3. WHY AND ON WHICH LEGAL BASIS DO WE USE YOUR PERSONAL DATA?
In this section we explain why we process your personal data and the legal basis for doing so.
3.1. Your personal data are processed to comply with our various regulatory obligations
Your personal data are processed where necessary to enable us to comply with the regulations to which we are subject,
including banking and financial regulations.
3.1.1. We use your personal data to:
- monitor operations and transactions to identify those which deviate from the normal routine/patterns (e.g., when you withdraw a large sum of money in a country other than your place of residence);
- monitor your transactions to manage, prevent and detect fraud;
- manage and report risks (financial, credit, legal, compliance or reputational risks etc.) that the BNP Paribas Group could incur in the context of its activities;
- record, in compliance with the Markets in Financial Instruments Directive (MiFID 2), communications in any form relating to, at the very least, transactions performed within proprietary trading and the provision of services relating to clients’ orders, in particular their receipt, transmission and execution;
- assess the appropriateness and suitability of the investment services provided to each client in compliance with the Markets in Financial Instruments regulations (MiFID 2);
- assist the fight against tax fraud and fulfil tax control and notification obligations;
- assess your level of credit risk and your ability to repay when you borrow;
- record transactions for accounting purposes;
- prevent, detect and report risks related to Corporate Social Responsibility and sustainable development;
- detect and prevent bribery;
- comply with the provisions applicable to trust service providers issuing electronic signature certificates;
- exchange and report different operations, transactions or orders or reply to an official request from a duly authorized local or foreign financial, tax, administrative, criminal or judicial authorities, arbitrators or mediators, law enforcement, state agencies or public bodies.
3.1.2. We also process your personal data for anti-money laundering and countering of the financing of terrorism purposes
As part of a banking Group, we must have a robust system of anti-money laundering and countering of terrorism financing (AML/TF) in each of our entities managed centrally, as well as a system for applying local, European and international sanctions.
In this context, we are joint controllers with BNP Paribas SA, the parent company of the BNP Paribas Group (the term "We" in this section also includes BNP Paribas SA).
The processing activities performed to meet these legal obligations are detailed in appendix 1.
3.2. Your personal data are processed to perform a contract to which you are a party or pre-contractual measures taken at your request
Your personal data are processed when it is necessary to enter into or perform a contract to:
- define your credit risk score and your reimbursement capacity;
- evaluate (e.g., on the basis of your credit risk score) if we can offer you a product or service and under which
conditions (e.g., price);
- provide you with the products and services subscribed to under the applicable contract;
- manage existing debts (identification of customers with unpaid debts);
- respond to your requests and assist you;
- assist you in the management of your budget by the automatic categorization of your transaction data;
- ensure the settlement of your succession
3.3. Your personal data are processed to fulfil our legitimate interest or that of a third party
Where we base a processing activity on legitimate interest, we balance that interest against your interests or fundamental rights
and freedoms to ensure that there is a fair balance between them. If you would like more information about the legitimate
interest pursued by a processing activity, please contact us using the contact details provided under section 2 "HOW CAN YOU CONTROL THE PROCESSING ACTIVITIES WE DO ON YOUR PERSONAL DATA?” above.
3.3.1. In the course of our business as a bank-insurer, we use your personal data to:
- Manage the risks to which we are exposed:
- we keep proof of operations or transactions, including in electronic evidence;
- we carry out the collection of debts;
- we handle legal claims and defences in the event of litigation;
- we develop individual statistical models in order to help define your creditworthiness and risk profile:
- Enhance cyber security, manage our platforms and websites, and ensure business continuity
- Use video surveillance to prevent personal injury and damage to people and property;
- Enhance the automation and efficiency of our operational processes and customer services (e.g., automatic filling of complaints, tracking of your requests and improvement of your satisfaction based on personal data collected during our interactions with you such as phone recordings, e-mails or chats, using these interactions to train our staff);
- Carry out financial operations such as debt portfolio sales, securitizations, financing or refinancing of the BNP Paribas Group;
- Conduct statistical studies and develop predictive and descriptive models for:
- commercial purposes: to identify the products and services that could best meet your needs, to create new
offers or identify new trends among our customers, similarities in behaviour, to develop our commercial policy
taking into account our customers’ preferences, to derive observations (e.g. aggregated consumption
patterns) that we can offer in the market;
- scientific and related purposes : to contribute to academic projects as well as to private and public projects
including micro- or macro-economic analysis for the benefit of the Society in particular;
- safety purpose: to prevent potential incidents and enhance safety management;
- de conformité, telle que la lutte contre le blanchiment de capitaux et le financement du terrorisme, et de gestion des risques de Lutte contre la fraude
- compliance purpose (e.g., anti-money laundering and countering the financing of terrorism) and risk
management;
- anti-fraud purposes;
- Organize contests, lotteries, promotional operations, conduct opinion and customer satisfaction surveys;
- Know your family environment on the basis of products you have in common with members of your family and/or
household, your own statements or those of a member of your family and/or household;
- Follow up our agreements with external partners when you approach them directly and they subsequently inform us.
3.3.2. We use your personal data to send you commercial offers by electronic means, post and phone
As part of the BNP Paribas Group, we want to be able to offer you access to the full range of products and services that best
meet your needs.
Once you are a customer and unless you object, we may send you these offers electronically for our products and services and those of the Group if they are similar to those you have already subscribed to.
We will ensure that these commercial offers relate to products or services that are relevant to your needs and complementary to those you already have to ensure that our respective interests are balanced.
We may also send you, by phone and post, unless you object, offers concerning our products and services as well as those of the Group and our trusted partners.
3.3.3. We analyse your personal data to perform standard profiling to personalize our products and offers
To enhance your experience and satisfaction, we need to determine to which customer group you belong. For this purpose, we build a standard profile from relevant data that we select from the following information:
-
- what you have directly communicated to us during our interactions with you or when you subscribe to a product or service
- resulting from your use of our products or services such as those related to your accounts including the balance of the accounts, regular or atypical movements, the use of your card abroad as well as the automatic categorization of your transaction data (e.g., the distribution of your expenses and your receipts by category as is visible in your customer area)
- from your use of our various channels: our websites, applications and social networks (e.g., if you are digitally savvy, if you prefer a customer journey to subscribe to a product, or service with more autonomy (selfcare))
Unless you object, we will perform this customization based on standard profiling. We may go further to better meet your needs, if you consent, by performing a tailor-made customization as described below.
3.3.4. We record electronic communications data
In addition to recordings of electronic communications permitted or required by law or to which you have consented, we may record electronic communications to which you are a party, including traffic data, in the course of lawful business transactions in order to:
- train and monitor our employees and improve the quality of our services
- provide evidence of business transactions or dealings that have taken place in the course of those electronic
communications, including the content of those communications (including any advice we give)
We retain records of electronic communications for as long as required or permitted by law, including for the period in which a dispute relating to those communications may arise.
This applies to both telephone conversations and electronic communications (such as e-mails, SMS, instant messaging or other similar technology) that you have with our call centre, (independent) branches, private banking and business centres, dealing rooms or one of our representatives.
3.4. Your personal data are processed if you have given your consent
For some processing of personal data, we will give you specific information and ask for your consent. Of course, you can
withdraw your consent at any time.
In particular, we ask for your consent for:
- tailor-made customization of our offers and products or services based on more sophisticated profiling (inferred from your current behaviours, skills and preferences) to anticipate your needs and behaviours
- any electronic offer for products and services not similar to those you have subscribed to or for products and services from our trusted partners
- use of your navigation data (cookies) for commercial purposes or to enhance the knowledge of your profile
You may be asked for further consent to process your personal data where necessary.