Data Protection Notice
Investec Bank plc
Personal data is information which directly or indirectly identifies you. We at Investec Bank plc are committed to processing your personal data in accordance with UK data protection laws. For the purposes of UK data protection laws, Investec Bank plc is the controller.
Collecting your personal data
We may collect your personal data in several ways, including from:
- you, for example, when you:
- apply for and use our products and services
- call us, we will monitor and/or record your telephone calls
- enter into any agreement with us
- contact and interact with us
- attend events, participate in surveys, prize draws or competitions
- someone else for example, if a person applies for a joint account with you they may share your personal data with us or if you are a stakeholder in or manager of a business, and the business applies for products or services or enters into an agreement or interacts with us, we may obtain personal data about you to carry out checks against the business
- third parties such as credit reference agencies, fraud prevention agencies, financial advisors, introducers
- public sources for example, Companies House
- introducers (e.g. an independent financial adviser)
What personal data we collect
Types of information we may collect includes:
| Type of information | Examples of information |
| Personal details |
|
| Financial information |
|
| Information we have from our dealings with you or from anyone acting on your behalf (“transactional details”) |
|
| Sensitive personal data: only with explicit consent or where authorised by law |
|
If you give us information about somebody else
If you give us personal data about another person, you must make sure you are entitled to share it with us and, that you have given them a copy of this Data Protection Notice or otherwise told them how we will use their personal data. We may ask for information to confirm that you are authorised to provide it.
How we will use your personal data
We may use the categories of personal data described above, depending on the product or service requested and the nature of our relationship with you. This may include personal details, financial information, transactional details, information from our dealings with you or anyone acting on your behalf, credit reference and fraud prevention information, communications records, marketing preferences and, where relevant and permitted by law, sensitive personal data such as biometric data. Not all categories will be used for every purpose:
| Purposes for Processing | Legal Bases for Processing |
|---|---|
| For identity verification, onboarding, customer due diligence, sanctions / PEP / source-of-funds checks | As necessary to enter your client agreement To comply with our legal / regulatory obligations |
| To provide products and/or services requested by you and to operate your accounts | As necessary to perform your client agreement |
| For account administration, transactions, service messages, customer support and general communications | As necessary to perform your client agreement To comply with our legal / regulatory obligations Our legitimate interest to manage the relationship, respond to enquiries, keep service records |
| To assess creditworthiness, affordability and lending decisions | As necessary to enter or perform your client agreement To comply with our legal / regulatory obligations Our legitimate interest for risk management purposes |
| CRA checks and reporting | As necessary to enter your client agreement To comply with our legal / regulatory obligations Our legitimate interest to manage credit risk, prevent fraud, support debt recovery, run accounts responsibly |
| For fraud prevention, account security, scam and APP fraud checks, and FPA data sharing | To comply with our legal / regulatory obligations Our legitimate interest to prevent fraud, money laundering, scams and unauthorised account misuse, and to protect customers and the bank |
| For debt tracing, arrears management and debt recovery | As necessary to perform your client agreement Our legitimate interest to recover sums lawfully owed and manage credit risk |
| For complaints, ombudsman matters, investigations, litigation, rights enforcement | To comply with our legal / regulatory obligations Our legitimate interest to respond to complaints, investigate disputes, defend or bring claims, preserve evidence |
| To administer surveys, prize draws, competitions and customer feedback | Where required by law, we will obtain your consent. Our legitimate interest in improving services and understanding customer experience |
| To host and manage events / hospitality | Our legitimate interest in running events relevant to clients and prospects |
| For analytics, service improvement and market research | Our legitimate interest to understand service usage, improve journeys, reduce friction and fix defects |
| For corporate transactions, due diligence, reorganisation and sale of assets | Our legitimate interest to evaluate and complete group or business transactions |
| To send you marketing communications | Where required by law, we will obtain your consent before sending you marketing communications. Our legitimate interest in promoting our relevant products and services You can opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us using the details below |
| For day-to-day business administration, accounting, internal reporting, audit, governance | To comply with our legal / regulatory obligations Our legitimate interest to run the bank safely, document decisions, manage finance and governance |
| For call recording and communication monitoring | To comply with our legal / regulatory obligations Our legitimate interest for training, QA, security, evidence, complaint resolution |
You have a right to object to processing of your personal data where that processing is carried out for our legitimate interest or for direct marketing purposes.
Consequences of not providing your personal data
Where we require your personal data to comply with contractual or legal requirements, failure to provide this information means we may not be able to provide goods / services to you.
How we will use your personal data to make automated decisions
Detecting and preventing fraud
We use real-time fraud detection systems to help identify suspected fraudulent use of your account. These systems make automated decisions based on information such as fraud patterns and unusual account activity, and may use your personal data for this purpose. For example, unusual activity on your account may indicate a risk of fraud. If we identify a potential fraud risk, we may take action to protect your account, including blocking transactions (such as, declining a card payment) or restricting access to your account. You have the right to object to a decision based solely on automated processing and to request that the decision is reviewed by a person.
Use of artificial intelligence (“AI”)
We may use artificial intelligence and similar technologies to help us provide and manage our products and services, including for fraud and financial crime prevention, regulatory compliance, service improvement, personalization, analytics, request triage, quality monitoring and staff support. We use AI only where we have a lawful basis, as explained in this Data Protection Notice.
We will not use AI as the sole basis for decisions that have a legal or similarly significant effect on you unless we tell you and provide the information and safeguards required by law, including how you can ask for human review or challenge the decision.
We use governance, testing, monitoring and human oversight designed to keep AI use fair, secure and accurate. Where we use third-party AI providers, we require appropriate contractual, security and data protection safeguards and do not allow them to use your personal data to train their AI models for their own purposes.
How we will disclose your personal data
We may disclose certain personal data as follows:
- to other affiliates in the Investec Group. Investec Group consists of Investec Bank plc (a company registered in the UK) and Investec Limited (a company registered in South Africa) and any of their direct or indirect subsidiaries and/or holding companies
- to our professional advisors, insurers, receivers and administrators
- to our service providers who help us provide, operate and administer our products and services
- to courts, governmental and non-governmental agencies, regulators and ombudsmen
- to law enforcement agencies
- to relevant tax authorities
- to any relevant third party during an acquisition, sale, transfer, reorganisation or merger of parts of our business or our assets
- to any relevant third party involved with the products or services we provide to you, such as a custodian
- as required or permitted by law or regulation, where we are under a duty to disclose or share your personal data to comply with any legal obligation or to protect the rights, property, or safety of the Investec Group, our clients, or others
- where you have been introduced to us by an introducer (e.g. an independent financial adviser), unless you have told us not to, we will inform the introducer of the outcome of the enquiry including whether we have agreed to provide you with the relevant product or service
- to credit reference agencies. See CRA section below
- to fraud prevention agencies. See FPA section below
Credit Reference Agencies
To assess your application and, where relevant, manage your account, we may check your identity and carry out credit reference and affordability searches with one or more credit reference agencies (“CRAs”). We share your personal data with CRAs, and they give us information about you, including credit application data, account performance, financial links, public records and fraud-prevention information. We use this to assess creditworthiness and affordability, verify identity and information you provide, manage your account, prevent fraud and money laundering, trace debts and make appropriate product or service decisions. CRA searches may leave a record on your credit file that other lenders may see. If you make a joint application, or have a financial associate, CRA records may be linked and may remain linked until a successful disassociation request is made. Further information about how the CRAs use and share personal data, retention periods and your rights is available in the CRA Information Notice available here.
Fraud Prevention Agencies
We may share your personal data with fraud prevention agencies (“FPA”) to help prevent fraud and money-laundering and to verify your identity before providing products / services to you. If fraud or suspicious activity is identified, we may refuse to provide certain services or financing to you. A record of any fraud or money laundering risk will be retained by the FPA, and may result in others refusing to provide services, financing or employment to you. Further information about how we and the FPAs use your personal data, can be found here.
Transfer of Personal Data Outside the United Kingdom (“UK”)
We may transfer your personal data outside the UK, including within our group (e.g., in South Africa and India) and to other recipients as identified above. Where we do so, we will make sure the transfer is permitted under UK data protection law, for example because the destination is covered by UK regulations approving transfers, because we use appropriate safeguards such as the UK International Data Transfer Agreement or Addendum, or because a limited legal derogation applies. You can ask us for more information about the transfer mechanism used for a particular transfer by contacting the Data Protection Officer using the contact details provided below.
Your data protection rights
You have the right – subject to certain limitations - to:
- request access to and rectification or erasure of your personal data
- obtain restriction of processing or to object to processing of your personal data
- request the transfer of personal data to another controller
- make a complaint about our handling of your personal data
If you wish to exercise any of these rights, you should contact the Data Protection Officer as described below. You also have the right to lodge a complaint about the processing of your personal data with your competent data protection authority.
Marketing
We may contact you periodically to provide information regarding events, products, services and content that may be of interest to you and to invite you to participate in market research. If applicable law requires that we receive your consent before we send you certain types of marketing communications, we will only send you those types of communications after receiving your consent.
If you wish to stop receiving marketing or market research communications from Investec Bank plc you can click on the unsubscribe link in the marketing communication or contact the Data Protection Officer as described below.
Security of personal data
We use appropriate technical and organisational measures designed to protect your personal data, taking into account the nature of the data and the risks of processing.
Retention of personal data
We keep personal data only for as long as necessary for the purposes described in this Data Protection Notice. The period will depend on the type of data, the product or service involved, and any legal or regulatory requirements that apply. In general, we keep core customer and account records for the duration of the relationship and for a further period afterwards to deal with complaints, legal claims, fraud prevention, regulatory obligations and audit requirements. We keep anti-money laundering customer due diligence records for the period required by law. Where we no longer need personal data, we delete it or anonymise it. If there is a legal claim, investigation, complaint or regulatory matter, we may keep relevant data for longer.
Changes to this Data Protection Notice
We may revise this Data Protection Notice from time to time to reflect for example, any changes in our business, law, markets, and/or the introduction of any new technology. We will publish the updated Data Protection Notice on our website here.
Enquiries, requests, complaints or concerns
All enquiries, requests, complaints or concerns regarding this Data Protection Notice or relating to the processing of personal data, including requests to exercise your data protection rights, should be sent to the Data Protection Officer at Investec Bank plc, 30 Gresham Street, London, EC2V 7QP or by email to dataprotection@investec.co.uk.
We are committed to working with you to resolve any complaint or concern. We will acknowledge your complaint within 30 days, or any shorter period required by law, and keep you informed of progress.