Data Privacy And Protection Policy

1. INTRODUCTION

As part of our operations, Uzondu Microfinance Bank Limited (“Uzondu Microfinance Bank”) collects and processes certain types of information (such as name, telephone numbers, address etc.) of Bank customers that makes them easily identifiable. These customers include active and inactive customers alongside their next-of-kin and other individuals whom Uzondu Microfinance Bank communicate or deals with jointly and/or severally (“Data Subjects”).

Maintaining the Data Subject’s trust and confidence requires that Data Subjects do not suffer negative consequences/effects as a result of providing Uzondu Microfinance Bank with their Personal Data. To this end, Uzondu Microfinance Bank is firmly committed to complying with applicable data protection laws, regulations, rules and principles to ensure security of Personal data handled by the Bank. This Data Privacy & Protection Policy (“Policy”) describes the minimum standards that must be strictly adhered to regarding the collection, storage, use and disclosure of Personal data and indicates that Uzondu Microfinance Bank is dedicated to processing the Personal Data it receives or processes with absolute confidentiality and security.

This Policy applies to all forms of systems, operations and processes within the Uzondu Microfinance Bank environment that involves the collection, storage, use, transmission and disposal of customer data.

Failure to comply with the data protection rules and guiding principles set out in the Nigeria Data Protection Regulations 2019 (NDPR) as well as those set out in this Policy is a material violation of Uzondu Microfinance Bank’s policies and may result in disciplinary action as required, including suspension or termination of employment or business relationship.

2. SCOPE

This Policy applies to all employees of Uzondu Microfinance Bank, customers of the Bank as well as to any external business partners (such as suppliers, contractors, vendors and other service providers) who receive, send, collect, access, or process Personal Data in any way on behalf of Uzondu Microfinance Bank, including processing wholly or partly by any automated means. This Policy also applies to third party Data Processors who process Individual’s data received from Uzondu Microfinance Bank.

3. GENERAL PRINCIPLES FOR PROCESSING OF PERSONAL DATA

Uzondu Microfinance Bank is committed to maintaining the principles in the NDPR regarding the processing of Personal Data.

To demonstrate this commitment as well as our aim of creating a positive privacy culture within the Bank, Uzondu Microfinance Bank adheres to the following basic principles relating to the processing of Personal data:

3.1 Lawfulness, Fairness and Transparency

Personal data must be processed lawfully, fairly and in a transparent manner at all times. This implies that Personal data collected and processed by or on behalf of Uzondu Microfinance Bank must be in accordance with the specific, legitimate and lawful purpose consented to by the Data Subject, save where the processing is otherwise allowed by law or within other legal grounds recognized in the NDPR.

3.2 Data Accuracy

The Personal data must be accurate and kept up-to-date. In this regard, Uzondu Microfinance Bank:
  1. a) shall ensure that any data it collects and/or processes is accurate and not misleading in a way that could be harmful to the Data Subject;
  2. b) will make efforts to keep Personal data updated where reasonable and applicable;
  3. c) will ensure timely efforts is made to correct or erase any personal data when inaccuracies are discovered.

3.3 Purpose Limitation

Uzondu Microfinance Bank collects Personal Data only for the purposes identified in the appropriate privacy notice of the Bank or any other relevant document or based on any other non – written communication (where applicable), provided to the Data Subject and for which Consent has been obtained. Such Personal data cannot be reused for another purpose that is incompatible with the original purpose, except were a new consent is obtained.

3.4 Data Minimization


3.4.1 Uzondu Microfinance Bank limits Personal data collection and usage to data that is relevant, adequate, and absolutely necessary for carrying out the purpose for which the data is processed.

3.4.2 Uzondu Microfinance Bank will evaluate whether and to what extent the processing of personal data is necessary and where the purpose allows, anonymized data must be used.

3.5 Integrity and Confidentiality

3.5.1 Uzondu Microfinance Bank shall establish adequate controls in order to protect the integrity and confidentiality of Personal Data, both in digital and physical format and to prevent personal data from being accidentally or deliberately compromised in any manner

3.5.2 Personal data of Data Subjects must be protected from unauthorized viewing or access and from unauthorized changes to ensure that it is reliable and correct at all times.

3.5.3 Any personal data processing undertaken by an employee of the bank who has not been authorized to carry such out as part of their legitimate duties is un-authorized.

3.5.4 Employees may have access to Personal data only as is appropriate for their specified job function and scope of the task in question and are forbidden to use Personal data for their own private or commercial purposes or to disclose them to unauthorized persons, or to make them available in any other way.

3.5.5 Human Resources Department of the Bank must inform employees at the commencement of their employment about the obligation to maintain personal data privacy. This obligation shall remain in force even after their employment has ended.

3.6 Personal Data Retention

3.6.1 All personal information shall be retained, stored and destroyed by Uzondu Microfinance Bank in line with relevant Legislative and Regulatory Guidelines. For all Personal Data and records obtained, used and stored within the Bank, Uzondu Microfinance Bank shall perform periodical reviews of the data retained to confirm the accuracy, purpose, validity and requirement to retain.

3.6.2 To the extent permitted by applicable laws and without prejudice to Uzondu Microfinance Bank’s Retention Policy, the length of storage of Personal Data shall, amongst other things, be determined by:


(a) the contract terms agreed between Uzondu Microfinance Bank and the Data Subject or as long as it is needed for the purpose for which it was obtained; or
(b) whether the transaction or relationship has statutory implication or a required retention period; or
(c) an express request for deletion by the Data Subject; except where such Data Subject is under an investigation or under a subsisting contract which may require further processing or where the data relates to criminal records; or
(d) whether Uzondu Microfinance Bank has another lawful basis for retaining that information beyond the period for which it is necessary to serve the original purpose.
Notwithstanding the foregoing and pursuant to the NDPR policy, Uzondu Microfinance Bank shall be entitled to retain and process Personal Data for archiving, CBN request, EFCC investigation or any other as may be required.

3.6.3 Uzondu Microfinance Bank would forthwith delete Personal Data in their possession where such Personal data is no longer required by Uzondu Microfinance Bank or in line with Uzondu Microfinance Bank’s Retention Policy, provided no law or regulation being in force requires Uzondu Microfinance Bank to retain such Personal data.

3.7 Accountability

3.7.1 Uzondu Microfinance Bank demonstrates accountability in line with the NDPR obligations by monitoring and continuously improving data privacy practices within Uzondu Microfinance Bank.

3.7.2 Any individual or employee who breaches this Policy may be subject to internal disciplinary action (up to and including termination of their employment); and may also face civil or criminal liability if their action violates the law.

4. DATA PRIVACY NOTICE

4.1 Uzondu Microfinance Bank considers Customer data as confidential and as such must be adequately protected from unauthorized use and/or disclosure. Uzondu Microfinance Bank will ensure that the Data Subjects are provided with adequate information regarding the use of their data as well as acquire their respective consent, where necessary.

4.2 Uzondu Microfinance Bank shall display a simple and conspicuous notice (Privacy Policy) on any medium through which the Customer data is being collected or processed. The following information must be considered for inclusion in the Privacy policy, as appropriate in distinct circumstances in order to ensure fair and transparent processing:

  1. a) Description of collectible Customer Data
  2. b) Purposes for which Customer Data is collected, used and disclosed
  3. c) What constitutes Data Subject’s Consent
  4. d) Purpose for the collection of Customer Data
  5. e) The technical methods used to collect and store the information
  6. f) Available remedies in the event of violation of the Policy and the timeframe for remedy.
  7. g) Adequate information in order to initiate the process of exercising their privacy rights, such as access to, rectification and deletion of Customer Data.

5. PURPOSE AND CATEGORY OF DATA COLLECTED AND PROCESSED

5.1. We will only collect and use your data if we have obtained your prior consent or have a lawful and legitimate interest to do so. You are at liberty to withdraw your consent at any time by contacting the Bank at dataprotection@uzondumfb.com The following are data collected and processed by Uzondu Microfinance Bank: