At Citi Handlowy, protecting your personal data is one of the most important aspects of our daily operation. This site has been created to provide you with useful information about how we process your personal data and what rights you have in respect of the processing of your personal data by us.
Data subjects have the right to obtain from the controller the information as to whether their data is being processed and to what extent. The data subject also has the right to request access to such data and the right to obtain a copy of the data upon request.
Data subjects have the right to correct personal data processed by the controller, where the data is inaccurate or incomplete. If an error is detected in the data, it is recommended to contact the controller to clarify the issue. It is worth noting that contracts with controllers often require Clients to update their information themselves if there has been a change in their data.
In certain cases, data subjects have the right to erasure of data processed by the controller. This right is also known as the "right to be forgotten” and is applicable in certain cases, including the withdrawal of consent, lack of necessity in relation to the purposes for which the data was collected or data subject’s objection to processing.
Data subjects have the right to request restriction of data processing. The possibility to request such a restriction of data processing occurs when, for example, data was collected incorrectly, there is no basis for processing it or if an objection to processing has been raised.
Data subjects have the right to receive personal data concerning him or her or to transfer such data between different controllers. This right will apply where data is processed by automated means on the basis of consent or a contract.
Where the controller processes data on the basis of legitimate interest, the data subject has the right to object. It is worth noting that if the data subject objects to the processing of his or her data for the purposes of direct marketing, the controller can no longer process data for such purposes.
Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, where the decision produces legal effects concerning him or her or similarly significantly affects him or her unless such processing is permitted by law, based on explicit consent, or is necessary for the performance of a contract.
When signing a contract, data subjects are often asked to provide a copy of their ID card. When entering into a contract with a bank, banks have a legal right to request such a copy. However, many controllers may not be authorized to process such ID copies. If you have doubts, it is recommended to ask about the reason and basis of obtaining such ID copies. You should make sure that your copy will not be used for other purposes. This can be done by, for example, redacting the unnecessary data, putting a watermark on the document, or adding a note that states the purpose of the copy by using a simple program for graphic editing. If it is necessary to send a copy of the ID via electronic means, make sure that the channel through which the copy will be provided ensures an adequate level of security. It is also recommended to encrypt the file and send the password through a separate channel.
According to the instructions of the President of the Office of Personal Data Protection, the PESEL number in combination with other identifying data such as name, surname or address may result in a high risk to the rights and freedoms of natural persons. If an entity asks you to provide your PESEL number, make sure it is necessary and justified. In many cases it may turn out that the collection of such data is not relevant.
There are many ways in which your personal data can be obtained e.g. by phone, email, via a link to a fake website. Make sure you know who wishes to receive your personal or financial information. Do not provide personal information over the phone, by post or online unless you have initiated the contact yourself or know who you are dealing with. If you have doubts as to whether the person who is calling you really represents the entity that he or she claims to represent, please tell them that before you provide your personal data you will disconnect and re-connect with the phone number provided by the entity.
Each person has a different understanding and need for personal data protection. For one person, it will be crucial to protect location data, and for another, the history of online searches. It is very difficult to protect all your data, so you should consider what information is the most important and disclosure of what data would have the most serious consequences for you.
Remember to provide only as much data as you need to – app and service creators often ask for a very wide scope of personal data. When signing a contract or installing an application, you should consider whether it is actually necessary to provide particular data. Perhaps an alternative service or app provider offers the same solution without requesting such a wide scope of data.
Although a number of online services offer a login option using another service, it is worth considering whether this facilitation is really needed. By logging into various services by connecting them with one of the popular social networks, we consent to the exchange of information that is not necessary for the functioning of any of these services separately. And, after all, creating a separate account does not take much more time.
The bank also recommends using a separate email address for less significant services.
The internet has accompanied people for many years and after some time it is difficult to remember all the services, websites and portals on which you have created an account or provided personal data. However, it is worth trying to make such a list. It may turn out that you do not use many of these services anymore and can delete personal data stored there.
After finishing a session, it is worth remembering to correctly log out of the service. Leaving active sessions can leave the data vulnerable to unauthorized access.
It is also worth remembering that some web browsers have the option to save passwords enabled by default. Although this is a very convenient solution, it is not without risk. We recommend disabling password auto save option and using it only where there is a low risk of potential data breach.
When providing personal data or making a financial transaction you need to make sure that you are using a secure website. Secure Socket Layers (SSL) is a commonly used security protocol that provides additional protection for data sent over the Internet. Before submitting data online, always make sure that the site is secure and that it has a valid security certificate.
You can find more information on financial security at the Bank here:
https://www.online.citibank.pl/en/safety.html
Working in your favorite café, though charming, can entail a number of risks for the security of your personal data. When using a public Wi-Fi connection, you should avoid making important operations, such as logging in to your bank or making online payments, as this information may be intercepted by another user of the network or controlled by the Wi-Fi provider. When using publicly available networks, try to limit your activity to the necessary minimum.
Make sure that a breach has actually occurred. Checking the service provider’s website or contacting the Data Protection Officer is a good start. GDPR requires many controllers to appoint a Data Protection Officer and publish their contact details. A DPO will be able to provide you with necessary information about the breach.
What is important is that in certain instances controllers will be required to inform the President of the Office of Personal Data Protection or data subjects that a breach occurred.
If personal data breach occurred on a website you use, consider whether your account on that site was linked to any other service or a card you use. It is worth realizing that the breach has occurred, its scale, the category of data concerned and the real threats that may result from the breach.
Not every breach of personal data will result in the risk of violating your rights or freedoms, but each breach should be treated with due care and diligence.
If the service you are using has become the target of an attack and a personal data breach took place, it is recommended to immediately change your password. This action is recommended even if you are unsure if your data in particular has been compromised. There are websites that will indicate in a secure manner whether your email address has been subject to a breach.
The Bank also recommends using two-step verification, where possible.
Has your card been stolen or lost? Relax, do not panic. The first step you need to take is to report your case to the bank to block your card.
Depending on the bank, you can do this by going to a bank branch, by calling the hotline or using the mobile application or an online account. There is also one common number (48) 828 828 828 maintained by the Polish Bank Association. This number is available from around the world 24 hours a day, 7 days a week. It facilitates the process of contacting the card issuer in order to block a card in situations where time plays a significant role. The only cost for the user (cardholder) is the cost of the phone call, in accordance with the operator's fee table.
Identity theft is a real threat. If a person with bad intentions comes into possession of your ID or other document, you may be subject to identity theft, and e.g. have a loan taken out under your name. That is why it is so important to react as soon as possible if you discover a loss of an identity document.
When you block an ID card, you exclude it from circulation, so that nobody will be able take out a loan using it.
In order to block an ID card, it is recommended to immediately report this fact to the municipal office. In cases where the ID has been stolen, you can also report the theft to the police instead of informing the municipal office.
The bank would like to inform you about the possibility to block the ID in the Blocked Documents system maintained by the Polish Bank Association, as well as to block the use of the PESEL number in the database of lending companies.
Please note that there are entities on the market offering so-called Collector's IDs, which can be hard to differentiate from original IDs, and which can be used by unauthorized persons with malicious intent.
If you are concerned that a breach may result in identity theft, special alerts can be set up. Thanks to them you will be notified as soon as someone tries to obtain a loan or credit in your name.
The system will also notify you when someone looks you up in the debtors register. Thanks to this service you will be notified, for example, that someone wants to sign up for a mobile subscription or enters into a gas supply contract on your behalf.
Controller – the controller is an entity which, alone or jointly with others, determines the purposes and means of the processing of your personal data. Bank Handlowy w Warszawie S.A. with its registered office in Warsaw is the personal data controller.
Personal data – means any information relating to an identified or identifiable natural person (‘data subject’). The examples of personal data that are processed by the Bank include: first name, surname, address of residence, e-mail address, telephone number, PESEL number, date of birth, personal ID card number, bank account number.
Processing – means operations on personal data, such as collecting, organizing, storing, modifying and using them. Personal data processing includes both operations carried out by automated means and by non-automated means (e.g. manual).
The purpose of your personal data processing by the Bank arises from the relationship between you and the Bank. The same natural person may at the same time have several relationships with the Bank (e.g. it may at the same time be a retail client, an additional card holder, a retail client’s attorney, and a corporate client’s representative) and for each of these roles purposes of data processing may be different.
Examples of purposes of personal data processing by the Bank include:
Detailed information about the purposes of personal data processing may be found in information clauses available below in the “Documents” section.
If you are the client of the Bank, you must provide your personal data to conclude and perform an agreement with the Bank. This condition results from performance of the obligations arising out of the legal provisions or is necessary for achievement of the objectives arising out of the Bank’s legitimate interest. The lack of provision of the required personal data may constitute an obstacle to concluding the agreement and provision of services by the Bank.
You can exercise your rights arising from the GDPR by submitting an application in the following manner:
Profiling should be understood as any form of automated processing of personal data consisting in the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
Similarly as the purposes of your personal data processing, the fact whether your data are profiled arises from the type of relationship between you and the Bank. In some processes we use personal data profiling to the extent necessary to conclude or perform an agreement or an obligation imposed on us by legal regulations, e.g. in order to prevent money laundering or terrorism financing, and evaluation of the credit rating. In some processes, in turn, profiling is used to achieve legitimate interests of the Bank as the data controller, e.g. in order to send you a personalized offer.
Detailed information about the personal data profiling may be found in information clauses available below in the “Documents” section.
Global security standards, multi-layered transaction authorization, SMS messages to confirm transactions or notify of a failed login attempt, specialists who monitor the system 24/7 – all this to ensure full security while using Citibank Online at every stage of interaction. For more information visit the website: https://www.online.citibank.pl/en/safety/how-citi-handlowy-protects-you.html
The European Economic Area includes European Union countries, as well as Norway, Iceland, and Liechtenstein). In justified cases (e.g. in order to correctly perform the agreement concluded with you), your data may be made available outside the EEA, however only to the extent permitted by legal regulations in force. Data recipients may be entities with the registered office among other things in the USA, Singapore, India, China, Hong Kong, and Canada, as well as international organizations (e.g. SWIFT).
Detailed information about the personal data transfer outside the EEA may be found in information clauses available below in the “Documents” section.