5. Who can have access to your data?
We do not share your personal data with third parties without your consent unless we are required to do so by law or we do so at your request.
In order to fulfil our contractual obligations towards you, we share some of your personal data with third parties such as outsourcing providers, correspondent banks, credit card issuers, payment providers, custodians, brokers, exchanges, clearing houses, trade repositories and other credit or financial services institutions. We are also required, in some cases (e.g. as required by law or applicable regulation or in order to safeguard our legitimate interests), to share information with public or regulatory authorities such as FINMA (Switzerland’s independent financial-markets regulator), external auditors, courts, government bodies or other law enforcement agencies, for example.
The Bank can give access to entities that provide services to the Bank to your personal information, such as IT partners, hosting providers, fraud prevention or credit reference agencies, among others. In these cases, inter alia the Bank legally binds them to confidentiality and data protection as well as takes the necessary steps to ensure the service providers meet our data security standards in order to keep your data secure.
To the extent permitted by applicable law or regulation, your personal data may be held or stored on cloud platforms belonging to Swiss third party service providers, subject to contractual obligations of confidentiality and data protection.
Any other legitimate recipient for which you have given us your consent or where required by applicable law or regulation.
In some cases, the recipients of personal data can be located outside Switzerland. If the relevant country has not been determined by the Federal Data Protection and Information Commissioner to provide an adequate level of protection, the Bank requires the data recipients to apply appropriate measures to protect personal data, e.g., by signing a binding legal agreement to comply with the data protection level in Switzerland and by taking organizational and technical measures. Transfers outside Switzerland are only made where the transfer is made to countries that can demonstrate equivalent standards of security and other relevant data processing requirements, except we have obtained your express written consent.