Rights of the data subject

Right of access

You can obtain confirmation from the Bank about whether your Personal Data is being processed or not and, in this case, obtain access to the Personal Data and the information envisaged under Article 15 of the Regulation, among which, by way of example: the purposes of the processing, the categories of Personal Data processed etc.

If the Personal Data is transferred to a third country or to an international organisation, you have the right to be informed of the existence of suitable guarantees relating to the transfer. If requested, the Bank can provide you with a copy of the Personal Data subject to processing. For any additional copies, the Bank may charge you a fee reasonably based on the administrative costs. If the request in question is submitted via electronic means, and unless otherwise specified, the information will be provided by the Bank in an electronic format of common usage.

Right to rectification

You may obtain rectification from the Bank of your Personal Data that is inexact as well as, taking into account the purpose of the processing, its integration, if the data is incomplete, by providing a supplementary declaration.

Right to erasure

You may obtain from the Data Controller the erasure of your Personal Data, if there is one of the reasons under Article 17 of the Regulation, including, by way of example, if the Personal Data is no longer necessary for the purposes for which it was collected or otherwise processed or if the consent on which the processing of your Personal Data is based was revoked by you or there is no other legal principle for the processing. We hereby inform you that the Bank may not erase your Personal Data: if its processing is necessary, for example, to fulfil a legal obligation, for reasons of public interest, to verify, exercise or defend a right in court.

Right to restriction of processing

You may obtain the restriction of your Personal Data if one of the hypotheses under Article 18 of the Regulation applies, among which, for example: given your objection to the accuracy of your Personal Data subject to processing or if your Personal Data is needed in order to verify, exercise or defend a right in court, although the Bank no longer needs it for the purposes of the processing.

Right to data portability

If the processing of your Personal Data is based on the consent or is necessary for the performance of a contract or pre-contractual measures and the processing is performed with automated means, you may:

  • request to receive the Personal Data provided by you in a structured format, of common usage and legible by an automatic device (e.g., a computer and/or tablet);
  • send your Personal Data received to another Data Controller with no barrier by the Bank.
In addition, you may request that your Personal Data is sent by the Bank directly to another data controller specified by you, if this is technically feasible for the Bank. In this case, you shall provide us with all the exact details of the new data controller to whom you intend to transfer your Personal Data, providing us with suitable written authorisation.

Right to object

You may object to the processing of Personal Data at any time if the processing is performed for the execution of an activity of public interest or to achieve a legitimate interest of the Data Controller (including profiling). Should you decide to exercise the right to object described here, the Bank will abstain from processing your personal data further, unless there are legitimate reasons to proceed with the processing (reasons prevailing over the interest, rights and freedoms of the data subject), or the processing is necessary to verify, exercise or defend a right in court.

Automated decision process relating to natural persons, including profiling

The Bank, in the presence of the creditworthiness requirements and to set amount thresholds, carries out automated decision-making processes, among others, to issue credit cards, for applications for personal loans and finalised loans, providing, in these cases, more details as part of specific information and acquiring, to this end, the explicit consent.

The Regulation grants the data subject the right not to be subject to a decision based only on the automated processing of your Personal Data, including profiling, which produces legal effects that concern you or significantly affect you, unless the above-mentioned decision:

  1. is necessary for the conclusion or performance of a contract between you and the Bank;
  2. is authorised by the Italian or European law;
  3. is based on your explicit consent.
In the cases under letters a) and c), the Bank will implement appropriate measures to protect your rights, your freedoms and your legitimate interest and you may exercise the right to obtain the human intervention by the Bank, to express your opinion or dispute the decision.

Right to lodge a complaint with the Data Protection Authority

Notwithstanding your right to appeal to any other administrative or jurisdictional court, should you deem that the processing of your Personal Data by the Data Controller takes place in breach of the Regulation and/or the applicable regulations, you may lodge a complaint with the competent Data Protection Authority. For all matters relating to the processing of your Personal Data and/or to exercise the rights provided for by the Regulation, you may contact:

In the “Data Controller” section, a form for exercising your rights with regard to the protection of personal data is available and may be used to submit your requests.