OTP Bank

Privacy policies

PRIVACY POLICY OF OTP BANK ALBANIA SH.A.

Last updated: November 2025

OTP Bank Albania sh.a. (the “Bank”, “OBA”, “we”, “our”, “us”, “Controller”) is committed to protectiong the personal data and respecting the privacy of the personal data subjects (“data subjects”, “you”) whose personal data it processes. This document constitutes the privacy policy (“Privacy Policy”/“Policy”) of the Bank regarding its processing activities and the personal data it processes during its operations.

This Privacy Policy explains, inter alia:

  • what personal data we collect,
  • how we collect, use, share and safeguard your information,
  • your rights under the Law no. 124/2024 “On personal data protection” (the “Law”),
  • how you can contact us with questions or concerns.

Personal data is processed in compliance with the provisions of the Law and relevant bylaws in force. Processing is carried out according to the principles of respecting and guaranteeing the fundamental human rights and freedoms and in particular the right to privacy. The Bank has taken the appropriate technical and organizational measures for the protection of personal data and to implement legal and regulatory obligations.

  1. WHO ARE WE

1.1 Bank is a financial institution licensed by the Bank of Albania.

  • Address: Bulevardi “Bajram Curri”, Godina “Down Town”, kati 8, Tirana, Albania
  • Contact: 0800 4848 info@otpbank.al
  • Data Protection Officer: Elton Rroji, rroji@otpbank.al, +35544538226

1.2 If you have any questions regarding the protection or processing of personal data, you can contact the Bank’s DPO in the above contacts or the Compliance Sector at the email address “compliance.sector@otpbank.al” or at the telephone number 0800 4848.

  1. SCOPE

2.1 This Policy applies to all personal data of the Bank’s clients that the Bank processes or determines the purpose and manner of processing, as well as to other persons listed herein.

2.2 This Policy applies to all services, products and activities of the Bank that include the processing of personal data and is primarily intended and refers to:

  1. natural persons who submit a request or use the services and products of the Bank (Clients),
  2. natural persons interested in using the services and products of the Bank (Potential Clients),
  3. other natural persons whose data the Bank obtains during its operations in accordance with the applicable legislation,
  4. natural persons employed by the Bank and related persons, where applicable;
  5. natural persons (e.g. legal representatives, authorised persons, beneficial owners) acting on behalf of legal persons or organizations or a)-b).

2.3 The Bank processes personal data for different purposes and the means of collection, the legal basis for processing, use, disclosure and retention periods may differ depending on the purpose.

2.4 The legal basis of this Policy is the applicable legislation in the field of personal data protection, including without limitation Law no. 124/2024 “On personal data protection” and the instructions and decisions of the Information and Data Protection Commissioner (the “Commissioner”).

2.5 The data subject is any natural person (individual) whose personal data is processed by the Bank.

  • PERSONAL DATA PROCESSING PRINCIPLES

3.1 Personal data processing is carried out in accordance with the following principles:

  • Principle of lawfulness, fairness, and transparency: processing is carried out lawfully, fairly and in a transparent manner in relation to the data subject.
  • Principle of purpose limitation: personal data are collected for specified, explicit and legitimate purposes, clearly determined at the moment of collection, and not further processed in a manner that is incompatible with those purposes.
  • Principle of data minimisation: personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
  • Principle of accuracy: personal data are accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate or incomplete, having regard to the purposes for which they are processed, are erased or rectified without delay.
  • Principle of storage limitation: personal data are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  • Principle of integrity and confidentiality: personal data are processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
  • Principle of accountability: the controller shall be responsible for and be able to demonstrate compliance with these principles.
  1. WHAT DATA WE COLLECT

4.1 The Bank collects and processes the following categories of personal data, in relation to different purposes of processing:

  • Data required for and contained in contracts with Clients and application forms of Potential Clients – e.g. identification data, name and surname, personal number, identification document number, date of issuance and issuing authority of identification document, identification document content, name of parent, address, citizenship, residence permit number, residence permit content, place of birth, date of birth, telephone number, contact data, data from account specification, standing orders, signature, etc.
  • Financial data – e.g. data on earnings, data on income, data on other accounts and liabilities, data from the Credit Register of the Bank of Albania, account number/s, card number/s, insurance policy number, data on tax residency, tax identification number, etc.
  • Property data (for certain producst/services) – real estate and movable property owned by the person to whom the data relates.
  • Information about the spouse/guarantor – data on the employment of the spouse/ guarantor, number of households members, etc.
  • Data on related parties – connection on the basis of management function, connection on the basis of kinship and other connections in accordance with the law.
  • Data necessary for loan products – activity, data on employer and employment contract, credit history, previous use of banking products and similar.
  • Data required for performing the tax liabilities of the data subject or of the Bank related to the data subject.
  • Data required for the Bank to fulfill its data reporting requirements in relation to the data subject.
  • Data related to the information provided by Clients and/or Potential Clients by filling the relevant forms on our website, including but not limited to: name, surname, address, telephone number and email address.
  • Data necessary to ensure security for its premises and activities (e.g. video surveillance).
  • Information related to complaint handling and/or contained in the records on communication and correspondence in situations of establishing contact by the Client, Potential Client and other natural persons, including recordings of conversations with customer support or relevant units of the Bank, written or electronic communication.
  • Information that the Bank collects and processes for the purposes of direct marketing and profiling, based on the freely given consent of the data subject.
  • Employees’ personal data pursuant to employment and tax/insurance legislation.
  • Personal data of third parties establishing a relationship with the Bank.
  • Other personal data for which there is a legal basis for their processing in accordance with the law.
  1. HOW WE COLLECT DATA

5.1 The Bank collects personal data in the following ways:

  1. directly from the Client or Potential Clients, by direct delivery by them (at branches, through website forms and/or social media, communication with customer support, contacting the Bank through any available channel),
  2. automatically when using the Bank’s products and services, if it is required that Client/Potential Client enter their data in order to use the relevant product and/or service of the Bank,
  3. directly from employees and third parties,
  4. from publicly available sources such as public registers.

5.2 Any collection of personal data has a legal basis in accordance with the Law.

  1. DATA PROCESSING PURPOSES

6.1 The Bank processes the data subject’s personal data for the following purposes or for one or more of these purposes:

  1. identification of the data subject,
  2. legal obligation,
  3. liaising,
  4. exercise of contractual rights and performance of obligations,
  5. direct marketing,
  6. Bank’s fulfilment of its tax legislation obligations in relation to the data subject,
  7. Bank’s fulfilment of its data reporting requirement in relation to the data subject,
  8. enforcement of the legitimate interest and interests of the Bank,
  9. other transaction-specific processing purposes.
  • LEGAL BASIS FOR PROCESSING

The Bank is committed to processing personal data only within the framework of lawful legal bases and selected purposes.

7.1 Performance of a contract (and steps necessary for concluding a contract) (Article 7 (1) (b) of the Law)

7.1.1 We process the personal data of individuals for the purpose of providing our services, employment and providing/receiving contracted services and measures necessary before concluding a contract such as:

  • opening and maintaining accounts, deposits, establishing direct debits and standing orders, receiving and executing Clients’orders,
  • making payments, various types of savings, loans, guarantees, letters of credit, purchasing securities, insurance, etc.,
  • sending notifications (e.g. SMS messages) about the account balance and transactions carried out with payment cards,
  • contacting in connection with the product/service,
  • engaging in an employment relationship,
  • engaging in a contractual relationship with third parties for the provision of services.

7.1.2 For the purposes stated, the data is processed on the basis of contracts that you conclude with us, in accordance with Article 7 (1) (b) of the Law. In these cases, the provision of your data is your contractual obligation, which means that we cannot enter into a business relationship with you if you do not provide us with the data.

7.2 Legal obligation (Article 7 (1) (c) of the Law)

7.2.1 Personal data of individuals is also processed for the purpose of fulfilling legal obligations applicable to the bank, such as:

  • establishing and verifying the Client’s identity,
  • carrying out (periodic) client due diligence,
  • implementing measures to prevent money laundering and terrorist financing,
  • ensuring compliance in the field of tax fraud prevention,
  • reporting to regulators,
  • keeping records and storing data,
  • establishing and verifying employees’ and third parties’ identity (representatives) identity.

7.2.2 The legal basis for the processing of personal data is represented by laws and regulations that bind the bank, such as Law no. 9662/2006 “On banks in the Republic of Albania”, Law no. 9917/2008 “On the prevention of money laundering and financing of terrorism”, Law no. 55/2020 “On payment services”, Labour Code, and in accordance with Article 7 (1) (c) of the Law.

7.3 Legitimate interest (Article 7 (1) (dh) of the Law)

7.3.1 The Bank may also process your personal data to meet the legitimate interests of the Bank in connection with the performance of its activities. These activities may include all or some of the following personal data processing:

  • implementing measures necessary to prevent and investigate fraud,
  • conducting market analysis and research, to monitor clients’ satisfaction with the aim of improving our products and services,
  • carrying out activities prior to implementing marketing campaigns, marketing communication, which may include developing and implementing marketing activities on the basis of which the Bank can provide you with offers that we estimate will be of interest to you, be useful to you or provide you with information that will simplify your cooperation with us,
  • requesting the provision of updated data,
  • carrying out video surveillance,
  • ensuring the security of our information system, which may include detecting, investigating, reporting and preventing incidents related to the security of the IT system and ensuring secure business activities for you,
  • managing your existing communication channels so that you can safely access your data via the internet, mobile banking, etc., including establishing and securely managing passwords.

7.3.2 For the purposes stated, the data is processed on the basis of legitimate interest in accordance with Article 7 (1) (dh) of the Law. You may object to the processing of your data for these purposes at any time. In such a case, the Bank will cease processing the data for these purposes, unless it demonstrates compelling legitimate grounds for the continued processing.

7.4 Consent (Article 7 (1) (a) of the Law)

7.4.1 Based on your explicit consent for marketing purposes, the Bank may prepare offers tailored to you. By further processing your personal data, we may assess personal aspects, such as predicting your interests and behavior (segmentation and/or profiling), and thus create a customized offer that will be as consistent as possible with your wishes, expressed interests and profile.

7.4.2 If we do not receive your consent for marketing purposes, we will consider that you have not provided your consent for marketing purposes, and your personal data will not be processed for marketing purposes. The conclusion of a contract or the provision of our services or products is not conditional on the provision of consent for marketing purposes. Providing consent is voluntary and if you decide not to provide it or withdraw your consent later, this does not in any way reduce your rights arising from the business relationship with the Bank, or does not entail additional costs for you.

7.4.3 When you withdraw your consent in part or in full, the Bank will no longer use your data for the purposes for which you have withdrawn it. If you wish to withdraw your consent for marketing purposes you can do so in one of the manners provided in our Privacy Information regarding direct marketing.

  • WHO ARE THE PROCESSORS OF YOUR DATA

8.1 Personal data are available to third parties outside the Bank only in the following cases:

  • if there is a legal obligation or explicit authority under the law (e.g. a court or authority request),
  • if a third party or subcontractor (processor) is engaged to perform certain tasks, whereby that processor acts exclusively in accordance with the orders of the Bank and under the relevant data protection agreement, and the Bank ensures all data protection measures as if it performs these tasks independently,
  • affiliated companies (parent bank) of the Bank provided that there is a legal basis for such transfer or access (consent of the person, legitimate interest),
  • if the data need to be forwarded for the purpose of performing the contract (e.g. execution of a transaction),
  • other persons outside the Bank for whom there is the explicit consent of the data subject.

The Bank may process this personal data in other countries or international organizations in accordance with the Law.

8.2 Personal data provided to the Bank may be processed by its employees and those of the Parent company (OTP Bank Plc.) as well as by employees of the Bank’s contractual partners/processors (e.g. information infrastructure/technology service providers, electronic communications notification service  providers, bank card manufacturing providers, payment services transaction providers, etc.), who are obliged to respect and protect your personal data based on the applicable legislation in the field of employment, personal data protection and data processing contracts  and/or confidentiality agreements, in accordance with the legislation on personal data protection  and the applicable legal-regulatory framework. The Bank, as controller, shall be responsible for the lawfulness of the instructions relating to processing operations. The processors, in turn, shall be responsible for compliance with The Bank’s lawful instructions and for performing their obligations specifically assigned to them under the Law.

8.3 In certain cases specified by regulations, we may also provide your personal data to public authorities and other third parties if this is necessary to fulfill our legal or contractual obligations (Financial Intelligence Agency, Financial Supervisory Authority, Bank of Albania, law enforcement authorities, courts, intermediary banks, etc.)

8.4 Users are subject to the relevant authorizations and access rights. All users are obligated to respect and protect your personal data in accordance with the Law and the applicable legal-regulatory framework.

  1. DATA TRANSFER

9.1 If your data is transferred outside the European Economic Area (EEA), we ensure adequate protection through EU-approved safeguards (e.g., Standard Contractual Clauses, that transfer is done in accordance with the relevant legal provisions). The Bank ensures that it will not transfer data without the appropriate legal basis or your consent.

9.2 The Bank shall transfer data pursuant to the provisions of law no. 4/2020 “On the automatic exchange of financial account information” and the multilateral competent authority agreement “For the automatic exchange of financial account information”, and the Foreign Account Tax Compliance Act (FATCA) to the competent authorities.

9.3 Transfer of data is made, if necessary, for the purposes of carrying out the Bank’s activities, according to the provisions of the Law, to parent company (OTP Bank Plc., Hungary). OBA and OTP Bank Plc. implement technical-organizational measures for data protection in accordance with applicable legislation and the highest security standards. The data subject may request a copy of his/her data from the Bank at any time. Such transfers may be done for the following purposes:

  • to perform creditworthiness assessment, risk assessment and risk evaluation as part of the preparations for the conclusion of contracts;
  • to monitor any material adverse changes in the collateral underlying the contract, the adequacy of the collateral or the Client’s circumstances during the performance of contracts;
  • to perform risk evaluations regarding transactions, etc.

The legal basis for processing under this section shall be the legitimate interest of the Bank

9.4 The Bank does not transfer or forward the collected personal data to countries outside the EEA/EU, unless this is necessary for the purposes of carrying out activities (e.g. supporting business processes). When transferring personal data to third countries outside of EEA/EU, the Bank will first check whether the Commissioner has issued a decision on the adequacy of the level of data protection for the third country, its territory or sector or ensure appropriate protective measures.

  1. HOW LONG WE KEEP YOUR DATA

10.1 The Bank stores and protects your personal data in a manner that prevents the unjustified disclosure of your data to unauthorized persons. We store personal data only for as long as is necessary to achieve the purpose for which it was collected/processed and pursuant to the legal terms provided in the relevant legislation. The retention period depends on the basis on which the data is processed and the purpose of the processing. After this period, your data will be securely deleted or anonymized.

10.2 Data processed on the basis of your consent or for legitimate interests will be stored until your consent withdrawal/request for erasure, or until the purpose for which they were collected has been fulfilled, and in the cases when you are a customer of the Bank for 5 (five) years from the date of termination of the business relationship between the customer and the Bank or from the date of the occasional transaction, but not more than 40 (forty) years from the date of each individual transaction or the date of collection of documentation or performed of an analysis. Applicable legislation may contain provisions for the extension of deadlines for legal reasons. The Bank may store your personal data for longer if it cannot be deleted for legal, regulatory or technical reasons.

  1. YOUR RIGHTS

Clients, Potential Clients and other individuals to whom personal data relate may exercise the following rights:

  • the right to information,
  • the right to access,
  • the right to rectification and erasure,
  • the right to be forgotten,
  • the right to restriction of processing,
  • the right to data portability,
  • the right to object,
  • the right not to be subject to automated decision-making,
  • the right to complain,
  • the right to compensation for damage.

These rights are exercised in the form and terms provided by the Law.

11.1 Right to information 

11.1.1 Where personal data are collected from the data subject and the data subject does not have the following information, the controller shall provide the data subject with all of the following information:

  1. the identity and the contact details of the controller and, where applicable, of the controller’s representative and of the controller’s data protection officer,
  2. the purposes of the processing for which the personal data are intended as well as the legal basis for the processing,
  3. the existence and logic of automated decision-making and profiling, referred to in the Law and, at least in these cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject,
  4. the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period,
  5. the existence of the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal, where the processing is based on the consent and the legitimate interests pursued by the controller or by a third party, where processing is based on legitimate interests,
  6. information, whether or not the data subject is obliged to provide the data and whether the provision of personal data is an obligation arising from the legislation in force, contract terms or conditions for entering into a contractual relationship, as well as the possible consequences of not providing this data,
  7. the recipients or categories of recipients of the personal data, if any,
  8. whether the data will be transferred to a third country and if so, how appropriate protection is guaranteed including information on appropriate safeguards and the means by which to obtain a copy of them or where they have been made available,
  9. the exercise of rights under the Law, as well as the right to lodge a complaint with the Commissioner.

11.2 Right to access

11.2.1 The data subject shall have the right to obtain from the controller, no later than 30 (thirty) days from the date of submission of the request, confirmation as to whether or not personal data concerning him/her are being processed, and, where that is the case, access to the personal data and the following information:

  1. the purposes of the processing,
  2. the existence and logic of automated decision-making and profiling and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject,
  3. the period for which the personal data will be stored, or if that is not possible, the criteria used to determine that period,
  4. the legal basis for the processing,
  5. the categories of personal data concerned, including, where the personal data are not collected from the data subject, any available information as to their source,
  6. the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations including where personal data are transferred to a third country and if so, the data subject shall have the right to be informed of the appropriate safeguards,
  7. the existence of the rights pursuant to the Law and the right to lodge a complaint with the Commissioner.

11.2.2 The controller shall provide the data subject, free of charge, with a copy of the list of categories of personal data processed, indicating the content of each category, which relates to the data subject and without prejudice to the fundamental rights and freedoms of other persons. For any subsequent copy requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means and has not specified another form in which the response is required, the information shall be provided in the electronic form commonly used.

11.3 The right to rectification and erasure

11.3.1 The data subject has the right to have inaccurate personal data concerning him/her rectified by the controller as soon as possible, but not later than 30 (thirty) days from the date of receipt of the request. In accordance with the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of a supplementary statement.

13.3.2 The data subject shall have the right to obtain from the controller the erasure of personal data concerning him/her and the controller shall have the obligation to erase personal data without undue delay but no later than 30 (thirty) days from the date of receipt of the request, where one of the following grounds applies:

  1. the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed,
  2. the data subject withdraws consent on which the processing is based and where there is no other legal ground for the processing,
  3. the data subject objects to the processing pursuant to the Law,
  4. the personal data have been unlawfully processed,
  5. the personal data have to be erased for compliance with a legal obligation of the controller,
  6. the personal data have been collected in relation to the online provision of goods or services as provided for by law.

Regarding this right, the Law provides for several exceptions in the cases of the processing mentioned therein.

11.4 Right to be forgotten

11.4.1 Where the controller has made the personal data public and is obliged pursuant to the Law to erase  the personal data, the controller, taking account of the available technology and the cost of  implementation, shall take reasonable steps, including technical measures, to inform controllers  which are processing the personal data that the data subject has requested the erasure by such  controllers of any links to, or copy or replication of, those personal data.

11.4.2 At the request of the data subject, internet search engines operators are obliged to delete from the results displayed following a search conducted on the basis of the data subject’s name, the information which is no longer up-to-date over time but which, when found, has a significant negative impact on the data subject’s reputation.

11.5 Right to restriction of processing

11.5.1 The data subject has the right to restriction of data processing by the Controller where one of the following applies:

  1. the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data,
  2. the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead,
  3. the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the filing of a claim or exercise or defense of legal claims, obligations or interests before a court or public authority, or
  4. the data subject has objected to processing pursuant to the Law. The restriction lasts for the period necessary for the verification whether the legitimate grounds of the controller override those of the data subject.

11.5.2 Where processing has been restricted under the above paragraph, such personal data shall, with the exception of storage, only be processed:

  1. after receiving the data subject’s consent,
  2. for the filing of a claim or exercise or defense of legal claims, obligations or interests before a court or public authority,
  3. for the protection of the rights of another natural or legal person which override the rights of the data subject, or
  4. for reasons of important public interest.

11.5.3 The Controller shall notify the data subject before the restriction of processing is lifted. If the Controller refuses the request, the data subject may lodge a complaint with the Commissioner and request a preliminary decision on the restriction of processing.

11.6 Right to data portability

11.6.1 Where personal data are provided to a controller by the data subject, with his/her consent or for  the performance of a contract, and the processing is carried out by automated means, the data  subject shall have the right to receive from the controller the personal data concerning him/her in  a structured, commonly used and machine-readable format and have the right to transmit those  data to another controller without hindrance from the controller to which the personal data have  been provided.

11.6.2 In exercising his/her right to data portability pursuant to the aforementioned paragraph, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.

11.6.3 The exercise of right to data portability shall not prejudice the right to erasure in accordance with the law. The right to data portability shall not apply to processing necessary for the performance of a task carried out in the public interest or where the controller has been granted the right to exercise public functions, tasks or powers by virtue of applicable law. The right to data portability shall not adversely affect the rights and freedoms of others.

11.7 Right to object

11.7.1 The data subject shall have the right to object, on grounds relating to his/her particular situation, at any time to processing of personal data concerning him/her including profiling based on provisions of the Law. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, especially when they concern the filing of a claim or exercise or defense of legal claims, obligations or interests before a court or public authority.

11.7.2 Where personal data are processed for direct marketing purposes, the data subject shall have the right to object, at any time and without having to give reasons, to processing of personal data concerning him/her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where the data subject objects to processing for direct marketing purposes, the controller shall be obliged to cease processing of the personal data for such purposes.

11.7.3 At the latest at the time of the first communication with the data subject, the controller shall inform the data subject of the right to object clearly and separately from any other information.

11.8 Right not to be subject to automated decision-making 

11.8.1 The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him/her or similarly significantly affects him/her.

11.8.2 This shall not apply if the decision:

  • is necessary for entering into, or performance of, a contract between the data subject and a data controller; or
  • is authorized by a law to which the controller is subject and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or – is based on the data subject’s consent.

In these cases, the controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests and the right to obtain human intervention on the part of the controller, to express his/her point of view and to contest the decision.

11.9 Right to complain

11.9.1 Every person who claims that his/her rights, freedoms and legal interests concerning his/her personal data have been violated shall have the right to complain or to notify the Commissioner and to request his intervention to remedy the infringed right. When the data subject has filed a complaint, the controller shall have no right to make any changes to the personal data until a final decision ruled.

11.10 Right to compensation of the damage

11.10.1 Everyone who has suffered damage due to an unlawful processing of personal data is entitled to compensation, pursuant to the rules defined by the Civil Code.

11.11 Exercise of rights

11.11.1 You may submit a request for a specific right in a manner that allows you to be identified by contacting the Bank in the manner provided herein. Therefore, in order to meet the data security requirements and to protect the rights of the data subject, the Bank must confirm the identity of the data subject or the identity of the person who wishes to exercise any of the rights. The Bank will respond to any request or complaint in accordance with the form and procedure provided for by the Law within 30 (thirty) days from the date of its receipt. This period may be extended up to 60 (sixty) days, where necessary, taking into account the complexity and number of requests received. The Bank shall inform the data subject in a reasoned manner of any extension of the deadline within 30 (thirty) days from the receipt of the request together with the reasons for the delay. The response shall be in writing to the address from which the request or complaint was received and/or in electronic form when the request or complaint was received electronically, unless otherwise requested by the data subject.

11.11.2 The data subject has the unconditional right to object to the processing of his/her data for direct marketing purposes, and the Bank will immediately stop processing such data for this purpose.

11.11.3 Any person who claims that their rights, freedoms and legitimate interests regarding personal data have been violated has the right to complain or notify the Commissioner and request his intervention to remedy the violated right at the following contacts:

Information and Data Protection Commissioner 

Adresa: Rr. “Abdi Toptani”, Nd. 5, Kodi postar 1001, Tirana

Tel: +355 42 23 7200

Green number: 0800 2050

email: info@idp.al

11.11.4 If the data subject has filed a complaint, the controller shall not have the right to amend the personal data until the final decision has been made.

11.11.5 The data subject may also file a lawsuit in court for alleged violations in the field of personal data protection. The competent court shall be the Court of Tirana.

  • AUTOMATED DECISION-MAKING AND PROFILING

12.1 Automated decision-making

12.1.1 Automated decision-making, where applicable, including profiling, is carried out in accordance with:

  • applicable laws,
  • fulfillment of contractual obligations,
  • the constent of the data subject/legitimate interests of the Bank.

In accordance with the Law, the Bank enables data subjects to exercise the right to object to automated decision-making, including profiling.

12.1.2 The Bank may use an automated process when deciding on the approval of consumer loans to natural persons up to the amount determined by the Bank. We are aware that this method of processing your personal data has legal effects that affect your rights, therefore we protect your rights, freedoms and legitimate interests with appropriate safeguards.

12.1.3 You will be informed at the stage of negotiations for the conclusion of a credit agreement that the decision on the approval of the loan may be automated. You have the right to express your point of view, the right to obtain an explanation of the decision that was made in an automated manner, the right to request the intervention of a person with appropriate competence and authorisation on the part of the Bank (human intervention) to inspect and potentially override the decision, and the right to challenge the decision that was made through automated decision-making. The processing uses the data that you provided in the loan application and the data that the Bank obtains by consulting the Credit Register of Bank of Albania. Through the automated decision-making process, the Bank ensures fair and objective results, as the same decision-making conditions are applied to all applications. The setting of criteria for approving loans is in accordance with the applicable internal acts of the Bank, and technical solutions are also subject to regular testing, analysis and supervision.

12.2 Profiling

12.2.1 Profiling means any form of automated processing of personal data that involves the use of personal data to evaluate certain personal aspects relating to an individual, in particular to analyze or predict the individual’s performance at work, economic situation, interests, etc.

12.2.2 The Bank performs profiling if you have given your consent for marketing purposes. Profiling is performed using various methods of statistics, mathematics or predictive analysis, which allows us to predict your needs and prepare appropriate offers for you on this basis. As part of profiling, we may analyze your demographic data, such as age, location, and data on banking services performed, based on which we place you in an individual profile and send you only offers that we believe meet your needs and habits.

  • PROCESSING METHODS AND SECURITY MEASURES

13.1 The personal data are processed with automated and non-automated instruments, only for the time strictly necessary to achieve the purposes for which they have been collected. We use advanced technical and organizational measures to protect your data and to prevent loss of data, illegal or incorrect uses and unauthorized access, including:

  • Encrypted communication.
  • Continuous monitoring of website usage.
  • Access controls and staff training on confidentiality.
  • Regular security monitoring.
  • Employee confidentiality agreements.

13.2 The IT systems and other data storage facilities of our Bank are located at its registered premises and on the servers leased by the processor. Bank selects and operates the IT tools and applications for the processing of personal data in such a way that the data processed are:

  • accessible for the authorised persons (availability),
  • credible and authenticated (authenticity),
  • verifiably unchanged (data integrity),
  • protected from unauthorised access (confidentiality).

13.3 We take particular care to ensure data security, take all technical and organisational measures and adopt procedural rules required for enforcing the safeguards specified in Law no. 124/2024 “On personal data protection” and the applicable legal-regulatory framework. We take appropriate measures to protect the data from unauthorised access, alteration, transfer, public disclosure, deletion or destruction, as well as damage and accidental loss, and ensure that the data stored cannot be corrupted or rendered inaccessible due to any changes in or modification to the applied technique.

13.4 The information systems of Bank and our partners are both protected from computer assisted fraud, computer viruses, hacking and distributed denial-of-service attacks (DdoS). Moreover, Bank ensures security by means of server-level and application-level security procedures. Data are backed up on a daily basis. Bank takes all possible measures to avoid personal data breaches and in the event of a data breach, it takes action immediately to minimise any risks and eliminate any damage, in accordance with our incident management regulations and the applicable legal regulatory framework.

  • UPDATES TO THIS POLICY

14.1 The Bank reserves the right to amend or supplement this Policy to ensure compliance with laws and regulations on the protection of personal data and the applicable legal-regulatory framework, changes in technology or products/services. The latest valid version of the Policy is available on its website (www.otpbank.al) with a revised “Last Updated” date.

14.2 Anything not specifically stipulated in this Policy or in the contract concluded between the Bank and the individual shall be subject to the provisions of applicable legislation.