Regional Development Bank
Privacy Notice
1. Introduction
This Privacy Notice applies to all information held by the Pradeshiya Sanwardena Bank (also known as Regional Development Bank, RDB, PSB or bank) collect, use, process and store about customer’s data pertaining to the products and services offered by the bank as data controller. It comprehensively explains:
- what personal identifiable information we collect.
- how we’ll utilize that information.
- With whom we’ll share.
- when we might share it.
- what actions we’ll take in order to assure it stays private and secure.
The bank highly concerns and respect about each individual’s rights to protects privacy of personal identifiable information(PII). The purpose of this Privacy Notice is to communicate how personal identifiable information is collected and utilized in relation to our banking business operations.
“Personal identifiable Information” is defined as information relating to a natural person who can be identified by using such information (either by itself or when it is combined with other related information).
You’re responsible for making sure the information you have given us is accurate and up to date. You must tell us if anything changes as soon as possible. when you are giving information on behalf of another person, for example, a joint account holder, a beneficiary or a dependent, you’ll need to tell them how to find this notice. You’ll also need to make sure they agree to using their information as described in it.
2. Who we are
The Pradeshiya Sanwardana Bank (PSB) also known as Regional Development Bank (RDB) was established as a statutory body under the Pradheshiya Sanwardana Bank Act No.41 of 2008. The 100% State owned bank was set up with the objective of improving the living standards of the rural population by providing them accessible and affordable credit facilities that in turn would contribute to strengthen the rural economy. The bank is keen on empowering its’ customers in the micro, small and medium scale industries, women as well as the agriculture, livestock and fisheries industries who would in turn contribute towards the country’s economic development.
3. Why We Collect Your Personal Information.
We’ll only use your personal identifiable information with your explicit permission, or we have separate legal obligation for using it. This includes meeting our compliance obligations and to comply with other laws and regulations.
The lawful reasons we use your data include:
- if we have your consent
- our legitimate interest
- legal obligation
- to perform our contract with you
- the public interest.
The bank will mainly collect your data for following activities.
a. To deliver our products and services
We’ll do this to enter into an agreement with you. We’ll maintain our relationship, manage your accounts, and carry out your instructions.
We do this to perform our contract with you.
b. To support banking operations
We’ll use your information to allow the delivery and function of our banking services.
c. Risk management and Credit Assessment
We’ll use your information to measure, detect and prevent the likelihood of financial, reputational, legal, compliance or counterparty risk. This includes credit risk, trade risk, operational risk.
d. To prevent and detect crime.
This includes monitoring, mitigation, and risk management. We’ll complete customer due diligence, name screening, transaction screening and customer risk identification. For example, fraud, terrorist financing and money laundering.
e. Online Banking platforms and Mobile Banking apps
We’ll use your information to allow us to provide you with access to RDB online services and mobile apps. This includes information you provide to us directly or indirectly when using bank’s mobile apps, Online Banking services.
f. Product and service improvement and Data analytics.
We’ll analyses your information to identify possible service and product improvements so we’re able to better suit the needs of our customers. Where we provide you with aggregated information services, we’ll use your information to understand how you use these products, which may include your transactional information from other financial institutions, to help improve our products and services.
g. Marketing
We’ll use your information to provide you with information about RDB products and services, as well as relevant third parties.
h. Protecting our legal rights.
We may need to use your information to protect or defend our legal rights. For example:
- collecting money owed,
- enforcing, or protecting our security
- defending rights of intellectual property
- court action
- managing complaints or disputes
- in the event of a restructuring of bank or other mergers or acquisition.
This may relate to action taken against you or other persons, such as joint borrowers or persons who give a guarantee or other security for your obligations to us.
4. What information we collect
We’ll only collect information about you as allowed by regulations and law. We collect information from a range of sources, such as:
- any of our products or services you apply for, currently hold, or have held in the past
- when you interact with us through our websites, mobile channels, telephone banking or by visiting one of our branches.
- directly from you
- indirectly from other companies, the insurance company providing policies we offer, or other sources you’ve asked us to get information from.
- publicly available sources, for example social media or websites.
- The type of information we collect differs depending on how we’re given it or the products that you hold.
The personally identifiable Information that we collect directly from you, such as:
| Types of information | Examples |
| Personal details | Your name
Your gender Your DOB and place of birth. |
| Contact details | Your postal address
Your email address Your telephone numbers. |
| Information about your identity | Photo identification
Passport information National Driving licenses number National ID card Number Nationality |
| Financial Information
|
Account Numbers
Card Numbers Transactional Information and History Financial Liabilities. Copies of Bank Statements Credit Card Details from other Institutions. Personal Wealth. Assets and Liabilities Borrowing History |
| Information About your Family | PEP Confirmation
Lifestyle and Social circumstances and preferences. |
| Education, Employments and Business Details. | |
| visual images and personal appearance (such as CCTV footages), voice recordings and fingerprints, video of e-KYC verification for digital on boarding. | |
| information relating to transactions performed by you as a customer /card holder of RDB Bank. | |
| when you use our digital /online services following facts will be gathered such as location information (if permission enabled on the device), social media information and activity, login information, Internet Protocol (IP) address, smart device information, mobile phone network information, site visits and spending patterns, information collected by using cookies as per your intervention with us and our online services and applications. | |
5. How We Collect Information
typically, RDB collects your personal information directly from you via KYC forms, mandates, loan applications, etc. or when you visit RDB branch or use our web sites, social media platforms, Digital and online services, engage at public and private events, engage in our marketing campaigns, surveys, etc. the Bank may also collect personal information through third-parties such as;
i) other banks
ii) Correspondent given by you
iii) Credit Information Bureau
iv) Information that is publically available
However, the personal information we collect is strictly limited to the purpose what it is collected.
6. Keeping your information secure.
We use a range of measures, technologies to keep your information safe and secure, which may include encryption and other forms of security. Our employees and any third parties, who carry out work for us, must comply with suitable compliance standards stipulated by bank time to time. This includes the responsibility to protect any information and apply suitable measures for the use and transfer of information.
Therefore, we ensure that your Personal Identifiable Information is stored in order to protect your privacy by assuring confidentiality, integrity and availability of such information as per the legitimate background and enforcement established in Sri Lankan judiciary.
7. How long we’ll keep your information
We keep your information as per our data retention policy. This means, we’ll keep your banking information for six years from when our relationship ends with you.
Sometimes we may need to keep your information for longer duration. The reasons for this include:
- when we need the information to meet regulatory or legal requirements.
- to help detect or prevent fraud and financial crime.
- for our legitimate purposes, such as managing your account or dealing with disputes
- to answer requests from regulators.
If we don’t need to keep information for that much length of time, we may destroy, delete or anonymize it sooner.
8. Sharing or Disclosing Your Information.
We may share your information with others where lawful to do so. The reasons for this may include:
- we or a third party have asked you for your permission to share it, and you’ve agreed.
- to provide you with products or services you’ve asked for, including your insurance policy.
- we have a public or legal duty to do so.
- regulatory reporting, litigation or asserting or defending legal rights and interests.
- to send marketing to you or others, where you’ve given us your permission, or it’s within our legitimate interest to do so.
- corporate restructuring, merger, acquisition or takeover, including any transfer or potential transfer of any of our rights or duties under our agreement with you.
- law enforcement, government, courts, dispute resolution bodies, our regulators, auditors and any party appointed or asked for by our regulators to carry out investigations or audits of our activities.
- fraud prevention agencies who will also use it to detect and prevent fraud and other financial crime and to confirm your identity.
- anybody else that we’ve been asked to share your information with by either you, a joint account holder or anybody else who provides instructions or operates any of your accounts on your behalf.
- our card processing suppliers to carry out credit, fraud, and risk checks, process your payments, issue and manage your card.
- to an external entity or third party who has been engaged by RDB to provide support services. These service providers may be within or outside Sri Lanka.
- with other Banks when responding to Enhanced Due Diligence inquiries.
Unless otherwise permitted by law, prior approval shall be obtained from you before sharing such information.
Sharing aggregated or anonymized information
We may share aggregated or anonymized information within and outside of RDB with third parties such as research groups, universities or advertisers.
9. Your Rights
Subject to prevailing legal and regulatory provisions:
- Right to Access your Information.
- Right to Withdraw Consent.
- Right to Rectify/ Complete.
- Right to Erasure or delete your information.
- Right to request bank to review Automated Decision Making (ADM)
- Right to Appeal.
However, following reasons may lead in order to refusal of your request to enjoying your rights such as:
a. National security
b. Public order
c. Inquiry under a written law
d. Prevent, detect, investigate crime
e. Rights and freedom of other persons under written law
f. Technical or operational feasibility
g. Unable to identify data subject
h. Required under a written law
10. Amendments to the Privacy Notice
We reserve the right to amend our current privacy notice at any time and we will publish any such amendments on the RDB official website.
11. How to Contact Us.
For any inquiries or complaints relating to how RDB handles your personal information, please contact us using the contact details as follows.
Your written request can be forwarded to:
Data Protection Officer.
Regional Development Bank.
Head office,
No 933,
Kandy Road,
KELANIYA.
We are committed to resolving your matter regarding personal information promptly and efficiently.
*****************
