PRIVACY POLICY OF OTP BANK ALBANIA SH.A.
Last updated: November 2025
OTP Bank Albania sh.a. (the “Bank”, “OBA”, “we”, “our”, “us”, “Controller”) is committed to protectiong the personal data and respecting the privacy of the personal data subjects (“data subjects”, “you”) whose personal data it processes. This document constitutes the privacy policy (“Privacy Policy”/“Policy”) of the Bank regarding its processing activities and the personal data it processes during its operations.
This Privacy Policy explains, inter alia:
Personal data is processed in compliance with the provisions of the Law and relevant bylaws in force. Processing is carried out according to the principles of respecting and guaranteeing the fundamental human rights and freedoms and in particular the right to privacy. The Bank has taken the appropriate technical and organizational measures for the protection of personal data and to implement legal and regulatory obligations.
1.1 Bank is a financial institution licensed by the Bank of Albania.
1.2 If you have any questions regarding the protection or processing of personal data, you can contact the Bank’s DPO in the above contacts or the Compliance Sector at the email address “compliance.sector@otpbank.al” or at the telephone number 0800 4848.
2.1 This Policy applies to all personal data of the Bank’s clients that the Bank processes or determines the purpose and manner of processing, as well as to other persons listed herein.
2.2 This Policy applies to all services, products and activities of the Bank that include the processing of personal data and is primarily intended and refers to:
2.3 The Bank processes personal data for different purposes and the means of collection, the legal basis for processing, use, disclosure and retention periods may differ depending on the purpose.
2.4 The legal basis of this Policy is the applicable legislation in the field of personal data protection, including without limitation Law no. 124/2024 “On personal data protection” and the instructions and decisions of the Information and Data Protection Commissioner (the “Commissioner”).
2.5 The data subject is any natural person (individual) whose personal data is processed by the Bank.
3.1 Personal data processing is carried out in accordance with the following principles:
4.1 The Bank collects and processes the following categories of personal data, in relation to different purposes of processing:
5.1 The Bank collects personal data in the following ways:
5.2 Any collection of personal data has a legal basis in accordance with the Law.
6.1 The Bank processes the data subject’s personal data for the following purposes or for one or more of these purposes:
The Bank is committed to processing personal data only within the framework of lawful legal bases and selected purposes.
7.1 Performance of a contract (and steps necessary for concluding a contract) (Article 7 (1) (b) of the Law)
7.1.1 We process the personal data of individuals for the purpose of providing our services, employment and providing/receiving contracted services and measures necessary before concluding a contract such as:
7.1.2 For the purposes stated, the data is processed on the basis of contracts that you conclude with us, in accordance with Article 7 (1) (b) of the Law. In these cases, the provision of your data is your contractual obligation, which means that we cannot enter into a business relationship with you if you do not provide us with the data.
7.2 Legal obligation (Article 7 (1) (c) of the Law)
7.2.1 Personal data of individuals is also processed for the purpose of fulfilling legal obligations applicable to the bank, such as:
7.2.2 The legal basis for the processing of personal data is represented by laws and regulations that bind the bank, such as Law no. 9662/2006 “On banks in the Republic of Albania”, Law no. 9917/2008 “On the prevention of money laundering and financing of terrorism”, Law no. 55/2020 “On payment services”, Labour Code, and in accordance with Article 7 (1) (c) of the Law.
7.3 Legitimate interest (Article 7 (1) (dh) of the Law)
7.3.1 The Bank may also process your personal data to meet the legitimate interests of the Bank in connection with the performance of its activities. These activities may include all or some of the following personal data processing:
7.3.2 For the purposes stated, the data is processed on the basis of legitimate interest in accordance with Article 7 (1) (dh) of the Law. You may object to the processing of your data for these purposes at any time. In such a case, the Bank will cease processing the data for these purposes, unless it demonstrates compelling legitimate grounds for the continued processing.
7.4 Consent (Article 7 (1) (a) of the Law)
7.4.1 Based on your explicit consent for marketing purposes, the Bank may prepare offers tailored to you. By further processing your personal data, we may assess personal aspects, such as predicting your interests and behavior (segmentation and/or profiling), and thus create a customized offer that will be as consistent as possible with your wishes, expressed interests and profile.
7.4.2 If we do not receive your consent for marketing purposes, we will consider that you have not provided your consent for marketing purposes, and your personal data will not be processed for marketing purposes. The conclusion of a contract or the provision of our services or products is not conditional on the provision of consent for marketing purposes. Providing consent is voluntary and if you decide not to provide it or withdraw your consent later, this does not in any way reduce your rights arising from the business relationship with the Bank, or does not entail additional costs for you.
7.4.3 When you withdraw your consent in part or in full, the Bank will no longer use your data for the purposes for which you have withdrawn it. If you wish to withdraw your consent for marketing purposes you can do so in one of the manners provided in our Privacy Information regarding direct marketing.
8.1 Personal data are available to third parties outside the Bank only in the following cases:
The Bank may process this personal data in other countries or international organizations in accordance with the Law.
8.2 Personal data provided to the Bank may be processed by its employees and those of the Parent company (OTP Bank Plc.) as well as by employees of the Bank’s contractual partners/processors (e.g. information infrastructure/technology service providers, electronic communications notification service providers, bank card manufacturing providers, payment services transaction providers, etc.), who are obliged to respect and protect your personal data based on the applicable legislation in the field of employment, personal data protection and data processing contracts and/or confidentiality agreements, in accordance with the legislation on personal data protection and the applicable legal-regulatory framework. The Bank, as controller, shall be responsible for the lawfulness of the instructions relating to processing operations. The processors, in turn, shall be responsible for compliance with The Bank’s lawful instructions and for performing their obligations specifically assigned to them under the Law.
8.3 In certain cases specified by regulations, we may also provide your personal data to public authorities and other third parties if this is necessary to fulfill our legal or contractual obligations (Financial Intelligence Agency, Financial Supervisory Authority, Bank of Albania, law enforcement authorities, courts, intermediary banks, etc.)
8.4 Users are subject to the relevant authorizations and access rights. All users are obligated to respect and protect your personal data in accordance with the Law and the applicable legal-regulatory framework.
9.1 If your data is transferred outside the European Economic Area (EEA), we ensure adequate protection through EU-approved safeguards (e.g., Standard Contractual Clauses, that transfer is done in accordance with the relevant legal provisions). The Bank ensures that it will not transfer data without the appropriate legal basis or your consent.
9.2 The Bank shall transfer data pursuant to the provisions of law no. 4/2020 “On the automatic exchange of financial account information” and the multilateral competent authority agreement “For the automatic exchange of financial account information”, and the Foreign Account Tax Compliance Act (FATCA) to the competent authorities.
9.3 Transfer of data is made, if necessary, for the purposes of carrying out the Bank’s activities, according to the provisions of the Law, to parent company (OTP Bank Plc., Hungary). OBA and OTP Bank Plc. implement technical-organizational measures for data protection in accordance with applicable legislation and the highest security standards. The data subject may request a copy of his/her data from the Bank at any time. Such transfers may be done for the following purposes:
The legal basis for processing under this section shall be the legitimate interest of the Bank
9.4 The Bank does not transfer or forward the collected personal data to countries outside the EEA/EU, unless this is necessary for the purposes of carrying out activities (e.g. supporting business processes). When transferring personal data to third countries outside of EEA/EU, the Bank will first check whether the Commissioner has issued a decision on the adequacy of the level of data protection for the third country, its territory or sector or ensure appropriate protective measures.
10.1 The Bank stores and protects your personal data in a manner that prevents the unjustified disclosure of your data to unauthorized persons. We store personal data only for as long as is necessary to achieve the purpose for which it was collected/processed and pursuant to the legal terms provided in the relevant legislation. The retention period depends on the basis on which the data is processed and the purpose of the processing. After this period, your data will be securely deleted or anonymized.
10.2 Data processed on the basis of your consent or for legitimate interests will be stored until your consent withdrawal/request for erasure, or until the purpose for which they were collected has been fulfilled, and in the cases when you are a customer of the Bank for 5 (five) years from the date of termination of the business relationship between the customer and the Bank or from the date of the occasional transaction, but not more than 40 (forty) years from the date of each individual transaction or the date of collection of documentation or performed of an analysis. Applicable legislation may contain provisions for the extension of deadlines for legal reasons. The Bank may store your personal data for longer if it cannot be deleted for legal, regulatory or technical reasons.
Clients, Potential Clients and other individuals to whom personal data relate may exercise the following rights:
These rights are exercised in the form and terms provided by the Law.
11.1 Right to information
11.1.1 Where personal data are collected from the data subject and the data subject does not have the following information, the controller shall provide the data subject with all of the following information:
11.2 Right to access
11.2.1 The data subject shall have the right to obtain from the controller, no later than 30 (thirty) days from the date of submission of the request, confirmation as to whether or not personal data concerning him/her are being processed, and, where that is the case, access to the personal data and the following information:
11.2.2 The controller shall provide the data subject, free of charge, with a copy of the list of categories of personal data processed, indicating the content of each category, which relates to the data subject and without prejudice to the fundamental rights and freedoms of other persons. For any subsequent copy requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means and has not specified another form in which the response is required, the information shall be provided in the electronic form commonly used.
11.3 The right to rectification and erasure
11.3.1 The data subject has the right to have inaccurate personal data concerning him/her rectified by the controller as soon as possible, but not later than 30 (thirty) days from the date of receipt of the request. In accordance with the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of a supplementary statement.
13.3.2 The data subject shall have the right to obtain from the controller the erasure of personal data concerning him/her and the controller shall have the obligation to erase personal data without undue delay but no later than 30 (thirty) days from the date of receipt of the request, where one of the following grounds applies:
Regarding this right, the Law provides for several exceptions in the cases of the processing mentioned therein.
11.4 Right to be forgotten
11.4.1 Where the controller has made the personal data public and is obliged pursuant to the Law to erase the personal data, the controller, taking account of the available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
11.4.2 At the request of the data subject, internet search engines operators are obliged to delete from the results displayed following a search conducted on the basis of the data subject’s name, the information which is no longer up-to-date over time but which, when found, has a significant negative impact on the data subject’s reputation.
11.5 Right to restriction of processing
11.5.1 The data subject has the right to restriction of data processing by the Controller where one of the following applies:
11.5.2 Where processing has been restricted under the above paragraph, such personal data shall, with the exception of storage, only be processed:
11.5.3 The Controller shall notify the data subject before the restriction of processing is lifted. If the Controller refuses the request, the data subject may lodge a complaint with the Commissioner and request a preliminary decision on the restriction of processing.
11.6 Right to data portability
11.6.1 Where personal data are provided to a controller by the data subject, with his/her consent or for the performance of a contract, and the processing is carried out by automated means, the data subject shall have the right to receive from the controller the personal data concerning him/her in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
11.6.2 In exercising his/her right to data portability pursuant to the aforementioned paragraph, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.
11.6.3 The exercise of right to data portability shall not prejudice the right to erasure in accordance with the law. The right to data portability shall not apply to processing necessary for the performance of a task carried out in the public interest or where the controller has been granted the right to exercise public functions, tasks or powers by virtue of applicable law. The right to data portability shall not adversely affect the rights and freedoms of others.
11.7 Right to object
11.7.1 The data subject shall have the right to object, on grounds relating to his/her particular situation, at any time to processing of personal data concerning him/her including profiling based on provisions of the Law. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, especially when they concern the filing of a claim or exercise or defense of legal claims, obligations or interests before a court or public authority.
11.7.2 Where personal data are processed for direct marketing purposes, the data subject shall have the right to object, at any time and without having to give reasons, to processing of personal data concerning him/her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where the data subject objects to processing for direct marketing purposes, the controller shall be obliged to cease processing of the personal data for such purposes.
11.7.3 At the latest at the time of the first communication with the data subject, the controller shall inform the data subject of the right to object clearly and separately from any other information.
11.8 Right not to be subject to automated decision-making
11.8.1 The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him/her or similarly significantly affects him/her.
11.8.2 This shall not apply if the decision:
In these cases, the controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests and the right to obtain human intervention on the part of the controller, to express his/her point of view and to contest the decision.
11.9 Right to complain
11.9.1 Every person who claims that his/her rights, freedoms and legal interests concerning his/her personal data have been violated shall have the right to complain or to notify the Commissioner and to request his intervention to remedy the infringed right. When the data subject has filed a complaint, the controller shall have no right to make any changes to the personal data until a final decision ruled.
11.10 Right to compensation of the damage
11.10.1 Everyone who has suffered damage due to an unlawful processing of personal data is entitled to compensation, pursuant to the rules defined by the Civil Code.
11.11 Exercise of rights
11.11.1 You may submit a request for a specific right in a manner that allows you to be identified by contacting the Bank in the manner provided herein. Therefore, in order to meet the data security requirements and to protect the rights of the data subject, the Bank must confirm the identity of the data subject or the identity of the person who wishes to exercise any of the rights. The Bank will respond to any request or complaint in accordance with the form and procedure provided for by the Law within 30 (thirty) days from the date of its receipt. This period may be extended up to 60 (sixty) days, where necessary, taking into account the complexity and number of requests received. The Bank shall inform the data subject in a reasoned manner of any extension of the deadline within 30 (thirty) days from the receipt of the request together with the reasons for the delay. The response shall be in writing to the address from which the request or complaint was received and/or in electronic form when the request or complaint was received electronically, unless otherwise requested by the data subject.
11.11.2 The data subject has the unconditional right to object to the processing of his/her data for direct marketing purposes, and the Bank will immediately stop processing such data for this purpose.
11.11.3 Any person who claims that their rights, freedoms and legitimate interests regarding personal data have been violated has the right to complain or notify the Commissioner and request his intervention to remedy the violated right at the following contacts:
Information and Data Protection Commissioner
Adresa: Rr. “Abdi Toptani”, Nd. 5, Kodi postar 1001, Tirana
Tel: +355 42 23 7200
Green number: 0800 2050
email: info@idp.al
11.11.4 If the data subject has filed a complaint, the controller shall not have the right to amend the personal data until the final decision has been made.
11.11.5 The data subject may also file a lawsuit in court for alleged violations in the field of personal data protection. The competent court shall be the Court of Tirana.
12.1 Automated decision-making
12.1.1 Automated decision-making, where applicable, including profiling, is carried out in accordance with:
In accordance with the Law, the Bank enables data subjects to exercise the right to object to automated decision-making, including profiling.
12.1.2 The Bank may use an automated process when deciding on the approval of consumer loans to natural persons up to the amount determined by the Bank. We are aware that this method of processing your personal data has legal effects that affect your rights, therefore we protect your rights, freedoms and legitimate interests with appropriate safeguards.
12.1.3 You will be informed at the stage of negotiations for the conclusion of a credit agreement that the decision on the approval of the loan may be automated. You have the right to express your point of view, the right to obtain an explanation of the decision that was made in an automated manner, the right to request the intervention of a person with appropriate competence and authorisation on the part of the Bank (human intervention) to inspect and potentially override the decision, and the right to challenge the decision that was made through automated decision-making. The processing uses the data that you provided in the loan application and the data that the Bank obtains by consulting the Credit Register of Bank of Albania. Through the automated decision-making process, the Bank ensures fair and objective results, as the same decision-making conditions are applied to all applications. The setting of criteria for approving loans is in accordance with the applicable internal acts of the Bank, and technical solutions are also subject to regular testing, analysis and supervision.
12.2 Profiling
12.2.1 Profiling means any form of automated processing of personal data that involves the use of personal data to evaluate certain personal aspects relating to an individual, in particular to analyze or predict the individual’s performance at work, economic situation, interests, etc.
12.2.2 The Bank performs profiling if you have given your consent for marketing purposes. Profiling is performed using various methods of statistics, mathematics or predictive analysis, which allows us to predict your needs and prepare appropriate offers for you on this basis. As part of profiling, we may analyze your demographic data, such as age, location, and data on banking services performed, based on which we place you in an individual profile and send you only offers that we believe meet your needs and habits.
13.1 The personal data are processed with automated and non-automated instruments, only for the time strictly necessary to achieve the purposes for which they have been collected. We use advanced technical and organizational measures to protect your data and to prevent loss of data, illegal or incorrect uses and unauthorized access, including:
13.2 The IT systems and other data storage facilities of our Bank are located at its registered premises and on the servers leased by the processor. Bank selects and operates the IT tools and applications for the processing of personal data in such a way that the data processed are:
13.3 We take particular care to ensure data security, take all technical and organisational measures and adopt procedural rules required for enforcing the safeguards specified in Law no. 124/2024 “On personal data protection” and the applicable legal-regulatory framework. We take appropriate measures to protect the data from unauthorised access, alteration, transfer, public disclosure, deletion or destruction, as well as damage and accidental loss, and ensure that the data stored cannot be corrupted or rendered inaccessible due to any changes in or modification to the applied technique.
13.4 The information systems of Bank and our partners are both protected from computer assisted fraud, computer viruses, hacking and distributed denial-of-service attacks (DdoS). Moreover, Bank ensures security by means of server-level and application-level security procedures. Data are backed up on a daily basis. Bank takes all possible measures to avoid personal data breaches and in the event of a data breach, it takes action immediately to minimise any risks and eliminate any damage, in accordance with our incident management regulations and the applicable legal regulatory framework.
14.1 The Bank reserves the right to amend or supplement this Policy to ensure compliance with laws and regulations on the protection of personal data and the applicable legal-regulatory framework, changes in technology or products/services. The latest valid version of the Policy is available on its website (www.otpbank.al) with a revised “Last Updated” date.
14.2 Anything not specifically stipulated in this Policy or in the contract concluded between the Bank and the individual shall be subject to the provisions of applicable legislation.