INTRODUCTION

Emirates NBD Asset Management, (referred to as “we”, “us”, “our” or “ENBD AM” in this Data Privacy Notice) primarily refers to all the Personal Data that is collected and used about ENBD AM Customers for the purposes of the DIFC Data Protection Law No.5 of 2020. Emirates NBD Asset Management is part of the Emirates NBD Group.

ENBD AM is registered in DIFC, Gate Building, East Wing, 8th Floor.

This Data Privacy Notice describes the Personal Data ENBD AM collect, how it is used and shared, and your choices regarding this data. ENBD AM is the Data Controller for the Personal Data collected in connection with the use of ENBD AM Services.

SCOPE

This Data Privacy Notice applies to all Customers of ENBD AM Services, including Customers of ENBD AM’s mobile application, websites, and other banking Services (collectively, the “Services”) and through other interactions and communications you may have with us. This Notice specifically applies to:

  • Consumers/Customers
  • This notice also governs Emirates NBD Asset Management’s other collection of Personal Data in connection with its Services.

ENBD AM’s most important asset is you and your trust. ENBD AM are committed to providing you with exceptional banking Services and want you to have confidence in the way ENBD AM use your Personal Data. Emirates NBD is committed to protecting your privacy and your Personal Data.

Further this Notice explains the various measures ENBD AM have in place to protect the security of your Personal Data and minimise the potential for its unauthorised use, disclosure, and destruction.

YOUR DATA PRIVACY JOURNEY WITH US

ENBD AM may act as a ‘Data Controller’ or a “Data Processor” in relation to your Personal Data.

Who is a Data Controller? ENBD AM will act as a Data Controller when processing your Personal Data. A Data Controller is an entity who solely, or jointly with others, determines the purposes (“why”) and means (“how”) of Personal Data Processing. In most cases, ENBD AM will act as the Data Controller when Processing your Personal Data – this means ENBD AM will decide on how to collect, process, and use Personal Data in this role.

Who is a Data Processor? In some other cases, ENBD AM will act as a Data Processor when Processing your Personal Data on behalf of another ENBD AM Group entity. In these cases, ENBD AM will perform the Processing of the Personal Data under the specific instructions from the ENBD AM Group entity acting as the Controller.

If you have any questions about how ENBD AM use your Personal Data, you can contact us by using the “Contact Us” information at the end of this Data Privacy Notice.

CONFIDENTIALITY OF PERSONAL DATA

When ENBD AM collects Personal Data, ENBD AM provides a safe, secure, and confidential environment in all our delivery Channels to ensure that your Personal Data remains private and used for the purposes for which it is held.
ENBD AM has a legal obligation to keep your data confidential, however, ENBD AM may disclose your data to a third party where:

  • ENBD AM is legally obliged to do so.
  • The disclosure of your data is imposed by a legal authority.
  • In circumstances where the disclosure is made with your express consent or through a representative nominated by you.

Personal Data and Processing have very specific meanings under the UAE Applicable Laws, including under the DIFC Data Protection Law, it is important that you understand these terms.

What is Personal Data?

Personal Data means any data which relates to a living individual who can be identified directly or indirectly from that data. The definition includes a wide range of personal identifiers that constitute Personal Data, or to one or more factors specific to their biological, physical, biometric, physiological, mental, economic, cultural, or social identity.

Examples of Personal Data include, but are not limited to the following:

  • Address
  • Contact information
  • Date of birth
  • Financial data
  • Gender
  • Identification number (e.g., national id, passport number, and driver’s license number)
  • Location data (e.g., gps coordinates)
  • Marital status
  • Name
  • Photographs, videos, voice recordings
  • Telephone, mobile, fax numbers and email addresses
  • Transactional data
  • Website technical data (e.g., your internet protocol (Ip) address, website login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our websites)
  • Website profile and usage data (e.g., your interests, preferences, feedback and survey responses, information about how you use our websites)
  • Transaction details while performing online payments (e.g., merchant name, location, device used).

What is Processing?

Processing means doing anything with Personal Data, e.g., viewing, collecting, using, storing, sharing, manipulating, printing, copying, archiving etc.

Processing activity means any task that involves doing anything with Personal Data.

Processing as per DIFC Data Protection Law means:

any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage and archiving, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, transfer or otherwise making available, alignment or combination, restricting (meaning the marking of stored Personal Data with the aim of limiting Processing of it in the future), erasure or destruction, but excluding operations or sets of operations performed on Personal Data by:

(a) a natural person in the course of a purely personal or household activity that has no connection to a commercial purpose; or

(b) law enforcement authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security.

Personal Data That You Provide to Us

ENBD AM collects Personal Data directly from you as our Customer or Potential Client ENBD AM collects information you provide directly to us through your access or use of ENBD AM Products and Services. For example, when you apply for a product or Service on our website(s), by telephone or when you enter an ENBD AM premises and engage with one of ENBD AM’s employees.

Personal Data ENBD AM Collects About You from Other Sources

ENBD AM may collect Personal Data about you from other sources such as, but not limited to the following:

  • Representative(s) of a corporate client.
  • Legal representatives (power of attorney) of a client.
  • People appointed to act on your behalf.
  • Other Emirates NBD Groups.
  • Your employer.
  • Credit Bureaus or credit reporting agencies.
  • Digital identity solutions.
  • Government databases.
  • Law enforcement officials.
  • Co-borrowers / guarantors.
  • Criminal records check from organisations authorised to provide this data.
  • Beneficiaries of your payment transactions.
  • Nominated contact person by an existing account holder.
  • Third party providers and partners to help us improve the Personal Data ENBD AM hold and to provide more relevant and interesting products and Services to you.
  • Reference contacts provided in the application form by you.

Personal Data ENBD AM May Collect About Other Individuals

In certain circumstances, ENBD AM may be provided Personal Data from you about individuals who do not have a direct relationship with us. This may happen, for instance, when you provide us with Personal Data about:

  • Beneficiaries of your payment transactions.
  • Co-borrowers / guarantors.
  • Employers of ENBD AM Customers.
  • Landlords.
  • Legal representatives (power of attorney) of a client.
  • Next of Kin
  • Reference contacts provided in the application Representative(s) of a corporate client.
  • Shareholder(s)/Director(s) of a corporate client.
  • Spouses
  • Successors and right holders.
  • Ultimate beneficial owners.
  • Form by an ENBD AM (potential) Customer.

Personal Data includes information that ENBD AM collect and process about you depending on the products or Services you obtain or receive.

The below is a non-exhaustive list which highlights some, but not all, examples of categories of Personal Data ENBD AM collect about you:

Category Description Example Lawful Basis
Account Management

Used to administer your account with ENBD AM.

Used to identify you when you sign-in to your account.

Used to provide you with Services, and to fulfil your requests for certain products and Services covering investment management (whether non-discretionary, discretionary or execution only).

To enable ENBD AM to process your data for the sole purpose of administering your relationship with the Bank. Performance of a Contract
Account Opening

Used for the setup and management of Customer accounts, including meeting the regulatory requirements such as KYC (Know Your Customer) process.

To enable Customers to create an Account, log in to your instance on the ENBD AM App, or verify their credentials. Performance of a Contract
Analytics

Used to collect data about how Customers use the ENBD AM App or how it performs.

Used to understand how you use and interact with our Services and the people or things you’re connected to and interested in.

To see how many Customers are using a particular gesture, to monitor app health, to diagnose and fix bugs or crashes, or to make future performance improvements. Legitimate Interest
App Functionality

Used for Features that are Available in the App.

Used to improve the design and functionality of ENBD AM Channels for a better Customer experience.

To enable app features, or to authenticate Customer. Legitimate Interest
Decline Onboarding

If your application is declined, ENBD AM will store your Personal Data in accordance with the ENBD AM record retention procedures and to comply with ENBD AM legal obligations.

To keep track of the reasons for the declining of Onboarding to be used as reference, if and when the Customer approaches the Bank again. Legitimate Interest
Developer Communications

Used to send news or notifications about the app or the developer.

Sending a push notification to inform Customers about an important security update.

Performance of a Contract

Legitimate Interest

General Correspondence

Personal Data you give to us by filling in any of ENBD AM forms or by communicating with us, whether face-to-face, by phone, email, online or otherwise.

To contact you if you have asked us to do so including to resolve troubleshooting problems and helping with any issues concerning ENBD AM website or apps. Performance of a Contract
Financial Mediations / Debt Recovery

Used to authorise debt Service partners to carry out collection activities on ENBD AM behalf.

Used to recover debt and exercise other rights ENBD AM have under any agreement with ENBD AM Customers as well as to protect ENBD AM against harm to ENBD AM rights and interests in property.

Partners of ENBD AM engage with Customers who have defaulted, to settle their liabilities with ENBD AM.

Performance of a Contract

Legitimate Interest

Fraud Prevention, Security and Compliance

Used for fraud prevention, security, or compliance with laws.

Used to prevent and detect fraud, money laundering and other crimes such as identity theft.

Monitoring failed login attempts to identify possible fraudulent activity.

Legal Obligation

Legitimate interest

Personalised Commercial and Promotional Communications (Marketing)

To send commercial and promotional communications through telematic or conventional means, in relation to similar goods and Services than the ones previously contracted or acquired from ENBD AM.

This also includes for the purpose of conducting market research and accompanying statistical analysis to better understand our Customer base and the markets in which we operate.

ENBD AM sends Customers a promotional email or SMS relating to a Product or Service on offer. Consent
Regulatory Requests

To handle requests and instructions from regulators, law enforcement Agencies, etc. that specific information about individuals.

To meet the legal and regulatory obligations ENBD AM has, as a Licenced Financial Institution, governed by the DIFC, DFSA, SCA Legal Obligation
Satisfaction Surveys

To contact you for your opinions about ENBD AM Services including through surveys and other market research.

Sending Customer satisfaction surveys. Consent
Service Communications

Used to keep Customers informed of the products and Services they are availing of.

Used to tell you about important updates and changes to ENBD AM Channels, including to ENBD AM Data Privacy Notice and other Policies and Terms.

Sending Customers reminders to update their Personal Data in the App such as their mobile number and home address. Performance of a Contract
Video Protection (CCTV)

Used at ENBD AM premises and ATMs for security purposes.

To protect ENBD AM Customers, employees, visitors, and its premises. Legitimate Interests

ENBD AM only discloses your Personal Data outside of ENBD AM in limited circumstances. If ENBD AM does share the Personal Data outside of ENBD AM, we will put in place appropriate controls and data sharing/processing agreements that require recipients to protect your Personal Data, unless ENBD AM is legally required to share that Personal Data. All contractors or recipients that work for ENBD AM will be obliged to follow ENBD AM instructions. ENBD AM does not sell your Personal Data to third parties.

ENBD AM may disclose your Personal Data to ENBD AM third-party Service providers, agents, and subcontractors (Suppliers) for the purposes of providing Services to us or directly to you on ENBD AM’s behalf.

When ENBD AM uses Suppliers, ENBD AM only discloses to them the Personal Data that is necessary to provide their Services and only where ENBD AM has a contract in place which requires them to keep your Personal Data secure and not to use it other than in accordance with ENBD AM’s specific instructions. ENBD AM take steps to ensure that any third-party service providers who handle your Personal Data comply with the Applicable Laws and protect your Personal Data to the same extent that ENBD AM does. ENBD AM will aim to anonymise your Personal Data or use aggregated non-specific data sets where possible. Find below the supporting Schedule with a list of categories of third parties with whom ENBD AM may share your data.

Category of Third Party Description of Service Provided Lawful Basis of Processing
Account Holders ENBD AM may share your Personal Data with any joint account holders, guarantors, trustees or beneficiaries assigned by you at the onset or during the course of receiving ENBD AM products/Services. Performance of a Contract
Affiliates ENBD AM may share your Personal Data with companies within the Emirates NBD Group who may support us in any of the purposes set out in this Data Privacy Notice to improve and enhance the Customer experience.

Legitimate Interest

Legal Obligation

Analytics Providers ENBD AM may share your Personal Data with analytics providers that assist us in the optimisation of ENBD AM website and apps including by measuring the performance of ENBD AM online campaigns and analysing visitor activity. Legitimate Interest
Asset Purchasers ENBD AM may share your Personal Data with any third party that purchases, or to which ENBD AM transfer, all or substantially all of ENBD AM assets and business. Should such a sale or transfer occur, ENBD AM will engage best efforts to try to ensure that the entity to which ENBD AM transfer your Personal Data uses it in a manner that is consistent with this Data Privacy Notice.

Performance of a Contract

Legitimate Interest

Business Partners

ENBD AM may share your Personal Data with ENBD AM business partners, together with whom ENBD AM provide Services such as hotels, restaurants, airline partners (whose logo may appear on a credit card ENBD AM provide) and Service providers or agents who provide Services on their behalf.

Business partners may also include any entity (including its professional advisors and authorised representatives), who provide funding to ENBD AM or members of the ENBD AM Group, any entity that provides us with debt or equity finance and any potential purchasers of any part of our business.

Business Partners may also include any party to a transaction acquiring an interest in, or assuming risk in, or in connection with, your banking relationship with ENBD AM.

Performance of a Contract

Consent

Courts, Regulators, and Government Authorities

ENBD AM may share your Personal Data with these parties where ENBD AM believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect ENBD AM rights or the rights of any third party.

To investigate or address claims or disputes relating to the use of ENBD AM’s Services, to satisfy requirements under applicable laws, regulations, or operating licences or agreements, or pursuant to legal process or governmental request, including from law enforcement.

Legal Obligation
Credit Information Agencies ENBD AM may share your Personal Data with government-authorised Credit Information Agencies and fraud prevention agencies to comply with ENBD AM’s legal and regulatory obligations. Legal Obligation
Debt Collection Agencies ENBD AM may share your Personal Data with any entity used for the recovery or collection of receivables to the bank from delinquent or defaulted Customers. Performance of Contract
Fund Managers ENBD AM may share your Personal Data with fund managers who provide asset management Services to you and any brokers who introduce you to us or deal with us for you. Performance of a Contract
Guarantors

ENBD AM may share your Personal Data with any person or entity that is to provide, or has provided, any security of guarantee (and their professional advisors) in respect of your agreement with ENBD AM.

This type of processing is necessary for the fulfilment of our contract with you, for example to enable us to recover any sums we have advanced under our agreement with you.

Performance of a Contract
Insurance Providers ENBD AM may share your Personal Data with insurance providers, including underwriters, brokers and associated parties.

Performance of a Contract

Legal Obligation

Legitimate Interest

IT Service Providers System based processing of personal details as part of organisational/ operational requirements. e.g., cloud hosting Services; application development and support Services; IT Infrastructure Services; email Services; call recording Services. Help maintain the safety, security, and integrity of ENBD AM Services and Customer. Performance of a Contract
Law Enforcement Agencies & Authorities To assist law enforcement agencies for the purposes of preventing, detecting, investigating, or prosecuting criminal offences. Legal Obligation
Legal/Professional Advisors The provision of business consulting, audit and legal Services including access to and analysis of Personal Data as part of business initiatives, statutory audits, legal claims, and ad-hoc consultancy advice.

Performance of a Contract

Legitimate Interest

Other Uses

Provide, maintain, and improve ENBD AM Services, including, for example, to facilitate payments, send receipts, provide products and Services you request (and send related information), develop new features, provide User support to Customer, develop safety features, authenticate Customer, and send product updates and administrative messages.

Perform internal administration and operations, including, for example, to prevent fraud and abuse of ENBD AM Services; to troubleshoot software bugs and operational problems; to conduct data analysis, testing, and research; and to monitor and analyse usage and activity trends.

Send you communications ENBD AM think will be of interest to you, including information about products, Services, promotions, news, and events of ENBD AM, where permissible and according to local applicable laws.

Notify you about changes to ENBD AM terms, Services or policies and other communications that aren’t for the purpose of marketing the Services or products of ENBD AM or its partners.

Legitimate Interest

Performance of a Contract

Payment Processing Services ENBD AM may share your Personal Data with providers of payment-processing Services and other businesses that help us process your payments to the extent required for us to meet the contractual and legal requirements. Performance of a Contract
Representatives ENBD AM may share your Personal Data with anyone who provides instructions or operates any of your accounts on your behalf including advisers (such as solicitors and accountants), intermediaries and those under power of attorney or Letter of Authorisation. Consent
Social Media Agencies ENBD AM may share your Personal Data with social media companies so they can display messages to you about ENBD AM products and Services or make sure you do not get irrelevant messages. Performance of a Contract
Intermediaries/Brokers through whom you are our Customers ENBD AM may share your Personal Data with third parties who have introduced you to us (e.g. an intermediary or broker) in order for them to manage their records about you, to ensure that the type of business that they refer to us is appropriate and to help ENBD AM to resolve any complaint made by you and/or any dispute between you and ENBD AM.

This type of processing allows us to ensure that the intermediary or broker is fulfilling the terms of their contract with us and for us to fulfil our legal and regulatory obligations.

Performance of a Contract

ENBD AM websites and apps are intended for use only by persons who are at least 18 years of age. If you are under the age of 18, your parent or guardian must consent on your behalf where ENBD AM asks for consent in relation to the use of your Personal Data.

Personal Data and Processing have very specific meanings under the UAE Applicable Laws, including under the DIFC Data Protection Law, it is important that you understand these terms.

What is Personal Data?

Personal Data means any data which relates to a living individual who can be identified directly or indirectly from that data. The definition includes a wide range of personal identifiers that constitute Personal Data, or to one or more factors specific to their biological, physical, biometric, physiological, mental, economic, cultural, or social identity.

Examples of Personal Data include, but are not limited to the following:

  • Address
  • Contact information
  • Date of birth
  • Financial data
  • Gender
  • Identification number (e.g., national id, passport number, and driver’s license number)
  • Location data (e.g., gps coordinates)
  • Marital status
  • Name
  • Photographs, videos, voice recordings
  • Telephone, mobile, fax numbers and email addresses
  • Transactional data
  • Website technical data (e.g., your internet protocol (Ip) address, website login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our websites)
  • Website profile and usage data (e.g., your interests, preferences, feedback and survey responses, information about how you use our websites)
  • Transaction details while performing online payments (e.g., merchant name, location, device used).

What is Processing?

Processing means doing anything with Personal Data, e.g., viewing, collecting, using, storing, sharing, manipulating, printing, copying, archiving etc.

Processing activity means any task that involves doing anything with Personal Data.

Processing as per DIFC Data Protection Law means:

any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage and archiving, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, transfer or otherwise making available, alignment or combination, restricting (meaning the marking of stored Personal Data with the aim of limiting Processing of it in the future), erasure or destruction, but excluding operations or sets of operations performed on Personal Data by:

(a) a natural person in the course of a purely personal or household activity that has no connection to a commercial purpose; or

(b) law enforcement authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security.

Personal Data That You Provide to Us

ENBD AM collects Personal Data directly from you as our Customer or Potential Client ENBD AM collects information you provide directly to us through your access or use of ENBD AM Products and Services. For example, when you apply for a product or Service on our website(s), by telephone or when you enter an ENBD AM premises and engage with one of ENBD AM’s employees.

Personal Data ENBD AM Collects About You from Other Sources

ENBD AM may collect Personal Data about you from other sources such as, but not limited to the following:

  • Representative(s) of a corporate client.
  • Legal representatives (power of attorney) of a client.
  • People appointed to act on your behalf.
  • Other Emirates NBD Groups.
  • Your employer.
  • Credit Bureaus or credit reporting agencies.
  • Digital identity solutions.
  • Government databases.
  • Law enforcement officials.
  • Co-borrowers / guarantors.
  • Criminal records check from organisations authorised to provide this data.
  • Beneficiaries of your payment transactions.
  • Nominated contact person by an existing account holder.
  • Third party providers and partners to help us improve the Personal Data ENBD AM hold and to provide more relevant and interesting products and Services to you.
  • Reference contacts provided in the application form by you.

Personal Data ENBD AM May Collect About Other Individuals

In certain circumstances, ENBD AM may be provided Personal Data from you about individuals who do not have a direct relationship with us. This may happen, for instance, when you provide us with Personal Data about:

  • Beneficiaries of your payment transactions.
  • Co-borrowers / guarantors.
  • Employers of ENBD AM Customers.
  • Landlords.
  • Legal representatives (power of attorney) of a client.
  • Next of Kin
  • Reference contacts provided in the application Representative(s) of a corporate client.
  • Shareholder(s)/Director(s) of a corporate client.
  • Spouses
  • Successors and right holders.
  • Ultimate beneficial owners.
  • Form by an ENBD AM (potential) Customer.

Personal Data includes information that ENBD AM collect and process about you depending on the products or Services you obtain or receive.

The below is a non-exhaustive list which highlights some, but not all, examples of categories of Personal Data ENBD AM collect about you:

Category Description Example Lawful Basis
Account Management

Used to administer your account with ENBD AM.

Used to identify you when you sign-in to your account.

Used to provide you with Services, and to fulfil your requests for certain products and Services covering investment management (whether non-discretionary, discretionary or execution only).

To enable ENBD AM to process your data for the sole purpose of administering your relationship with the Bank. Performance of a Contract
Account Opening

Used for the setup and management of Customer accounts, including meeting the regulatory requirements such as KYC (Know Your Customer) process.

To enable Customers to create an Account, log in to your instance on the ENBD AM App, or verify their credentials. Performance of a Contract
Analytics

Used to collect data about how Customers use the ENBD AM App or how it performs.

Used to understand how you use and interact with our Services and the people or things you’re connected to and interested in.

To see how many Customers are using a particular gesture, to monitor app health, to diagnose and fix bugs or crashes, or to make future performance improvements. Legitimate Interest
App Functionality

Used for Features that are Available in the App.

Used to improve the design and functionality of ENBD AM Channels for a better Customer experience.

To enable app features, or to authenticate Customer. Legitimate Interest
Decline Onboarding

If your application is declined, ENBD AM will store your Personal Data in accordance with the ENBD AM record retention procedures and to comply with ENBD AM legal obligations.

To keep track of the reasons for the declining of Onboarding to be used as reference, if and when the Customer approaches the Bank again. Legitimate Interest
Developer Communications

Used to send news or notifications about the app or the developer.

Sending a push notification to inform Customers about an important security update.

Performance of a Contract

Legitimate Interest

General Correspondence

Personal Data you give to us by filling in any of ENBD AM forms or by communicating with us, whether face-to-face, by phone, email, online or otherwise.

To contact you if you have asked us to do so including to resolve troubleshooting problems and helping with any issues concerning ENBD AM website or apps. Performance of a Contract
Financial Mediations / Debt Recovery

Used to authorise debt Service partners to carry out collection activities on ENBD AM behalf.

Used to recover debt and exercise other rights ENBD AM have under any agreement with ENBD AM Customers as well as to protect ENBD AM against harm to ENBD AM rights and interests in property.

Partners of ENBD AM engage with Customers who have defaulted, to settle their liabilities with ENBD AM.

Performance of a Contract

Legitimate Interest

Fraud Prevention, Security and Compliance

Used for fraud prevention, security, or compliance with laws.

Used to prevent and detect fraud, money laundering and other crimes such as identity theft.

Monitoring failed login attempts to identify possible fraudulent activity.

Legal Obligation

Legitimate interest

Personalised Commercial and Promotional Communications (Marketing)

To send commercial and promotional communications through telematic or conventional means, in relation to similar goods and Services than the ones previously contracted or acquired from ENBD AM.

This also includes for the purpose of conducting market research and accompanying statistical analysis to better understand our Customer base and the markets in which we operate.

ENBD AM sends Customers a promotional email or SMS relating to a Product or Service on offer. Consent
Regulatory Requests

To handle requests and instructions from regulators, law enforcement Agencies, etc. that specific information about individuals.

To meet the legal and regulatory obligations ENBD AM has, as a Licenced Financial Institution, governed by the DIFC, DFSA, SCA Legal Obligation
Satisfaction Surveys

To contact you for your opinions about ENBD AM Services including through surveys and other market research.

Sending Customer satisfaction surveys. Consent
Service Communications

Used to keep Customers informed of the products and Services they are availing of.

Used to tell you about important updates and changes to ENBD AM Channels, including to ENBD AM Data Privacy Notice and other Policies and Terms.

Sending Customers reminders to update their Personal Data in the App such as their mobile number and home address. Performance of a Contract
Video Protection (CCTV)

Used at ENBD AM premises and ATMs for security purposes.

To protect ENBD AM Customers, employees, visitors, and its premises. Legitimate Interests

ENBD AM only discloses your Personal Data outside of ENBD AM in limited circumstances. If ENBD AM does share the Personal Data outside of ENBD AM, we will put in place appropriate controls and data sharing/processing agreements that require recipients to protect your Personal Data, unless ENBD AM is legally required to share that Personal Data. All contractors or recipients that work for ENBD AM will be obliged to follow ENBD AM instructions. ENBD AM does not sell your Personal Data to third parties.

ENBD AM may disclose your Personal Data to ENBD AM third-party Service providers, agents, and subcontractors (Suppliers) for the purposes of providing Services to us or directly to you on ENBD AM’s behalf.

When ENBD AM uses Suppliers, ENBD AM only discloses to them the Personal Data that is necessary to provide their Services and only where ENBD AM has a contract in place which requires them to keep your Personal Data secure and not to use it other than in accordance with ENBD AM’s specific instructions. ENBD AM take steps to ensure that any third-party service providers who handle your Personal Data comply with the Applicable Laws and protect your Personal Data to the same extent that ENBD AM does. ENBD AM will aim to anonymise your Personal Data or use aggregated non-specific data sets where possible. Find below the supporting Schedule with a list of categories of third parties with whom ENBD AM may share your data.

Category of Third Party Description of Service Provided Lawful Basis of Processing
Account Holders ENBD AM may share your Personal Data with any joint account holders, guarantors, trustees or beneficiaries assigned by you at the onset or during the course of receiving ENBD AM products/Services. Performance of a Contract
Affiliates ENBD AM may share your Personal Data with companies within the Emirates NBD Group who may support us in any of the purposes set out in this Data Privacy Notice to improve and enhance the Customer experience.

Legitimate Interest

Legal Obligation

Analytics Providers ENBD AM may share your Personal Data with analytics providers that assist us in the optimisation of ENBD AM website and apps including by measuring the performance of ENBD AM online campaigns and analysing visitor activity. Legitimate Interest
Asset Purchasers ENBD AM may share your Personal Data with any third party that purchases, or to which ENBD AM transfer, all or substantially all of ENBD AM assets and business. Should such a sale or transfer occur, ENBD AM will engage best efforts to try to ensure that the entity to which ENBD AM transfer your Personal Data uses it in a manner that is consistent with this Data Privacy Notice.

Performance of a Contract

Legitimate Interest

Business Partners

ENBD AM may share your Personal Data with ENBD AM business partners, together with whom ENBD AM provide Services such as hotels, restaurants, airline partners (whose logo may appear on a credit card ENBD AM provide) and Service providers or agents who provide Services on their behalf.

Business partners may also include any entity (including its professional advisors and authorised representatives), who provide funding to ENBD AM or members of the ENBD AM Group, any entity that provides us with debt or equity finance and any potential purchasers of any part of our business.

Business Partners may also include any party to a transaction acquiring an interest in, or assuming risk in, or in connection with, your banking relationship with ENBD AM.

Performance of a Contract

Consent

Courts, Regulators, and Government Authorities

ENBD AM may share your Personal Data with these parties where ENBD AM believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect ENBD AM rights or the rights of any third party.

To investigate or address claims or disputes relating to the use of ENBD AM’s Services, to satisfy requirements under applicable laws, regulations, or operating licences or agreements, or pursuant to legal process or governmental request, including from law enforcement.

Legal Obligation
Credit Information Agencies ENBD AM may share your Personal Data with government-authorised Credit Information Agencies and fraud prevention agencies to comply with ENBD AM’s legal and regulatory obligations. Legal Obligation
Debt Collection Agencies ENBD AM may share your Personal Data with any entity used for the recovery or collection of receivables to the bank from delinquent or defaulted Customers. Performance of Contract
Fund Managers ENBD AM may share your Personal Data with fund managers who provide asset management Services to you and any brokers who introduce you to us or deal with us for you. Performance of a Contract
Guarantors

ENBD AM may share your Personal Data with any person or entity that is to provide, or has provided, any security of guarantee (and their professional advisors) in respect of your agreement with ENBD AM.

This type of processing is necessary for the fulfilment of our contract with you, for example to enable us to recover any sums we have advanced under our agreement with you.

Performance of a Contract
Insurance Providers ENBD AM may share your Personal Data with insurance providers, including underwriters, brokers and associated parties.

Performance of a Contract

Legal Obligation

Legitimate Interest

IT Service Providers System based processing of personal details as part of organisational/ operational requirements. e.g., cloud hosting Services; application development and support Services; IT Infrastructure Services; email Services; call recording Services. Help maintain the safety, security, and integrity of ENBD AM Services and Customer. Performance of a Contract
Law Enforcement Agencies & Authorities To assist law enforcement agencies for the purposes of preventing, detecting, investigating, or prosecuting criminal offences. Legal Obligation
Legal/Professional Advisors The provision of business consulting, audit and legal Services including access to and analysis of Personal Data as part of business initiatives, statutory audits, legal claims, and ad-hoc consultancy advice.

Performance of a Contract

Legitimate Interest

Other Uses

Provide, maintain, and improve ENBD AM Services, including, for example, to facilitate payments, send receipts, provide products and Services you request (and send related information), develop new features, provide User support to Customer, develop safety features, authenticate Customer, and send product updates and administrative messages.

Perform internal administration and operations, including, for example, to prevent fraud and abuse of ENBD AM Services; to troubleshoot software bugs and operational problems; to conduct data analysis, testing, and research; and to monitor and analyse usage and activity trends.

Send you communications ENBD AM think will be of interest to you, including information about products, Services, promotions, news, and events of ENBD AM, where permissible and according to local applicable laws.

Notify you about changes to ENBD AM terms, Services or policies and other communications that aren’t for the purpose of marketing the Services or products of ENBD AM or its partners.

Legitimate Interest

Performance of a Contract

Payment Processing Services ENBD AM may share your Personal Data with providers of payment-processing Services and other businesses that help us process your payments to the extent required for us to meet the contractual and legal requirements. Performance of a Contract
Representatives ENBD AM may share your Personal Data with anyone who provides instructions or operates any of your accounts on your behalf including advisers (such as solicitors and accountants), intermediaries and those under power of attorney or Letter of Authorisation. Consent
Social Media Agencies ENBD AM may share your Personal Data with social media companies so they can display messages to you about ENBD AM products and Services or make sure you do not get irrelevant messages. Performance of a Contract
Intermediaries/Brokers through whom you are our Customers ENBD AM may share your Personal Data with third parties who have introduced you to us (e.g. an intermediary or broker) in order for them to manage their records about you, to ensure that the type of business that they refer to us is appropriate and to help ENBD AM to resolve any complaint made by you and/or any dispute between you and ENBD AM.

This type of processing allows us to ensure that the intermediary or broker is fulfilling the terms of their contract with us and for us to fulfil our legal and regulatory obligations.

Performance of a Contract

ENBD AM websites and apps are intended for use only by persons who are at least 18 years of age. If you are under the age of 18, your parent or guardian must consent on your behalf where ENBD AM asks for consent in relation to the use of your Personal Data.

The way ENBD AM analyses Personal Data relating to ENBD AM Services may involve profiling or other automated methods to make decisions about you that relate to the following:

  • Credit and affordability checks (including credit limits) – ENBD AM will consider several factors including information about your income, expenses and how well you have kept up on payments in the past.
  • Anti-money laundering, sanctions checks and screening 'politically exposed' people.
  • Monitoring your account for fraud and other financial crime – ENBD AM will assess your transactions to identify any that are unusual.
  • Assessments required by regulators and appropriate authorities.

You may have a right to certain information about how ENBD AM make these decisions. You may also have a right to request human intervention in case it pertains to a fully automated process and to challenge the decision. Refer the “How to Contact Us” section for further details on reaching out to us with your request.

ENBD AM needs your Personal Data to provide you with the Services or products requested by you. On execution of the investment management agreement, you authorize Emirates NBD Asset Management to hold and process both electronically and manually, the data (including personal sensitive data and information contained in e-mail and e-mail attachments) it collects, stores and / or processes, which relate to you for the purposes of the administration and management of its business, you also agree to Emirates NBD Asset Management forwarding this data to other offices it may have for storage, processing, or administrative purposes and consent to Emirates NBD Asset Management disclosing personal data collected from you (including sensitive personal data) to third parties where such disclosure is for the legitimate business purposes of Emirates NBD Asset Management or is necessary for administrative (including but not limited to data processing) personnel, management, legal and/or regulatory purposes.

MARKETING

It is voluntary for you to provide us your Personal Data or consent for direct sales or marketing purposes.

ENBD AM makes it clear on the ENBD AM physical application forms, during your onboarding digitally and on all communications received from the Bank as to what data is required to be provided by you by marking the mandatory fields with the asterisk symbol (*). You can object to further marketing at any time by:

Further details of how ENBD AM will use your Personal Data can be found below.

ENBD AM collects Personal Data about your internet activity using technology known as cookies, which can often be controlled through internet browsers and by using ENBD AM cookie preference center on the ENBD AM website.

  • Technical information, such as your IP address and device ID.
  • Information about your visit, such as your URL and website interaction.
  • Location data, with your approval, used to show you the location of the nearest branch or ATM based on your IP address, coordinates or a unique device code.
  • Networks and connections, when you interact with us and the people and groups that you are connected to (for example, through social media).

ENBD AM is a global organisation, and your Personal Data may be stored or processed in any country where ENBD AM has facilities or in which ENBD AM engages Service providers and subcontractors. ENBD AM has put in place appropriate safeguards in accordance with applicable legal and data protection requirements to ensure that your data is adequately protected.

ENBD AM, its officers, and employees may use, store, process, disclose, transfer (including outside the place in which the Client’s accounts are held) and exchange information to or with any person that the Asset Manager considers necessary or desirable for any purpose in connection with Services or in order to comply with Applicable Laws or the Asset Manager’s internal policies and procedures.

You have certain rights in respect of your Personal Data, and ENBD AM have processes to enable you to exercise these rights. Your rights are as follows:

  • Opt Out / Unsubscribe: You can request to be removed from the ENBD AM marketing mailing list, from the unsubscribe button in the email itself. We have other channels to request removal as well, such as calling the customer care centre and sending SMS to the designated number communicated to you as part of the marketing content.
  • Right to Access (also known as a ‘Subject Access Request’): You have the right to obtain confirmation as to whether ENBD AM processes Personal Data about you, receive a copy of your Personal Data held by us, and obtain certain other information about how and why ENBD AM processes your Personal Data.
  • Right to Rectification: You have the right to request for your Personal Data to be amended or rectified where it is inaccurate (for example, if you change your name or address) and to have incomplete Personal Data completed.
  • Right to Erasure (also known as 'the Right to be Forgotten'): You have the right to deletion of your Personal Data in the following cases:
  • The Personal Data are no longer necessary in relation to the purposes for which they were collected and processed.
  • Where our lawful basis for processing your information is consent and you then withdraw your consent. However, please note that the lawfulness of any previous processing carried out based on your valid consent earlier shall not be affected.
  • Our lawful basis for processing is that the processing is necessary for a legitimate interest pursued by ENBD AM, you object to our processing, and ENBD AM do not have overriding legitimate grounds.
  • You object to our processing for direct marketing purposes and advanced analytics.
  • Your Personal Data has been unlawfully processed.
  • Your Personal Data must be erased to comply with a legal obligation to which ENBD AM are subject.
  • Right to Object: You have the right to object to our processing of your Personal Data in the following cases:
  • Our lawful basis for processing is that the processing is necessary for a legitimate interest pursued by us.
  • Our processing for direct marketing purposes and advanced analytics.
  • Right to Data Portability: You have the right to request for your personal information to be prepared and arranged and sent to another organisation (or ask us to do so if technically feasible).
  • Right to Withdraw Consent: Where ENBD AM process Personal Data based on consent, individuals have a right to withdraw their consent at any time. To do so, please use the contact details below in the “How to Contact Us” section.
  • Right to Lodge a Complaint with a Supervisory Authority: ENBD AM sincerely hope that you will never need to, but if you do want to complain about our use of Personal Data, please send an email with the details of your complaint using the contact details set out below. You may lodge a complaint with the supervisory authority in your country of residence, place of work or the country in which an alleged infringement of data protection law has occurred. The contact details of the competent national supervisory authority, The Commissioner of Data Protection (“Commissioner”), are as follows:

Address: Dubai International Financial Centre Authority, Level 14, The Gate, Dubai, UAE.
Telephone: +971 4 3622222
Website/Email: commissioner@dp.difc.ae

Please note, all rights are subject to qualifications and limitations. In other words, there may be instances and justifiable grounds to deny any request where ENBD AM are required or permitted by law to do so. ENBD AM will always be clear and communicate this to you if these instances arise.

Also note, for the purpose of upholding the security, confidentiality, and integrity of your Personal Data, ENBD AM may verify your identity before allowing you to access your Personal Data.

The Security of your Personal Data is important to us. We make every effort to ensure that your Personal Data is secure on our system. ENBD AM has staff dedicated to maintaining the ENBD AM security standards as set forth herein. ENBD AM implements technical and organisational measures to ensure a level of security appropriate to the risk to the personal information ENBD AM processes. These measures are aimed at ensuring the on-going integrity and confidentiality of personal information. ENBD AM evaluates these measures on a regular basis to ensure the security of the processing.

Your ENBD AM profile is password-protected so that only you and authorised ENBD AM employees have access to your account information. ENBD AM staff will never reach out to you and ask for any personal account information, including your password.

ENBD AM make every effort to ensure that your Personal Data is secure on its system. ENBD AM have staff dedicated to maintaining the ENBD AM security standards as set forth herein. ENBD AM implement technical and organisational measures to ensure a level of security appropriate to the risk to the personal information ENBD AM process. These measures are aimed at ensuring the on-going integrity and confidentiality of personal information. ENBD AM evaluate these measures on a regular basis to ensure the security of the processing.

Unfortunately, you would appreciate that, no data transmission over the Internet can be fully guaranteed to be 100% secure. As a result, ENBD AM cannot guarantee the security of any Personal Data you transmit to us, and you do so at your own risk.

Whilst ENBD AM takes measures to secure your Personal Data, risks to data security do exist, and there is always a possibility of unauthorised use, disclosure, modification and/or destruction of your Personal Data. In the event of a Personal Data Breach, ENBD AM will notify you about it and its likely consequences, measures taken by us to mitigate the increased risk and avenues available to you to mitigate the risk as a result of the Personal Data Breach.

For reporting Personal Data Breaches or further information on how ENBD AM respond to and handle Personal Data Breaches, please contact us at assetmanagement@emiratesnbd.com.

The ENBD AM website and apps may, from time to time, contain links to external sites. If you follow a link to any of these websites, please note that these websites have their own Data Privacy Notices. Please check these Notices before you submit any Personal Data to these websites. ENBD AM is not responsible for the Data Privacy Notices, content of such sites or any Personal Data collected by such sites.

ENBD AM has appointed a Data Protection Officer (“DPO”) to oversee compliance with this Data Privacy Notice. The DPO can be contacted on ENBDAMDPO@emiratesnbd.com.

ENBD AM will keep your Personal Data for as long as ENBD AM has a relationship with you. Once the ENBD AM relationship with you has come to an end, ENBD AM will retain your Personal Data for a period that enables us to:

  • Maintain business records for analysis and/or audit purposes.
  • Comply with record retention requirements under the law.
  • Defend or bring any existing or potential legal claims.

ENBD AM will delete your Personal Data when it is no longer required for these purposes. If there is any information that ENBD AM is unable, for technical reasons, to delete entirely from ENBD AM systems, we will put in place appropriate measures to prevent any further processing or use of the data.

In some circumstances you can ask us to delete your data. For further information, please see the “What are your Rights” section.

If you have questions or concerns regarding the way in which your Personal Data is being used, please contact the ENBD AM Data Privacy Office by emailing ENBDAMDPO@emiratesnbd.com.

If you are unsatisfied with the way your Personal Data is being processed, please raise a complaint by reaching out to assetmanagement@emiratesnbd.com.

If you would like to lodge a complaint to your local supervisory authority, please get in touch and ENBD AM will provide you with instructions and contact details to your local supervisory authority.

If you would like to stop receiving marketing or promotional communications, please email ENBD AM at assetmanagement@emiratesnbd.com or call at +971 4 3700022 or by unsubscribing through any of the communications received.

ENBD AM are committed to working with you to obtain a fair resolution to any complaint or concern you may have. If, however, you believe that ENBD AM have not been able to assist with your complaint or concern you have the right to make a complaint to the data protection authority of your country.

ENBD AM may occasionally update this notice. If ENBD AM make significant changes, ENBD AM will notify Customer in advance of the changes through the ENBD AM apps or through other means, such as email. ENBD AM encourages Customers to periodically review this Data Privacy Notice for the latest information on the ENBD AM data privacy practices.

Should you wish to contact us to discuss any questions, concerns, and comments you may have regarding your Personal Data that we process, please reach us through our contact details provided in the “How to Contact Us” section of this Notice.

Term Definition
Anonymisation Means the process of removing direct personal identifiers that may lead to an individual being identified or re-identifiable.
Anonymous Data Means any information relating to a natural person where the person cannot be identified whether by the Data Controller or by any other person, taking account of all the means reasonably likely to be used either by the Data Controller or by any person to identify that individual.
Applicable Law(s) Means all Applicable Law(s) relating to the Processing of Personal Data, in each case which are in force at the date on which this policy is updated in the UAE including the DIFC Data Protection Law, UAE Data Protection Law, UAE Outsourcing Regulations as well as the UAE Central Bank Consumer Protection Regulation and accompanying Consumer Protection Standards as amended.
Authority(ies) Means legal, supervisory, regulatory, governmental, and quasi-governmental bodies such as the UAE Central Bank, the Securities and Commodities Authority (“SCA”), Dubai Financial Services Authority (DFSA), Abu Dhabi Global Market (ADGM), fraud prevention agencies, tax authorities etc.
Automated Processing Means Processing that is conducted using an electronic application or system that operates automatically, either independently without any human intervention or under the supervision and limited intervention of a human.
Binding corporate rules Personal Data protection policies and procedures, aggregated or incorporated in a single written document, which regulate the transfer of Personal Data between members of a Group, legally bind such members to comply, and which contain provisions for the protection of such Personal Data.
Biometric Data Means Personal Data resulting from specific technical processing relating to the physical, physiological and behavioral characteristics of the Data Subject, which allow the identification or confirm the unique identification of the Data Subject, such as facial recognition images.
Central Bank of the United Arab Emirates or UAE Central Bank (CBUAE) Means the Central Bank of the United Arab Emirates.
Consent Means the Consent by which the Data Subject authorises ENBD AM or third parties to process their Personal Data, provided that such Consent is freely given, informed, clear, specific, and unambiguous indication of the Data Subject's agreement, by a statement or by a clear affirmative action, to the Processing of their Personal Data.
Commissioner The person appointed by the President pursuant to Article 43(1) of the Law to administer the Law
Court The DIFC Court as established under Dubai Law.
Potential Client Potential client as per DFSA COB rule book is a person who is likely to obtain a Financial Service from the firm.
Data Breach(es) Means, as per the UAE Data Protection Law, a breach of information security and Personal Data through unauthorised or unlawful access thereto, including replication, transmission, distribution, exchange, transfer, communication, or Processing in such a manner leading to the disclosure or divulgence to third parties, or otherwise the destruction or modification of such data while being stored, transferred and processed.
Data Controller(s) Means a person or organisation who (alone or with others) determines the purposes and the way any Personal Data are or are to be processed.
Data Processor Means a person or organisation that holds or processes Personal Data on the instructions of the Data Controller, but does not exercise responsibility for, or control over the Personal Data.
Data Protection Officer (DPO) Means any natural or legal person appointed by the Controller or the Processor who undertakes responsibilities to verify that the entity he belongs to complies with the Personal Data Protection controls, requirements, procedures, and rules provided for herein, and to verify the integrity of its systems and procedures to achieve the compliance with the provisions hereof.
Data Protection Regulator Means any governmental or regulatory body or authority with responsibility for monitoring or enforcing Applicable Law(s).
Data Rights Request Means specific rights that individuals may exercise depending on the jurisdiction they are based in and the maturity of their local data protection laws. Such legislation bestows on individuals several rights that they may exercise.
Data Subject(s) Means the individual to whom the Personal Data relates to.
Data Subject Right(s) Means the set of rights afforded to individuals, as per Applicable Data Protection Law(s), who request information about the Personal Data collected or stored by ENBD AM and to exert choice or control over how that data is used by ENBD AM in accordance with Applicable Data Protection Law(s).
Data Transfer(s) Means the transfer of data from one jurisdiction to another.
Destruction of Personal Data Means Personal Data no longer exists.
DFSA The Dubai Financial Services Authority.
DIFCA The DIFC Authority established under Dubai law.
DIFC The Dubai International Financial Centre.
DIFCA board of directors The governing body of the DIFCA established under Dubai Law No. 9 of 2004 (as repealed and substituted by Dubai Law No. (5) of 2021).
DIFC body

Includes the Commissioner, DIFCA, DFSA, DIFC Courts, and any other person, body, office, registry or tribunal established under DIFC Laws or established upon approval of the President that is not revoked by this Law or any other DIFC Law.

“DIFC Bodies” shall have a corresponding meaning.

DIFC Data Protection Law Means the DIFC data protection law no. 5 of 2020 applicable in the jurisdiction of DIFC to provide standards and controls for the processing and free movement of personal data.
ENBD AM Means Emirates NBD Asset Management Limited
Encryption Means the process of encoding information stored on a device and can add a further layer of security. It is considered an essential security measure where Personal Data is stored on a portable device or transmitted over a public network.
International organization An organization and its subordinate bodies governed by public international law, or any other body that is set up by, or on the basis of, an agreement between two (2) or more countries.
Joint controllers Any Controller that jointly determines the purposes and means of Processing with another Controller.
Know Your Customer or KYC Means mandatory requirements to ensure updated information about ENBD AM’s Customers, to perform identity verification and prevention of illegal transactions through the business relationship with ENBD AM such as money-laundering, identity theft.
Loss of Personal Data Means that the Controller has lost control or access to the Personal Data.
Personal Data Means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as an identification number or to one or more factors specific to their biological, physical, biometric, physiological, mental, economic, cultural or social identity.
Processing Means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, such as collection, recording, organisation, structuring, storage, adaptation or alteration retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Processor(s) Means an establishment or a natural person who processes Personal Data on behalf of the Controller and under his supervision and instructions.
Profiling Means a form of Automated Processing consisting of the use of Personal Data to evaluate certain personal aspects relating to the Data Subject.
Pseudonymisation Means the processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the Personal Data are not attributed to an identified or identifiable natural person.
SCA Securities and Commodities Authority
Special Category Personal Data (Sensitive Personal Data). Personal Data revealing or concerning (directly or indirectly) racial or ethnic origin, communal origin, political affiliations, or opinions, religious or philosophical beliefs, criminal record, trade-union membership and health or sex life and including genetic data and biometric data where it is used for the purpose of uniquely identifying a natural person.
Staff Means full time employees and contractors of ENBD AM.
Sub processor A processor appointed by the Processor
Subject Access Request Means a request to receive a copy of one's data from an organisation in an accessible, readily available, and legible format. Such requests are limited to information that is specific and limited to that one individual.
UAE Data Protection Law Means Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data issued by the Cabinet of United Arab Emirates.
Means Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data issued by the Cabinet of United Arab Emirates. Means the United Arab Emirates.

Thank you for your feedback!

How was your experience?

We'd love to know.

1 = Poor, 10 = Excellent