Privacy Policy
Origin of Personal Data & Sensitive Personal Data
Eskan Bank collects your personal data directly:
- During the interview process and employment
- While providing housing-related services
- While resolving your complaints and queries
- While opting the services for you
Categories of Personal Data
Eskan Bank may process the following of your personal data: Identity and Contact details such as Full name, postal addresses, email address, phone numbers, account no., CPR, passport details, and smart card data.
Purposes for Data Collection and Lawful Basis for Processing
Eskan Bank only processes your personal data based on one or more of the following lawful basis under Bahrain PDPL:
Purpose | Lawful Basis |
To open new accounts to potential customers. |
Contractual Obligation |
To acknowledge collections from customers from all locations. |
Contractual Obligation |
To offer credit to the customers |
Contractual Obligation, Legitimate Interest |
To apply online backups, system support and maintenance activities. |
Legal Obligation, Legitimate Interest |
To provide your information to auditors during and after your contract to verify compliance with Bahrain Laws. |
Legal Obligations |
To store your contact details electronically in our records for communication. |
Legitimate Interests, Data Subject Consent |
To comply with Eskan Bank internal policies and procedures. |
Contractual Obligations, Legitimate Interests |
Payment of your salary, allowances, bonuses, medical insurance, and other benefits. |
Contractual Obligations, Legal Obligations |
Enrolment with Labour Market Regulatory Authority (LMRA). |
Legal Obligations |
Attendance monitoring, vacation, absence and leave administration. |
Contractual Obligations, Legal Obligations |
Employees’ training and development programs. |
Data Subject Consent, Legal Obligations |
Arrangement of business and personal trips including visa processing, flight booking, and accommodation. |
Contractual Obligations |
Monitoring through CCTV cameras for the safety and security of individuals and assets. |
Legitimate Interests, Data Subject Consent |
Providing access to Eskan Bank facilities and assets through access cards and fingerprint. |
Legitimate Interests, Data Subject Consent |
Making decisions about your performance and eligibility of getting bonuses or moving to higher positions. |
Contractual Obligations, Legitimate Interests |
Due diligence and pre-employment activities for new employees. |
Legal Obligations, Legitimate Interests |
Initiating and following-up on any complaint, lawsuit, and criminal proceedings between you and Eskan Bank and coordination with external lawyers to manage court cases. |
Legal Obligations, Contractual Obligations |
Exit interviews, incident reporting/ investigation, and learning. |
Legitimate Interests, Data Subject Consent |
Disciplinary Actions |
Legal Obligations, Contractual Obligations |
Provide internship program for interns. |
Contractual Obligations, Data Subject Consent |
To apply online backups, system support and maintenance activities. |
Legal Obligations, Legitimate Interests |
Provide your information to auditors during and after your employment contract to verify compliance with Bahraini Labour Law and Customer Code of conduct. |
Legal Obligations |
Store your contact details electronically in our records. |
Legitimate Interests, Data Subject Consent |
Comply with Eskan Bank internal policies and procedures. |
Contractual Obligations, Legitimate Interests |
To store CVs and your contact details in Eskan Bank’s records for job vacancies. |
Legitimate Interest, Data Subject Consent |
For supply chain management process to invite and confirm quotes from suppliers. |
Contractual obligations |
For registration process or to respond to online queries. |
Legitimate Interest, Data Subject Consent |
Categories of Recipients of your Data
Your personal data will be processed by Eskan Bank and may be shared with third parties including cloud providers for email communication and online and disaster recovery storage, when required by the law, or where it is necessary to administer the relationship with you or where we have one of the above-mentioned legitimate interests in doing so. This includes sharing your personal data with banks, auditors, system support vendors, and governmental bodies.
Your rights under Bahrain Personal Data Protection Law (PDPL) (Act No. 30 of 2018)
You have the rights to submit your request free of charge to Eskan Bank:
- To be notified about the complete data concerning you and request its rectification.
- Remove, block, or restrict your personal data.
- Object if your personal data is being used for direct marketing.
- Object if processing may result in defamation or discrimination causing possible financial or moral damage.
- Object if your personal data is being used for decisions based on automated data processing and request that the processing be solely automated.
- Withdraw your consent to the processing of your personal data in cases where you have provided your consent for the processing and, as such, your consent is the lawful basis that Eskan Bank is relying on for processing.
- Eskan Bank shall process such request free of any charges within a period of 10 working days, otherwise as stipulated by the law.
- A consent once given by the prospect and/or customer can be withdrawn at any time for any future actions.
- You have the right to lodge a complaint to Bahrain Personal Data Protection Authority (Bahrain PDPA) regarding any violation of Bahrain PDPL and its implementing Orders.
Contact Information
All queries and objections to the consent or withdrawing the consent can be routed to the contact point within Eskan Bank at DataPrivacy@eskanbank.com, P.O. Box 5370, Manama, Kingdom of Bahrain.
Decisions based on automated processing
Eskan Bank will not take decisions based on automated processing of your personal data and will inform you in writing in case this condition is changed.
Security of your Personal Data
Your personal data is protected under Bahrain PDPL and Eskan Bank ensures implementing selective security measures for protecting your privacy. Eskan Bank shall implement technical and organisational security measures to keep your personal data secured and protected including when cross border transfer and storage.
Retention Period of your Personal Data
The personal data collected by Eskan Bank is retained for as long as necessary to fulfil the purpose for which it was collected, and/or based on the validity of the contract, legal retention period requirements, and historical archiving. We securely destroy and erase or anonymize your personal data to ensure that it cannot be restored after exceeding the retention criteria. Hence, Eskan Bank will not be able to support you with any further processing or information request on your personal data.
Contact details
If you have any questions or would like to obtain more details about how we use your personal data, you may contact Eskan Bank at DataPrivacy@eskanbank.com, P.O. Box 5370, Manama, Kingdom of Bahrain.
Your Role to Keep your Personal Data Accurate
It is essential for Eskan Bank to keep your personal data up to date and accurate. Therefore, kindly provide your updated information in case there is any change to your personal data during your business relationship with us.
Update on Privacy Policy
Eskan Bank has the right to review and update the privacy policy. In the event of any changes, we will inform you of any substantial change in how we process your personal data.
Requirements for Transferring Personal Data to a Third Party / Data Controller under Contract
If Eskan Bank is to transfer Personal Data to another Data Controller / Third Party residing outside the whitelist issued by PDPA but is under a contract, Eskan Bank shall obtain authorization from the PDPA authority and submit a copy of contract while ensuring the below requirements:
- Data processing shall be limited to the purposes specified in the contract.
- Data is not retained longer than is required for the purpose of the transfer.
- The data are correct, accurate, relevant, up-to-date and subject to updates when required.
- Adhere to all technical and organizational measures for the processing.
- The Data Subject shall be informed of the purpose of processing, and other information necessary to ensure fair processing.
- Ensure that the Data Subject can view all the personal data related to him that is being processed and able to correct, block or delete the data.