Skip to main content
Personal data is information which directly or indirectly identifies you. We at Investec Bank plc are committed to processing your personal data in accordance with UK data protection laws. For the purposes of UK data protection laws, Investec Bank plc is the controller.
 
Collecting your personal data

We may collect your personal data in several ways, including from:

  • you, for example, when you:
    1. apply for and use our products and services
    2. call us, we will monitor and/or record your telephone calls
    3. enter into any agreement with us
    4. contact and interact with us
    5. attend events, participate in surveys, prize draws or competitions
  • someone else for example, if a person applies for a joint account with you they may share your personal data with us or if you are a stakeholder in or manager of a business, and the business applies for products or services or enters into an agreement or interacts with us, we may obtain personal data about you to carry out checks against the business
  • third parties such as credit reference agencies, fraud prevention agencies, financial advisors, introducers
  • public sources for example, Companies House
  • introducers (e.g. an independent financial adviser) 
What personal data we collect

Types of information we may collect includes:

Type of informationExamples of information
Personal details
  • date of birth
  • contact details
  • nationality
  • tax details
  • employment details
  • regulatory history (where applicable)
Financial information
  • income and outgoings
  • assets and liabilities
  • bank details
  • account information and history
  • account activity
  • credit history and information (where applicable)
  • shareholdings (where applicable)
Information we have from our dealings with you or from anyone acting on your behalf (“transactional details”)
  • recordings of telephone calls with us
  • records of our interactions/correspondence with you
  • details of your transactions
Sensitive personal data: only with explicit consent or where authorised by law
  • biometric data, such as voice or fingerprint information
If you give us information about somebody else

If you give us personal data about another person, you must make sure you are entitled to share it with us and, that you have given them a copy of this Data Protection Notice or otherwise told them how we will use their personal data. We may ask for information to confirm that you are authorised to provide it.

How we will use your personal data

We may use the categories of personal data described above, depending on the product or service requested and the nature of our relationship with you. This may include personal details, financial information, transactional details, information from our dealings with you or anyone acting on your behalf, credit reference and fraud prevention information, communications records, marketing preferences and, where relevant and permitted by law, sensitive personal data such as biometric data. Not all categories will be used for every purpose:

Purposes for ProcessingLegal Bases for Processing
For identity verification, onboarding, customer due diligence, sanctions / PEP / source-of-funds checksAs necessary to enter your client agreement

To comply with our legal / regulatory obligations
To provide products and/or services requested by you and to operate your accountsAs necessary to perform your client agreement
For account administration, transactions, service messages, customer support and general communicationsAs necessary to perform your client agreement

To comply with our legal / regulatory obligations

Our legitimate interest to manage the relationship, respond to enquiries, keep service records
To assess creditworthiness, affordability and lending decisionsAs necessary to enter or perform your client agreement

To comply with our legal / regulatory obligations

Our legitimate interest for risk management purposes
CRA checks and reportingAs necessary to enter your client agreement

To comply with our legal / regulatory obligations

Our legitimate interest to manage credit risk, prevent fraud, support debt recovery, run accounts responsibly
For fraud prevention, account security, scam and APP fraud checks, and FPA data sharingTo comply with our legal / regulatory obligations

Our legitimate interest to prevent fraud, money laundering, scams and unauthorised account misuse, and to protect customers and the bank
For debt tracing, arrears management and debt recoveryAs necessary to perform your client agreement

Our legitimate interest to recover sums lawfully owed and manage credit risk
For complaints, ombudsman matters, investigations, litigation, rights enforcementTo comply with our legal / regulatory obligations

Our legitimate interest to respond to complaints, investigate disputes, defend or bring claims, preserve evidence
To administer surveys, prize draws, competitions and customer feedbackWhere required by law, we will obtain your consent.

Our legitimate interest in improving services and understanding customer experience
To host and manage events / hospitalityOur legitimate interest in running events relevant to clients and prospects
For analytics, service improvement and market researchOur legitimate interest to understand service usage, improve journeys, reduce friction and fix defects
For corporate transactions, due diligence, reorganisation and sale of assetsOur legitimate interest to evaluate and complete group or business transactions
To send you marketing communicationsWhere required by law, we will obtain your consent before sending you marketing communications.

Our legitimate interest in promoting our relevant products and services

You can opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us using the details below
For day-to-day business administration, accounting, internal reporting, audit, governanceTo comply with our legal / regulatory obligations

Our legitimate interest to run the bank safely, document decisions, manage finance and governance
For call recording and communication monitoringTo comply with our legal / regulatory obligations

Our legitimate interest for training, QA, security, evidence, complaint resolution


You have a right to object to processing of your personal data where that processing is carried out for our legitimate interest or for direct marketing purposes.

Consequences of not providing your personal data

Where we require your personal data to comply with contractual or legal requirements, failure to provide this information means we may not be able to provide goods / services to you.

How we will use your personal data to make automated decisions

Detecting and preventing fraud

We use real-time fraud detection systems to help identify suspected fraudulent use of your account. These systems make automated decisions based on information such as fraud patterns and unusual account activity, and may use your personal data for this purpose. For example, unusual activity on your account may indicate a risk of fraud. If we identify a potential fraud risk, we may take action to protect your account, including blocking transactions (such as, declining a card payment) or restricting access to your account. You have the right to object to a decision based solely on automated processing and to request that the decision is reviewed by a person.

Use of artificial intelligence (“AI”)

We may use artificial intelligence and similar technologies to help us provide and manage our products and services, including for fraud and financial crime prevention, regulatory compliance, service improvement, personalization, analytics, request triage, quality monitoring and staff support. We use AI only where we have a lawful basis, as explained in this Data Protection Notice.

We will not use AI as the sole basis for decisions that have a legal or similarly significant effect on you unless we tell you and provide the information and safeguards required by law, including how you can ask for human review or challenge the decision.

We use governance, testing, monitoring and human oversight designed to keep AI use fair, secure and accurate. Where we use third-party AI providers, we require appropriate contractual, security and data protection safeguards and do not allow them to use your personal data to train their AI models for their own purposes.

How we will disclose your personal data

We may disclose certain personal data as follows:

  • to other affiliates in the Investec Group. Investec Group consists of Investec Bank plc (a company registered in the UK) and Investec Limited (a company registered in South Africa) and any of their direct or indirect subsidiaries and/or holding companies
  • to our professional advisors, insurers, receivers and administrators 
  • to our service providers who help us provide, operate and administer our products and services
  • to courts, governmental and non-governmental agencies, regulators and ombudsmen
  • to law enforcement agencies
  • to relevant tax authorities
  • to any relevant third party during an acquisition, sale, transfer, reorganisation or merger of parts of our business or our assets
  • to any relevant third party involved with the products or services we provide to you, such as a custodian
  • as required or permitted by law or regulation, where we are under a duty to disclose or share your personal data to comply with any legal obligation or to protect the rights, property, or safety of the Investec Group, our clients, or others
  • where you have been introduced to us by an introducer (e.g. an independent financial adviser), unless you have told us not to, we will inform the introducer of the outcome of the enquiry including whether we have agreed to provide you with the relevant product or service
  • to credit reference agencies. See CRA section below
  • to fraud prevention agencies. See FPA section below
Credit Reference Agencies

To assess your application and, where relevant, manage your account, we may check your identity and carry out credit reference and affordability searches with one or more credit reference agencies (“CRAs”). We share your personal data with CRAs, and they give us information about you, including credit application data, account performance, financial links, public records and fraud-prevention information. We use this to assess creditworthiness and affordability, verify identity and information you provide, manage your account, prevent fraud and money laundering, trace debts and make appropriate product or service decisions. CRA searches may leave a record on your credit file that other lenders may see. If you make a joint application, or have a financial associate, CRA records may be linked and may remain linked until a successful disassociation request is made. Further information about how the CRAs use and share personal data, retention periods and your rights is available in the CRA Information Notice available here.

Fraud Prevention Agencies

We may share your personal data with fraud prevention agencies (“FPA”) to help prevent fraud and money-laundering and to verify your identity before providing products / services to you. If fraud or suspicious activity is identified, we may refuse to provide certain services or financing to you. A record of any fraud or money laundering risk will be retained by the FPA, and may result in others refusing to provide services, financing or employment to you. Further information about how we and the FPAs use your personal data, can be found here.

Transfer of Personal Data Outside the United Kingdom (“UK”)

We may transfer your personal data outside the UK, including within our group (e.g., in South Africa and India) and to other recipients as identified above. Where we do so, we will make sure the transfer is permitted under UK data protection law, for example because the destination is covered by UK regulations approving transfers, because we use appropriate safeguards such as the UK International Data Transfer Agreement or Addendum, or because a limited legal derogation applies. You can ask us for more information about the transfer mechanism used for a particular transfer by contacting the Data Protection Officer using the contact details provided below.

Your data protection rights

You have the right – subject to certain limitations - to:

  • request access to and rectification or erasure of your personal data
  • obtain restriction of processing or to object to processing of your personal data
  • request the transfer of personal data to another controller
  • make a complaint about our handling of your personal data 

If you wish to exercise any of these rights, you should contact the Data Protection Officer as described below. You also have the right to lodge a complaint about the processing of your personal data with your competent data protection authority.

Marketing

We may contact you periodically to provide information regarding events, products, services and content that may be of interest to you and to invite you to participate in market research. If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent.

If you wish to stop receiving marketing or market research communications from Investec Bank plc you can click on the unsubscribe link in the marketing communication or contact the Data Protection Officer as described below.

Security of personal data

We use appropriate technical and organisational measures designed to protect your personal data, taking into account the nature of the data and the risks of processing.

Retention of personal data

We keep personal data only for as long as necessary for the purposes described in this Data Protection Notice. The period will depend on the type of data, the product or service involved, and any legal or regulatory requirements that apply. In general, we keep core customer and account records for the duration of the relationship and for a further period afterwards to deal with complaints, legal claims, fraud prevention, regulatory obligations and audit requirements. We keep anti-money laundering customer due diligence records for the period required by law. Where we no longer need personal data, we delete it or anonymise it. If there is a legal claim, investigation, complaint or regulatory matter, we may keep relevant data for longer.

Changes to this Data Protection Notice

We may revise this Data Protection Notice from time to time to reflect for example, any changes in our business, law, markets, and/or the introduction of any new technology. We will publish the updated Data Protection Notice on our website here.

Enquiries, requests, complaints or concerns

All enquiries, requests, complaints or concerns regarding this Data Protection Notice or relating to the processing of personal data, including requests to exercise your data protection rights, should be sent to the Data Protection Officer at Investec Bank plc, 30 Gresham Street, London, EC2V 7QP or by email to dataprotection@investec.co.uk.

We are committed to working with you to resolve any complaint or concern.  We will acknowledge your complaint within 30 days, or any shorter period required by law, and keep you informed of progress.