DATA PRIVACY

The Standard Bank of South Africa Limited
Privacy Statement

Your privacy is important to us and we know that you are concerned about how we use your personal information. Standard Bank Group Limited, its subsidiaries and their subsidiaries* (Group, we, us, our) collect and process your personal information according to the data protection principles set out below. Reference to personal information means any information which identifies you, and includes information such as your name/s, email address, telephone number, biometric information and password, as well as any other personal information collected. This Privacy Statement and our Cookie Notice applies when you use our Channels (this website, associated websites, mobile sites, mobile applications and other channels).


  • These principles are in line with our Code of Ethics and comply with applicable laws, rules and standards.

    1. We maintain and continuously improve our data privacy culture by providing training and awareness sessions for all employees, and where relevant, for third-party service providers.
    2. All employees are made aware of their responsibilities in terms of laws and internal rules that apply to protecting personal information.
    3. We promote the protection of personal information by ensuring that we comply with applicable laws, rules and standards when processing your personal information.  
    4. We will be transparent in our dealings with you and will tell you how we collect and use your personal information. These practices can be found in our privacy statements and all our products and services agreements.
    5. We rely on lawful grounds with respect to the collection, use, and sharing of personal information and collect personal information only for the purposes identified in our privacy statements and all our products and services agreements. Lawful grounds include consent (when needed we may ask for consent), contract (where processing is necessary for the performance of a contract with you for example, to deliver the products or services you have requested) and for the purposes of our legitimate interests (to manage corporate transactions, such as mergers or acquisitions) or your legitimate interests (to protect you or others from threats such as security threats or fraud) or for the legitimate interests of third parties.
    6. When you use our Channels, we collect your personal information through cookies enabled on these channels. A “cookie” is a small text file that is stored on your computer, smartphone, tablet, or other device when you visit a website or use an app. They contain specific information relating to your use of our website or app, such as login credentials; your preference settings or tracking identifiers. Cookies make it easier for us to give you a better experience online. For all optional types of cookies, we will obtain your consent before these cookies can be used or stored on your device.

    For this reason, we limit our use of cookies as explained below to: 

    • provide products and services that you request; 
    • deliver advertising via marketing communications;   
    • provide you a better personalised online experience and track website performance;
      and
    • help us make our website more relevant to you. 

  • Types of cookies used on our Channels

    Mandatory cookies

    Strictly necessary cookies – These cookies are required for the effective operation of our website on your system. These are necessary for the website to function, meaning that the collection of information via these cookies cannot be switched off.

    Cookie name Cookie description and purpose Expiry
    SFSESSID Allows users to connect to their account Session
    accepter_cookies Allows to save user acceptance for cookies. Session

    Optional cookies

    Preferences cookies:
    These are the cookies, such as language or country identifier, that are used to allow you to keep your preferences from one session to the other

    Cookie name Cookie description and purpose Expiry
    countryIso3166 Allows to identify the country of the website Session

    Insights cookies:
    These are cookies that allow us to learn more about the usage and performance of our site, to establish statistics of usage of various elements of our site. This analytics work enables us to improve the interest and the UX of our services.

    Cookie name Cookie description and purpose Expiry
    _ga Allows to collect anonymous data on website use 2 years
    _gid Allows to collect anonymous data on website use 1 day
    accepter_cookies Allows to collect anonymous data on website use 1 minut

    Session cookies - These cookies are temporary and only exist while you browse our website. As soon as you close your browser or move to a different website, they are removed. They allow our website to link your actions during a browser session.

    Persistent cookies - These are permanent cookies that are stored on your device until they reach a set expiry date or until you delete them. They remember your preferences or actions across our site (or in some cases across different websites). We may use them for various reasons, such as remembering your preferences and choices when using our site, or to display only relevant advertising messages to you.

    First-party cookies – We own and create these cookies.

    Third-party cookies - These cookies are owned and created by another company that provides a service to us, such as social media sharing, website analytics or content marketing.

    How to disable cookies

    You can stop your browser from accepting cookies by changing the settings on your web browser. Please note that restricting cookies may impact the functionality of our websites. We recommend that you allow cookies, to enable the efficient and proper functioning of the website. Explore the settings and options on your browser to disable or enable them, or visit https://www.aboutcookies.org for detailed information about managing cookies on different browsers.

    Links to other websites

    Our website, related websites and mobile applications may have links to or from other websites. Although we try to link only to websites that also have high privacy standards, we are not responsible for their security, privacy practices or content. We recommend that you always read the privacy and security statements on these websites.

    Monitoring of electronic communications

    We communicate with you through different methods and Channels. Where permitted by law, we may record and monitor electronic communications to make sure that we comply with legal and regulatory responsibilities and internal policies.

    Monitoring and analysis

    We will monitor and analyse your account for credit, fraud, compliance and other risk-related purposes as required by law. However, you may not be subject to a decision which results in legal consequences for you or which affects you to a great degree, which is based only on the automated processing of personal information.

    How we use your Personal Information

    1. We process your personal information in a lawful and reasonable manner that does not infringe your privacy.
    2. We will take reasonably practicable steps to ensure that the personal information is complete, accurate, not misleading and updated where necessary. 
    3. We limit the use of personal information to the purposes identified in our privacy statements and all our products and services agreements and for which the individual has provided consent. We store your personal information securely and retain or keep your personal information for only as long as necessary to fulfil the stated purposes or as required by law or regulations and thereafter appropriately dispose or anonymise of such personal information.
    4. We will take note of the rights you have under applicable privacy and data protection laws and will make sure that we respond to and manage data subject rights requests as soon as reasonably possible and as prescribed by law.
    5. In terms of our operating model, we may share your personal information with our subsidiaries* and affiliates and third parties only for the purposes identified in the privacy statement and with your explicit consent, where required to provide the services to you. Standard Bank Group ensures that our subsidiaries and affiliates, including third parties, receiving your personal information have appropriate, reasonable technical and organisational measures in place which adhere to our privacy principles and practices.
    6. We comply with data protection laws and other related laws and codes of conduct that apply in the countries where we operate.
    7. We protect personal information against unlawful and/or unauthorised access (both physical and logical), use, sharing, loss and damage.
    8. We will take reasonable actions to make sure that adequate privacy and security measures are in place before we transfer your personal information to other countries if the transfer is necessary to provide services to you. Data and personal information we collect may be transferred to, stored and processed in any country or territory where one or more of our group companies or service providers are based or have facilities. While other countries or territories may not have the same standards of data protection as those in your home country, we will continue to protect personal information that we transfer in line with our privacy principles and practices. We only transfer data and personal information to places where we are satisfied that adequate protection can be provided and we use due diligence and appropriate contractual clauses to make sure that adequate and appropriate levels of data protection are used.
    9. We process the personal information of minors (minors defined under applicable laws within the jurisdictions we operate), only when a competent person consents to the processing or as allowed by law.
    10. We respect your data protection rights although rights vary depending on the relevant data protection laws. However, at a minimum we include:
      1. Your right of access - You have the right to ask us for copies of your personal information.
      2. Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete
      3. Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.
      4. Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.
      5. Your right to object to processing - You have the the right to object to the processing of your personal information in certain circumstances.
      6. Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
    11. We monitor compliance with data privacy-related policies and procedures and have procedures to address data privacy related complaints and disputes.
    12. We may update this privacy statement from time to time. We will publish all changes on our website. The latest version of our privacy statement will replace all earlier versions, unless otherwise indicated. If you have any questions or complaints about privacy, please contact the Group Privacy Officer:

      Vivian Reddy
      Deputy Information Officer

      Physical address:
      Standard Bank Centre
      5 Simmonds Street
      Johannesburg
      2001
      Telephone: +27 11 636 7385
      Email: [email protected]


    Regulatory

    Version: 3
    Date published: March 27, 2024
    Standard Bank of South Africa Limited Privacy Statement