouses, and identity card and/or passport numbers
- Information about potential employees compiled during recruitment, including references
- Records of remuneration, job postings, transfers, training, medical checks, sick leave, and performance appraisals
- Relevant data pertaining to former employees required to fulfil legal obligations
- Information which is in the public domain, if required
The Bank may hold other kinds of personal data which it needs in the light of experience and the specific nature of its business.
3. Purposes The Personal Data Are Held
It is necessary for customers to supply the Bank with data in connection with the opening or continuation of accounts and the establishment or continuation of banking facilities or provision of banking and other financial services. Data are also collected in the ordinary course of the continuation of the banking relationship.
3.3 Purposes for customer data:
- Processing of applications for, and daily operation of, services and credit facilities
- Conducting credit checks and data verification
- Assisting other financial institutions to conduct credit checks and collect debts
- Ensuring ongoing creditworthiness of customers
- Designing financial services and/or related products
- Marketing financial services or related products to customers
- Determining the amount of indebtedness owed to or by customers
- Creating and maintaining the Bank's credit and risk related models
- Collection of amounts outstanding and bills providing security for obligations
- Meeting disclosure requirements under applicable laws, rules, regulations, orders, or directives
- Enabling actual or proposed assignees of the Bank to evaluate transactions
- Any other purposes permitted by law
3.4 Purposes for employee and potential employee data:
- Processing employment applications
- Determining and reviewing salaries, bonuses and other benefits
- Consideration for promotion, training, secondment or transfer
- Administration of staff loans and other benefits and entitlements
- Providing employee references
- Registering employees as intermediaries or licensees with statutory authorities
- Monitoring compliance with internal rules of the Bank
- Meeting disclosure requirements under applicable laws or regulatory guidelines
4. Security of Personal Data
It is the policy of the Bank to ensure an appropriate level of protection for personal data in order to prevent unauthorised or accidental access, processing, erasure or other use of that data, commensurate with the sensitivity of the data. The Bank achieves appropriate security protection by restricting physical access to data, providing secure storage facilities, and incorporating security measures into equipment in which data is held. Measures are taken to ensure the integrity, prudence, and competence of persons having access to personal data. Data is only transmitted by secure means to prevent unauthorized or accidental access. Where a data processor is engaged, the Bank adopts contractual or other means to prevent unauthorized or accidental access, processing, erasure, loss or use of the transferred data.
5. Accuracy of Personal Data
It is the policy of the Bank to ensure accuracy of all personal data collected and processed. Appropriate procedures are implemented to provide for all personal data to be regularly checked and updated to ensure it is reasonably accurate having regard to the purposes for which that data is used. Where data consists of statements of opinion, all reasonably practicable steps are taken to ensure that any facts cited in support are correct. Where a data processor is engaged, the Bank adopts contractual or other means to prevent personal data from being kept longer than is necessary for processing.
6. Collection of Personal Data
In the course of collecting personal data, the Bank will provide individuals with a Personal Data (Privacy) Ordinance Notice informing them of the purpose of collection, classes of persons to whom the data may be transferred, their rights to access and correct the data, and other relevant information.
Prior to collecting any personal data from the public domain, the Bank will observe the original purposes of making the personal data available and any restrictions imposed by the original data users.
6.3 On-line data collection practices:
a. On-line Security
The Bank follows strict standards of security and confidentiality. Encryption technology is employed for sensitive data transmission on the Internet.
b. On-line Correction
Personal data provided online, once submitted, may not be deleted, corrected or updated on-line. Users should approach relevant members of the Bank for corrections.
c. On-line Retention
Personal data collected on-line will be retained normally for a period of not longer than 8 years. No personal data (name, mobile number, personal email address) collected via on-line is shared with any third party vendor.
6.4 Use of Cookies, Tags and Web Logs
Cookies are small pieces of data transmitted from a web server to a web browser, stored locally to allow a website to maintain information on a particular user. Cookies are designed to be read only by the website that provides them and cannot obtain data from a user's hard drive or gather sensitive information.
The Bank uses cookies, tags and web tags for:
- Session identifier: To identify a user during a session without storing sensitive information in cookies.
- Analytical Tracking: Users' visits are recorded anonymously for analysis of demographics, interests, and usage patterns. No personally identifiable information is collected.
- Google Analytics: Used to collect anonymous information on how visitors use our website, including number of visitors, referral sources, and pages visited.
7. Data Access Requests and Data Correction Requests
It is the policy of the Bank to comply with and process all data access and correction requests in accordance with the provisions of the Ordinance, and for all staff concerned to be familiar with the requirements for assisting individuals to make such requests.
The Bank may, subject to the Ordinance and guidelines issued by the Privacy Commissioner for Personal Data, impose a fee for complying with a data access request ("DAR"). The Bank is only allowed to charge for costs directly related to and necessary for complying with a DAR.
Data access and correction requests may be addressed to the Bank's Data Protection Officer ("DPO") or other person as specifically advised.
8. Retention of Personal Data
The Bank shall usually hold data relating to the customer(s) for a period of at least eight years after the business relationship is ended or such other period as prescribed by applicable laws and regulation after closure of account/termination of service.
9. Appointment of Data Protection Officer
To co-ordinate and oversee compliance with the Ordinance and the personal data protection policies of the Bank, a Data Protection Officer (DPO) has been appointed by the Bank.
Contact Details of the Data Protection Officer:
Data Protection Officer
UCO Bank, Hong Kong Branch
2/F, Astoria Building, Ashley Road,
Tsim Sha Tsui, Kowloon, Hong Kong
Telephone: (852) 2524 9240
Fax: (852) 2810 6954
Website: www.ucobankhongkong.com
UCO Bank Limited Hong Kong Branch — Privacy Policy Statement
Download PDF