Privacy Notice
Last Updated 02 December 2025
Your privacy and the security of your Personal Data is very important to us. At Arab Bank plc UAE, hereinafter referred to as the “Bank”, we ensure that Personal Data you provided to us is always treated as private and confidential, afforded the highest level of security, and is processed in accordance with UAE’s Central Bank’s Consumer Protection Regulation – Circular 8/2020 – Protection of Consumer Data and Assets, hereafter referred to as the “Personal Data Protection Requirements”. This Privacy Notice, hereinafter referred to as “Notice”, aims to provide you with information on how we will use your Personal Data, what steps we will take to ensure it stays private and secure and what Personal Data we collect and process about, you as well as your data privacy rights and how you can exercise them.
How we collect your data
The Bank collects your data through one of the following methods:
- Directly: we obtain Personal Data directly from you in order to receive a service from the Bank or transacting with the Bank, including without limitation, log a complaint, enter a business relationship, or for other purposes depending on the services requested for or agreed upon.
- Indirectly: we may obtain Personal Data about you indirectly from a variety of sources, including: Cookies, device ID's, social media, public sources, and recruitment services to better understand and serve you, satisfy a legal obligation, or in pursuance of another legitimate interest.
How we use your data
We collect your Personal Data for various reasons in relation to our services, products or interacting with us, and for other business purposes, including, but not limited to:
- to provide and manage your account(s) and our relationship with you.
- to give you statements and other information about your account or our relationship.
- to handle enquiries and complaints.
- to provide our services to you.
- to conduct assessment, testing, and analysis for statistical purposes or other analysis for market research purposes.
- to evaluate, develop, and improve our services to you and other customers.
- to protect our business interests and to develop our business strategies.
- to contact you, by post, phone, text, email and other digital methods.
- to collect any debts owing to us.
- to meet our regulatory compliance and reporting obligations in relation to protecting against financial crime.
- to assess any application, you make.
- to monitor, record, and analyze any communications between you and us.
- to share your information with the Central Bank of UAE and other governmental authorities, credit reference agencies, fraud prevention agencies, and overseas regulators and authorities.
- to share your information with our service providers and external auditors as clarified in the section below (Who has access to your personal data and to whom it is disclosed)
- recruitment and vetting agencies for prospective job applicants.
- For purpose of litigation, consultation, legal advices or documentation of transactions.
On what legal grounds do we process your information
We process your Personal Data to comply with a legal obligation, to meet regulatory and public interest obligations, or mandates or for otherwise a legitimate purpose related to our activities as a banking financial institution and in compliance with applicable laws and regulations. In the event our processing is not based on any of these bases, we shall in such case collect your consent on any such processing.
Which Personal Data do we collect and process
The Personal Data we collect includes data provided by you at the start of our relationship or at any time thereafter such as:
- Personal details such as name, date of birth, email, nationality, marital status, and gender and contact information.
- Current residential address and permanent residential address, and proof of address documents.
- Data about your identity including documents, details of ID cards, details of passports.
- Employer, employment status, job title, full name, email, address and telephone number(s) used for work purposes.
- Financial data: income and source of income, source of wealth, average account financial activity, and engagement data.
- Data about your tax status such overseas tax-identification number, FATCA forms, etc.
- Details of transactions done by you or by any of your connected persons including dates, amounts, currencies, and payer and payee details.
- Sound and visual images including CCTV footage.
- Digital identifiers (IP address, email).
- Cookies (please refer to our Cookie Notice).
- Risk rating information, e.g., credit risk rating and data about your ability to manage credit.
- Recruitment information and qualifications for prospective job applicants.
- Due diligence data, e.g., data required to comply with financial crime regulations (anti-money laundering, anti-terrorism financing, etc.) and data we need to fulfil regulatory obligations such as Suspicious Activity Reporting.
- Other people’s data, such as family and household members, emergency contacts, and guardians, which include their signatures, addresses and relationship with you.
- Legal dispute, complaints, and grievance information.
- Agreements, contracts, billing and commissions information.
- Security Information.
- Data about your geographic location, ATMs used, and branches you visit.
How long do we keep your Personal Data
We retain Personal Data to provide our services, stay in contact with you and to comply with applicable laws, regulations, and professional obligations, which we are subject to. This includes regulatory requirements for record retention applicable to banks. For example, customer identification Personal Data such as your ID, personal and work details, need to be retained for 5 years. Sometimes we may need to keep your data for longer. The reasons for this include:
• where we need the data to meet regulatory or legal requirements
• to help detect or prevent fraud and financial crime
• to answer requests from regulators
We will dispose of your Personal Data in a secure manner when we no longer need it for the above justifications. Please refer to Privacy Office at Privacy.Office@Arabbank.com.ae for further details on our records retention practices.
Processing Sensitive Personal Data
Sensitive Personal Data as any data which directly or indirectly reveals a natural person's family, ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, or any data relating to such person's health and physical, psychological, mental, genetic or sexual condition, including information related to the provision of healthcare services to him/her which reveals his/her health status. Biometric data refers to Personal Data resulting from Processing using a specific technology related to the physical, physiological or behavioral characteristics of the individual, which allows the identification or confirmation of the unique identification of the individual, such as facial images or fingerprints. The Bank ensures there is a lawful basis for Processing of Sensitive Personal Data. For example:
- Biometric Data: The Bank shall process your finger vein where you decide to use your finger vein as an authentication method for the Bank such as where you wish to make cash withdrawals from your account or conduct other transactions that require validation. Note that selfie photos are also considered Biometric Data when used to identify or validate the identity of an individual. As such, the Bank processes your selfie photo (Biometric Data) as part of authentication when you use the Bank’s digital apps.
-
- Health Data: we process your health data as part of procedures for granting loans and financial facilities. However, this is conducted following your consent including your consent on the sharing of this data with the insurance company.
Marketing
The Bank may send you marketing messages about our products and services. You have the right to opt-in or out of receiving marketing messages by us at any time. You can also object to your Personal Data being used for marketing purposes by calling the Call Center, sending secure mail via Arabi mobile or visiting our Branch.
How we protect and safeguard your Personal Data
We will take reasonable technical and organizational precautions to prevent the loss, misuse, or alteration of your Personal Data. We aim to ensure that access to your Personal Data is limited only to those who need to access it, and those individuals who have access to the data are required to maintain the confidentiality of such data (for more information please refer to our Security Statement https://www.arabbank.ae/footernavigation/security-statement).
If you are using online services from the Bank, you remain responsible for keeping your user ID and password confidential.
Who has access to your Personal Data and to whom it is disclosed
We keep your Personal Data confidential. However, in order to service your needs to the best of our ability, we may share your Personal Data with other parties bound via contractual agreements to safeguard your data and only process it under our strict instructions. We may also transfer your Personal Data to other Arab Bank Group members and third-party organizations outside of United Arab Emirates when we have a business reason to engage Arab Bank Group members or third-party organizations. Each organization is required to safeguard Personal Data in accordance with our contractual obligations.
In essence, we may share the Personal Data about you and your dealings with us, in alignment with Personal Data Protection Regulatory Requirements, with:
- The Bank’s Head Office in Jordan or members of the Arab Bank Group for legitimate business purposes such as data backup processes.
- Correspondent banks such as, as part of funds transfers, trade services, and other services and products you may request from the Bank.
- Entities involved in cards and digital payments processing.
- Other third party service providers including cloud service providers or instant payment providers for legitimate business purposes and in line with applicable laws and regulations.
- External Auditors which need to conduct audits of the Bank per applicable laws and regulations and may request sample Bank data for validation and testing purposes.
- Regulatory authorities, governmental bodies, financial crime prevention agencies, and tax authorities.
- Courier and postal services as necessary to make deliveries such as for requested Bank cards.
- Printing companies such as cheque printing companies.
- Credit reference organizations.
- Law firms, lawyers, or professional advisors where we need to revert to such legal advisors.
- Real Estate Assets Evaluation firms where needed such as were you mortgage a property for the benefit of the Bank.
- Debt collection agencies where we revert to such agencies to support collection of customer debts owed to the Bank.
- Messaging service providers such as agencies we rely on to deliver email or SMS communication.
- Other parties with which you have agreed to share your information with.
Please refer to Privacy.Office@arabbank.ae for further details and contact details of such third parties as well as their respective Privacy Notices (where applicable).
What are your rights and how you can exercise them
- Right to withdraw consent: you can withdraw your consent that you have previously given to one or more specified purposes to process your Personal Data. This will not affect the lawfulness of any Processing carried out before you withdrew your consent. It could mean we are not able to provide certain products or services to you and we will advise you if this is the case.
- Right to be informed: you have the right to be informed of certain information at the time of information collection, such as details of the Bank, the purpose of Processing, and any other necessary information.
- Right to demand rectification: you have the right to submit an application to rectify your Personal Data, in particular if the data is incorrect, incomplete, or not updated.
- Right of Access to Personal Data: you have a right to request a copy of your Personal Data held by Arab Bank UAE at any time.
Please note that our fulfillment to your requests may be subject to limitations, in certain circumstances, in accordance with the applicable laws and regulations. For example, a request to erase your Personal Data in the custody of the Bank may not apply where we are required to retain this data under regulatory requirements on data retention.
To submit a request to exercise any of these rights, or to submit a complaint, please send an email to Privacy.Office@arabbank.ae
Contact information
Arab Bank - UAE management:
Downtown, EMAAR Square, Building 2, Floor 6.
P. O. Box: 11364 Dubai-UAE
For More Information
Should you have any questions regarding this Notice or want to learn more about our security practices, please read our Security Statement section posted on the website (https://www.arabbank.ae/footernavigation/security-statement), or contact us at: Privacy.Office@arabbank.ae
Arab Bank Supplier Privacy Notice
Arab Bank also maintains a dedicated Supplier Privacy Notice which aims to clarify how we collect, use, store, share, and protect Personal Data of individuals who are officers, directors, contractors, agents, or representatives of our current, prospective, and former Suppliers. Click to view Notice
Changes to this Notice
We reserve the right to update this Notice to reflect changes to our information practices in alignment with the Personal Data Protection Requirements. Any updates will become effective immediately after posting the updated Notice on our website.
Key Definitions:
Personal Data: Any data related to a specific natural person or related to a natural person that can be identified directly or indirectly by linking the data, through the use of identification elements such as his/her name, voice, image, identification number, his/her electronic identifier, his/her geographical location, or by one or more physical, physiological, economic, cultural or social characteristics. It includes Sensitive Personal Data and Biometric Data.
Processing: Any operation or set of operations performed on Personal Data using any electronic means, including processing and other means. This processing includes collecting, storing, recording, organizing, adapting, modifying, circulating, altering, retrieving, exchanging, sharing, using, characterizing, disclosing Personal Data by broadcasting, transmitting, distributing, making available, coordinating, merging, restricting, blocking, erasing or destroying it or creating forms thereof.