• 1. Who we are

    Absa Bank Tanzania Limited, a subsidiary of Absa Group Limited (“Absa Group”) has its head office at Absa House, Ohio Street, Dar es Salaam, Tanzania. (“Absa, we, us or our”).

    Absa Group is a prominent, diversified financial services group and one of Africa’s largest financial institutions. Headquartered in Johannesburg, South Africa, and listed on the Johannesburg Stock Exchange, Absa operates in 15 countries across the African continent, with international offices in London and New York. 

    Absa is committed to protecting your personal data and ensuring that your personal information is handled in accordance with the Personal Data Protection Act, 2022 and Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023. This Privacy Notice explains how we collect, use, disclose and protect your personal data. We shall treat all your personal information carefully and responsibly. We are committed to ensuring the highest level of security for your personal information. This Privacy Notice applies to any individual located within or outside the United Republic of Tanzania who enquire about, purchase or make use of our products and services provided by the Bank.

  • 2. When does the Privacy Notice apply?

    This Privacy Notice applies when you:

    • Sign up for a new product or service with us.
    • Use our websites (www.absa.co.tz), our Banking App or other digital service platforms
    • Visit our offices, visit one of our branches or interact with us through any of our service channels
    • Engage with us as a prospective employee, an employee, a contract worker, a supplier or a third party.
  • 3. When does the Privacy Notice NOT apply?

    This Privacy Notice does not apply to the data protection practices of third parties with which we may engage to provide products or services, including their websites or mobile apps. If a third party uses your personal information for its own purposes, it is solely responsible for complying with applicable data protection laws.

    When you leave our website or digital platforms and access a third-party site, please be aware that you are subject to that third party’s terms, conditions and privacy policies. We do not review or endorse the content, privacy practices or policies of any external sites, and we are not responsible for how they handle your personal information.

  • 4. Data protection principles

    We collect and process personal information to comply with a legal duty or mandate imposed on us under Tanzanian laws. Collection and processing of personal data is necessary for the legitimate interests pursued by us provided they do not override your fundamental rights and freedom as data subjects. We are obliged to collect data that is adequate, relevant and strictly limited to explicit, legitimate purpose. In addition, the core principles of data protection include the following:

    • Lawfulness, fairness, and transparency: Processing of your personal data should be lawful and fair. It should be transparent to individuals that personal data concerning them are collected, used, consulted, or otherwise processed and to what extent the personal data is or will be processed. The principle of transparency requires that any information and communication relating to the processing of those personal data be easily accessible and easy to understand, and that clear and plain language be used.
    • Purpose Limitation: Personal data should only be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. In particular, the specific purposes for which personal data are processed should be explicit and legitimate and determined at the time of the collection of the personal data.
    • Data Minimisation: Processing of personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. Personal data should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. This requires, in particular, ensuring that the period for which the personal data are stored is limited to a strict minimum.
    • Accuracy: Controllers must ensure that personal data are accurate and, where necessary, kept up to date; taking every reasonable step to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay. In particular, controllers should accurately record information they collect or receive and the source of that information.
    • Storage Limitation: Personal data should only be kept in a form which permits identification of data subjects for as long as is necessary for the purposes for which the personal data are processed. In order to ensure that the personal data is not kept longer than necessary, time limits should be established by the controller for erasure or for a periodic review.
    • Integrity and Confidentiality: Personal data should be processed in a manner that ensures appropriate security and confidentiality of the personal data, including protection against unauthorised or unlawful access to or use of personal data and the equipment used for the processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures.
    • Accountability: Finally, the controller is responsible for, and must be able to demonstrate, their compliance with all of the above-named Principles of Data Protection. Controllers must take responsibility for their processing of personal data and how they comply with applicable law.
  • 5. Legal basis for processing personal data

    • Consent: You have given clear consent for us to process your personal data for a specific purpose.
    • Contract: The processing is necessary for the performance or conclusion of a contract to which you are a party.
    • Legal obligation: The processing is necessary as it complies with an obligation imposed by law.
    • Legitimate Interest: Processing protects your legitimate interests.
    • Public law: The processing is necessary to perform a public law duty by a public body.
    • Legitimate interests: The processing is necessary for pursuing the legitimate interests of the responsible party or the legitimate interests of a third party to whom the information is supplied.
  • 6. What is personal information and what do we collect?

    Personal information includes but is not limited to any information that lets us uniquely identify you, such as your name and surname combined with your physical address, contact details, photograph or image, biometric information and any unique identifiers.

    Under applicable laws in the United Republic of Tanzania, including the Personal Data Protection Act, 2022, personal information also refers to the personal information that uniquely identifies a juristic person or legal entity as a data subject, such as the trading name of a company combined with the company registration number.

    Special personal information, or sensitive data, includes information about your race or ethnic origin, religious and philosophical beliefs, political persuasion, trade union membership, health or sex life, biometric information (for example, your voice or fingerprints) and any criminal behaviour that relates to alleged criminal offences or proceedings. Also, gender, religious, philosophical and conscience beliefs, political persuasion, property details, marital status, family details including details of children, parents, spouse or spouses, health status, genetic, biometric information, sex or sexual orientation or any criminal behaviour which relates to alleged criminal offences or proceedings.

    Any information that does not identify you, such as anonymised or deidentified data, is not covered by this Privacy Notice. 

  • 7. How do we use your personal information and what is the lawful basis for doing so?

    We always need a lawful basis for using your personal information. The broad lawful basis for processing your personal information is:

    Customers and prospective customers

    • Where you, either in your own capacity or acting under a legal mandate for a juristic entity or child, consent to our processing of your information.
    • Where we provide a service or product to you, and your personal information is required to be processed for the effective functioning of the product or service (such as the facilitation of payments).
    • Where we need to meet our lawful obligations, such as anti-money laundering and fraud detection or tax reporting.
    • Where you, Absa or a third party has an evidenced legitimate interest in processing the information (such as where we use analytics to assess the viability of a product offering and understand our customers’ needs). In these cases, we carefully balance the legitimate interest against the importance of respecting your privacy to ensure that there is no negative effect on you.
    • Where we design, manage, price and provide you with the products or services in which you may have expressed an interest or for which you have applied (including value-added services), and then communicate with you and keep you informed about these products or services.
    • Assessing whether you qualify for credit or for an increase or decrease of your credit limit and conducting credit scoring.
    • Delivering your credit or debit card to you at your chosen address, where you have applied for a credit or debit card.
    • Meeting your financial services needs by providing you with customised offers, experiences and communications.
    • Providing discretionary and administrative financial services.
    • Responding to any correspondence with us, including via email or by telephone.
    • Identifying you and verifying your physical address, source of funds, income and similar information.
    • Assessing your personal financial circumstances and needs before providing advice, products or services to you. In this regard, we may collect your personal information from you in your capacity as our prospective customer.
    • Minimising risk and identifying or investigating fraud or other related activities.
    • Any purpose related to the prevention of financial crime, including fraud detection and prevention, sanctions screening, adverse media screening, monitoring of anti-money laundering and any financing of terrorist activities.
    • Managing our business and identifying potential trends in the market, to ensure that our products are future fit.
    • Enforcing our obligations and any contract we have concluded with you, including without limitation the collection of amounts outstanding from you and your provision of security for banking facilities. Enforcement actions may include tracing you through the use of a tracing agent or instituting legal proceedings against you.
    • Further processing for historical, statistical or research purposes where the outcomes will not be published in an identifiable format.
    • Conducting analytics to better understand you as our customer so that we can tailor our product or service offerings to you, where relevant and applicable.
    • Improving our service to you and your experience with us.
    • Providing income tax-related information to tax authorities.
    • For purposes relating to the sale or transfer of any of our businesses, legal entities or assets as part of corporate transactions.
    • Conducting surveys to gauge customers’ satisfaction or to improve our product and service offering.
    • Contacting you for marketing purposes regarding products and services, competitions and other promotional products, rewards or value-added services, which we or any of our partners offer, unless you have opted out from, objected to or, where required, not consented to receiving marketing material from us.
    • For such other purposes to which you may consent from time to time.
    • For purposes of monitoring the use of our electronic systems and platforms by customers.
    • Complying with internal and external auditing and reporting requirements, as well as related information requests from regulatory bodies.
    • Processing payment instructions (such as debit orders) and instructions received via payment devices (such as debit cards).
    • Complying with the requirements of specific local or foreign laws by which we are governed (including codes of conduct, industry agreements and any joint standards, directives, guidelines and rules issued by regulatory bodies from time to time) or complying with any regulations, directives, judgments or court orders, government sanctions or embargoes, reporting requirements under financial transactions legislation, and demands of any supervising authority, regulator, tribunal, enforcement agency or exchange body.    

    Employees and prospective employees

    Where you are an employee of Absa, we collect your personal information to comply with applicable employment laws. Continuous monitoring of employee conduct is essential for ensuring that we uphold our ethical and legal obligations as a responsible corporate citizen.

    Where you have applied for employment at Absa, we perform applicant screening and background checks, and such screening may include social media screening and screening relating to any information about you obtained from publicly available sources such as search engine results.

    Where you are a student, graduate or employment seeker, we will process your personal information only for socioeconomic development purposes, to assist you with job placements through Absa’s designated youth employment agencies, for entrepreneurial upliftment purposes, for skills development and to comply with our applicable legal obligations.

    Where you are an Absa employee (including contractors), we create an employment record of you on our system to facilitate continuous monitoring during your employment with us.

    As part of our responsibilities in the financial services sector, we may need to report certain employee conduct to relevant authorities or industry databases. This could include cases of dishonesty, misconduct or regulatory breaches. These reports help maintain the industry’s integrity and allow other organisations to check suitability before hiring. Where applicable, such reporting will be carried out in accordance with relevant laws, regulations and guidance, and you will be informed, where required.

    Where you are an Absa director, we create a record of you as a director on our internal systems and update your personal information on government databases (such as the Companies Registry and regulators) as required.

    Where you have been identified as a next of kin by an employee or customer, we create a record of you on our system.

    Third parties

    Where you are a supplier or third party to Absa, we process your personal information for due diligence, risk assessment, administrative and payment purposes. Your responsibilities as a third-party provider to Absa are outlined in our contract and in the Absa Third-party Control Obligations (available on our external website).

    In all circumstances, we will not process your special personal information unless:

    • You have consented to our processing thereof (in circumstances where we are legally obliged to obtain your consent); or
    • It is necessary to exercise or defend a right or obligation in law; or
    • It is necessary to comply with an international legal obligation of public interest; or
    • It is for certain historical, research or statistical purposes that would not adversely affect your privacy; or
    • You have deliberately made your personal information public.
  • 8. Where do we collect your personal information?

    Personal information may be given to or collected by us in writing as part of a written application form or electronically (including email, messaging applications or other digital service platforms).

    In most cases, personal information will be collected directly from you, but there may be other instances when we will collect personal information from other sources where such information is available. These may include public records, places where you may already have made your personal information public (for example, on social media where your settings on such social media are set to “public”) or third parties such as credit bureaus, regulatory bodies or enforcement agencies, and other mandated representatives where you are a corporate entity. We will only collect your personal information from other sources where we are legally entitled or obliged to do so.

    Where you share your information on social media pages or electronic communication channels (such as Facebook, WhatsApp or Instagram), and you have already provided your consent through these channels, we can use the information collected through these social media pages to garner customer insights and help us to offer you relevant marketing offers. Through these customer insights, we are able to learn more about our customers’ preferences and improve product development and customer support.

    If you provide personal information about another person, you warrant that you have that person’s express permission to give us their personal information to process for the specified purpose for which you are sharing such personal information with us. 

  • 9. What happens if you do not provide us with your personal information?

    There are some personal information fields that you must fill in or provide for us to provide you with your chosen product or service, to fulfil a legal obligation or to perform an obligation in terms of an agreement with you.

    Such mandatory information or fields will be indicated to you, for example, by an asterisk on the respective forms or electronic channels. If we do not receive the necessary personal information, we will be unable to continue with your application, to perform our obligations under applicable law or any relevant contract we have or are attempting to enter with you, or to provide the chosen product or service. In such cases, we may have to decline to provide you with the product or services and you will be notified accordingly. If you are already a customer, employee or third party of Absa and we ask you for this information and you do not provide it, we may have to suspend the provision of the product or service for a period of time or, as the case may be, even terminate our relationship with you.

    Any information you provide must be accurate and complete and you must notify us of any changes to your personal information.

  • 10. Do we share (disclose) your personal information?

    For the purposes outlined in this Privacy Notice, we will, in most instances, collect and process your personal information internally. However, there are times when we need to outsource these functions to trusted third parties, including parties in other countries.

    We may also need to share your personal information with external organisations, such as our divisions or third parties involved in providing the products or services to you, fraud detection services, credit bureaus, professional advisers (including auditors, attorneys and external professional consultants), tax authorities or other regulatory or industry bodies, other banks or financial institutions, and courts of law or tribunals, so that we can meet our due diligence or regulatory requirements or provide the products or services to you.

    We may share your information for analytics, research and product development purposes, to ensure product suitability and to enable us to better understand customers’ needs, improve our offerings and enhance your experience. Third parties may assist us to provide telephone support, assist in facilitating our IT or marketing products or services, or provide data storage.

    We may need to share your personal information with our business partners or counterparties, where we are involved in corporate transactions relating to the sale or transfer of any of our businesses, legal entities or assets, or with any party to whom we assign our rights under any of our agreements for particular products and services.

    We will enter into written agreements with all third parties to ensure that they process any personal information in accordance with applicable laws and Absa standards. Where personal information is transferred to a foreign jurisdiction, including for processing and storage by third parties, we will ensure that there are adequate levels of data protection.

    When Absa (including any entity within the Absa Group) transfers your personal information to other Absa Group entities located outside South Africa, such transfers will be governed by our internal data sharing agreements and policies, which ensure an adequate level of protection in accordance with applicable laws.

    Consent will not be required for intra-group transfers where such transfers are necessary for the performance of a contract, compliance with legal obligations or legitimate business interests, and appropriate safeguards are in place.

    Where personal information is transferred to external third parties in a foreign jurisdiction, we will put in place appropriate safeguards and adhere to any applicable laws. 

  • 11. What are your rights when an automated decision is made about you?

    There may be instances where we will process your personal information through a secure automated tool (without any human intervention used in the decision-making process) or perform profiling and make decisions based on such profiling, which may affect you significantly (for example, the automatic non-approval of a personal loan for which you may have applied through any of our online channels, or the automatic non-approval of an application for employment or engagement as a supplier).

     

    If you are unhappy about the outcome of such a decision or would like further information on how such outcome was reached, please contact:

    • Your local Customer Service centre (for customers);
    • Your resourcing consultant (for job applicants);
    • The people partner for your business (for employees);
    • Your supplier relationship manager (for suppliers); or
    • Absa’s Company Secretary (for directors of Absa-owned companies).
  • 12. How do we process personal information relating to children?

    • We are committed to protecting the privacy of children and complying with all applicable data protection laws regarding the collection and processing of children’s personal information. We take additional steps to safeguard children’s data, including providing clear notice to parents or guardians and ensuring that where required by law, we obtain consent from a parent or guardian before collecting, using or sharing a child’s personal information.
    • Where permitted by applicable law, including but not limited to the Age of Majority Act, Cap 43 (as amended), we may process personal information of a child 18 or older without consent from a competent person for the specific purpose of opening and managing the child’s bank accounts, including to make deposits.
  • 13. What rights do you have?

    Privacy matters to us, and we want you to be familiar with your rights under the legislation and to know how you can exercise them in your interactions with the bank. You have the right to:

    • To be informed: With this Privacy notice, we inform you about what we do with your personal data.
    • Access your personal data: you have the right to check whether we hold personal data about you, and you can ask us for a copy of such data and information on how we have used it.
    • Correct your personal data: if your personal details have changed, or you believe we have incorrect or out-of-date information about you can ask us to update it.
    • Request deletion of your personal data - you can ask us to delete your personal data. However, we may need certain personal details to provide our products and services to you.
    • Restrict or object to processing - you can ask us to stop using your data or change how we use it. However, we may need certain personal details to engage with you or provide our products and services to you.
    • Object to automated decision making - you have the right to reject or request for a review of a decision made solely based on an automated process if it negatively impacts you.
    • Data portability: you can ask us to provide your personal data to another organisation in a format that can easily be read by machines.
    • Complaint: you can log your complaints in relation to our processing of your personal data through the contact details below. and, if your complaints have not been handled to your satisfaction, you can contact the Personal Data Protection Commission (PDPC).
    • Not to provide consent or to change or to withdraw consent provided: we may from time to time ask for your consent to process your personal data. You can choose not to provide such consent or let us know at any time if you change your mind about the consent already provided. However, we may not be able to provide our products and services or engage with you without certain personal data.
    • Withdraw from direct marketing: you can withdraw your consent and tell us to stop sending you direct marketing at any time.
    • We will respond to requests to exercise your personal data rights in line with applicable laws. We will ask you to verify your identity before processing your request.
  • 14. How is your information used for direct marketing?

    • If you are a customer of Absa, we would like to keep you informed of updates to our products or services, competitions and other promotional products, rewards or value-added services that we or any of our partners offer, which we think may benefit your lifestyle.
    • To do this, we may contact you via SMS, email, telephone or post.
    • If you do not want to receive direct marketing communication from us, you can immediately update your preferences to opt out by contacting our contact centre or a service representative at any of our branches or by contacting us on the contact details that appear in paragraph below, all at no cost to you.
    • If you are not a customer, we may contact you to provide information about our products and services, but only if you have shared your contact details for that purpose. You can opt out of receiving these marketing messages at any time by notifying the Absa representative who contacts you, or by making a request in writing.
    • We will adhere to your communication channel preferences whenever we can, but we may need to send you important communications via a channel that is not your preference. We will only do so in cases where we deem the information to be important and relevant for you.
  • 15. Retaining and deleting personal information

    • We will not retain any personal information for longer than is necessary to achieve the purpose of such collection.
    • We will retain your personal information for as long as it is legally required and where we have a defined purpose to retain it. Thereafter we will destroy it, deidentify it or anonymise it.
  • 16. How do we secure and protect your personal information?

    • The security of your personal data matters to us, and we take reasonable steps to keep your personal data safe and to prevent loss, destruction of and damage or unlawful access to your personal data by unauthorised parties. We take appropriate and reasonable technical and organisational steps to protect your personal data in line with industry’s best practices. Absa’s security measures include physical, technological and procedural safeguards.  We will take appropriate technical and organisational precautions through a multi-layered defence strategy to secure your personal information and to prevent the loss, misuse, unauthorised access, disclosure or alteration of your personal information.
    • We will store all your personal information on secure servers, in cloud technology and in secure manual record-keeping systems, in accordance with internationally accepted banking information security practices.
      •  We use a range of physical, electronic and other security measures to protect the security, confidentiality, integrity and availability of the personal information that we hold. For example:
      • Access to our information systems is controlled through identity and access management and through logging and monitoring controls.
      • Our employees and our contracted service providers are bound by internal information security policies and standards and are required to keep information secure.
      • Our employees are required to complete annual training about privacy and information security.
      • We regularly monitor and review our compliance with internal policies and industry best practices and standards.
      • It is your responsibility to ensure that your password is complex, that it is not susceptible to being guessed (whether by a person or by a computer program) and that you do not use the same banking password on other sites. You are responsible for keeping the password that you use for accessing our website confidential. We will not ask you for your password or PIN (except when you log in to our digital channels or are performing a transaction).
  • 17. Your data protection rights

    To the extent that local legislation permits, you have the following rights regarding your personal information:

    • The right to request us to confirm whether any personal information is held about you and to access your personal information that we have on record.
    • The right to ask us to correct or delete any of your personal information (if applicable in your jurisdiction) that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully.
    • You can ask us to delete or destroy your personal information that we are no longer authorised to retain. Our records are subject to regulatory retention periods, which means that we may not be able to delete or destroy your personal information immediately on request.
    • You can also object on reasonable grounds to our processing of your personal information. However, the result of such a request may be that we have to suspend the provision of products and/or services for a period of time or even terminate our relationship with you.
    • The right to withdraw consent at any time, where you have previously consented to the processing of your personal information, by providing us with notice to that effect.
    • The right to be notified that your personal information is being collected and processed by us. This Privacy Notice seeks to give effect to this right.
    • The right to be notified in any situation where we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person (e.g. data breach or security compromise).
    • The right not to be subject to a decision based solely on the automated processing of your personal information that is intended to provide a profile about you, where we have not complied with the requirements under applicable law and/or our commitments in paragraph 11 above.
    • If you have a complaint relating to the protection of your personal information, including the way in which it has been collected or processed by us, please contact us using the local contact details listed in paragraph below.
    • If you have not had your complaint dealt with satisfactorily in accordance with our internal dispute resolution process, you may lodge a complaint directly with Personal Data Protection Commission (PDPC). 
  • 18. Right to change this Privacy Notice

    • We reserve the right to change this Privacy Notice at any time. All changes to this Privacy Notice will be posted on our website.
    • Unless otherwise stated, the current version will supersede and replace all previous versions of this Privacy Notice.
  • 19. Cookies Statement

    In order to meet customer expectations and improve the services offered on our website, we employ the use of cookies. By accessing Absa’s website, you agreed to use cookies in agreement with our Cookies policy available on the bank’s website. 

  • 20. Third Party Links

    Please note our website may, from time to time, contain links to and from the websites of our partners or affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we have no control over how they may use your personal information. You should check the privacy policies of third-party websites before you submit any personal information to them. 

  • 21. Cross-Border Data Transfer

    We will only transfer your personal data to third parties in another country in any one or more of the following circumstances:

    • Where your personal information will be adequately protected under the other country’s laws or an agreement with the third-party recipient
    • Where the transfer is necessary to enter into, or perform, under a contract with you or a contract with a third party that is in your interes
    • Where you have consented to the transfer; and/or;
    • Where it is not reasonably practical to obtain the customer’s consent, but the transfer is in your interest. This transfer will happen within the requirements and safeguards of applicable laws or privacy rules that are binding to Absa. Where possible, the party processing your personal data in another country will agree to apply the same level of protection as available by law in Tanzania, or if the other country’s laws provide better protection, the other country’s laws would be agreed to and applied.
  • 22. Updates to this Notice

    If you have any questions about this Privacy Notice or a complaint regarding the treatment of your personal information, please use the contact link on our website or contact our Data Protection Officer using the details set out below:

    Tanzania: Toll Free 08007500 78 and International Number +255 746 882 000

    Email address: (i) talktous@absa.co.tz (ii) abtzdataprivacy@absa.africa.

    You also have the right to lodge a complaint with the personal data protection commission, if you believe that we have not complied with applicable data protection laws

Need more help?

Call us:
0800750078 (Toll free)
+255 (0)746 882 000 (Network charges apply)

Email us:

talktous@absa.co.tz