PRIVACY POLICY

 

General principles

Odotobri Community Bank PLC is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information, and the principles that guide our approach. We comply with the requirements of the Ghana Data Protection Act, 2012 (Act 843). In accordance with the Act, we base on the following to collect your data:

 

 

PERSONAL DATA

Personal data refers to any information that identifies you directly or indirectly as an individual customer of the bank.

 

Types of personal data we collect include:

Identification Information: Full name, date of birth, gender, national ID/passport number, and photographs used to confirm your identity.

Contact Information: Phone number, email address, residential and postal address for communication purposes.

Financial Information: Bank account details, transaction history, income details, credit history, and loan records.

Employment Information: Employer name, job title, and income level, especially when assessing creditworthiness.

Technical and Usage Data: IP address, device information, login activity, and online banking usage to ensure system security.

Legal and Compliance Data: Information is collected for regulatory purposes such as anti-money laundering (AML) and Know Your Customer (KYC) checks.


WHY DO WE COLLECT YOUR PERSONAL DATA?

We collect personal data to provide secure banking services and to meet legal and regulatory obligations.

 

Reasons for collection include:

To deliver banking services: Opening accounts, processing transactions, issuing cards, and managing loans.

To verify your identity: Preventing fraud, identity theft, and financial crime.

To meet legal and regulatory requirements: Complying with banking laws, AML regulations, and reporting obligations.

To improve our services: Understanding customer needs and enhancing products and customer experience.

To communicate with you: Sending account updates, security alerts, and service-related notifications.


Automated Decision-making?

Automated decision-making occurs when decisions are made using technology without direct human involvement.

 

We may use automated decision-making when:

Assessing loan or credit applications: Systems may automatically evaluate affordability and credit risk.

Monitoring transactions for fraud: Automated tools detect unusual activity to protect your account.

Complying with regulatory screening: Systems check customer details against sanctions and watchlists.

Personalizing services: Offering relevant products based on your banking behavior.

 

Where required by law, customers retain the right to request human review of significant automated decisions.

 

 

Sharing of Your Personal Information

 

We do not sell or unlawfully disclose your personal information. Your information may be shared only where necessary, including:

 

With regulatory authorities, including the Bank of Ghana, where required by law

 

With service providers and partners who support our operations, under strict confidentiality and data protection obligations

 

Where disclosure is required or permitted by law

 

Your Rights Under the Law

 

 

Data may be shared with:

 

Regulators and government authorities: When required by law (e.g., central bank, tax authorities, law enforcement).

Service providers and partners: Such as payment processors, IT support providers, and credit bureaus under strict confidentiality agreements.

Other financial institutions: For transaction processing, fraud prevention, or interbank services.

Auditors and professional advisers: To ensure compliance with legal and financial standards.

 

We do not sell customer personal data to third parties.

Where do we transfer personal data?

Personal data may be transferred to locations where processing or storage is required to deliver banking services.

 

Data transfers may occur:

 

Within the country: Between our branches, departments, and secure data centers.

 

Outside the country (international transfers): Where we use international service providers (e.g., cloud services, card networks like Visa/Mastercard).

With appropriate safeguards: All transfers are protected using contracts, encryption, and data protection standards to ensure your information remains secure.

 

 

ACCESS TO PERSONAL INFORMATION

1.         A data subject (customer) who provide proof of identity may request the data controller (Bank):

a.         Confirm at reasonable cost to the data subject whether or not the data controller holds personal information about that data subject.

b.         Give a description of the data which is held by the party, including data about the identity of the third party or a category of a third party who has or has had access to the information, and

c.         Correct data held on the data subject by the data controller.

2.         The request shall be made:

a.         Within a reasonable time;

b.         After the payment of the prescribed fee, if any; 

c.         In a reasonable manner and format; and

d.         In a form that is generally understandable.

 

 

CORRECTION OF PERSONAL DATA

1.         A data subject may request data controller to:

a.         Correct or delete personal data about the data subject held by or under the control of the bank that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, or

b.         Destroy or delete a record of personal data about the data subject held by the data controller that the data controller no longer has the authorization to retain.

2.         On receipt of the request, the data controller shall comply with the request or provide the data subject with credible evidence in support of the data.

3.         Where the data controller and the data subject are unable to reach an agreement and if the data subject make a request, the data controller shall attached to the record an indication that the request for the data has been made but has not been complied with.

4.         Where the data controller complies with the request, the data controller shall inform each person to whom the personal information have been disclosed of the correction made.

5.         The data controller shall notify the data subject of the action taken as a result of the

request.

 

RIGHT TO PREVENT PERSONAL DATA FOR DIRECT MARKETING

1.         The Bank shall not provide, use, obtain, procure or provide information related to a data subject for the purposes of direct marketing without the prior written consent of the data subject. 

2.         A data subject is entitled to at any point in time by notice in writing to the Bank to require the Bank not to process personal data for the purposes of direct marketing.

3.         Where the Commission is satisfied on a complaint by a person who has given notice and the Bank fails to comply, the Commission may order the Bank to comply.

4.         In respect of this policy, direct marketing includes the communication by whatever means of advertising or marketing material which is directed to particular individual or entity.

 

DATA BREACH RESPONSE

1.         Notification:

In the event of data breach, the Bank shall notify the relevant authorities and the affected data subjects.

2.         The Bank shall investigate the data breach and take appropriate action to mitigate its effects.

 

COMPENSATION FOR FAILURE TO COMPLY

 

Where an individual suffers damage or distress through the contravention by the Act, the individual who suffered the breach shall be entitled to compensation from the Bank for the damage or distress.  

 

REVIEW AND UPDATE

This policy shall be reviewed and updated to ensure it remains effective and compliant with relevant laws and regulations.

 

For questions, requests, or concerns regarding this Privacy Policy or the handling of your personal information, please contact:

 

Data Protection Officer

Odotobri Community Bank PLC

Jacobu Ashanti