| What we use your personal data for | The legal basis for doing so (one of more under each sub-heading) |
|---|---|
To provide our products and services to you and perform our contract with you Manage and administer your accounts, policies, benefits or other products and services |
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you
|
To manage our business for our legitimate interests
|
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you
|
To run our business on a day to day basis
|
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you
|
To share your information with Indian or other relevant tax authorities, Reserve Bank of India and other government authorities, credit reference agencies, fraud prevention agencies, and India and overseas regulators and authorities
|
Where the law requires this
|
To send electronic messages to you about product and service offers from our Bank.
|
Where necessary for the performance of our agreement or to take steps to enter into an agreement with you
|
We only share your personal data with the following persons and/or in the following circumstances,and only as may be necessary:
Your authorised representatives
Third parties we need to share your personal data with in order to facilitate payments you have requested (for example, SWIFT, credit card issuers and merchant banks) and those you ask us to share your personal data with.
We may also share your personal data with the following third parties to help us manage our business for our legitimate interests:
Statutory and regulatory bodies and authorities (including central and local government) and law enforcement authorities, investigating agencies and entities or persons, to whom or before whom it is mandatory to disclose the personal data as per the applicable law, courts, judicial and quasi-judicial authorities and tribunals, arbitrators and arbitration tribunals.
Overseas regulators and authorities in connection with their duties (such as crime prevention).
Third parties bank may engage to provide services to you.
Processors and service providers of HDFC Bank engaged for its various activities and services.
Credit information companies or Credit reference entities, identity and address verification organizations who may record and use your information and disclose it to other lenders, financial services organizations and insurers. Your information may be used by those third parties to make assessments in relation to your creditworthiness for debt tracing
Other banks and financial institutions, quasi governmental institutions like clearing houses, network associations etc where required in terms of contract or legal requirements
Transferees and assignees and potential transferees and assignees of HDFC Bank
Courier or postal service providers for the purpose of sending or collecting of mails to you as a customer
Any other person or organization after a restructure, sale or acquisition, as long as that person uses your information for the same purposes as it was originally given to us or used by us (or both)
HDFC Bank’s branches in India or outside India, its subsidiaries, Affiliates and group entities.
For further information, please refer to our product specific terms and conditions and application form.
We will keep the personal data we collect about you on our systems or with third parties for as long as required for the purposes set out above or even beyond the expiry of transactional or account based relationship with you: (a) as required to comply with any legal and regulatory obligations to which we are subject or (b) for establishment, exercise or defence of legal claims.
Sharing personal data with us is in both your interest and ours.
We need your personal data in order to:
Provide our products and services to you and fulfil our contract with you.
Manage our business for our legitimate interests.
When we request personal data, we will inform you if providing it is a contractual requirement, a statutory requirement or not, and whether or not we need it to comply with our legal obligations.
You may choose not to share personal data or withdraw consent, but doing so may limit the services we are able to provide to you (unless consent is not the only legal basis for processing and there are other legal basis as well), particularly as under.
We may not be able to provide you with certain products and services that you request. We may not be able to continue to provide you with or renew existing products and services if such collection or updating of personal data is a legal or regulatory requirement to which we are subject.
We may not be able to assess your suitability for a product or service, or, where relevant, give you a recommendation to provide you with a HDFC Bank financial product or service.
However, if you withdraw your consent, it will not affect the lawfulness of processing based on your consent before its withdrawal or the other legal basis which we may have for such processing.
HDFC Bank is incorporated and regulated in India, its overseas branches are regulated by host country regulations and subsidiaries are governed under applicable laws. As such, your personal data is stored on secure systems within HDFC Bank premises within India and with providers of secure information storage in India. Further, we may transfer or allow the transfer of personal data about you and your products and services with us to our service providers and other organisations outside the European Economic Area (EEA), with adequate safeguards to ensure your personal data remains adequately protected.If you need copy of safeguards provided to transferred personal data, please notify us in accordance with the “How to contact us?” section below. These jurisdictions and countries outside EEA may have different and less stringent laws relating to the degree of confidentiality afforded to the personal data and that such information can become subject to the laws and disclosure requirements of such countries, including disclosure to governmental bodies, regulatory agencies and private persons, as a result of applicable governmental or regulatory inquiry, court order or other similar process. In addition, a number of countries have agreements with other countries providing for exchange of information for law enforcement, tax and other purposes.
For example, we may process payments using third parties (including other financial institutions such as banks and the worldwide payments system operated by the SWIFT organisation)
HDFC Bank is ISO 27001:13 compliant. We seek to use reasonable organizational, technical and administrative measures to protect Personal data within our organization. However, if you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “How to contact us?” section below.
You have the following rights, in accordance with and subject to the qualifications and provisions under GDPR:
The right to request from us as the controller, the access to and rectification or erasure of your personal data or restriction of processing concerning you or to object to processing as well as the right to data portability.
Where the processing is based on your consent, the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before such withdrawal. Please however note that in case such processing is also based on other legal basis like our legitimate interest or legal obligation or contractual performance or a necessity for entering into contract, and such legal basis continues to hold good, the processing will be continued despite such withdrawal of the consent.
A right to lodge a complaint with a supervisory authority in accordance with the GDPR.
From time to time, our website may contain links to and from websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites may have their own privacy notices and that we do not accept any responsibility or liability for any such notices. Please check these notices, where available, before you submit any personal data to these websites
If you are a parent of a child under 16 (or such age as applicable for GDPR purposes in the respective EU Member States), you give your consent or authorise the consent if you wish your child to access HDFC Bank Services.
We may use cookies and similar technologies on our websites, mobile apps, and in our emails. Cookies are text files that get small amounts of information, which your computer or mobile device stores when you visit a website or use a mobile app. When you return to the websites or mobile apps – or visit websites and mobile apps that use the same cookies – they recognise these cookies and therefore your device.
We use cookies to do many different jobs, like letting you navigate between pages efficiently, remembering your preferences and generally improving your online experience. They can also help ensure that the advertisements and marketing material(“ads”) you see online are more relevant to you and your interests. We also use similar technologies such as pixel tags and JavaScript to undertake these tasks. We also use cookies in some of our emails to help us to understand a little about how you interact with our emails, and to help us improve our future email communications. These cookies also help ensure that the ads you see online are more relevant to you and your interests.
Our respective websites and mobile app terms and conditions give you more information on these technologies, how and where we use them and how you can control them.
For instructions on blocking and deleting cookies, see the privacy settings and help documentation of your specific browser’s website. If you use more devices and/or browsers, you will need to disable cookies on each device and on each browser separately. Here are the locations of the cookie settings for all major web browsers:
Internet Explorer – Tools > Internet Options > Privacy tab.
Mozilla Firefox – Tools > Options > Privacy menu.
Safari users – Edit > Preferences > Privacy menu.
Chrome users – Settings > Content Settings > Privacy > Cookies.
If you limit the ability of our websites to set cookies, this may prevent you from using certain features of our website properly and your user experience – which will no longer be personalised for you – may deteriorate. You may also be able to opt out from certain cookies through third party cookie management sites. Disabling cookies may prevent you from using certain parts of our website. If you delete your cookies from the browser, you may need to remember to re-install opt-out cookies.
In the past we would have dropped the cookies in your device when you accessed our online platforms. For removing these cookies, you will need to go to your respective browser settings in your devices and remove them.