1) INTRODUCTION
Your privacy is important to us.
This Privacy and Data Protection Statement explains how Pride Bank Limited (“Pride Bank”, “the Bank”, “we”,
“us”, or “our”) collects, processes, stores, protects and shares personal data.
As a licensed financial institution regulated by the Bank of Uganda (BoU), Pride Bank is committed to
processing personal data lawfully, fairly, transparently and securely in accordance with:
This Statement applies to:
This Statement should be read together with our account terms and conditions and product-specific
agreements. Where there is any conflict relating to personal data protection, this Statement shall prevail.
2) DEFINITIONS
“Personal Data” means any information relating to an identified or identifiable natural person as defined
under the Data Protection and Privacy Act, 2019.
“Processing” includes collection, recording, organization, storage, use, disclosure, transmission, erasure or
destruction of personal data.
“You” means any individual whose personal data is processed by Pride Bank.
3) SCOPE AND APPLICATION
This Statement applies to all personal data processed by Pride Bank in the course of its banking and related
operations, whether such processing occurs at our branches, through digital platforms, via third-party service
providers, or through other lawful channels.
It covers personal data processed in connection with:
4) COLLECTION OF PERSONAL DATA
A. We collect personal data when you:
B. We may also collect personal data from:
We collect only personal data that is necessary and proportionate for legitimate purposes.
5) CATEGORIES OF PERSONAL DATA PROCESSED
We may collect and process the following categories:
A. Identity Information
B. Contact Information
C. Financial Information
D. Transaction and Usage Data
E. CCTV and Premises Data
F. Special Categories of Data (Where Applicable)
Special categories of data are processed strictly in accordance with Ugandan law.
6) PURPOSES FOR PROCESSING PERSONAL DATA
Pride Bank processes personal data for legitimate and lawful purposes, including:
7) LAWFUL BASIS FOR PROCESSING
The Bank processes personal data on one or more of the following lawful bases:
8) DISCLOSURE OF PERSONAL DATA
We may disclose personal data to:
All disclosures are made in accordance with Ugandan law. We will obtain your consent before sharing personal
data for direct marketing by third parties.
THIRD PARTIES
We ask third-party service providers to agree to our privacy policies if they need access to any Personal
Information to carry out their services.
We will not disclose your personal information to external organizations that are not our service providers,
unless you gave us your consent, or unless we may do so by law, or if it is necessary for the conclusion or
performance of our agreement with you.
9) INTERNATIONAL DATA TRANSFERS
Where personal data is transferred outside Uganda (e.g., cloud service providers), we ensure appropriate
safeguards are implemented in accordance with the Data Protection and Privacy Act, 2019, including:
10) DATA RETENTION
We retain personal data:
Anonymized data may be retained indefinitely for statistical and research purposes.
11) SECURITY AND SAFEGUARDS
We implement appropriate technical and organizational safeguards including:
Employees and service providers are subject to strict confidentiality and data protection obligations.
12) COOKIES, WEBSITE TECHNOLOGY AND SOCIAL MEDIA
13) MONITORING AND RECORDING
We may monitor and record:
This is done for compliance, training, fraud prevention and security purposes.
14) MARKETING COMMUNICATIONS
Where you have provided consent, we may use your personal data to inform you about products, services, and
offers from Pride Bank or selected partners via email, SMS, mobile applications, or social media. You may optin to receive such marketing communications and may opt-out at any time without affecting mandatory servicerelated communications.
You can opt-out through:
Opting out does not affect mandatory service-related communications. Marketing communications may also
be used for compliance, training, fraud prevention, security, and risk management purposes.
15) MINORS
We do not knowingly process personal data of persons under 18 years without consent of a parent or legal
guardian, except where permitted by law.
16) RIGHTS OF DATA SUBJECTS
Subject to legal limitations, you have the right to:
Requests may be submitted to the Data Protection Officer and may require identity verification.
17) DATA BREACH MANAGEMENT
In the event of a personal data breach likely to result in risk to individuals’ rights and freedoms, we shall:
18) GOVERNANCE AND ACCOUNTABILITY
The Board of Directors retains oversight of data protection governance. Senior Management is responsible for
implementing systems, controls, and policies to ensure compliance.
The Data Protection Officer (DPO) provides advisory oversight, monitors compliance, liaises with regulators,
and handles data subject requests and complaints.
This Statement may be reviewed and updated periodically. The latest version will be published on our website
and supersede previous versions. Nothing in this Statement limits statutory rights of data subjects under
applicable law.
19) AMENDMENTS
This Privacy and Data Protection Statement may be amended from time to time to reflect changes in law,
regulatory requirements or operational practices. The most current version shall be published on the Bank’s
website and shall take effect upon publication.
20) QUERIES AND COMPLAINTS
If you have any queries or complaints about privacy, please contact the Data Protection Officer/Head Risk
Management.
Mr. Edward Mutyaba
Head Risk Management
Bukoto, Victoria Office Park, Plot 6 – 9 Okot Close, Block B
P.O BOX 7566, Kampala Uganda
TEL: +256-200505230