Home > Privacy Policy
Privacy Policy
Privacy Policy
Table of Contents
Document Maintenance
This notice is owned by the Chief Data Officer / Data Protection Officer and is reviewed at least every 12 months, and sooner on any material change in law, regulation or the Bank’s processing. It is classified as a Procedure under the Policies and Documents Management Policy v2.0 and is approved by the Chief Operating Officer.
1. About this notice
1.1 Who we are
FirstBank UK Limited (“FirstBank UK”, “the Bank”, “we”, “us”, “our”) is the data controller for the personal data described in this notice. Our registered office is at 28 Finsbury Circus, London EC2M 7DT and our UK registered company number is 04459383. The Bank is a member of the FirstBank group, whose ultimate holding company is FBN Holdings Plc; more information about the Group is available at www.fbnholdings.com. The Bank is registered with the Information Commission under registration reference Z879195X.
1.2 Purpose and scope
This notice explains how the Bank collects and uses personal data about its clients and customers when you use our products, services and websites, and how it meets its obligations under the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Please read it carefully so that you understand how and why we use your data. The Bank’s own staff, and individuals applying for roles with the Bank, are covered by separate privacy notices.
1.3 Contact us
The Bank has appointed a Data Protection Officer (DPO). If you have any questions about this notice, the Bank’s approach to data protection, or you wish to exercise your rights, please contact:
Data Protection Officer, FirstBank UK Limited, 28 Finsbury Circus, London EC2M 7DT
Email: [email protected] Telephone: 020 3595 1173
2. What information we collect
We limit the collection and use of personal data to what is necessary for the purposes described in this notice. The
personal data we collect may include:
- basic identity data, such as your title, first, maiden and last names, marital status, gender and date of birth;
- contact data, including your address, email address and telephone numbers;
- financial data, including your bank account and card payment details and your transaction information and
history; - details of the products and services provided to you by the Bank and the Group;
- identity-verification data, including copies of your passport, driving licence or other identity documents, and
images such as CCTV; - technical data, including your IP address, login data, device, browser and location data, and your activity on our
websites and apps; - profile and usage data, including your username, preferences, feedback, survey responses and how you use
our products, services and website;
• records of your communications with us, including telephone calls, emails and live chat, and summaries
produced from them;
• marketing and communications data, including your marketing and communication preferences.
Some information may be criminal offence data (for example, the results of fraud, sanctions or financial-crime
checks) or, in limited cases, special category data. The Bank processes such data only under the conditions described
in sections 4.4 and 4.5, and does not deliberately collect special category data unless it is necessary and permitted
by law.
| Personal Data Type | Description of Personal Data |
|---|---|
Identity Data | Basic personal data to identify you, such as your first name, maiden name, last name, marital status, title, date of birth; |
Contact Data | Your contact information including your email address, address and telephone numbers; |
Financial Data | Financial information including bank account details, card payment details and transactional information and history; |
| Product & Service Data | Information regarding the products and services provided to you by the Group; |
| Technical Data | Technical data including online activity based on your interaction with us, our websites and applications – for example your internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types, searches, site visits and versions, operating system and platform, and other technology on the devices you use to access this website;” |
Image Data | Personal images such as copies of your passport or driver’s licence or CCTV images; |
| Profile Data | Profile data which may include your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses; |
| Usage Data | Usage data including statistical data including information about how you use our website, products and services; |
| Marketing and Communications Data | Information about data subject communications with the Bank including your marketing preferences from us and our third parties and your communication preferences. |
3. Where we obtain your data
We collect most of this data directly from you, for example, through account-opening and onboarding forms, identity documents, other forms you complete, correspondence, calls, meetings and other interactions, our websites and mobile applications, and when you use our products and services.
In some cases, we obtain personal data about you from third parties, such as credit reference, fraud-prevention, and sanctions-screening agencies, identity-verification providers, and account information or payment initiation service providers authorised to act on your behalf, as well as from public sources and Group companies.
4. Why we use your data and our lawful bases
4.1 To provide our products and services (UK GDPR Article 6(1)(b))
We use your personal data to enter into and perform our contract with you, for example to open and administer your account, to carry out payments, money transfers and foreign-exchange transactions, and to provide customer support. If you do not provide certain information, we may be unable to provide the product or service requested.
4.2 To comply with legal and regulatory obligations (UK GDPR Article 6(1)(c))
We process your data to meet our legal and regulatory obligations, including anti-money-laundering and counter terrorist-financing requirements; the detection, prevention and investigation of fraud and financial crime; sanctions screening; identity verification; tax reporting; and responding to lawful requests from regulators, courts and law enforcement agencies.
4.3 Our legitimate interests (UK GDPR Article 6(1)(f))
We rely on our legitimate interests to: analyse and improve our products, services, websites and customer experience; provide and administer customer service; manage security, fraud and identity risk; protect the integrity of our systems and services; conduct analysis to understand our customers better; and pursue our reasonable commercial interests. Where we rely on legitimate interests, we have considered whether they are overridden by your rights and freedoms and concluded that they are not. Where a recognised legitimate interest under the Data (Use and Access) Act 2025 applies, we will rely on it. You have the right to object to processing based on legitimate interests (see section 10).
4.4 Special category data (UK GDPR Article 9)
In limited circumstances we may process special category data, for example where it is necessary for reasons of substantial public interest such as the prevention or detection of unlawful acts, or to support customers in vulnerable circumstances (UK GDPR Article 9(2)(g)). Where we do so, we apply the conditions and safeguards in Schedule 1 to the Data Protection Act 2018 and maintain an Appropriate Policy Document (FBUK-PROC-OPS-008).
4.5 Criminal offence data (UK GDPR Article 10)
We process criminal-offence-related data, for example the results of fraud, sanctions and financial-crime checks, where this is necessary to comply with our legal obligations and for the prevention and detection of unlawful acts in the substantial public interest, under the conditions in Schedule 1 to the Data Protection Act 2018, with the Appropriate Policy Document in place.
4.6 How we use artificial intelligence
We use automated software tools, including artificial intelligence, to help us run our services. For example, we use AI to transcribe and summarise customer calls so that we can capture key points, requests, complaints and follow up actions, and we may analyse customer interactions to help us improve the service and the outcomes our customers receive. These tools support our staff: they do not make decisions about you by solely automated means that produce legal or similarly significant effects, and a member of staff is always involved in any such decision (see section 9). Where this use is not required by law, we rely on our legitimate interests (UK GDPR Article 6(1)(f)) and you have the right to object. We keep call summaries only for as long as needed and apply access controls, a retention schedule and encryption to them.
4.7 Marketing
Where we send you marketing, we do so in line with your preferences and applicable law, including the Privacy and Electronic Communications Regulations. You can ask us to stop sending you marketing at any time, by contacting us or using the unsubscribe options in our communications.
5. Who we share your data with
We may share your personal data, where appropriate and subject to confidentiality, with: our service providers, commercial partners, agents, professional advisers and subcontractors (including credit reference, fraud-prevention and sanctions-screening agencies) who provide products, services or administrative support; banking and other regulators, courts, statutory auditors, tax authorities, and law-enforcement and governmental bodies where required by law; payment systems, correspondent banks and other financial institutions in order to execute your transactions; prospective buyers as part of any sale or reorganisation of our business; and anyone else with your consent.
Other members of the FirstBank group are involved only where they act as our processors on our documented written instructions, in particular the Microsoft 365 hosting arrangement described in section 6. They do not access your personal data for their own purposes, and do not access it at all unless authorised in writing by FirstBank UK as the data Controller. Any transfer to a Group company outside the UK is subject to the safeguards described in section 6.
Our service providers act as our processors only on our documented written instructions under UK GDPR Article 28 contracts.
6. Transferring personal data overseas
Some of the recipients above are located outside the United Kingdom, including in countries that do not have a UK adequacy decision. This can happen when we share data within the Group, when we use service providers based overseas, and when you send or receive money to or from another country and we transmit the information needed to complete the payment.
Where we make a restricted transfer of your personal data to a country without UK adequacy, we put in place an appropriate safeguard under Article 46 of the UK GDPR, such as an International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment, unless a limited exception under the UK GDPR applies (for example, where the transfer is necessary to perform a contract with you, such as an international payment you have instructed).
The Bank also uses the Microsoft 365 environment for its email and collaboration tools. The Microsoft 365 tenant licence is held by the FirstBank group in Nigeria and the Bank’s data is stored at rest in Microsoft’s data centres in Ireland. The Group acts as the Bank’s processor under Article 28 of the UK GDPR and does not access your personal data unless authorised in writing by FirstBank UK as the data Controller.
7. How we protect your data
The Bank takes the security of your data seriously. It has internal policies and controls in place, including under its Information Security Management System, to ensure that your data is not lost, accidentally destroyed, misused or disclosed, and is not accessed except by authorised people in the performance of their duties. Where the Bank engages third parties to process personal data on its behalf, they do so under written instructions, are under a duty of confidentiality and are required to implement appropriate technical and organisational measures (UK GDPR Article 32).
8. How long we keep your data
We do not keep your personal data for longer than necessary. Retention periods depend on the category of data, the nature of the activity, the product or service, and applicable legal and regulatory requirements (for example, anti-money-laundering records are generally kept for at least five years after the end of the relationship). For the most part, your personal data is retained for no longer than seven years after the end of our relationship, unless a longer period is required by law or by our regulatory obligations. The exact periods are set out in the Information Retention and Disposal Policy.
9. Automated decision-making and artificial intelligence
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. We use automated software tools, including artificial intelligence, to support our services and customer outcomes (see section 4.6), but these support human review and a member of staff is always involved in any decision that significantly affects you. Where we introduce any solely automated decision-making with legal or similarly significant effects, we will do so in accordance with Articles 22A to 22D of the UK GDPR (as amended by the Data (Use and Access) Act 2025) and our AI Governance, and we will provide the required safeguards, including informing you and giving you the opportunity to make representations, to obtain human intervention and to contest the decision.
10. Your rights
As a data subject you have the right to: be informed about how your data is used; access a copy of your data; have inaccurate or incomplete data corrected; have your data erased; restrict processing; data portability; object to processing carried out on the basis of our legitimate interests; and object to direct marketing. You also have rights in relation to automated decision-making (see section 9). Where we rely on your consent, you may withdraw it at any time.
To exercise any of these rights, please contact the DPO using the details in section 1.3. We will respond within one month. That period may be paused where we reasonably need further information to deal with your request, and may be extended for complex or numerous requests. We may ask you to verify your identity before we act.
11. Cookies and other websites
Our websites use cookies and similar technologies. How we use them, and how you can manage your preferences, is explained in our Cookie Notice. Our websites may also contain links to third-party websites, plug-ins and applications; we do not control those sites and are not responsible for their privacy practices, so we encourage you to read their privacy notices.
12. Complaints
If you are concerned about how the Bank has handled your personal data, please contact the DPO in the first instance. The Bank will acknowledge your complaint within 30 days. If you remain dissatisfied, you have the right to complain to the Information Commission, the UK data protection regulator (formerly the Information Commissioner’s Office), at www.ico.org.uk.
13. Changes to this notice
The Bank keeps this notice under regular review and will update it at least annually and whenever there is a material change in law, regulation or the Bank’s processing.
Appendix: Glossary of Terms
| Term | Definition |
|---|---|
| UK GDPR | The retained EU General Data Protection Regulation as it forms part of UK law, as amended by the Data (Use and Access) Act 2025. |
| DPA 2018 | Data Protection Act 2018. |
| DUAA 2025 | Data (Use and Access) Act 2025. |
| Special category data | Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic or biometric data; and data concerning health, sex life or sexual orientation (UK GDPR Article 9(1)). |
| Criminal offence data | Personal data relating to criminal convictions and offences (UK GDPR Article 10; DPA 2018 section 11(2)). |
| Controller / Processor | As defined in UK GDPR Article 4. The Bank is the controller of your personal data; its service providers act as processors on its instructions. |
| DPO | Data Protection Officer (UK GDPR Articles 37 to 39). |
| Information Commission | The UK data protection regulator (formerly the Information Commissioner’s Office), as renamed by the Data (Use and Access) Act 2025. |
| Appropriate Policy Document | The document required by Schedule 1, Part 4 of the DPA 2018 governing the processing of special category and criminal offence data (FBUK-PROC-OPS-008). |
| PECR | The Privacy and Electronic Communications Regulations 2003, which govern cookies and electronic marketing. |