Privacy Policy: Information on Personal Data Processing
We protect your data
You may contact the Data Protection Officer (DPO) for matters concerning your personal data. You can find out DPOs within the ČSOB group in the chapter About us – who is the ČSOB Group.
Information on personal data processing – document for download in PDF format.
Last modified: 1 April 2026 (archived original versions).
We protect your data
This document provides you with information about your rights in relation to the processing of your personal data within the ČSOB Group. The processing thereof is subject to applicable legal regulations, in particular to the EU General Data Protection Regulation. The data processing therefore always only takes place in a scope which is commensurate to the specific service or purpose of the processing.
This document will be updated regularly. The currently applicable version can always be found at www.csob.cz/en/csob/protection-of-personal-data. Previous versions are available in the archive of previous versions listed hereinabove.
You can be absolutely sure that we will treat your personal data with all due care and in accordance with applicable legislation. In the course of processing we always commit to the highest standards.
The ČSOB Group applies strict rules in order to determine which employees or departments are authorised to access your personal data and which data may be processed. We do not transfer your personal data outside the ČSOB Group or the KBC Group, our parent company, as a matter of principle, with the exception of those cases where we have your consent to do so or where we are required or authorised to do so by law or in our legitimate interest (for example, in the case of suppliers or a request from the competent law enforcement authorities, etc.).
We prevent data leakage by rigorously managing access to all confidential information and the channels through which such information can leave our Group. To ensure the proper handling of information, all highly confidential documents are marked visibly and electronically. We use sophisticated technical tools to detect any unauthorised access to the data or transfer thereof outside our Group.
The procedures that have been put in place allow us to respond promptly to any potential incidents, thus ensuring a timely response.
We only process the personal data of children (i.e., individuals under 18 years of age) if the child has been represented by his/her parent or other guardian. The high standards of personal data protection which are applied to the personal data processing in our Group also apply with regard to children to an unchanged extent. These standards are fully sufficient for the processing of children’s personal data. As the parent or other guardian of a child, you bear full responsibility for ensuring that the provision of the information is not at odds with the child’s interests and for comprehensibly informing the child about the fact that we have processed said information and about the child’s rights.
We encourage you to read the present information carefully. No effort has been spared to make the information as comprehensible as possible. If, however, anything should remain unclear, we will be happy to explain any of the terms or passages contained in the information. You can find out more about personal data processing at www.csob.cz/en/csob/protection-of-personal-data. If you have a query, please contact our free help line at 800 023 003.
You may contact the Data Protection Officer to consult the matters concerning your personal data we process. The Data Protection Officer for Československá obchodní banka, a.s. (active in retail banking in the Czech Republic under the core trademarks ČSOB and Poštovní spořitelna) is Mgr. Lucie Hloušková (dataprotectionofficer@csob.cz) acts as the Data For contact details of the other Data Protection Officers within the ČSOB Group, see the section About Us – What is the ČSOB Czech Republic Group..
To send letters to the Data Protection Officers, please use the address of the relevant company from the ČSOB CR Group and be sure to mark the envelope “For the attention of the Data Protection Officer”.
You can take the following steps to protect your rights if you disagree with the method used to process your personal data.
The Office for Personal Data Protection is charged with ensuring the protection of privacy and personal data.
Address: Pplk. Sochora 27, 170 00 Praha 7
tel.: 234 665 111
website: www.uoou.cz
Examples of the personal data processing undertaken by the ČSOB Group
| When do we work with your data? | Whenever you visit our website, take part in our contests or show an interest in our offers. | When you are arranging a new product with us – we need to see an identity document before we can conclude a contract. | When we try to find out whether any of our products which you are currently not using could be of use to you. | On a continuous basis, we assess if we could provide you with even better care. | When we protect your money against various risks. | When you need to finance your home, vacation or car. | When you need to take out insurance. | Our branch offices are usually equipped with CCTV. | When we archive your data in an anonymous form for historical, scientific and statistical purposes. |
|---|---|---|---|---|---|---|---|---|---|
| What kind of data do we work with? | We use the contact details which you have supplied. | We copy the data from your ID card. | We evaluate the way you use your account and the services you are interested in. |
We monitor how much money you deposit into your account, the amount of your savings or whether you
have a mortgage or an insurance policy with us. We record your telephone calls. |
We examine and investigate any suspicious transactions, such as large amounts of randomly transferred money. | We check your loans and how successful you have been at repaying them; we look at the register of debtors. | We ascertain your state of health, we verify your claim history or the condition of the insured property. | The records are only archived for the essential period and they can only be accessed by the authorised staff and the Police. | These activities result in large sets of anonymous data on our clients’ behaviour. |
| Why do we do this? | We send you offers based on your interest. |
We always need to know who we are concluding the contract with. Moreover, we are required to do so by law. |
We only want to send you relevant offers which suit your needs as much as possible. | We try to satisfy those clients who demand superior service, such as premium service or a gold card. This is also due to the MiFIR rules. | The law obliges us to fight against fraud and money laundering, to prevent cyber risks and to generally act with due diligence (for example, according to the MiFIR). | We verify that you are able to repay the loan. | So that we can provide you with the best insurance scheme in relation to your health or your existing insurance history. | The CCTV is used as a means of prevention or as evidence during the investigation of criminal offences. | We improve our services according to how society is changing. The Czech Statistical Office (CZSO) may require us to disclose the data. |
| Can you limit this? | ✔ Yes | ✘ No | ✔ Yes | ✘ No | ✘ No | ✘ No | ✘ No | ✘ No | ✘ No |
Controller of your data
The controller of your personal data is always the company from the ČSOB Group which you provided the data to or which acquired the data about you in order to fulfil one or more purposes. Your data is typically controlled by the company where you are a client. If you are a client with several of our companies, each company will primarily control the data which concerns its product. Where we collect personal data on the basis of your visits to us or our mutual communication, the controller of that data will always be the company involved in the event.
The controller collects your data, handles it and bears responsibility for its correct and legal processing. You may exercise your personal data protection rights with that controller.
The controller is the company which provided you with this document at the moment when it collected your personal data. If we request your consent to process your personal data, the controller of your personal data is the company which you give the consent to. The question as to “who the controller of your personal data is” is primarily based on how we acquired the data about you:
-
When you arrange one of our products or services
Whenever you arrange one of our products or services with us or you express an interest in them, you provide us with basic information and, depending on the situation, profile information or any other data which is essential so that you can conclude a contract with us or so that we can assess whether and what product or service we can offer you. The controller of that personal data is the product provider.
-
When you use our products or services
The use of our products includes, for example, any requests for indemnity under an insurance policy, the drawing down of a mortgage or ATM withdrawals. However, you can also use a product or service passively, for example merely by having a bank account with us. In such cases, the controller of your personal data is the company where you are a client (the so-called product provider). This is the company which is stated as a party in the contract for the given product. That company controls the data which you have provided, as well as any other data which the company has been authorised or obliged to acquire from any third parties for the given purpose. If you are a client with several of our companies, each company will control the data which concerns its product.
-
When you communicate and negotiate with us
In those cases where we collect personal data during the course of your communication with us, no matter whether it takes place electronically, in writing, by telephone or in person, the data will be controlled by the company which the communication concerned. CCTV recordings are administered by the company which operates the given branch. When using our website and applications, your personal data is controlled by the company which is listed as the operator or as the product provider in the appropriate section of the given electronic channel (for example, at the foot of the website).
-
When you communicate with a different company than the one which your arrangements concern
In order to simplify your access to our products as much as possible, we offer you the option of concluding, operating, administering and communicating about a number of our products with companies which are not the product providers. This involves cases where, for example, you arrange pension or building savings at the bank. In such cases, part of your personal data, especially the basic data which is essential for your identification and authentication, is also controlled by the company you are dealing with.
The data we process
We only process the data which is necessary to enable us to provide professional and user-friendly services and to enable us to adhere to our statutory obligations and protect our legitimate interests. We mainly collect information about the users of our products, including prospective clients who are interested in our services or whom we have addressed an offer to. For example, we process data about company representatives, including members of the governing bodies and employees, the beneficial owners of companies, payment recipients, guarantors, pledgors, policyholders, insured persons and beneficiaries, persons who will become entitled to indemnity in the event of the client’s death, as well as other persons for the purpose of controls under the Anti-Money Laundering Act. This includes, for example, the parties to a contract in proving the origin of assets. We also process data about other persons with whom we do not have a direct contractual relationship, for example when we manage securities records or do so under a contract with you.
We process your basic data, our product and service data, data about which products and services you use and how you use them, our communication and interaction data, your profile data and any other appropriate data so that the range of the data is commensurate, relevant and limited to the extent which is necessary for the purposes for which we collect and process data about you. Our aim is to provide you with professional and user-friendly services, but we must also comply with our statutory obligations and want to protect our legitimate interests. For a complete list of the purposes for which we process your data, as well as a clarification of the specific data processed for each purpose, please see the section “Why do we process your data?”
We process mainly the following categories of data:
-
Basic data and identification details
The basic identification details include your name, gender, date of birth, birth certificate number, identity document number and type (your passport or identity card), the photograph from your identity document, the address of your place of residence, your citizenship and nationality, an image of your signature and your Company ID No. and the address of your registered office if you are an entrepreneur. The identification details are an essential part of any contract which you conclude with us.
We collect your identification details in the scope which is required by the applicable legal regulations, such as the Act on Banks, the Insurance Act, the Supplementary Pension Savings Act, the Building Savings Act and the Anti-Money Laundering Act, which also oblige us to collect those details. The legal regulations, for example the Act on Banks and the Insurance Act, directly authorise us to ascertain birth certificate numbers. As part of technical data, your IP address is also included in identification details. In connection with the ČSOB eID service, we use a Non-Meaningful Directional Identifier (pseudonym).
We also enable you to conclude contracts using a biometric signature at selected points of sale. If you install a dedicated app on your mobile device, you can also sign contracts remotely with a biometric signature. This applies only to certain products and services.
We process biometric personal data in case of conclusion of a contract by means of a biometric signature in order to verify the authenticity of the signature and the contractual documentation in case of litigation, where the biometric data serves as evidence. When concluding a contract by means of a biometric signature, we record the following biometric data: coordinates – pen positions, time points and, where applicable, pressure force (if the device can sense it). We also use other personal data to log into a special remote signing app to prove that you are the signatory (for example, information about the device, the location of the device, or a selfie of you when you log into the app and sign, which we compare to the photo on your ID card.
-
Contact details
If you give us your contact details, mainly including your email address, the address of your profile on social networks and your phone number, we will be able to provide you with a more user-friendly service in accordance with your preferences. There are even some services which we cannot offer you without knowing your phone number or email address. In order to enable you to use our products using applications and to communicate with us electronically, we control your access data – primarily your user name, password, PIN and any other security elements – which is used to securely authenticate your identity. We also use that data for easy switching between individual portals and applications across the ČSOB Group.
-
Product and service data
We also process data which is closely associated with how you use our services or data which you provide us with or otherwise create when you use our services. For example, in order to be able to execute your payment orders, we need to know the essential payment details, such as the amount, the identity of the recipient and the payer, the place of payment and the phone number associated with the Payment to Contact service (the transaction data). Some data facilitates and accelerates our services. This includes your account number, your payment card number, the number of your contract, data on the use of our products or the preferred language. Overall, we can process data such as your bank account number, your debit and credit cards, any financial products in your portfolio, your transactions and contracts, data on your income, property and capital, data on any investment, leasing, loans, insurance, benefits, pensions, potential interest, appetite and opportunities in the area of financial products, financial goals, limitations and limits, authorisations or powers of attorney, signature specimens, our previous simulations, recommendations and offers.
We also collect information on the devices which you use to access our services electronically. This helps us to optimise and further develop our platforms, as well as to improve security. Apart from the aforementioned IP address, the data includes information about the browser and the device’s hardware. So-called cookies are also saved on your device in this regard. In order to be able to serve you properly, we also need information on your financial goals and sales information.
-
Data from mutual communication and interaction
Your opinions and preferences enable us to improve our services and to offer you products which are tailored to meet your needs. That data also includes information on the use of our website and applications, as well as information about our mutual contact via any contact point (the length of the contact, the topic of discussion and the used communication channel), including the resolution of any complaints and service requests. We also process any feedback, comments, proposals and results of non-anonymous research as personal data.
We also process data about user behaviour in the digital environment (website, email communication), such as information about your visit to our website, the frequency of visits, preferred content or the time you visited the website. The data is stored on your web browser or device in the form of cookies or similar tools. The data related to the monitoring of your behaviour also includes email interactions, namely the delivery of an email message or the fact that you have read an email message or clicked on links in an email message.
-
Profile data
We process your basic physical characteristics (age), socio-economic and socio-demographic characteristics (marriage/partnership, number of children, information on your housing and household, your work position and experience, skills, education and qualifications), information about your lifestyle (your habits, ways of spending your free time), significant relevant milestones in your life (moving house), commercial information (on the basis of your payment transactions or inferred from analytical modelling) and risk data (the evaluation of any loan, insurance, cyber or other risks). This information enables us to offer you a service which meets your needs and to ensure our and your security (cyber and otherwise).
We acquire data concerning your payment history, which reveals your creditworthiness and reliability, in order to be able to responsibly provide you with loan products. We collect data from an investment questionnaire if you are interested in our investment products. The investment questionnaire determines your investment profile when deciding on the selection of investments. The application of the results from the questionnaire when selecting and allocating investments contributes to the elimination of the most common causes of mistakes in investment behaviour, which may subsequently lead to losses. Similarly, if you opt for a pension savings product, we assess information about your requirements and needs to recommend an appropriate savings strategy.
-
Other data
In order to be able to provide proper services to persons with disabilities, to meet their needs and to provide them with a suitable method of service, we process personal data about their disability for this purpose. We use the data, for example, to identify and authenticate the client and to ensure the client’s comfort in the electronic channels.
It is essential for the insured persons to provide us with data on their state of health for the purposes of life and non-life insurance, in particular but not exclusively for accident and sickness insurance. When we are handling loss-incurring events under life and non-life insurance, we obtain and process data about the state of health of the insured and other persons involved.
When arranging life insurance, we process information on the state of health with the policyholder’s consent. If consent is not given, the insurance policy may not be concluded at all, in accordance with national insurance legislation.
However, for the settlement of insured events under life and non-life insurance, the processing of data on the state of health (special categories of personal data) of the insured and other persons involved is necessary for the establishment, exercise or defence of legal claims. If the data subject concerned does not consent to such processing, he/she may not receive the indemnity in full, or may not receive it at all.
If you exercise the option to repay your housing loan early following a sudden hardship, you must provide proof that the hardship has occurred.
If you have been injured in a traffic accident, we need to document information about your medical condition so that we can pay you compensation from the compulsory motor liability insurance of the person at fault. In that case, we process a category of sensitive personal data for the establishment, exercise or defence of legal claims.
Those members of the Group which offer mobile applications may collect data on the location of your mobile device if you use it in conjunction with their services. Geolocation data is also used to prevent fraudulent practice.
We make recordings at our business premises and facilities (e.g., ATMs) for security reasons.
We verify that your appearance corresponds with the photograph on your identity card during the identification process and we use your photo to improve our services as well as for prevention of fraudulent practices. We also make and store recordings of telephone calls, video calls (if you use that service), emails, online chats and communication with our digital assistant for the purposes of operations and improved client services, but mainly for the resolution of your requests and suggestions, on the basis of the controller’s legitimate interest. These recordings are stored and may be used as evidence in the case of a dispute. We are also required to record and archive these communications by some legal regulations, for example the MiFIR.
You can find the scope of the data which we process about you in each individual case in the section “Why do we process your data?”
Why do we process your data?
We process your data to the extent which is essential for the given purpose – for example, so that we can provide the given service. This also includes cases where we conclude a new contract or where an already concluded contract is being fulfilled. This typically involves the identification of you. Another example involves the assumption of insured risks, insurance administration, the settlement of insured events and the provision of indemnity, including assistance services on the basis of an insurance policy concluded with our insurance company, where we need to know your identification details as well as the information associated with the insured individual and the insured event.
We are obliged to process data in accordance with a number of laws. For example, the Anti-Money Laundering Act requires us to acquire your identification details. We have to process a lot of data for archiving purposes. We process some data because it is necessary to do so in order to protect the rights and legally protected interests of both our Group and third parties. Nevertheless, the processing of data to this end is restricted and we are always careful to assess the existence of a legitimate interest. In all other cases, we only process your data with your consent.
To continuously improve the quality of our services, security and internal processes, we may also use modern technologies, including artificial intelligence and machine learning, to process data. These technologies help us, for example, to prevent fraud more effectively, optimise our IT systems and develop new models for an efficient provision of services. In such processing, we always make sure that the processing is still supervised by people and takes place with high security standards.
The purposes of processing include the following categories:
-
Service and client care
Client identification and authentication
We need to know your basic personal data in order to be able to conclude a contract with you and to provide you with our services. Your identification is required by the Anti-Money Laundering Act; for this purpose, we are entitled to make copies of all documents submitted by you.
The obligation to ensure identification also arises from the Act on Banks (identification for the purposes of deposit insurance) and the Insurance Act. We also require your identification and authentication if you exercise your rights in matters pertaining to personal data protection. We administer your access data (especially your user name and password which are used to securely authenticate your identity across the ČSOB Group for easy switching between the various portals and applications) so that you can use our products via our applications and communicate with us electronically. As part of our efforts to improve our services, we also enable you to conclude contracts with us using a biometric signature in some cases. In order to ensure your maximum protection, we only save your biometric information as an imprint or in encrypted form, i.e., in a manner which does not enable your biometric information to be reverse-engineered for these purposes.
Why we process the data:
- for your contract
- to fulfil our obligations imposed by law
- for the performance of tasks carried out in the public interest
- to prevent money laundering
- on the basis of your consent – some biometric data
- for the establishment, exercise or defence of legal claims – biometric signature
-
Authorisation of legal actions
As part of our efforts to improve our services, we enable you to take legal action, for example conclude contracts with us, electronically in some cases. We can issue you a one-time guaranteed electronic signature certificate or provide you with a qualified electronic signature certificate. We can also provide a remote signing service with a guaranteed or qualified electronic signature from a qualified trust service provider. In some cases, you can also sign using a biometric signature. In those cases, we process the data necessary for the issuance of the relevant certificate and sometimes also other data (the type and number of identity document, the authority or State that issued it) that can be used for the recognition of official electronic signature authentication, for example in proceedings conducted by land registry authorities. For your maximum protection, we process your biometric data exclusively in encrypted form.
Why we process the data:
- for your contract
- to fulfil our obligations imposed by law
- for the establishment, exercise or defence of legal claims (some biometric data)
-
Simulation of products and services
We provide you with a simulation of our products/services in order to assist you in selecting to most suitable product. We further process the product and service data which you enter in the given Internet or mobile application or which you submit to our employees during a simulation for this purpose, and the data is used to simulate the price and the other conditions pertaining to the product.
Why we process the data:
- to protect our rights and legitimate interests – the simulation of products and services
-
Convenience in electronic channels
For this purpose, we process information about which device you use to access our services electronically, your preferences for the service settings and the data which you enter on our website because we want to make sure that the use of our website is a comfortable experience for you. We save information on your device in the form of so-called cookies. Cookies enable us to respect your choice of language and to store the values which you have entered into web forms in case you need them for future reference. You are informed separately about the processing of the cookies. More information can be found here: www.csob.cz/en/terms-of-use.
We also track client behaviour in email interactions, such as whether an email message has been delivered and read, and whether the client has clicked on the links contained therein. We perform such tracking through a pixel tracking tool.
Why we process the data:
- based on your consent – cookies, marketing
- to protect our rights and legitimate interests – opening of correspondence sent in pursuance of the fulfilment of a contract or legal regulations
- significant public interest (e.g., information on disability)
Digitisation of payment cards
If you decide to use applications that allow you to digitise your payment card on your mobile device, perform transactions through it and display transaction history, or, so-called mobile wallets (e.g., Apple Pay, Google Pay, Garmin Pay), we process mainly the following personal data for this purpose: first name and surname, PAN number (payment card number), expiry date, CVV/CVC of the payment card and the history of payment transactions.
Drafting a contract at your request
We only collect and process the data which is necessary and essential for your draft contract. We need to know your name, birth certificate number and contact details in order to be able to conclude the contract with you. Any other data depends on the nature of the services covered by the contract. For example, loan products require the acquisition of information about your creditworthiness. Certain types of insurance, such as sickness insurance, require data about your state of health. However, we process health data only with your consent or where necessary for the establishment, exercise or defence of legal claims and only where there are grounds for doing so. When arranging compulsory motor liability insurance, we calculate your bonus (or malus) on the basis of data available from the Czech Insurers’ Bureau, based on our statutory obligations in accordance with the legislation governing the insurance industry. It is possible to obtain state aid with some of our products. We are required to process your personal data and submit it to the state authorities (the Ministry of Finance) by law (for example, pursuant to the Building Savings Act and the Supplementary Pension Savings Act) in order to obtain the state aid for you. The required data includes a copy of your identity document and a residence permit for the Czech Republic if you are not a Czech citizen; this is necessary for the purposes of verification and granting of state aid with building savings by the Ministry of Finance of the Czech Republic. Without this, we cannot guarantee that any state aid will be granted.
We only use the data to prepare the draft contract which you have requested up until the moment when the contract is signed. Once the contract has been signed, we process the data for the purposes of the implementation of the contract; if the contract is not signed, we only process the data if there is a different reason to do so.
If you enter into a contract as a legal guardian on behalf of a minor, we also process, to the extent necessary, the identification and contact details of the minor and, where applicable, of another legal guardian if his/her details are apparent in the documents submitted.
We also organise various events for our clients, and the scope of the data we process is proportionate to the nature of these services. In particular, we will ask you for your name, contact details and information about possible transportation or accommodation and meals.
Why we process the data:
- for your contract
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – prevention of the risk of any non-fulfilment of the contract, improvement of our services
- on the basis of your consent – health data, TelcoScore service
Customer relations management
We respect your needs and preferences. To this end, we endeavour to achieve a comprehensive overview of what services you use and what your wishes are. We resolve various matters with you concerning the given product, especially the establishment of the product, the product settings, any changes, the provision of information about the product and so on. We also resolve your requirements, wishes and complaints at our branches, on our customer lines and our website, in our mobile applications and otherwise. As well as our products and services, these requirements may also concern the exercising of your rights in matters pertaining to personal data protection. We ascertain whether you are satisfied with our Group and wish to remain our customer. If you come to a branch, we wish to identify you according to your photograph and to offer you suitable services. We process mainly the appropriate product and service data, the profile data and the data from our communication and interaction which you have provided us with to this end.
Why we process the data:
- for your contract
- fulfilment of our legal obligations – such as complaints or exercising of rights in personal data protection matters
- to protect our rights and legitimate interests – customer relationship management
Use of products and services
We begin processing your data as of the very moment when you choose our products and use our services. This primarily involves your basic data, the product and service data and geolocation data. We register and administer the data and maintain the data in an up-to-date state. If you use our services on a mobile device or via an Internet application, we collect data about your location. We will display the basic information about you and your products on the electronic portals which you use to work with our products and we will administer that information in order to simplify the use of our products for you. We enable you to easily switch between the portals and applications across the ČSOB Group. We also organise various contests for you.
Why we process the data:
- for your contract
To send service messages
We will send you service messages to assist you in the use of our products, as part of the provision of our services. We will process your contact details for this purpose.
Why we process the data:
- for your contract
- to protect our rights and legitimate interests – sending service messages
Development of analytical models
When developing analytical models, we combine data from different sources. We collate and analyse a wide range of data, such as data on products, services and their usage, including information on financial transactions, profile data, data from electronic channels and websites, information from customer communications, etc. We use the outputs of analytical models, for example, for risk management, prevention of fraudulent practice, optimisation of our services and processes, and also for marketing purposes.
We work with anonymised and/or aggregated data as well as personal data in the development of the models. We work with personal data in cases where anonymisation or aggregation of data would have a negative impact on the quality, reliability and accuracy of the outputs generated by the model. Where appropriate, we also use artificial intelligence (AI) technologies, such as large language models (LLMs).
When working with data, we always respect the requirements for information security, in particular secure storage and removal of data, data access control, data processing records and protection against the risk of data leakage. This also applies if we use AI tools.
Why we process the data:
- to protect our rights and legitimate interests – the creation of data analyses and statistics
Profiling for commercial use
We need to carry out analyses of your profile data and product and service data, including the profiling thereof, in order to be able to provide services to you and your family which are relevant or to designate the parameters of your contract as precisely as possible: this process commences even before the conclusion of the contract. In some cases, based on such a profile, we automatically decide to enter into a contract with you and on the contractual terms. We also use the analyses for marketing purposes, i.e., to decide which products we will contact you about. Profiling also helps us when arranging insurance for you, where we process data obtained from the Czech Insurers’ Bureau, among other things.
Why we process the data:
- to ensure compliance with legal obligations – e.g., compliance with the duty to act prudently
- to protect our rights and legitimate interests
- for your contract
- on the basis of your consent – consent to data processing and sharing within the ČSOB Group for marketing purposes
- automated decision-making in arranging insurance
-
Marketing
We send commercial communications concerning the products and services provided by the members of our Group and our business partners in various forms, including the use of letters, telephone calls, text messages, fax, emails and the Internet, our client portals, mobile applications and social networks, within the framework of our marketing activities.
We understand the processing of data for marketing purposes to mean the acquisition of knowledge with regard to your preferences and offers of products for you. We use the grouping and evaluation of the basic data, the product and service data and the profile data, including profiling, for this purpose. This is also carried out using automated means. We are able to find the best products for you on the basis of the results of analyses. These activities are designed to help make sure that we do not bother you with irrelevant offers. As part of our marketing activities, we also process your data at specific events to reward you, for example, for setting up or using a specific product or service. However, data processing for direct marketing purposes can also be regarded as data processing undertaken on the basis of our legitimate interest (i.e., sending emails and text messages to clients). You are entitled to refuse being sent commercial communications or to restrict their delivery to selected communication channels. The ways in which you may refuse or restrict the sending of commercial communications are listed below in the section “Do you want to limit direct marketing?”
Why we process the data:
- on the basis of your consent – consent to data processing and sharing within the ČSOB Group
- for marketing purposes
- to protect our rights and legitimate interests – direct marketing
We also use new forms of marketing. We use your basic data, the data from our communication and interactions and your profile data within the framework of these forms of marketing in order to improve the distribution channels so that you can communicate with us and we can inform you of our products and services in an engaging way.
We endeavour to make our portals attractive to you so that our products and services are easy to find. We focus on the content which we disseminate via diverse online channels, including social networks, within the framework of this activity and we combine it with care for you.
Why we process the data:
- to protect our rights and legitimate interests – direct marketing
Kate – your digital assistant
Kate, our digital assistant, is gradually becoming a core functionality in our various mobile applications and services (DoKapsy, ČSOB Smart, CEB, etc.).
More information about Kate herself and what services to expect from her can be found in the terms and conditions of the individual ČSOB applications or services in which this functionality is available. Kate may have different properties depending on which application or service you use her in.
Kate is a sophisticated version of a digital assistant that you can talk or text with.
Kate may use generative artificial intelligence (AI) technologies, especially large language models, to provide assistance. In that case, the generation of the answers is based on machine learning algorithms and probabilistic calculations, and therefore these answers may not always be completely accurate and fitting due to how these models work.
Kate can answer a variety of questions while assisting you directly and personally, thanks to the personalisation process. She will send you news about products, services and applications offered by the ČSOB Group that may be of interest to you, your family or your business.
In order for Kate to function as intended, i.e., to be your personal assistant and to respond to your needs, behaviour and wishes and identify your potential risks, she will analyse the historical and new data about you, your family and your business that we have at our disposal (e.g., transaction data, data on the use of products, services and applications offered by the ČSOB Group, observations obtained from market analyses, analyses of customer behaviour and general analyses on the use of ČSOB products and services). In order to offer personalised services, Kate uses these analyses of your specific situation (so-called profiling).
In this processing, we ensure maximum security of your data. While Kate is constantly improving and is more and more personalised in the banking environment, we have put measures in place to ensure that your data is not used by our IT vendors to train their AI models.
If you do not wish to be actively addressed by Kate, you can turn off active messaging at any time with immediate effect in Kate’s settings.
To enable you to use some of Kate’s functionalities in our apps (such as ATM search by mobile device location), we may process data about the location of your mobile device (geolocation), but only if you have enabled sharing such data in your mobile device settings. You can turn location sharing on and off at any time in your mobile device settings.
We may also communicate with you independently of the basic documents of individual ČSOB applications (the contract and the relevant terms and conditions) where this functionality will be launched. In that case, personal data will only be processed if we have another legal reason for that processing.
Such other legal reason may be consent (for example, consent to data processing and sharing within the ČSOB Group for marketing purposes).
If we need consent that you have not yet given, Kate may ask you for that consent. The processing of personal data may also take place on the basis of a legitimate interest.
For example, the ČSOB Group can send you marketing offers via Kate, independently of the basic documents of the various ČSOB applications. If ČSOB does this, it will always respect the conditions of direct marketing.
If you give us your consent for marketing purposes, Kate may send you an offer for a savings deal or home insurance, notification that you may apply a discount with our business partner, etc. For example: “We offer a discount on your home insurance, just give us a call.”
Even if you do not give us consent for marketing purposes, you can communicate with Kate about our services, for example, “Show me my PIN” or “Where can I find an ATM?”. Kate can also make your day with a birthday wish.
Why we process the data:
- for your product or service contract and the applicable Terms and Conditions to protect our rights and legitimate interests
- on the basis of your consent – consent to the use of data for the ČSOB Group
Kate Coins
Kate Coins are digital “coins” issued by ČSOB, which ČSOB allocates to its clients in predefined situations via the ČSOB Smart mobile application. Kate Coins can then be redeemed to earn rewards when purchasing products and services from ČSOB or our contractual partners, or rewards for other behaviour defined by ČSOB. The digital wallet, or, KTC Store for earning and redeeming Kate Coins is made available in the respective mobile application. The processing of data in relation to the provision of the digital wallet takes place on the basis of a contract.
Your consent (consent to data processing and sharing within the ČSOB Group for marketing purposes) is the ground for the processing of your personal data for the purpose of earning and redeeming Kate Coins.
For the purpose of allocating Kate Coins, profiling and other processing of your personal data may take place.
If you revoke your consent, we will not be able to allow you to earn any Kate Coins or redeem the Kate Coins already earned; you will merely see the balance of unused Kate Coins. However, we will continue to process your personal data in that case on the basis of our legitimate interest for the purpose of recording information about the balance of Kate Coins should the digital wallet be restored, and so that the legal claims of ČSOB, if any, are protected.
Why we process the data:
- for your contract
- to protect our rights and legitimate interests based on your consent – consent to the use of data in the ČSOB Group
-
Security and risk management
Profiling for the assessment of credit and insured risk
We use profiling when deciding to undertake risk management in relation to our loan and insurance products.
In the case of life insurance, we use your profile data as well as health data to create an individual profile and to assess the risks, for example the probability of an insured event occurring.
The Act on Banks, the Insurance Act and other legal regulations require us to act with due diligence when providing you with our services, for example a loan or insurance, and we therefore evaluate the loan risks using your data and the credit registers and internal databases which also contain negative information.
As part of the creditworthiness assessment, we are required to assess your income and expenses. For these purposes, we process information from your accounts with ČSOB or accounts with other banks that you have linked to your ČSOB accounts.
Our obligation to proceed with due diligence is also projected into a number of other areas in this category titled “security and risk management”.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – security and risk management
- on the basis of your consent – health data
Client profiling in securities transactions (MiFIR)
We have to acquire the relevant product and service data, the profile data and any other essential information about you and your requirements for the purpose of offering the correct investment product (for example, investments in unit certificates). We acquire this information from you on the basis of the investment questionnaire.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – security and risk management
MiFIR non-compliance monitoring and prevention
We carry out activities which involve the prevention, discovery, investigation and any other required steps for the investigation of any (potential) non-compliance with the requirements of the MiFIR. To this end, we process your data profile, which results from the client profiling process during securities trading (MiFIR). The MiFIR and the associated legal regulations also require us to record your identification details, your instructions and the data on the provided transactions, to report the undertaken transactions and to archive all the data.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – security and risk management
Profiling for the prevention and detection of fraudulent practice
We analyse your identification details, product and service data, profile data and other data in order to prevent any fraudulent practice undertaken either physically or digitally. We use the information to create profile indicators to indicate possible fraud (such as information about a stolen identity card or the usual country for online banking), including risk analysis performed under effective legislation in connection with card payments on the Internet (i.e., to perform a transaction without two-factor authentication). For risk analysis, we may also process data about the history and nature of your purchases from merchants. For these purposes, personal data is also transferred to other banks and other payment participants – see paragraph 8, section “Exchange of data between banks to prevent fraud”.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – control and prevention of fraudulent practice
Fraudulent practice monitoring and prevention
Due professional care in the performance of our work involves monitoring and preventive measures. These activities involve prevention, detection, investigation and other performance required for the exploration of (potential) fraud or (potentially) unethical behaviour. We use your data profile created in the profiling process to prevent and reveal any fraudulent practice.
Our reason for data processing:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – control and prevention of fraudulent practice
-
Risk assessment/profiling for the purpose of preventing money laundering
We analyse your identification details, the data on the transactions which you have undertaken and any other essential data according to the Anti-Money Laundering Act in order to prevent money laundering, whereby we also take some of that data from our internal databases.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – control and prevention of fraudulent practice for the performance of tasks carried out in the public interest
- to prevent money laundering
Monitoring and prevention of money laundering and financing of terrorism, embargoes
We check your data in order to prevent illegal practices such as money laundering. We use the data profile from the risk monitoring/profiling process to prevent money laundering.
Why we process the data
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – control and prevention of fraudulent practice
- for the performance of tasks carried out in the public interes
- to prevent money laundering
Market abuse monitoring and prevention
This involves prevention, detection and investigation activities and the performance of any other steps required for investigating market abuse. We are obliged to look into any noncompliance with the Capital Market Undertakings Act and the Market Abuse Regulation, which could damage our other clients or our Group.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – control and prevention of fraudulent practice
Accounting and taxes
We collect and process your identification details and transaction data for the purpose of fulfilling our accounting and taxation obligations with regard to the regulatory and state authorities which have been imposed upon us by the Accounting Act, the VAT Act and other Czech accounting and tax laws, including the FATCA, and on the basis of the compulsory reporting to the regulatory bodies.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – security and risk management
Security and protection against malware
We protect physical property, for example by placing cameras at our points of sale or ATMs, as well as data for these purposes. The CCTV systems have been installed in order to protect individuals and property from any unlawful acts, but primarily to prevent and clarify any robberies, break-ins, theft, vandalism and fraudulent practices. We process the recordings from the cameras. We have put in place strict mechanisms in order to protect your data. The processing of your profile data, which we use to create security profiles, assists us in the prevention of cyber risks.
Our banking applications (especially ČSOB Smart, ČSOB Smart Key) and tools include antimalware/antivirus detection and root/jailbreak detection, which detect whether the device from which you access our applications or tools is secure and whether it has been infected with a risky virus. These tools collect and then process information about the security settings of your device (e.g., screen lock disabled, etc.), information about the integrity of the application and operating system (e.g., changed admin rights [root/jailbreak], running in an emulator, using a hooking framework, etc.), device information (e.g., device model, anonymous device identifier to check that the application is running on the same device on which it was originally installed), metadata of all the applications installed to evaluate potentially malicious applications on the device, notification settings, and IP address. This data is processed for the purposes of fraud prevention, user security, regulatory compliance, as well as for analyses to improve security and evaluate potential threats. In some cases, third parties are also used for the analyses according to the previous sentence, see the section “Recipients of personal data” for details. The identification of malicious applications (malware) in installed applications on your mobile device is provided by Wultra, which does not pass on your data to any third parties.
Why we process the data:
- to protect our rights and legitimate interests – security and risk management
- to fulfil our obligations imposed by law
Internal administration
Exercise or defence of rights (disputes)
In the event that we are forced to recover our receivables through the courts or if we are participants in judicial proceedings and the proceedings in question concern you, we will make commensurate use of your basic data, product and service data, the data from our communication and interactions or any other data which is essential for the protection of our rights. In the event that you have concluded a contract with us using a biometric signature and this is essential for the establishment, exercise or defence of our legal claims or for the execution of a judicial ruling, we can use your biometric data and transfer it to a court expert in order to identify you. For the purpose of paying compensation under compulsory motor liability insurance, we may process your health data to establish and defend legal claims.
Why we process the data:
- to protect our rights and legitimate interests – the right to judicial and other protection
- for the establishment, exercise or defence of legal claims – health data, biometric data
ICT and software change testing
For a limited period of time, we store technical data about the clients’ use of our applications and web portals to help us minimise incidents and improve the security of the applications and web portals. In some cases your new software cannot be introduced without effective testing using client data. We therefore use the data about you stored in the given software to test the software and any software changes and to train our staff in essential cases where there is not sufficient testing data.
Why we process the data:
- for your contract
- to protect our rights and legitimate interests – the proper functioning of our portals and applications
- to protect our rights and legitimate interests – software change testing
Internal administration, reporting, information management, process optimisation and training
Our employees process your personal data when performing the internal duties which exist within every company. For example, we have established a comprehensive approval and reporting system for individual transactions. Your basic data, profile data and product and service data is used for the purposes of planning, evaluation or greater efficiency, for example during the evaluation of when clients usually visit the branches and when payment orders are usually paid, checks of account balances and so on. The average age of the insured person, the claim history or the region are evaluated for the insurance industry. The data is aggregated for these purposes (this involves the summarising of a large amount of individual pieces of data) and this results in a general profile, an aggregate number, which no longer has any connection to a specific individual.
We compile various reports on the basis of the legal regulations. We also report some data to the KBC Group, especially the basic data about the individuals acting on behalf of our corporate clients and about their end owners.
Why we process the data:
- to fulfil our obligations imposed by law
- to protect our rights and legitimate interests – internal administration, reporting, information management, process optimisation and training
-
Research and development of products/services and market trend analysis
We use the product and service data and the profile data for research into products and services so that we can analyse the market situation and improve our offer to include new and better services and innovated products. We also want to know the latest development trends.
Why we process the data:
- to protect our rights and legitimate interests – research and development of products/services and market trend analysis
-
Historical, statistical and scientific purposes
Your data is processed for scientific and historical purposes. It is also used for statistical purposes. In this case, however, we primarily use data which has already been aggregated or fully anonymised.
With reference to the European Sustainable Agenda and the EU Taxonomy Regulation, i.e., a classification system that provides a list of environmentally sustainable economic activities in order to achieve the objectives of the EU Green Deal, we report information on sustainable investment and financing of private individual entrepreneurs and legal entities with a ČSOB credit product. This information will be shared for the internal statistical purposes of the parent company KBC and, in anonymised form, with the Czech National Bank and the European Central Bank.
Why we process the data:
- for historical or scientific research
- fulfilment of legal obligations to protect our rights and legitimate interests – internal administrative purposes
How long do we keep your data?
Your data is kept only for as long as necessary. We keep it for 10 years due to archiving obligations, due diligence obligation and due professional care, and then for another 2 years especially with respect to the statutory limitation periods. The long-term nature of certain claims, such as payments of the money deposited by you into your account or pensions or the safekeeping of securities, extends the need for retention.
We respect the rules of data minimisation when handling your data. This means that we have set strict internal archiving rules in order to ensure that we do not hold any data for longer than we are authorised to do so. We are obliged to implement the measures prescribed by the Anti-Money Laundering Act in the case of most business relationships. According to that Act, we are required to archive the appropriate data, i.e., especially your identification details and transaction data, for a period of 10 years from the moment of the realisation of the transaction or the termination of the business relationship with you. This period is also stipulated in other legislation. For example, the Act on Banks requires us to store documents on the realised transactions, the Capital Market Undertakings Act requires us to store data from the records of investment tools and all the documents concerning the data contained in these records for 10 years from the end of the calendar year in which the data was recorded, and the VAT Act obliges us to keep tax documents and records with details related to the provision of selected services for a period of 10 years from the end of the taxation period in which the performance occurred. We are therefore generally obliged to archive the majority of the basic data and the product and service data on the basis of these Acts. Data with a shorter required retention time includes, for example, the data on transactions using financial instruments according to the MiFIR, which must be stored for at least 5 years.
In addition to the aforementioned archiving rules, we store most of the data for a longer period with respect to our prudential and professional care responsibilities, especially if we have to provide evidence in judicial or administrative proceedings.
The data processed with your consent is used for as long as your consent has been validly granted. If you have given us consent to process and share your data within the ČSOB Group for marketing purposes, we use your personal data for marketing throughout the period of the duration of our contractual relationship and then for a further 5 years after the relationship has ended. If you do not become our client, i.e., if you have not used any service, we only use your data for a period of one year from the date when you gave your consent. In order to dispel any doubts, we may store the consent form and any changes to or retraction thereof on the basis of our legitimate interests even after the consent expires.
Are you obliged to provide us with your personal data?
The submission of the data which you give us with your consent is voluntary. We require the submission of the other data because its processing is essential for the fulfilment of the contract, the fulfilment of our legal obligations or the protection of our legitimate interests. If you do not provide us with that data, we cannot provide you with any products, services or performance for which we require the provision of personal data.
There is some data which we only collect and process with your consent. This mainly involves data processed within the ČSOB Group for marketing purposes, data used to ensure your comfort in the electronic channels or in certain cases for the submission of data to ad hoc recipients. The submission of this data to us is voluntary. You can withdraw your consent at any time.
The submission of the data is compulsory in all the other cases where we request it. We typically collect identification details from you. We need those details to conclude and fulfil the contract with you, to fulfil our other legal obligations and to protect our legitimate interests.
Sources of personal data
Depending on the situation, we process data that we have received from you, as well as data from public and non-public sources and registers, such as the Trade Licensing Register or the National Identification and Authentication Point, as well as data from third parties (e.g., payees). We transfer data within the framework of the ČSOB Group or the KBC Group for internal administrative purposes.
We mainly process data which you have given us or which you have created by means of your activity. We enhance the data with information from further sources (internal and external) in those cases where it is essential and appropriate to do so in order to achieve the purpose of processing your data. This especially involves the following cases:
-
Marketing
We use data which we have collected ourselves, as well as published data or data obtained from third parties. As such, we process your contact details and profile data, especially from social networks, and any other data which you publish about yourself or which is published about you on the Internet.
-
Security and risk management
In those cases where we use our internal databases, these databases contain information which is essential for assessing the security and risk management. We also collect this data from external public sources. In some cases we need to assess the ability and willingness of our clients to fulfil their obligations. To this end, we process data from the databases of the Banking Client Information Register (BRKI), the Non-Banking Client Information Register (NRKI), SOLUS and the Central Credit Register. You can find more information about this in the section “Credit registers”. We also use the TelcoScore service. We work with data obtained on the basis of enquiries sent to us by state administration authorities (e.g., law enforcement authorities).
-
Processing of data from public registers
We acquire your basic data from public registers, for example from the Trade Licensing Register or the Register of Territorial Identification, Addresses and Real Estate (RÚIAN) in those cases where we exercise our legitimate interests, especially our interest in acting with due diligence and the option of using profiling.
-
Processing data from non-public registers
In order to fulfil our obligations under the law, we are entitled to use data from the national registers (from the national population register, the information system of civil records or the information system for the registration of identity cards, etc.), for example, to update your personal data and, in the case of pension savings, to verify your entitlement to a state contribution.
-
Transfer of data within the framework of the ČSOB Group and the KBC Group
We transfer your personal data within the framework of the ČSOB Group and the KBC Group. We mainly use this data for the purposes of internal administration and reporting, but the transfer of this information can also simplify things for you such as the conclusion of contracts and the resolution of matters concerning our products across the entire Group. We also transfer data to comply with our duty of professional care and to monitor and prevent fraudulent practice.
-
Verification of identity through the banking identity with another bank
We can also verify your identity through the electronic banking identity you have with another bank. If you allow us to do so, we will pass on the data necessary for your identification and authentication.
-
Use of our products and services
In some cases of the settlement of claims related to insured events, we obtain information also from non-public sources, especially from the Police of the Czech Republic through the Czech Insurers’ Bureau regarding the cause and course of traffic accidents or the extent of injuries. We also obtain information from the vehicle register, medical facilities and health insurance companies or from the central register of civil records.
-
Depositary services
When providing the services as an investment fund depositary, ČSOB processes investors’ personal data for the purpose of fulfilling its statutory obligations under the Act on Management Companies and Investment Funds, on the basis of documents sent by the fund manager.
Recipients of personal data
We keep your personal data within our Group. The data is only transferred outside the Group on the basis of your consent or if required by law. Your data may be processed by cooperating distributors and suppliers if it is essential to do so for the purposes stated above and especially if the external entity in the given area has the essential professionalism and level of expertise. We are obliged to transfer your data to various state and international bodies, but always under the conditions set out by law.
Data sharing within the ČSOB Group
-
Service and client care
Every company will share your basic data, product and service data and the data from our communication and interactions with the other companies in the ČSOB Group in the Czech Republic and Slovakia. We do so to protect our rights and legitimate interests and if you have given your express consent. We need to share the data to maintain the integrity and timeliness of our data and the speed and quality of service in client identification and authentication, customer relationship management, offering products and services within the ČSOB Group and for your use of products and services. This enables us to serve you and to meet your requirements across the entire ČSOB Group. For example, if you change your surname or contact details, each company in the Group will not bother you separately with regard to the change in this information, provided that this is technically possible. We also allow you to switch between the various portals and applications within the ČSOB Group without having to re-enter your login details; we will verify your identity by passing on your contact and identification details. For the above purposes, your data may also be shared with sales representatives of individual companies of the ČSOB Group. We also share the data within the ČSOB Group for our administrative purposes and for the purposes of measures against money laundering and financing of terrorism, international sanctions and fraud prevention and investigation.
If a product is being arranged for you and you are an existing client of another company from the ČSOB Group, the AML identification obligation under the AML Act may also be fulfilled by its assumption under the AML Act. Thus, the data for AML identification of the client is transferred by one company to another company in the Group.
Both the companies are then in the position of controller in relation to the data transferred.
To facilitate customer service across borders, we also share your personal data with Československá obchodná banka, a.s., based at Žižkova 11, 811 02 Bratislava, Slovakia.
-
Consent to data processing and sharing within the ČSOB Group for marketing purposes
If you have provided us with consent to use your data within the ČSOB Group as a client or an applicant for any of our services, we can share your data for marketing purposes and as such provide you with a simpler, faster and higher-quality services across the entire ČSOB Group. We may also use information about your accounts with other banks that is at ČSOB’s disposal with your consent. Thanks to your consent, we are able to take better account of your preferences, while you acquire access to a much wider range of services which is more relevant to you. Your consent is completely voluntary and you can restrict or withdraw it at any time. Find the procedure under the headings “Do you want to withdraw your consent?” and “Do you want to limit marketing?”
If a member of the ČSOB Group acts as a product broker outside the ČSOB Group, the personal data that it processes for other product providers (such as cooperating insurance companies) will not be transferred to ČSOB Group members based on your consent.
We can use your data for profiling, we may carefully monitor, analyse or store the data in our database and we are authorised to use it to create personal profiles, including the use of automated technology, and to use it for determination of specific conditions of the products offered. The data is processed to create business recommendations for our branch employees, so that we can offer you products and services which are tailored to your needs. The data is also used for creating marketing campaigns or earning and redeeming Kate Coins.
We can contact you by post, by telephone from our Client Centre, directly via our branch employees and via our sales representatives in order to inform you of any new products and services. Other channels include emails, text messages and so on. You can choose whether you wish to receive offers by text message, by email, by telephone or by letter or from our electronic portals or mobile applications.
The consent applies to the members of the ČSOB Group. For the purposes for which you have given your consent, the members of the Group act as joint controllers.
You can grant, withdraw or change your consent for a given company or for the entire Group at any of these companies:
Československá obchodní banka, a.s., ČSOB Pojišťovna, a.s., member of the ČSOB Group, ČSOB Hypoteční banka, a.s., ČSOB Stavební spořitelna, a.s., ČSOB Leasing, a.s., ČSOB Penzijní společnost, a.s., member of the ČSOB Group, ČSOB Asset Management, a.s., management company, Patria Finance, a.s., Ušetřeno.cz s.r.o., Ušetřeno s.r.o., Skip Pay s.r.o., Igluu s.r.o., ČSOB Pojišťovací makléř, s.r.o. and others.
You can find the current list at www.csob.cz/skupina.
You can also use the Group call line at +420 800 023 003 or write to us at osobni-data@csob.cz.
The marketing consent replaces your previous actions with regard to the same processing purposes, supplements any further consents pertaining to data processing and does not cancel or limit the right of the appropriate members of the ČSOB Group to process your data, provided that we are directly permitted to do so by law.
-
Security and risk management
We also share your data for security and risk management purposes to comply with legal obligations, including the sharing of information about your accounts with other banks which you have linked to your ČSOB accounts, for example to assess your creditworthiness, for tax purposes, or to comply with anti-money laundering rules.
KBC Group
Our shareholders and other associated entities from the KBC Group are data recipients on the basis of the prudent management of the entire KBC Group, of which the ČSOB Group is a member. We mainly transfer data for the purposes of reporting to the extent of the basic data about the individuals acting on behalf of our corporate clients and their end owners. We only transfer data to the KBC Group within the framework of the EU and we adhere to the same high data protection standards as in the ČSOB Group when processing the data.
Our distributors
We mainly sell and service our products through the companies which belong to the ČSOB Group. However, we also have an extensive network of external financial advisors. Internal and external distributors process our clients’ basic data and their appropriate product and service data and as such they become personal data processors for us. Czech Post and its partners are significant brokers for our services.
Our suppliers
If we commission another entity with the performance of certain activities which constitute part of our services, this may lead to the processing of relevant personal data. In some cases, these suppliers become personal data processors. The processor is only authorised to handle the data exclusively for the purposes of the performance of the activity which it has been commissioned to undertake by the appropriate controller under a contract. Your consent is not required for the performance of the processing activities in such a case because this type of processing is directly permitted by law.
The suppliers are primarily the companies operating within the ČSOB Group and the KBC Group. Some activities are secured using entities from outside the Group.
The suppliers who come from outside the ČSOB Group especially include:
- providers of IT services, including cloud storage, AI technologies and IT security services (e.g., Salesforce, Microsoft – including the services of Azure, Open AI, Wultra, Amazon Web Services);
- providers of printing and postal services, including couriers (e.g., Czech Post);
- marketing agencies and entities working with us on events for clients (e.g., IPSOS s.r.o., Mailkit s.r.o.);
- Bankovní identita a.s. (banking identity, data exchange between banks);
- attorneys (e.g., Havel & Partners s.r.o.);
- archiving service providers, debt collectors;
- bulk product providers, such as group insurance;
- property appraisers for mortgage purposes;
- entities which cooperate with us on payment card loyalty schemes.
Ensuring the functioning of a payment card and the provision of related services requires that we pass on your personal data for processing to card associations (e.g., VISA, MasterCard). If you agree, we will pass on your data and card details to the Click to Pay payment solution.
Data transfer outside the EU/EEA
ČSOB prefers suppliers and providers based in the EU/EEA. This is because, with exceptions approved by the European Commission (e.g., Canada), legislation in non-EEA countries (such as the United States or India) does not always provide an adequate and comparable level of personal data protection as in the EU/EEA. However, if we exceptionally cooperate with suppliers established outside the EEA, ČSOB is obliged to guarantee a sufficiently high level of protection, for example in the form of standard contractual clauses approved by the European Commission, binding corporate rules, etc., and also to put in place adequate control mechanisms and take technical and organisational measures such as encryption and other actions to ensure a level of protection comparable to that within the EEA.
If we use cloud storage, it is located within the EU as a matter of principle. Even if the data centre is located in the EU, there is a possibility that access from outside the EU may be granted for 24/7 incident management, for example in cases where ČSOB works directly or indirectly with its suppliers and providers. In such a case, the rules for the transfers of personal data outside the EU will apply in order to ensure an adequate level of protection comparable to that within the EU.
With reference to the above, these are typically processors/suppliers such as Microsoft, Amazon or the VISA and Mastercard associations. The scope of the personal data processed always depends on the specific product the client has with ČSOB; the scope covers mainly basic identification details and product information.
Our partners
For the purpose of evaluating cooperation with third parties (e.g., for loyalty schemes), ČSOB provides reports based on the processing of clients’ personal data. The reports contain only data that has been pseudonymised and, as a matter of principle, aggregated, unless a more detailed level of data is necessary to fulfil the purpose of the report. ČSOB never provides third parties (for their own business purposes) with data in a form that allows the third party to identify a specific person. The data is shared exclusively with partners that are carefully selected by ČSOB and that meet the contractual, technical and organisational requirements for processing such data.
ČSOB Identity – electronic banking identity (ČSOB eID service)
The ČSOB Banking Identity is used to electronically verify your identity with third parties, such as some public administration portals and private partners involved, e.g., e-shops. Identity verification can also be done through Bankovní identita.
For this purpose and only upon your request, we will share the requested scope of personal data.
For more information, visit: www.csob.cz/identita
Before you use your ČSOB Banking Identity for the first time, we will verify your identity and register your Electronic Identification Means in the portal of the National Identification and Authentication Point, with which we share the necessary personal data for this purpose.
Electronic signing
If we enable you to sign electronically on the basis of signature certificates issued by qualified trust service providers, we will share with these providers your personal data which is necessary for the issuance of the respective certificates, such as those from Ardaco, a.s. As Ardaco, a.s. is a Slovak company, we transfer the personal data abroad within the EU. In some cases, we also allow you to use the signing services provided by Bankovní identita, a.s., which uses its own qualified trust service provider with whom it shares your personal data required to provide the service.
Verification of creditworthiness (ability to pay) and trustworthiness through credit registers
Some members of our Group look for information on matters which testify to your creditworthiness, payment history and trustworthiness in the credit registers in order to fulfil the obligations involving the assessment of the clients’ ability and willingness to fulfil their loan obligations. The data is taken from the databases of the Banking Client Information Register (BRKI), the Non-Banking Client Information Register (NRKI) or SOLUS. ČSOB, ČSOB Stavební spořitelna and ČSOB Hypoteční banka are participants in the Central Credit Register (CRÚ), which is an information system of the Czech National Bank collecting information on credit commitments of private individual entrepreneurs and legal entities.
-
BRKI/NRKI
The BRKI is part of a system which collects information about the creditworthiness, trustworthiness and payment history of bank clients. The BRKI is operated by the CBCB (Czech Banking Credit Bureau) joint-stock company, whose website at www.cbcb.cz provides all the necessary information on the register. The BRKI shares data with the Non-Banking Client Information Register (NRKI), which collects information from leasing and credit companies. The NRKI is operated by the CNCB (Czech Non-Banking Credit Bureau) professional association. No consent is required to use the registers. For more, see the Information Memoranda of the Banking Client Information Register (BRKI) and the Non-Banking Client Information Register (NRKI).
-
SOLUS
According to the Consumer Protection Act, or based on your consent, your personal data may be kept in registers which are used to inform their users about a consumer’s identification details and about any matters which may reveal their creditworthiness, payment history and trustworthiness. The ČSOB Group is a participant in the SOLUS registers, which are held by an association of legal entities. For more information, see the Instruction on the SOLUS Registers.
-
TelcoScore
Our Group also uses the TelcoScore service. This service provides predictions of a customer’s behaviour – the probability of customer default based on telecommunication data. The score providers are mobile network operators. The operation of the score publication platform is provided by Společnost pro informační databáze, a.s. (SID). The use of TelcoScore is always subject to your consent.
For more, see www.sid.cz/informacni-databaze/telco-score and the Privacy Statement – TelcoScore.
Records of dematerialised investment instruments
Your investment data is provided to third parties for processing for the purpose of keeping records of the dematerialised investment instruments which you own. These third parties especially involve the Central Securities Depository Prague, as well as other entities which keep independent records of these investment instruments. In the case of foreign registering entities, the personal data is disclosed to the extent designated by the local legislation. All of these cases involve the fulfilment of the contracts which form the legal framework for reinvestment. Your consent is not required to process the data held in these records because the data is processed in accordance with a contract.
State aid for building and pension savings
The building savings bank or the pension company submits data about your contract, including the identification details and information provided in your residence permit, if relevant, to the Ministry of Finance in order to secure the state aid for building and pension savings.
Exchange of information in the insurance industry
The system for the exchange of information about suspicious circumstances, known in Czech by the acronyms SVIPO and SVIPO II, is used to secure the fulfilment of the insurance companies’ statutory obligations during the exchange and sharing of information for the purpose of monitoring and preventing fraudulent practice (the prevention and discovery of insurance fraud) via SUPIN, a subsidiary of the Czech Insurance Association and the Czech Insurers’ Bureau. The ELVIS system allows the insurance companies to fulfil their statutory obligation to exchange and share information on insurance brokers with a view to preventing and detecting unlawful conduct. The performance of the obligation was transferred to the Czech Insurance Association by insurance companies that are members of that Association.
The REDOS system is used to ensure that the insurance companies fulfil their statutory obligation to exchange and share information with a view to preventing and detecting insurance fraud and other cases of unlawful conduct. The performance of the obligation was transferred to the Czech Insurance Association by insurance companies that are members of that Association.
All participants in the SVIPO, SVIPO II, ELVIS and REDOS systems have thus become joint controllers in relation to the personal data managed by those systems.
Recipients under insurance coverage
The securing of some of the products which we offer you (life and non-life insurance) requires us to provide your basic data, the product and service data concerning the given insurance and some financial information and other data (your health data) to the reinsurance companies and reinsurance brokers. In addition to the reinsurance company’s branches in EU countries, we also transfer the data to Switzerland on the basis of and in accordance with the Commission Decision on the adequate protection of personal data provided in Switzerland, and to other non-EU countries (the UK and the U.S.). However, we always carefully assess whether your personal data is provided with a level of protection comparable to that granted in the EU under the GDPR, or we use additional technical and organisational measures to ensure this (e.g., encryption). We provide the data to reinsurance companies and reinsurance brokers on the basis of the Insurance Act.
Recipients within the framework of the exchange of information concerning tax matters
We are obliged to provide the Ministry of Finance with the appropriate information about our clients within the framework of our cooperation in the area of taxes. The data is submitted on the basis of international agreements concluded by the Czech Republic or the EU (for example, the FATCA Agreement). Information on these international agreements is available at www.mfcr.cz. More detailed information about this exchange is also stated in the Automatic Information Exchange in the Area of Taxes section on the website at www.csob.cz.
Account information service providers
Subject to your consent, we will provide your account information to our payment account information provider.
Correspondent banks
A list of ČSOB’s correspondent banks can be found at:
https://www.csob.cz/en/businesses/contacts/correspondent-banks
Exchange of data between banks to prevent fraud
In the framework of the investigation of fraudulent activities and prevention necessary for the avoidance, investigation and detection of fraud in the field of payment transactions, identification services or other acts that show signs of fraud, data is transferred and processed between banks or foreign branches of banks that have joined the SAFE D programme. SAFE-D involves the processing of personal data of persons with whom the bank has concluded or is in the process of concluding a contract for the provision of services, i.e., clients, former clients and prospective clients of the bank, as well as authorised account users of bank accounts maintained by the bank, or other persons involved or potentially involved in fraud in the area of payments and identification services or other conduct that shows signs of fraud. The object of the processing is identification details, contact details and transaction data. Bankovní identita a.s. is the operator of the solution through which banks transfer data among themselves. Personal data is processed for a period of 10 years after its collection.
Ad hoc recipients
-
No consent
Some public administration authorities and other organisations are entitled to request information about you. This mainly involves the supervisory activities of the Czech National Bank, but also the courts, the Police of the Czech Republic, compensation funds or health insurance companies, for example. We only provide the information to these institutions if such a request is permitted by law. Data is also transferred when the relevant claims and receivables are assigned.
If you place a direct debit order that is not executed, we will share your first name and surname or other name with the payer so that the situation can be resolved and the payment can be completed successfully.
-
On the basis of your consent
During the course of our work, we also handle information requests from third parties in the form of references and confirmations. We do this at your request or with your consent.
Automated decision-making
We use automated decisions to provide some of our services. If you do not want us to process your data in this way, you do not have to ask for a service or enter data in online forms at all. Yet, if you do, you can request a review of the final decision and other rights listed in the section “What are your rights?”
We also use the automated process to comply with anti-money laundering rules.
Automated individual decision-making is the process by which a computer judges and decides on your situation. As a result, we are able to immediately assess whether or not you are entitled to a particular product, and/or under what conditions, and arrange the product with you. This only means more comfort and time savings for you.
We also carry out the automated processing to mitigate and effectively manage the risks of money laundering and financing of terrorism, as required by the Anti-Money Laundering Act.
Automated arranging of our products and services
Some of our products and services can be arranged automatically without human intervention. In that case, your product application is automatically evaluated and, if you meet all the conditions, the contract is concluded immediately. If the computer assesses that any of the conditions for automated arranging are not met (e.g., changed identification details, insolvency, business interruption, etc.), your application will be referred to our staff for manual processing, or you may submit a new application through our branch.
Insurance
When arranging insurance, we review the information you have provided or entered in the web form (for insurance policies arranged via the Internet), such as your identification details, vehicle registration number, policy period, location of insurance, your residence and other information about you and the object of the insurance. Based on the data entered, we look for further information from available sources. We have a software which uses all the data to determine the price of the insurance and other conditions and allows you to take out insurance under the specified conditions, or tells you that it is not possible to arrange it. Similarly, automated decision-making may take place for the purpose of determining any discount on premiums if you have given your explicit consent to this. On the basis of your consent, data may be transferred and subsequently processed across the ČSOB Group.
This process means that you can quickly and, if possible, online get an idea of what conditions you are entitled to and conclude the contract with us right away. Consequently, the computer will automatically decide on these conditions, or it may also decide that we will not enter into a contract with you.
For the settlement of simple insurance claims reported via web reporting, which enables the collection of structured data, the insurance company uses automated decision-making, which is always carried out with a final check by an insurance company employee.
Payment transactions entered online
If you conduct transactions in your Electronic Banking, we use an automated process to process them. We typically check balances, limits, etc.
Loan granting
Approval of the loan, including the risk assessment, and any immediate withdrawal of funds are all carried out automatically. As part of this automated process, you are identified first. The data necessary to grant the loan is then collected, verified in our internal systems, including the processing of information from your accounts with ČSOB or accounts with other banks you have linked to your ČSOB accounts, and data in credit registers, or the TelcoScore service is used; then a decision is made on whether you can be granted the loan, i.e., draw down the loan funds. Preapproved limits are used throughout the process to help you get the loan more easily. The automated process is also used to detect and resolve repayment problems.
Review of the suitability of the client investment portfolio
We are contractually and legally obliged to review the suitability of the client investment portfolio at least annually for clients who have arranged the service of investment portfolio consultancy. In some cases, we perform this review using automated portfolio modelling. When it is automatically assessed that there are appropriate actions to address any portfolio deficiencies, the client will be proposed adequate actions in his/her portfolio to address those deficiencies.
Kate
Kate’s assistance is usually fully automated and can lead to decisions being made without human involvement. For more information on personal data processing in the context of using Kate, please see above.
What are your rights?
We process your data transparently, fairly, correctly and in accordance with the law. You have the right to access your data and to have it explained, the right to data portability, as well as other rights, if you are of the opinion that there is something wrong with the data processing. You have the right to object to the processing of data on the basis of a legitimate interest and/or direct marketing. You may also submit a complaint to the Office for Personal Data Protection. In general, we process your rights free of charge. We would, however, like to point out that we are entitled to request a commensurate fee for your request or even to reject it, if it is clearly groundless or inappropriate and especially if it involves a repeated request. We may ask you provide us with more information, such as to confirm your identity. You can best exercise your rights at the branch office or in your controller’s business network. Your controller may offer other easy ways to exercise your rights: typically in Internet Banking or other electronic portals, by email with your electronic signature or by phone. You can also communicate with us via data mailbox. You can also send your requests by regular letter or email. Requests submitted in this way must include your identification details, such as your birth certificate number or date of birth.
We will respond to your request appropriately. It can be handled, for example, through an electronic portal. If you choose to deliver your request by post, please note that we are not responsible for the content of the letter after shipment. We always do our best to communicate in such a way as to make it clear what method will be used to process the request.
If you have any questions, call +420 800 023 003, visit www.csob.cz/osobni-udaje or write to us at osobni-data@csob.cz.
Do you wish to know which data about you we process and how we handle it?
You have the right to obtain from us a confirmation as to whether or not we process personal data concerning you, and an overview of such data. You are further entitled to be informed about the purposes of the processing, the categories, the envisaged period of storage, from which sources we obtained the data and with whom we share the data, about your right to request rectification or erasure of personal data or restriction of processing of personal data or to object to such processing with us or the supervisory authority, and to obtain information as to whether this involves any automated decision-making and the information associated with that. We are entitled to ask you to specify which data or type of information you are interested in. We do not charge any payments for the first extract of the data; we can require a commensurate payment for any extra copies, which shall not exceed the costs which are essential for the provision of the information. You will always receive the transaction data in the form of a statement for the given service which you use. Please note that the overview does not include the data which we are not authorised to provide due to its specific nature. We may also exclude the listing of data which, by its very nature, is not used on an on-going basis and is therefore not readily available. We also process such data, however, in accordance with the applicable legal regulations.
Are you interested in rectifying your data?
We will naturally rectify any personal data concerning you if it is incorrect or inaccurate. We may also complete the data upon your request, while taking into account the purpose for which the data is processed.
Do you want us to erase your data?
You are entitled to have the personal data concerning you erased in the following cases:
- we no longer need the data for the purposes for which we have collected it;
- we process the data based on your consent, which you have withdrawn, and we cannot process the data based on another legal purpose (such as our legitimate interest);
- you have objected to the processing on the basis of legitimate interests or public interests or for the purpose of direct marketing, as described below;
- the processing is unlawful;
- by erasing the data, we must comply with a legal obligation; or
- we have collected the data in connection with an offer of information society services on the basis of the consent granted by a child.
Please note that we will not erase the data if the data processing is necessary, inter alia:
- to comply with a legal obligation or task carried out in the public interest;
- for archiving purposes in the public interest or for historical and scientific research, if it is not possible to grant the right to data erasure on these grounds;
- to secure and enforce legal claims;
- for another purpose which is compatible with the original purpose.
Do you wish to restrict the processing of your personal data?
You are entitled to have the processing of the personal data concerning you restricted in the following cases:
- if you exercise your right to rectification, until we verify the accuracy of the data;
- the processing is unlawful;
- we no longer need your personal data for the original purposes, but you request the data for the purposes of securing and exercising your legal claims; in that case, we restrict the processing for a period of your preference, otherwise for 5 years;
- if you are objecting to the processing on the basis of our legitimate interests or public interests, until we verify the data.
The restriction means that we will retain the data but will not process the data in any way, with the exception of its archiving, use to protect our rights or third-party rights, due to significant public interests or in a way for which you have given us your consent. Once the reason for the restriction is removed or expires, we may lift the restriction while notifying you of the fact. You may also withdraw the restriction yourself.
We can then continue to process the data but we may also be required to erase it (e.g., if any further processing proves unlawful).
Are you unwilling or unable to provide us with your data?
You can refuse to provide us with the personal data which we request from you. If, however, this involves information which must be compulsorily provided, we will be unable to provide you with the associated services.
Do you want to be sure that your personal data is secure?
We treat your personal data with all due care and in accordance with the applicable legislation.
We protect your data to the greatest possible extent in accordance with the technical level of the available means. If there is a breach of your personal data security for any reason which gives rise to a high degree of risk to the rights and freedoms of individuals, we will inform you of this without any undue delay.
Do you disagree with our right to process your personal data?
You have the right to object to our processing of personal data (including profiling) concerning you:
- based on our – as we claim – legitimate interests (see, e.g., Kate, your digital assistant) or to carry out a task or an activity in the public interest (such cases are primarily explained among the purposes of processing); in that case, we will not continue to process your personal data unless we demonstrate that there are compelling legitimate interests to carry on with the processing which override your rights and freedoms or to secure and exercise our legal claims;
- for the purpose of direct marketing, that is, to offer you relevant products and services; in that case your personal data for direct marketing will not be further processed;
- for scientific or historical research purposes or statistical purposes.
You can object for reasons relating to your specific situation, and we can therefore ask you to provide an adequate justification.
Do you wish to obtain your data or to transfer it elsewhere?
You have the right to obtain your personal data and to transfer that data to another controller under the following conditions:
- it is personal data concerning your which you have provided to us;
- the processing is based on your consent or it is for the purposes of a contract;
- the processing is carried out automatically.
We will provide the required data in a structured, commonly used and machine-readable format. If it is technically feasible and you so wish, we will transfer the data directly to your designated controller. In that case, however, we will not be responsible for the data transferred to such other controller, as we have no control over that data. Please note that we may not satisfy your request if it should adversely affect the rights and freedoms of others (such as another subject’s personal data or a trade secret) or where we process the data to carry out a task or an activity in the public interest. We may also exclude the listing of data which, by its very nature, is not used on an ongoing basis and is therefore not readily available. We also process such data, however, in accordance with the applicable legal regulations. You can download your transaction data in the electronic portal.
Do you want to withdraw your consent?
You are authorised to withdraw your consent at any time in those cases where we have requested your consent to carry out the data processing. The withdrawal of your consent will not influence the processing of your data (specifically the data provided for the purpose of marketing processing, information on your state of health or cause of death or biometric data) throughout the period when you have validly issued the consent and it will likewise not influence the processing of your data on other legal grounds if they apply (for example, the adherence to legal obligations or for the purposes of our legitimate interests). Please note that for technical reasons, the processing of your request to withdraw your consent may take up to one month.
Do you want to limit direct marketing?
If you are receiving commercial offers from us, you can unsubscribe from the offers or certain channels in one of the following ways:
- you can disable the offers in electronic channels;
- all our commercial communications include an unsubscribe option to stop them being sent;
- if you no longer wish us to contact you by phone, please tell us so during the call;
- you can also inform us at our branch or in writing that you no longer wish to receive any offers.
You can unsubscribe from commercial communications at any time, we respect your wishes and you can also disable this option before a commercial communication is sent.
If you do not want us to transfer your personal data for marketing purposes within the Group, i.e., if you wish to limit or withdraw your consent to the processing and sharing of data within the ČSOB Group for marketing purposes, please call us at 800 023 003, visit our branch office or email us at osobni-data@csob.cz, and we will get back to you. Please provide your phone number to enable a verification call. You can also alter the consent settings in some of our electronic portals if you have access thereto within our services. You can choose whether you wish to receive offers by text message, by email, by telephone or by letter or from our electronic portals or mobile applications.
Please note that, if you limit direct marketing, we can still continue to contact you because of our services, i.e., we can still use your contact details for the purpose of sending service messages and for purposes other than marketing.
Visitors to our websites can withdraw their consent to the processing of cookies in the manner set out on the relevant website.
Do you want us not to automatically decide in your case?
If we use automated decisions to provide a service, it is easiest to prevent such processing by not requesting the service or by not submitting your data via the online form at all. If you do, but you disagree with the final decision, you can exercise your following rights:
- the right to human intervention by the controller – we will ensure that the relevant data is evaluated by a responsible person;
- the right to express your opinion – we will take into account all your relevant opinions;
- the right to challenge the decision – if you have not been offered the opportunity to enter into a contract, or if you find the terms inadequate, we will review the decision.
All the aforementioned measures will be taken at your request, as in other cases. If your request concerns a specific decision, please specify the decision and all related circumstances as accurately as possible (what matter, on which day, etc.).
Right of complaint to the supervisory authority and other supervisory procedures
If we have not complied with your request or you are not satisfied with the information provided or the way of processing your request, we recommend that you first contact us with a request for a re-examination or file a complaint with our Data Protection Officer. The contact details of our DPO can also be found on the first page.
You can lodge a complaint to the Office for Personal Data Protection. The contact details of the Office can be found on the first page. For more information on how to lodge a complaint, please visit the Office’s website; you may also contact the Office by phone using the indicated number. You may also seek judicial remedy.
About us – what is the ČSOB Group
The ČSOB Group provides, in the territory of the Czech Republic, financial products and services, especially the administration of bank accounts, the securing of finances, the acquisition and use of various assets, particularly by means of loans and leasing, various types of insurance, products aimed at securing individuals in their old age and disability, especially in the form of supplementary pension schemes, housing financing in the form of mortgages or building savings, collective investment and asset management, as well as services relating to share trading in the financial markets. Our Group is a member of the international KBC Group, which operates in the field of banking and insurance. Some of our services are provided in collaboration with our business partners. These services involve distributors or loyalty schemes, for example.
You can find the current list of all the ČSOB Group members at www.csob.cz/skupina.
The following are the contact details of the Data Protection Officers at the major companies:
| Company name | Data Protection Officer – contact | Address | |
|---|---|---|---|
| Československá obchodní banka, a. s. (it is active in retail banking in the Czech Republic under the core trademarks ČSOB and ČSOB Poštovní spořitelna) | Mgr. Lucie Hloušková | dataprotectionofficer@csob.cz | Radlická 333/150, 150 57 Praha 5 |
| ČSOB Stavební spořitelna. a. s. | Mgr. Lucie Hloušková | dataprotectionofficer@csobstavebni.cz | Radlická 333/150, 150 57, Prague 5 |
| ČSOB Asset Management, a. s., management company | Mgr. Kateřina Bobková | dataprotectionofficerAM@csob.cz | Radlická 333/150, 150 57 Praha 5 |
| ČSOB Pojišťovací makléř, s. r. o. | Mgr. Lucie Hloušková | dataprotectionofficer@csobpm.cz | Výmolova 353/3, 150 57 Praha 5 |
| ČSOB Leasing, a. s. | Mgr. Lucie Hloušková | dataprotectionofficer@csobleasing.cz | Výmolova 353/3, 150 57 Praha 5 |
| ČSOB Penzijní společnost, a. s., member of the ČSOB Group | Mgr. Lucie Hloušková | dataprotectionofficerPS@csob.cz | Radlická 333/150, 150 57 Praha 5 |
| ČSOB Pojišťovna, a. s., member of the ČSOB Group | Mgr. Anna Soldánová | dataprotectionofficer@csobpoj.cz | Masarykovo náměstí 1458, Zelené Předměstí, 530 02 Pardubice |
| ČSOB Hypoteční banka, a. s. | Mgr. Lucie Hloušková | dataprotectionofficer@csobhypotecni.cz | Radlická 333/150, 150 57 Praha 5 |
| Patria Finance, a. s. | Mgr. Lucie Hloušková | dataprotectionofficer@patria.cz | Výmolova 353/3, 150 57 Praha 5 |
| Patria Corporate Finance, s.r.o. | Mgr. Lucie Hloušková | dataprotectionofficer@patria.cz | Výmolova 353/3, 150 57 Praha 5 |
| Patria investiční společnost, a.s. | Mgr. Lucie Hloušková | dataprotectionofficer@patria.cz | Výmolova 353/3, 150 57 Praha 5 |
| Ušetřeno s. r. o. | Mgr. Tomáš Ryza | dataprotectionofficer@usetreno.cz | Lomnického 1742/2a, 140 00 Praha 4 |
| Ušetřeno.cz s. r. o. | Mgr. Tomáš Ryza | dataprotectionofficer@usetreno.cz | Lomnického 1742/2a, 140 00 Praha 4 |
| Skip Pay, s.r.o. | Mgr. Michal Briš | dpo@skippay.cz | U Garáží161/1, 170 00 Praha 7 |
| ČSOB Pojišťovací servis, s. r. o., member of the ČSOB Group | Mgr. Anna Soldánová | dataprotectionofficer@csobpoj.cz | Masarykovo náměstí 1458, Zelené předměstí, 532 18 Pardubice |
| Igluu s.r.o. | Mgr. Pavlína Hojecká | dpo@igluu.cz | Lomnického 1742/2a, 140 00 Prague 4 |
| BUSINESS LEASE s.r.o. | dataprotectionofficer@csobleasing.cz | Radlická 714/113a, 158 00 Prague 5 |
The email address and telephone contact number for questions concerning personal data are the same for all the companies: 800 023 003 and osobni-data@csob.cz.
Our business partners
Our business partners are distributors of the Group’s products, as well as partners of the ČSOB Premium scheme and loyalty schemes such as the World of Rewards, partner insurance companies of Top-Pojištění.cz, ČSOB Leasing insurance broker, Ušetřeno.cz, as well as providers of assistance services, including services for the ČSOB Premium and Private Banking clients. Our strategic business partner is Czech Post.
Our business partners:
- https://www.csob.cz/en/csob/protection-of-personal-data/partners
- Partner insurance companies of Ušetřeno s.r.o., which operates mainly the TopPojištění.cz portal: https://www.top-pojisteni.cz/partnerske-pojistovny
- Partners of the World of Rewards scheme: https://svetodmen.cz/
KBC Group
The ČSOB Group is part of the KBC Group. The KBC Group is an integrated banking-insurance group which focuses on individuals, small and medium-sized enterprises, medium-sized corporations and private banking. Geographically, the Group operates primarily in its home markets in Belgium, the Czech Republic, the Slovak Republic, Bulgaria and Hungary, and it is also active in several other countries to a lesser extent. The major companies in the KBC Group in Belgium are KBC Group NV, KBC Bank NV, KBC Insurance NV, CBC Banque SA, KBC Autolease NV, KBC Securities NV and KBC Asset Management NV. More information is available in the list of companies in the KBC Group at https://www.kbc.com/en/our-structure.
Which laws contain provisions governing the issue of personal data?
When processing your data, we adhere to the applicable legislation, primarily to the EU General Data Protection Regulation, acts governing the duty of confidentiality (e.g., the Civil Code, the Act on Banks and the Insurance Act) and the Anti-Spam Act, which prevents the sending of unsolicited commercial communications
The main legal regulations in the area of the protection of your data (or which are associated with data protection):
| Anti-Money Laundering Act | Act No. 253/2008 Coll., on selected measures against legalisation of proceeds of crime and financing of terrorism | Prevention of Money Laundering |
| Anti-spam Act | Act No. 480/2004 Coll., on certain information society services | Commercial communications contained in emails, text messages |
| Charter of Fundamental Rights of the European Union | 2012/C 326/02 | Personal Data Protection |
| FATCA | Agreement No. 72/2014 Coll. between the Czech Republic and the United States of America on improving the adherence to tax legislation on an international scale and Act No. 164/2013 Coll., on international cooperation in tax administration | The Bank’s obligation with regard to inspecting the fulfilment of tax obligations |
| Charter of Fundamental Rights and Freedoms | Czech National Council Resolution No. 2/1993 Coll., on the promulgation of the Charter of Fundamental Rights and Freedoms as part of the constitutional order of the Czech Republic | Right to privacy and personal data protection |
| MiFIR | Regulation No. 600/2014 on markets in financial instruments and Directive No. 2014/65/EU | The Regulation and Directive which have introduced a common market and regulatory scheme for the provision of investment services in the EU |
| Market abuse regulation | Regulation No. 596/2014 on market abuse and Directive 2014/57/EU on market abuse | Market manipulation |
| Civil Code | Act No. 89/2012 Coll., the Civil Code | Privacy protection |
| EU General Data Protection Regulation – GDPR | Regulation (EU) 2016/679 / EU of the European Parliament and of the Council | Primary regulation governing the protection of (your) personal data, applicable to the EU |
| Payment System Act | Act No. 370/2017 Coll., on payments | Regulation of payment services |
| Act on Banks | Act No. 21/1992 Coll., on banks | Bank operations |
| VAT Act | Act No. 235/2004 Coll., on value added tax | Processing of tax data |
| Supplementary Pension Savings Act | Act No. 427/2011 Coll., on supplementary pension savings | Operations of pension savings companies |
| Act on International Cooperation in Tax Administration | Act No. 164/2013 Coll., on international cooperation in tax administration | International exchange of information on tax matters |
| Consumer protection Act | Act No. 634/1992 Coll., on consumer protection | Credit registers |
| Capital Market Undertakings Act | Act No. 256/2004 Coll., on capital market undertakings | Operations of securities dealers and investment firms |
| Insurance Act | Act No. 277/2009 Coll., on insurance | Insurance company operations |
| Insurance and Reinsurance Distribution Act | Act No. 170/2018 Coll., on insurance and reinsurance distribution | Authorisation to calculate the bonus/malus when arranging certain types of insurance |
| Building Savings Act | Act No. 96/1993 Coll., on building savings | Operations of building savings banks |
| Accounting Act | Act No. 563/1991 Coll., on accounting | Processing of accounting data |
| Personal Data Processing Act | Act No. 110/2019 Coll., on the processing of personal data, EU Regulation | Implementing Regulation to the EU General Data Protection Regulation |
| ZISIF | Act on Management Companies and Investment Funds | Operations of management companies |
Glossary
| Sensitive data | Data of a special nature, such as information about your health or biometric data which allows the identification of a person. |
| Cookies | Short text files which are sent to your browser by a visited website; they allow the website to remember information about your visit, for example the preferred language and other settings. Your next visit to the website can then be easier and more productive. Cookies are important; web browsing would be much more complicated without these files. |
| Geolocation | Information on the geographical location of a mobile phone or a computer connected to the Internet (either accurate or country-specific). |
| Legitimate interest | The interest of the controller or a third party, for example in a situation where the data subject is the controller’s client. |
| Personal data | Information about a specific, identifiable person. |
| Product | Means the banking, insurance or other products and services offered by our companies. |
| Profiling | Automatic processing of your data used, for example, to analyse and forecast your behaviour in your personal and professional life, your economic situation and your personal preferences. |
| Recipient | A person whom the data are transmitted to. |
| Service | Means any of the services which we offer you, including our products, services offered online and support for them. |
| Controller | An entity which determines the purposes and means of the personal data processing; the controller may entrust the act of processing to a processor. |
| Data subject | A live person whom the personal data relates to. |
| Purpose | The reason for which the controller uses your personal data. |
| Processing | The activity which the controller or the processor carries out on the personal data, either automatically or in any records. |
| Processor | An entity which processes the personal data for the controller. |
Consent to the use of data for the ČSOB Group
Based on your consent to the use of data for the ČSOB Group, we can transfer your data within the ČSOB Group, we can analyse the data, and we can use automatic data processing to do so. Based on this, we can make decisions and offer you services from the portfolio of the ČSOB Group and our business partners, who we choose very carefully. According to your preferences, we can reach out to you with marketing offers in various forms.
Consent to the use of data for the ČSOB Group
Last modified: 1 April 2025 (archived original versions).