Datenschutz

Datenschutzhinweise

Datenschutzhinweise für Kunden der KEB Hana Bank (D) AG

 1.         Inhalt

Mit diesen Datenschutzhinweisen informieren wir Sie, unsere Kunden, gemäß der Europäischen Datenschutz-Grundverordnung (DSGVO) und des Bundesdatenschutzgesetzes (BDSG) über die Verarbeitung Ihrer personenbezogenen Daten durch uns sowie über die Ihnen zustehenden Rechte. Diese Hinweise werden soweit erforderlich aktualisiert und unter www.kebhana.de/datenschutz veröffentlicht. 

Wenn Sie nicht selbst unser Kunde sind, sondern ein Organ (z.B. Vorstand, Geschäftsführer), Beschäftigter oder wirtschaftlicher Berechtigter unseres Kunden sind, gelten diese Datenschutzhinweise ebenfalls. 

Welche Daten im Einzelnen verarbeitet und in welcher Weise genutzt werden, richtet sich nach den jeweils vereinbarten Dienstleistungen. 

Bitte geben Sie diese Datenschutzhinweise auch an vertretungsberechtigte Personen, Mitarbeiter, wirtschaftlich Berechtigte oder Bevollmächtigte weiter.

2.         Verantwortlicher und Kontakt

Verantwortlicher sind wir, die

KEB Hana Bank (D) AG

Bockenheimer Landstr. 33-35
60325 Frankfurt/Main
Telefon: +49 69 7129-0
info (at) kebhana.de 

Die Kontaktdaten unseres Datenschutzbeauftragten sind: 

thomas.helbing (at) datenschutz-helbing.de 

Diese Datenschutzhinweise gelten auch für unsere rechtlich unselbstständigen Niederlassungen, etwa in Polen. Diese sind Teil der oben genannten Stelle und keine eigenständigen Verantwortlichen im Sinne der DSGVO.

3.         Datenarten

Wir verarbeiten Daten, die wir aus der Geschäftsbeziehung mit Ihnen erhalten. Die Daten erhalten wir direkt von Ihnen oder dem Kunden, z. B. im Rahmen der Kontoeröffnung, Vertragsanbahnung und dem Vertragsschluss. 

Konkret verarbeiten wir insbesondere folgende Datenarten:

3.1.      Stammdaten: Basisangaben zu Ihrer Person,  z. B. Name, Anschrift und Kontaktdaten, Bankverbindung, Beruf, Familienstand, ihre Rolle bzw. Funktion beim Kunden, etwaige Eigenschaft als politisch exponierte Personen (PEP))

3.2.      Legitimationsdaten: Daten, die zu Ihrer Identitätsfeststellung verarbeitet werden (z. B. für die Identifizierung zu erhebende persönliche Angaben sowie Ausweisdaten und eindeutige Kennungen wie Steuernummern oder nationale Identifikationsnummern)

3.3.      Durchführungsdaten: Daten im Zusammenhang mit der Durchführung der Verträge zwischen uns und dem Kunden (z. B. Aufträge) einschließlich Zahlungsverkehrs- und Trade-Finance-Daten (SWIFT/SEPA/TARGET, Akkreditive, Inkassi, Forfaitierung), „Interbank-/Correspondent-Banking-Daten“

3.4.      Steuerdaten: steuerrelevante Daten (z. B. zur Abgeltungsteuer und zu Freistellungsaufträgen, Nichtveranlagungsdaten, Kirchensteuerabzugsmerkmal)

3.5.      Vertragsdaten zu anderen Produkten: Vertragsdaten z.B. zu geschlossenen Kreditverträgen

3.6.      Korrespondenzdaten: Daten aus Korrespondenz mit Ihnen (z. B. Schriftverkehr mit Ihnen)

3.7.      Werbe- und Vertriebsdaten: Daten in Bezug auf Werbung durch uns an Sie (z. B. für Sie potenziell interessante Produkte)

3.8.      Technische Daten (sofern genutzt): Logfiles, Zugriffsprotokolle, IP-Adressen, Gerätekennungen, Sitzungsdaten und sonstige IT-sicherheitsrelevante Informationen. 

4.         Pflicht zur Bereitstellung von Daten

Im Rahmen unserer Geschäftsbeziehung müssen Sie nur diejenigen personenbezogenen Daten bereitstellen, die für die Begründung, Durchführung und Beendigung einer Geschäftsbeziehung mit dem Kunden erforderlich sind oder zu deren Erhebung wir gesetzlich verpflichtet sind. 

Ohne diese Daten werden wir in der Regel den Abschluss des Vertrages oder die Ausführung des Auftrages mangels Durchführbarkeit ablehnen müssen oder einen bestehenden Vertrag nicht mehr durchführen können und ggf. beenden müssen. Insbesondere sind wir nach den geldwäscherechtlichen Vorschriften verpflichtet, Sie vor der Begründung der Geschäftsbeziehung beispielsweise anhand Ihres Personalausweises zu identifizieren und dabei Ihren Namen, Geburtsort, Geburtsdatum, Staatsangehörigkeit sowie Ihre Wohnanschrift zu erheben. Damit wir dieser gesetzlichen Verpflichtung nachkommen können, haben Sie uns nach dem Geldwäschegesetz die notwendigen Informationen und Unterlagen zur Verfügung zu stellen und sich im Laufe der Geschäftsbeziehung ergebende Änderungen unverzüglich anzuzeigen. Sollten Sie uns die notwendigen Informationen und Unterlagen nicht zur Verfügung stellen, dürfen wir die von Ihnen gewünschte Geschäftsbeziehung nicht aufnehmen bzw. fortführen.

5.         Datenquellen

Wir erhalten die Daten direkt von Ihnen oder dem Kunden oder Ihren Vertragspartnern oder Korrespondenzbanken. 

Soweit zulässig können wir Daten auch aus öffentlichen Quellen (z.B. Grundbücher, Handels- und Vereinsregister, Presse, Medien, Internet), von Auskunfteien, Wirtschaftsinformationsdiensten und öffentlichen Stellen (z.B. Einwohnermeldeamt) oder von unserer Muttergesellschaft, der Hana Bank Co., Ltd. (Handelsname KEB Hana Bank), 35 Eulji-ro, Jung-gu, Seoul 04523, Republic of Korea („Muttergesellschaft“) beziehen. 

6.         Zweck der Verarbeitung und Rechtsgrundlage

Wir verarbeiten personenbezogene Daten im Einklang mit den Bestimmungen der DSGVO und des BDSG. Im Nachfolgenden informieren wir Sie darüber, wofür und auf welcher Rechtsgrundlage wir Ihre Daten verarbeiten. 

6.1.      Zur Erfüllung von vertraglichen Pflichten
            (Art. 6 Abs. 1 Buchst. b DSGVO)

Wir verarbeiten Ihre Daten zur Durchführung unserer Verträge mit unseren Kunden oder vorvertraglicher Maßnahmen, d. h. insbesondere zur Kontoführung, Durchführung von Kreditverträgen, Trade-Finance-Abwicklung, Devisengeschäfte und Ausführung Ihrer Aufträge sowie aller mit dem Betrieb und der Verwaltung eines Kredit- und Finanzdienstleistungsinstituts erforderlichen Tätigkeiten. 

Die Zwecke der Datenverarbeitung richten sich im Einzelnen nach dem konkreten Produkt und den Vertragsunterlagen. 

6.2.      Im Rahmen der Interessenabwägung
            (Art. 6 Abs. 1 Buchst. f DSGVO)

Wir verarbeiten Ihre Daten über die eigentliche Erfüllung des Vertrags hinaus außerdem auf Basis einer Interessenabwägung zur Wahrung der berechtigten Interessen von uns oder von Dritten. Dies erfolgt – jeweils im Rahmen des rechtlich Zulässigen – zu folgenden Zwecken:

  • allgemeine Geschäftssteuerung und Weiterentwicklung von Dienstleistungen und Produkten
  • Werbung, Markt- und Meinungsforschung
  • Geltendmachung rechtlicher Ansprüche und Verteidigung bei rechtlichen Streitigkeiten und Sicherung entsprechender Beweismittel
  • Verhinderung und Aufklärung von Straftaten
  • Gewährleistung der IT-Sicherheit und des IT-Betriebs
  • Sicherstellung der wirksamen und effizienten Einhaltung gesetzlicher und regulatorischer Bestimmungen und Nachweis der Einhaltung
  • Erkennung, Bewertung und Steuerung von Risiken
  • Verhinderung, Prävention, Erkennung und Beendigung von Betrug und Missbrauch
  • Erstellung von Analysen, Berichten und Auswertungen zur Entwicklung und Verbesserung unserer Produkte, Leistungen und internen Prozesse und zur Geschäftssteuerung.

 

Die Interessen an der jeweiligen Verarbeitung ergeben sich aus den jeweiligen oben genannten Zwecken und umfassen auch:

  • Verbesserung unserer internen Prozesse, sowie unserer Leistungen und Produkte (z.B. für einen besseren Kundenservice)
  • Steigerung der Effizienz und Wirtschaftlichkeit (z.B. durch Zentralisierung und Vereinheitlichung von Prozessen und Funktionen innerhalb der KEB Hana Gruppe sowie durch den Einsatz moderner IT-Systeme und spezialisierter Dienstleister)
  • Absatzförderung
  • Schutz von Vermögen (z.B. vor Betrug), Eigentum und Gesundheit
  • Sicherstellung der Informations-Sicherheit und des Datenschutzes 

6.3.      Aufgrund Ihrer Einwilligung
            (Art. 6 Abs. 1 Buchst. a DSGVO)

Soweit Sie uns eine Einwilligung zur Verarbeitung von personenbezogenen Daten erteilt haben, ist die jeweilige Einwilligung Rechtsgrundlage für die dort genannte Verarbeitung. Dies betrifft insbesondere Ihre etwaige Einwilligung zum Erhalt von Werbung.

6.4.      Aufgrund gesetzlicher Vorgaben
            (Art. 6 Abs. 1 Buchst. c DSGVO)

Wir unterliegen verschiedenen rechtlichen Verpflichtungen, das heißt gesetzlichen Anforderungen (z. B. Kreditwesengesetz (KWG), Geldwäschegesetz (GWG), Steuergesetze, Außenwirtschaftsrecht, Sanktionsregime, Zahlungsverkehrsregelwerke) sowie aufsichtsrechtlichen Vorgaben (z. B. der Europäischen Zentralbank, Europäischen Bankenaufsicht, Deutschen Bundesbank und Bundesanstalt für Finanzdienstleistungsaufsicht). Zu den Zwecken der Verarbeitung gehören die Identitäts-, Betrugs- und Geldwäscheprävention, die Verhinderung der Finanzierung des Terrorismus, die Erfüllung steuerrechtlicher Kontroll- und Meldepflichten sowie die Bewertung und Steuerung von Risiken.

7.         Art der Verarbeitung, Profiling

Im Rahmen der genannten Verarbeitungen, können wir unter Einhaltung der rechtlichen Vorgaben Daten auch für die Entwicklung, das Training sowie die Anwendung, Verbesserung und Kontrolle von Modellen und Systemen künstlicher Intelligenz verwenden. Mögliche Einsatzfelder sind etwa die Erfassung und Klassifizierung von Daten (z.B. in eingehenden Unterlagen), das Erkennen von Mustern und Zusammenhängen in großen Datenmengen (z.B. zur Betrugsbekämpfung oder bei der Kundenberatung, -betreuung und im Vertrieb) sowie die Unterstützung bei der Prozessautomatisierung (z.B. im Kundenservice). 

Wir können Ihre Daten teilweise automatisiert verarbeiten mit dem Ziel, bestimmte persönliche Aspekte zu bewerten (sog. „Profiling“ gemäß Art. 4 Nr. 4 DSGVO). Wir können Profiling beispielsweise in folgenden Fällen einsetzen: Aufgrund gesetzlicher, regulatorischer und sanktionsrechtlicher Vorgaben im Rahmen der Bekämpfung von Geldwäsche und Terrorismusfinanzierung, der Verhinderung von strafbaren Handlungen, die zu einer Gefährdung unseres Vermögens führen können sowie zur Einhaltung von Sanktionsvorgaben sind wir verpflichtet, Vorkehrungen zu treffen, welche auch Datenauswertungen Ihrer Legitimationsdaten, Durchführungsdaten und Steuerdaten, z.B. in Bezug auf Ihre Transaktionen, umfassen. Diese Maßnahmen dienen zugleich auch Ihrem Schutz. 

8.         Datenempfänger

Eine Weitergabe Ihrer Daten erfolgt nur unter Wahrung des Bankgeheimnisses und nur soweit eine Rechtsgrundlage dies gestattet (insbesondere zur Ausführung Ihrer Aufträge). 

Innerhalb unserer Bank erhalten diejenigen Stellen Ihre Daten, die diese zur Erfüllung unserer vertraglichen und gesetzlichen Pflichten oder zur Erfüllung ihrer jeweiligen Aufgaben benötigen (z. B. Kreditabteilung, Kundenservice, Geldwäschebeauftragter). 

Darüber hinaus können folgende Stellen Ihre Daten erhalten, wenn und soweit hierfür eine Rechtsgrundlage besteht:

  • von uns eingesetzte Auftragsverarbeiter (Art. 28 DSGVO) insbesondere im Bereich IT-Dienstleistungen, die Ihre Daten weisungsgebunden für uns verarbeiten
  • öffentliche Stellen und Institutionen (z. B. Deutsche Bundesbank, Bundesanstalt für Finanzdienstleistungsaufsicht, Europäische Bankenaufsicht, Europäische Zentralbank, Finanzbehörden) bei Vorliegen einer gesetzlichen oder behördlichen Verpflichtung oder anderen Rechtsgrundlage,
  • Andere Kredit-/Finanzinstitute, Korrespondenzbanken, Clearing-/Settlement-Stellen (z. B. im Rahmen von SEPA, TARGET, SWIFT)
  • unsere Muttergesellschaft, die uns z.B. im Wege der Auftragsverarbeitung bestimmte IT-Systeme bereitstellt.
  • externe Anwälte, Datenschutzbeauftragte, Gerichte, Schieds- und Mediationsstellen, Wirtschaftsprüfer und Auditoren,
  • Auskunfteien und Wirtschaftsinformationsdienste (z.B. im Rahmen zulässiger Anfragen durch uns),
  • Wirtschaftsberatungsgesellschaften und Outsourcing-Dienstleister, sowie
  • sonstige Stellen, für die Sie uns Ihre Einwilligung zur Datenübermittlung erteilt haben.

9.         Speicherdauer

Soweit erforderlich, verarbeiten wir Ihre personenbezogenen Daten für die Dauer unserer Geschäftsbeziehung, was auch die Anbahnung und Abwicklung eines Vertrags zwischen uns dem Kunden umfasst. Dabei ist zu beachten, dass unsere Geschäftsbeziehung mit dem Kunden häufig ein Dauerschuldverhältnis ist (Kreditverträge, Kontoführung), welches auf Jahre angelegt ist. 

Ihre Daten werden regelmäßig gelöscht, sobald diese nicht mehr für die Erfüllung vertraglicher oder gesetzlicher Pflichten erforderlich sind oder Sie Ihre Einwilligung in die Verarbeitung widerrufen haben, es sei denn, die Weiterverarbeitung ist aus den folgenden Gründen erforderlich:
Aufbewahrungs- und Dokumentationspflichten, die sich unter anderem aus dem Handelsgesetzbuch (HGB), der Abgabenordnung (AO), dem Kreditwesengesetz (KWG) oder dem Geldwäschegesetz (GwG) ergeben. Die dort vorgegebenen Fristen zur Aufbewahrung bzw. Dokumentation betragen zwei bis zehn Jahre.

Nach den gesetzlichen Verjährungsfristen, die zum Beispiel nach den §§ 195 ff. des Bürgerlichen Gesetzbuchs (BGB) in der Regel drei Jahre, in gewissen Fällen aber auch bis zu dreißig Jahre betragen können.

10.      Drittlandsübermittlung

Wir übermitteln Ihre Daten in Staaten außerhalb des Europäischen Wirtschaftsraums (EWR) (sog. „Drittländer“) nur, soweit dies zur Durchführung unseres Vertrags mit dem Kunden oder der Ausführung Ihrer Aufträge (z. B. Überweisungen) erforderlich oder gesetzlich vorgeschrieben ist, Sie uns Ihre Einwilligung erteilt haben oder im Rahmen einer Auftragsverarbeitung. 

Soweit wir Daten an unsere Muttergesellschaft nach Korea übertragen gilt: Die Europäische Kommission hat mit der Entscheidung (EU) 2022/254 vom 17. Dezember 2021 festgestellt, dass die Republik Korea (Südkorea) nach der DSGVO ein angemessenes Schutzniveau für personenbezogene Daten gewährleistet. 

Sofern wir Daten an Unternehmen in den USA übermitteln, die nach dem EU-US Data Privacy Framework zertifiziert sind, wird hierdurch ein angemessenes Schutzniveau sichergestellt.

In allen anderen Fällen haben wir, sofern nicht anders angegeben, mit dem Datenempfängern im Drittland einen Vertrag gemäß den EU Standarddatenschutzklauseln geschlossen, um ein angemessenes Schutzniveau sicherzustellen. Eine Kopie der verwendeten EU-Standarddatenschutzklauseln können Sie bei uns anfordern. 

11.      Betroffenenrechte

Sie haben unter den jeweiligen gesetzlichen Voraussetzungen in Bezug auf Ihre personenbezogenen Daten das Recht auf

  • Auskunft (Art. 15 DSGVO, § 34 BDSG),
  • Berichtigung (Art. 16 DSGVO),
  • Löschung (Art. 17 DSGVO, § 35 BDSG),
  • Einschränkung der Verarbeitung (Art. 18 DSGVO) sowie
  • Datenübertragbarkeit (Art. 20 DSGVO),
  • Widerruf von Einwilligungen (Art. 7 As. 3 DSGVO)
  • Beschwerderecht bei einer Datenschutzaufsichtsbehörde (Art. 77 DSGVO i.V.m. § 19 BDSG), sowie
  • Folgende Widerspruchsrechte (Art. 21 DSGVO) :

 

Widerspruchsrecht aufgrund besonderer Situation bei Interessenabwägungen
Sie haben das Recht, aus Gründen, die sich aus Ihrer besonderen Situation ergeben, jederzeit gegen die Verarbeitung Sie betreffender personenbezogener Daten, die aufgrund von Art. 6 Abs. 1 Buchst. f DSGVO (Datenverarbeitung auf der Grundlage
einer Interessenabwägung) erfolgt, Widerspruch einzulegen. Dies gilt auch für ein auf diese Bestimmung gestütztes Profiling im Sinne von Art. 4 Nr. 4 DSGVO. 

Legen Sie Widerspruch ein, werden wir Ihre personenbezogenen Daten nicht mehr verarbeiten, es sei denn, wir können zwingende schutzwürdige Gründe für die Verarbeitung nachweisen, die Ihre Interessen, Rechte und Freiheiten überwiegen, oder die Verarbeitung dient der Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen.

 

Widerspruchsrecht gegen eine Verarbeitung von Daten für Zwecke der Direktwerbung
Wir können Ihre Daten im Rahmen der gesetzlichen Bestimmungen auch für Direktwerbung verarbeiten. Sie haben das Recht, jederzeit Widerspruch gegen die Verarbeitung Sie betreffender personenbezogener Daten zum Zwecke derartiger Werbung einzulegen. Dies gilt auch für das Profiling, soweit es mit solcher Direktwerbung in Verbindung steht.

Widersprechen Sie der Verarbeitung für Zwecke der Direktwerbung, so werden wir Ihre personenbezogenen Daten nicht mehr für diese Zwecke verarbeiten.

Der Widerspruch kann jeweils formfrei erfolgen. Unsere Kontaktdaten finden Sie unter Ziffer 1.

 

 

Data Protection Information for Business Partners of KEB Hana Bank (D) AG
Status: 29 May 2026

Introduction

With this data protection information, we inform our current and prospective business partners, including suppliers, service providers, vendors, contractors, consultants, office visitors, correspondent banks and other financial institution counterparties, as well as other business contacts that are not our customers (together the “Business Partners”) in accordance with the European General Data Protection Regulation (GDPR), about the processing of their personal data by us as well as about their rights. These notices will be updated as necessary and published at www.kebhana.de/datenschutz.

This data protection information applies to you if you are a Business Partner yourself or act on behalf of a Business Partner, for example as a board member, managing director, partner, authorized representative, employee, beneficial owner or other contact person of the Business Partner (together “Data Subjects”). If other Data Subjects act on your behalf in connection with our business relationship (for example employees, sub-contractors or agents), please pass on this data protection information to them as appropriate.

Which data are processed in detail and how they are used depends on the nature of the respective business relationship (for example: provision of goods or services to us, performance of a correspondent banking or interbank relationship, or other business contact).

Controller and Contact

The data controller within the meaning of the GDPR is

KEB Hana Bank (D) AG Bockenheimer Landstr. 33–35 60325 Frankfurt am Main Germany Telephone: +49 69 7129-0 Diese E-Mail-Adresse ist vor Spambots geschützt! Zur Anzeige muss JavaScript eingeschaltet sein!

The contact details of our Data Protection Officer are:

Diese E-Mail-Adresse ist vor Spambots geschützt! Zur Anzeige muss JavaScript eingeschaltet sein!

This data protection information also applies to our legally dependent branches, for example our branch in Poland. These are part of the entity mentioned above and are not independent controllers within the meaning of the GDPR.

Categories of Data

We process data that we receive in connection with the business relationship with you or the Business Partner you represent. We collect such data directly from you, from the Business Partner, from other companies, or from third parties (in each case in compliance with data protection law).

Specifically, we process in particular the following categories of data:

  • Contact and master data: name, business address, business telephone and e-mail address, job title, department or function, language, role within the Business Partner.
  • Identification data: data processed for the purpose of identifying you or the Business Partner, for example personal details collected for KYC purposes, identity card or passport data, date and place of birth, nationality, residential address, tax identification numbers, national identification numbers, information on beneficial owners, signature cards and powers of attorney, status as a politically exposed person (PEP).
  • Contract and order data: contractual documentation, orders placed, deliveries received, services provided, performance data, complaints, dispute and warranty information.
  • Payment and banking data: bank account details, IBAN/BIC, correspondent and clearing account information, payment instructions, SWIFT/SEPA/TARGET data, credit/debit card information, tax data required for payment processing, and other data required for invoicing, accounting, settlement and the prevention of fraud.
  • Credit and compliance data: credit rating documentation, financial information of the Business Partner, sanctions and embargo screening results, information on material criminal, regulatory, sanctions-related or insolvency proceedings involving Data Subjects, in each case to the extent relevant e.g. for Know-Your-Customer, Anti-Money-Laundering, sanctions, credit or reputational risk assessment, anti-bribery and counter-terrorist-financing information.
  • Correspondence data: data from correspondence with you, including written communication, e-mails, calls (where logged), records of meetings and visitor data.
  • Marketing and sales data: data relating to products or services that may be of mutual interest, including information on relationship-management activities towards business contacts.
  • Technical data: log files, access logs, IP addresses, device identifiers, session data and other IT-security-related information, in particular where you access our systems, portals or buildings.
  • Visitor data: data collected when you visit our premises, for example for access control, reception logs and the use of our guest Wi-Fi (e.g. first name, last name and business e-mail address provided in the course of voucher-based Wi-Fi access).
  • Other personal data that is necessary for us to perform compliance duties or satisfy legal requirements (for example as part of the KYC process, sanctions and watchlist screening or PEP screening) and that is processed in compliance with data protection provisions.

Obligation to Provide Data

Within our business relationship with the Business Partner, you are only required to provide those personal data that are necessary for the establishment, performance and termination of the business relationship, or which we are legally obliged to collect.

Without these data, we will generally be unable to enter into or to continue the business relationship with the Business Partner, to perform our contractual obligations or to execute orders. In particular, under the provisions of anti-money-laundering law and supervisory law (in particular the German Banking Act (KWG) and the German Anti-Money Laundering Act (GwG)), we are obliged to identify the Business Partner and, where applicable, its representatives and beneficial owners prior to establishing a business relationship, for example on the basis of identity documents, and to collect their name, place and date of birth, nationality and address. To enable us to comply with these legal obligations, you must provide us with the necessary information and documents and promptly notify us of any changes arising during the course of the business relationship. If the required information and documents are not provided, we may not be able to establish or continue the business relationship.

In all other cases, the provision of personal data may be on a voluntary basis.

Sources of Data

We receive the data directly from you, from the Business Partner you represent, or, where permissible, from third parties, for example from the Business Partner’s contractual partners, payment service providers or correspondent banks.

In addition, we may, where permissible, obtain data from public sources (for example commercial and association registers, land registers, press and other media, the internet), from credit agencies and business information services, from sanctions and PEP databases, from public authorities (for example residents’ registration offices) and from our parent company,

Hana Bank Co., Ltd. (trading as KEB Hana Bank), 35 Eulji-ro, Jung-gu, Seoul 04523, Republic of Korea (“Parent Company”),

as well as from other companies of the Hana Financial Group.

Purpose of Processing and Legal Basis

We process personal data in accordance with the provisions of the GDPR and applicable national data protection law. Below, we inform you about the purposes for which and the legal bases on which we process your data.

For the Initiation, Performance and Termination of Contracts (Art. 6 para. 1 lit. b GDPR)

We process the Data Subjects’ personal data to initiate, perform and terminate our contracts with Business Partners, for example to communicate about products and services, to respond to inquiries, to enter into contracts, to fulfil orders, to receive and verify deliveries and services, to verify a Data Subject’s identity, to process payments, for accounting, verification, billing or collection purposes, and to manage the on-going relationship with the Business Partner.

To the extent that the contractual partner is not the Data Subject personally but the Business Partner on whose behalf the Data Subject acts (which is the regular case for representatives, employees and beneficial owners of a corporate Business Partner), the legal basis for the processing is Art. 6 para. 1 lit. f GDPR (balancing of interests, see below).

Within the Scope of the Balancing of Interests (Art. 6 para. 1 lit. f GDPR)

We also process your data beyond the actual performance of the contract on the basis of a balancing of interests to safeguard our legitimate interests or those of third parties. This takes place, each within the limits of what is legally permissible, for the following purposes:

    • general business management and further development of services and products
    • managing relationships with Business Partners, including communication with their representatives, employees and beneficial owners
    • procurement, vendor management and supplier risk management
    • correspondent banking and interbank relationship management, including SWIFT/SEPA/TARGET processing
    • internal reporting, group reporting and consolidated reporting within the Hana Financial Group
    • advertising, market and opinion research, including business-relationship-management activities
    • assertion of legal claims and defence in legal disputes and securing of relevant evidence
    • prevention and investigation of criminal offences
    • ensuring IT security, physical security of our premises, and IT operations
    • ensuring effective and efficient compliance with statutory and regulatory provisions, and demonstrating such compliance
    • identification, assessment and control of risks (including counterparty, credit, operational, compliance and reputational risks)
    • prevention, detection and termination of fraud and abuse
    • preparation and execution of corporate transactions (e.g. M&A, outsourcing arrangements)
    • preparation of analyses, reports and evaluations for the development and improvement of our products, services and internal processes and for business management.

The interests in the respective processing arise from the aforementioned purposes and also include:

  • improvement of our internal processes as well as our services and products
  • increase of efficiency and profitability (for example through centralization and standardization of processes and functions within the KEB Hana Group, including the use of group-wide IT systems and specialized service providers)
  • protection of assets (for example against fraud), property and health
  • ensuring information security and data protection.

To the extent possible and reasonable based on the specific purpose, we process your data in an anonymized or pseudonymized manner.

Based on Your Consent (Art. 6 para. 1 lit. a GDPR)

Where you have given us consent to process personal data, this consent constitutes the legal basis for the processing referred to therein. This applies in particular to your possible consent to receive marketing communications. You may withdraw your consent at any time with effect for the future. This also applies to declarations of consent given to us prior to the GDPR. The withdrawal applies only to future processing of data.

Based on Legal Obligations (Art. 6 para. 1 lit. c GDPR)

We are subject to various legal obligations, that is statutory requirements (for example the German Banking Act (KWG), the German Anti-Money Laundering Act (GwG), tax laws, foreign trade law, sanctions regimes, payment system regulations and commercial law) as well as supervisory requirements (for example of the European Central Bank, the European Banking Authority, the Deutsche Bundesbank and the Federal Financial Supervisory Authority, BaFin). The purposes of processing include identity verification, fraud, money-laundering and terrorist-financing prevention, compliance with tax control and reporting obligations, accounting and book-keeping retention obligations, and the assessment and management of risks.

Sanctions and Watchlist Screening

In order to comply with statutory and regulatory obligations under foreign trade law, EU and international sanctions regimes (in particular EU regulations on restrictive measures), as well as anti-money-laundering and counter-terrorist-financing rules, we screen Business Partners as well as Data Subjects acting on their behalf, including representatives, contact persons, beneficial owners and parties to payment transactions, against applicable sanctions lists, watchlists and PEP (politically exposed persons) lists. This screening is carried out both at the establishment of the business relationship and on an on-going basis during its term, and may also be performed in connection with individual payment transactions. The legal basis is Art. 6 para. 1 lit. c GDPR (compliance with legal obligations) and, where applicable, Art. 6 para. 1 lit. f GDPR (legitimate interests in preventing financial crime and reputational harm).

Nature of Processing, Profiling

Within the scope of the aforementioned processing operations, we may, in compliance with legal requirements, also use data for the development, training, application, improvement and monitoring of artificial intelligence models and systems. Possible areas of application include, for example, the recording and classification of data (for example in incoming documents and invoices), the recognition of patterns and relationships in large data sets (for example for combating fraud, sanctions screening, or in procurement and supplier management), and support for process automation.

We may process your data partly automatically with the aim of evaluating certain personal aspects (so-called “profiling” according to Art. 4 No. 4 GDPR). We may use profiling, for example, in the following cases: Based on statutory, regulatory and sanctions-related requirements in the context of combating money laundering and terrorist financing, prevention of criminal acts that may endanger our assets, and compliance with sanctions requirements, we are obliged to take precautions which also include data analyses of identification data, transaction data and tax data, for example in relation to payments to or from the Business Partner. These measures also serve to protect you.

Data Recipients

Your data will only be disclosed where permitted by applicable law and in compliance with applicable banking secrecy obligations.

Within our bank, those departments receive your data which require them to fulfil our contractual and legal obligations or to perform their respective tasks (for example procurement, accounting, payment operations, credit department, customer service, anti-money-laundering officer, compliance, IT security).

In addition, the following entities may receive your data where and insofar as a legal basis exists:

  • Processors used by us (Art. 28 GDPR), in particular in the area of IT services, printing and logistics, document processing, archiving and destruction, and other support functions, which process your data on our instructions
  • Public authorities and institutions (for example Deutsche Bundesbank, Federal Financial Supervisory Authority, BaFin, European Banking Authority, European Central Bank, tax authorities, customs authorities, law enforcement authorities) where a legal or regulatory obligation or another legal basis exists
  • Other credit/financial institutions, correspondent banks, clearing and settlement institutions (for example within SEPA, TARGET, SWIFT), to the extent necessary for processing payments and other transactions
  • Our Parent Company and other entities of the Hana Financial Group, in particular where they provide IT systems or other support functions to us as processors (for example for IT services, credit assessment, KYC support, refinancing), or for group reporting and consolidated supervision purposes
  • External lawyers, data protection officers, courts, arbitration and mediation bodies, auditors and auditors-in-charge
  • Credit agencies and business information services (for example within the scope of permissible inquiries by us)
  • Consulting firms, outsourcing service providers and other advisors, as well as
  • Other recipients to which you have given us your consent to transfer data, or to which a transfer is required to investigate or prevent illegal activities, fraud or potential threats to the safety of any person.

Retention Period

We process your personal data only as long as necessary for the purpose for which the data were collected, or as long as we are permitted or required to do so under applicable law.

As a rule, we process your personal data for the duration of our business relationship, which also includes the initiation and processing of a contract. Longer retention periods may result from various statutory retention and documentation obligations, among other things from the Commercial Code (HGB), the Fiscal Code (AO), the Banking Act (KWG) or the Anti-Money Laundering Act (GwG). The periods prescribed therein for retention or documentation are typically two to ten years.

In addition, we may store your data for a reasonable period in order to be able to prove compliance with legal obligations and to defend ourselves against claims. According to the statutory limitation periods under §§ 195 et seq. of the German Civil Code (BGB), claims generally become time-barred after three years; in certain cases the limitation period may be up to thirty years.

Transfer to Third Countries

We transfer your data to countries outside the European Economic Area (EEA) (“third countries”) only insofar as this is necessary for the performance of our contract with the Business Partner or the execution of an order, or required by law, or you have given us your consent, or within the scope of processing by a processor.

Insofar as we transfer data to our Parent Company in Korea, for example in the context of IT services, credit assessment, KYC support or refinancing provided to us by the Parent Company, the following applies: The European Commission determined by Decision (EU) 2022/254 of 17 December 2021 that the Republic of Korea (South Korea) ensures an adequate level of protection for personal data in accordance with the GDPR.

If we transfer data to companies in the USA that are certified under the EU–US Data Privacy Framework, this ensures an adequate level of protection.

In all other cases, unless otherwise stated, we have concluded a contract with the data recipients in the third country based on the EU Standard Contractual Clauses to ensure an adequate level of protection. You may request a copy of the EU Standard Contractual Clauses used from us.

Rights of the Data Subject

Under the respective legal conditions, you have the following rights concerning your personal data:

  • right of access (Art. 15 GDPR, § 34 BDSG)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR, § 35 BDSG)
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to withdraw consent (Art. 7 para. 3 GDPR)
  • right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG), and
  • the following rights to object (Art. 21 GDPR):

Right to object due to a particular situation in case of balancing of interests

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6 para. 1 lit. f GDPR (data processing on the basis of a balancing of interests). This also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims.

Right to object to data processing for direct marketing purposes

We may also process your data for direct marketing purposes within the framework of statutory provisions. You have the right to object at any time to the processing of personal data concerning you for such marketing purposes. This also applies to profiling insofar as it is associated with such direct marketing.

If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection may be made in any form. You can find our contact details under the section “Controller and Contact”.

 

 

 

Tags:

Asiens N0.1 Bank

Bank of the Year 2015 - Asia Pacific

Ausgewählt von The Banker, die weltweit führende Autorität unter den Finanzzeitschriften .

2015 Bank des Jahres in Asien-Pazifik

Unser Sitz

Bockenheimer Landstr. 33-35
60325 Frankfurt/Main
+49 (69) 7129-0
+49 (69) 7129-122
info@kebhana.de
Mo-Do | 08:00 - 12:00 & 13:00 - 16:00
Fr | 08:00 - 12:00 & 13:00 - 15:00