This Privacy Notice outlines HDFC Bank Limited’s (“HDFC Bank”) approach to data protection to fulfil its obligations under the EU General Data Protection Regulation 2016/679 ("GDPR"). This Privacy Notice applies to personal data of the Covered Person(s) which is processed by or for HDFC Bank as a controller, whether in physical or electronic mode. In this Privacy Notice, the expressions ‘personal data’, ‘data subject’, ‘controller’, ‘processor’ and ‘processing’ shall have the meanings given to them in the GDPR.
HDFC Bank is committed to treating data privacy seriously. It is important that you know exactly what we do with the personal data you and others provide to us, why we process it and what it means to you. Please read this Privacy Notice carefully to understand our views and practices regarding your personal data and how we will treat it.
| What we use your personal data for | The legal basis for doing so (one of more under each sub-heading) |
|---|---|
To provide our products and services to you and perform our contract with you.
Recover debts you may owe us.
|
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you.
|
To manage our business for our legitimate interests.
|
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you.
|
To run our business on a day to day basis.
|
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you.
|
To share your information with Indian or other relevant tax authorities, Reserve Bank of India and other government authorities, credit reference agencies, fraud prevention agencies, and India and overseas regulators and authorities.
|
Where the law requires this.
|
To send electronic messages to you about product and service offers from our Bank.
|
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you.
|
We only share your personal data with the following persons and/or in the following circumstances,and only as may be necessary:
Your authorised representatives
Third parties we need to share your personal data with in order to facilitate payments you have requested (for example, SWIFT, credit card issuers and merchant banks) and those you ask us to share your personal data with.
We may also share your personal data with the following third parties to help us manage our business for our legitimate interests:
Statutory and regulatory bodies and authorities (including central and local government) and law enforcement authorities, investigating agencies and entities or persons, to whom or before whom it is mandatory to disclose the personal data as per the applicable law, courts, judicial and quasi-judicial authorities and tribunals, arbitrators and arbitration tribunals.
Overseas regulators and authorities in connection with their duties (such as crime prevention).
Third parties bank may engage to provide services to you.
Processors and service providers of HDFC Bank engaged for its various activities and services.
Credit information companies or Credit reference entities, identity and address verification organizations who may record and use your information and disclose it to other lenders, financial services organizations and insurers. Your information may be used by those third parties to make assessments in relation to your creditworthiness for debt tracing
Other banks and financial institutions, quasi governmental institutions like clearing houses, network associations etc where required in terms of contract or legal requirements
Transferees and assignees and potential transferees and assignees of HDFC Bank
Courier or postal service providers for the purpose of sending or collecting of mails to you as a customer
Any other person or organization after a restructure, sale or acquisition, as long as that person uses your information for the same purposes as it was originally given to us or used by us (or both)
HDFC Bank’s branches in India or outside India, its subsidiaries, Affiliates and group entities.
For further information, please refer to our product specific terms and conditions and application form.
We will keep the personal data we collect about you on our systems or with third parties for as long as required for the purposes set out above or even beyond the expiry of transactional or account based relationship with you: (a) as required to comply with any legal and regulatory obligations to which we are subject or (b) for establishment, exercise or defence of legal claims.
Sharing personal data with us is in both your interest and ours.
We need your personal data in order to:
Provide our products and services to you and fulfil our contract with you.
Manage our business for our legitimate interests.
Comply with our legal obligations.
When we request personal data, we will inform you if providing it is a contractual requirement, a statutory requirement or not, and whether or not we need it to comply with our legal obligations.
You may choose not to share personal data or withdraw consent, but doing so may limit the services we are able to provide to you (unless consent is not the only legal basis for processing and there are other legal basis as well), particularly as under.
We may not be able to provide you with certain products and services that you request. We may not be able to continue to provide you with or renew existing products and services if such collection or updating of personal data is a legal or regulatory requirement to which we are subject.
We may not be able to assess your suitability for a product or service, or, where relevant, give you a recommendation to provide you with a HDFC Bank financial product or service.
However, if you withdraw your consent, it will not affect the lawfulness of processing based on your consent before its withdrawal or the other legal basis which we may have for such processing.
HDFC Bank is incorporated and regulated in India, its overseas branches are regulated by host country regulations and subsidiaries are governed under applicable laws. As such, your personal data is stored on secure systems within HDFC Bank premises within India and with providers of secure information storage in India. Further, we may transfer or allow the transfer of personal data about you and your products and services with us to our service providers and other organisations outside the European Economic Area (EEA), with adequate safeguards to ensure your personal data remains adequately protected.If you need copy of safeguards provided to transferred personal data, please notify us in accordance with the “How to contact us?” section below. These jurisdictions and countries outside EEA may have different and less stringent laws relating to the degree of confidentiality afforded to the personal data and that such information can become subject to the laws and disclosure requirements of such countries, including disclosure to governmental bodies, regulatory agencies and private persons, as a result of applicable governmental or regulatory inquiry, court order or other similar process. In addition, a number of countries have agreements with other countries providing for exchange of information for law enforcement, tax and other purposes.
For example, we may process payments using third parties (including other financial institutions such as banks and the worldwide payments system operated by the SWIFT organisation)
HDFC Bank is ISO 27001:13 compliant. We seek to use reasonable organizational, technical and administrative measures to protect Personal data within our organization. However, if you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “How to contact us?” section below.
You have the following rights, in accordance with and subject to the qualifications and provisions under GDPR:
The right to request from us as the controller, the access to and rectification or erasure of your personal data or restriction of processing concerning you or to object to processing as well as the right to data portability;
Where the processing is based on your consent, the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before such withdrawal. Please however note that in case such processing is also based on other legal basis like our legitimate interest or legal obligation or contractual performance or a necessity for entering into contract, and such legal basis continues to hold good, the processing will be continued despite such withdrawal of the consent.
A right to lodge a complaint with a supervisory authority in accordance with the GDPR.
Right to object
You shall have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which processing is based on necessity for the purposes of legitimate interests pursued by us or third party, including profiling. Upon such exercise of your right, we shall no longer process the personal data unless we demonstrate compelling legitimate grounds: (a) for the processing which override your interests, rights and freedoms or (b) for the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, you shall have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. If you object to this use, we will stop using your information for direct marketing purposes.
If you exercise any of the aforesaid rights, in most instances, we will respond within one calendar month. If we are unable to deal with your request fully within a calendar month (due to the complexity or number of requests), we may extend this period by a further two calendar months. Should this be necessary, we will explain the reasons.However, where we have reasonable doubts concerning your identity, we may request the provisions of additional information necessary to confirm your identity. Ordinarily, we will not charge a fee for the exercise by you of any rights as above. However, we may charge a reasonable fee if your request for access is found to be excessive or unfounded. Alternatively, we may refuse to comply with the request in such circumstances.
If you make your request electronically, we will, where possible, provide the relevant information electronically unless you ask us otherwise.
From time to time, our website may contain links to and from websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites may have their own privacy notices and that we do not accept any responsibility or liability for any such notices. Please check these notices, where available, before you submit any personal data to these websites
If you are a parent of a child under 16 (or such age as applicable for GDPR purposes in the respective EU Member States), you give your consent or authorise the consent if you wish your child to access HDFC Bank Services.