OWN BANK PRIVACY POLICY
At Own Bank, The Rural Bank of Cavite City, Inc. ("Own Bank," "the Bank," "we," "our," or "us"), trust is the foundation of every relationship we build, whether with a depositor opening a first savings account, a borrower accessing credit, a business partner integrating with our digital platforms, or an employee who calls the Bank their workplace. Protecting the personal data entrusted to us is not a peripheral compliance exercise; it is central to how we operate as a digital-centric rural bank licensed by the Bangko Sentral ng Pilipinas (BSP).
This Privacy Policy (the "Policy") describes how Own Bank collects, uses, stores, shares, retains, and disposes of personal data in the course of our business. It explains the rights you hold as a data subject under Philippine law, the safeguards we maintain to protect your information, and how you can reach us if you have questions or concerns. We have written this Policy to be read, not merely filed away, and we encourage you to take the time to understand it. This is the full version of our Privacy Policy, published on our website. A shorter notice, provided to you at the point we collect your information (for example, when you open an account or fill out a form), summarizes the essentials for that specific interaction and refers back to this Policy for complete detail; see Section 23 (Layered Notices) below. This Policy is addressed to our customers and other external data subjects; it does not describe our internal data governance controls and procedures, which are set out in a separate internal policy maintained by the Data Protection Officer.
Own Bank processes personal data in accordance with Republic Act No. 10173, or the Data Privacy Act of 2012 ("DPA"), its Implementing Rules and Regulations, the issuances and advisories of the National Privacy Commission ("NPC"), the regulations of the BSP, and other applicable Philippine laws. Where relevant, we also draw on internationally recognized privacy and information security practices, including principles reflected in ISO/IEC 27001 and 27701, the NIST Cybersecurity Framework, and globally accepted data protection standards, to inform how we design our controls. This remains, first and foremost, a Philippine privacy policy grounded in Philippine law; references to international frameworks describe practices we choose to adopt, not additional legal obligations we owe under foreign law.
This Policy may be revised from time to time to reflect changes in law, regulation, technology, or our business operations. Whenever we make a material change, we will publish the updated Policy on our official website and, where appropriate, notify you through our usual communication channels. We encourage you to review this Policy periodically.
This Policy applies to personal data that Own Bank collects, processes, stores, shares, retains, and disposes of in connection with our banking business and digital platforms. It covers our relationships with customers, depositors, borrowers, cardholders, applicants, guarantors, beneficiaries, authorized representatives, merchants, business partners, suppliers, contractors, job applicants, employees, and visitors to our branches, offices, and digital channels, as well as any individual who contacts us, transacts with us, or otherwise interacts with our services. Where we refer to employees, job applicants, suppliers, and contractors below, this Policy describes what we tell them as external data subjects; our internal handling of their data as members of our workforce or vendors is governed by separate internal policies.
The Policy applies regardless of the channel through which we obtain your personal data, whether that is a branch counter, our mobile application, our website, a contact center call, an email, a partner integration, or a public record. It applies to personal data we hold in the Philippines and, where applicable, to personal data processed on our behalf outside the Philippines by our service providers, subject to the safeguards described later in this Policy.
This Policy does not govern the practices of third-party websites, applications, or services that we do not own or control, even where those services are linked from our platforms or where we have a commercial relationship with the provider. We encourage you to read the privacy notices of any third party you deal with, including merchants, payment networks, and social media platforms, before sharing your personal data with them.
To help you understand this Policy, the terms below carry the meanings assigned to them under the Data Privacy Act and its Implementing Rules and Regulations, expressed here in plain language.
Personal Data is a broad term we use in this Policy to refer collectively to personal information, sensitive personal information, and privileged information, as applicable under Philippine law..
Personal Information refers to any information, whether recorded in material form or not, from which the identity of an individual is apparent, or can reasonably and directly be ascertained by the entity holding the information, or when combined with other information would directly and certainly identify an individual. Examples include your name, address, and contact details.
Sensitive Personal Information refers to personal information:
(1) About an individual's race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
(2) About an individual's health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such person, the disposal of such proceedings, or the sentence of any court in such proceedings;
(3) Issued by government agencies peculiar to an individual which includes, but not limited to, social security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; and
(4) Specifically established by an executive order or an act of Congress to be kept classified
Privileged Information refers to information that, under the Rules of Court and other applicable laws, is protected by a recognized privilege, such as communications between a lawyer and client, a physician and patient, or a priest and penitent.
Processing refers to any operation or any set of operations performed upon personal information including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.
Data Subject refers to the individual whose personal data is processed, that is, you.
Consent refers to any freely given, specific, informed indication of will by which you, or your lawful representative, agree to the collection and processing of your personal data. Consent must be evidenced by written, electronic, or recorded means, and you have the right to withdraw it, subject to the limitations explained in this Policy.
Personal Data Breach refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Automated Decision-Making refers a wholly or partially automated processing operation that can make decisions using technological means totally independent of human intervention; automated decision-making often involves profiling.
Profiling refers to any form of automated processing of personal data intended to evaluate certain personal aspects of an individual, such as analyzing or predicting your economic situation, creditworthiness, preferences, or behavior.
We use these defined terms consistently throughout the rest of this Policy. Where we refer generally to "personal data," we mean the combined category of personal information, sensitive personal information, and privileged information described above, unless the context makes clear that we are referring to one category specifically, such as the heightened protections that apply to sensitive personal information.
Own Bank observes the core principles that underpin the Data Privacy Act in everything we do with personal data. We describe how each principle shapes our practice below, rather than simply listing them, because we believe you deserve to understand what these principles mean in practice rather than as abstractions.
Transparency means that we tell you, in language you can understand, what personal data we collect, why we collect it, and what we do with it; this Policy is itself an expression of that principle. Legitimate purpose means we only process personal data for purposes that are not contrary to law, morals, or public policy, and we do not collect information simply because it might be useful someday. Proportionality means the personal data we collect and process is adequate, relevant, and limited to what is necessary for the purposes we have declared; we do not ask for more than we need to serve you or to meet our regulatory obligations.
Fairness requires that we process your personal data in ways that would not surprise you if you understood the full context, and that we do not use your information to your unjust detriment. Accountability means the Bank remains responsible for personal data under our control even when it is processed by a third party on our behalf, and we hold our service providers to standards consistent with our own obligations and we use contractual or other reasonable means to require appropriate privacy and security safeguards from our service providers. Data minimization is closely related to proportionality: wherever possible, we design our systems and forms to collect the least amount of personal data necessary to achieve a stated purpose.
Accuracy means we take reasonable steps to ensure the personal data we hold is correct and, where necessary, kept up to date, and we provide you with ways to correct inaccurate information. Integrity and confidentiality mean we protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, through the organizational, physical, and technical measures described later in this Policy. Storage limitation means we do not keep personal data for longer than necessary for the purposes for which it was collected, subject to applicable legal and regulatory retention requirements.
The personal data Own Bank collects depends on the nature of your relationship with us, whether you are a depositor, a borrower, a digital banking user, a job applicant, or simply a visitor to one of our branches. We describe the general categories below.
We collect identity and contact information, such as your full name, date and place of birth, gender, nationality, civil status, residential and business addresses, and contact details including mobile number, landline, and email address. Because we are a BSP regulated financial institution and covered person under the Anti-Money Laundering Act, we are required to collect government-issued identification numbers, which may include your Tax Identification Number, Social Security System number, Government Service Insurance System number, Unified Multi-Purpose ID, passport number, driver's license number, PhilHealth number, or Philippine National ID, as applicable to your circumstances and as needed to comply with Know Your Customer and Customer Due Diligence requirements under BSP regulations and the Anti-Money Laundering Act.
We collect financial information relevant to your accounts and transactions with us, including account and card numbers, deposit and loan balances, sources of income and funds, transaction and payment history, and credit information obtained from credit bureaus or the Credit Information Corporation where relevant to assessing your creditworthiness. Where you are employed or self-employed, we may collect employment and livelihood information, such as your employer's name, occupation, job title, employment history, and declared source of income, which helps us assess suitability for products and comply with our regulatory obligations.
Where our products or channels require it, we may collect biometric information, such as facial images captured for identity verification, or your signature, always with appropriate safeguards and, where required by law, your explicit consent. We also collect digital and device information when you use our website, mobile application, or online banking channels, including your IP address, device identifiers, browser type, operating system, approximate geolocation, cookies, and system logs, which help us secure your account and improve our digital services. For security purposes, we may collect “CCTV footage,” access logs, and visitor records when you visit our branches or offices.
Finally, where relevant to a specific relationship, we may collect other categories of information necessary for credit evaluation, fraud prevention, suitability assessment, litigation or dispute resolution, and compliance with regulatory reporting obligations. We do not collect sensitive personal information such as health data or information about criminal proceedings unless it is necessary for a specific, lawful purpose, such as processing an insurance-linked product or complying with a legal requirement, and we apply heightened safeguards to that category of data.
We design our onboarding forms and digital workflows to request only the information relevant to the product or service you are applying for, rather than a single, undifferentiated data collection form used across every product line. A basic savings account, for instance, does not require the same depth of financial and employment information as a credit facility, and our collection practices reflect that distinction. Where a field on a form is optional rather than required, we indicate this clearly, so that you can make an informed choice about what to share with us beyond what the law or the product genuinely requires.
Where our digital onboarding, account opening, or identity re-verification features require it, OwnBank collects facial data — specifically a facial image and, where applicable, a short liveness capture such as a selfie or brief video — through your device camera. Facial data is used to confirm your identity by comparing it against your submitted government-issued identification and, where relevant, previously enrolled facial data, consistent with BSP Know-Your-Customer and Customer Due Diligence requirements.
We use facial data solely for identity verification and fraud-prevention purposes in connection with onboarding, account access, and specific transactions that require re-authentication. We do not use facial data for advertising, marketing profiling, or any purpose beyond identity verification and fraud prevention, and we do not use facial data to derive additional attributes about you, such as race, health, or emotional state, beyond what is necessary for identity matching.
Facial data is processed by OwnBank and, where necessary to perform identity verification, by our contracted eKYC or identity-verification service provider(s), acting solely as our Personal Information Processor(s) on our documented instructions. We do not sell facial data, and we do not share facial data with any third party for that party's own independent purposes. Where facial data is shared with a third-party processor for the purposes described above, our contract with that processor requires it to provide the same or an equivalent level of protection for your facial data as described in this Policy, including confidentiality, security, retention, and deletion obligations no less protective than our own.
We retain facial data only for as long as necessary to complete the identity-verification purpose for which it was collected and to comply with applicable BSP Know-Your-Customer and Anti-Money Laundering record-keeping requirements. Once that retention period has lapsed and no other legal or regulatory basis requires us to keep it, we securely delete or irreversibly anonymize your facial data, consistent with Section 19 (Secure Disposal).
Where we rely on your consent to collect or use facial data, you may withdraw that consent at any time by contacting our Data Protection Officer using the details in Section 28. Withdrawing consent will not affect the lawfulness of processing carried out before your withdrawal, and may mean that a facial-data-dependent feature, such as a specific digital onboarding path, becomes unavailable to you; where this occurs, we will offer an alternative identity-verification method where one exists.
You may request that we delete your facial data by contacting our Data Protection Officer using the details in Section 28. We will act on legitimate deletion requests within the timeframe described in Section 20 (Your Rights as a Data Subject), subject to our right to retain facial data, or the underlying Know-Your-Customer record it supports, where retention is required by BSP, Anti-Money Laundering, or other applicable law.
We obtain personal data through a variety of channels in the ordinary course of our banking relationship with you. Most directly, we collect information you provide when you open an account, apply for a loan or card, complete a Personal Information Sheet or Know Your Customer form, or otherwise transact with us at a branch, through our contact center, or through our digital platforms, including our website, mobile application, and online banking portal.
We also collect information generated through your use of our services, such as transaction records, login activity, and communications you send us by email, SMS, live chat, or social media. In certain circumstances, we obtain personal data from other sources authorized to disclose it to us where such collection is permitted under applicable law and supported by an appropriate lawful basis, which may include credit bureaus and the Credit Information Corporation, government agencies and public registries, our affiliates and business partners with whom you have a relationship, and, where permitted by law, publicly available records. Where a third party such as an employer, guarantor, or co-borrower provides us with your personal data in connection with a transaction, we expect that party to have secured the appropriate consent or legal basis to do so, and we process that information subject to the same standards described in this Policy.
Consent is important, but it is not the basis for everything we do with your personal data. Depending on the purpose and circumstances, the Data Privacy Act allows us to process personal data on other lawful bases.
A significant portion of our processing is necessary to perform our contract with you, such as maintaining your deposit account, processing a loan you have applied for, or executing a payment instruction you have given us. Much of our processing is also necessary to comply with a legal obligation, including our duties under the Anti-Money Laundering Act, BSP regulations on Know Your Customer and reporting, tax laws, and directives from courts or regulators; in these cases, we process your personal data because the law requires us to, independent of any consent you may or may not give. Certain processing is carried out to protect vital interests, for instance where we need to act quickly to prevent harm to you or another person, such as in suspected elder financial abuse or fraud targeting your account.
Where none of these bases applies, we rely on your consent, particularly for optional activities such as certain marketing communications, participation in loyalty programs, or the use of certain biometric features that are not otherwise required by law or contract. We may also process personal data based on our legitimate interests, such as preventing fraud, maintaining the security of our systems, or improving our products, provided that our interests do not override your fundamental rights and freedoms; where we rely on this basis, we take care to balance our interests against any potential impact on you. Finally, certain processing, particularly disclosures to regulators and government agencies, is carried out in the exercise of a public authority's mandate or in response to a valid legal or regulatory directive.
The bases above apply to ordinary personal information under Section 12 of the Data Privacy Act. Sensitive personal information and privileged information are subject to stricter conditions under Section 13 of the Data Privacy Act, and contractual necessity and legitimate interest are not, by themselves, available bases for that category. For sensitive personal information and privileged information, we rely instead on your explicit, purpose-specific consent; an existing law or regulation that itself guarantees the protection of personal data; the protection of life and health where you are unable to give consent; the lawful, non-commercial objectives of public organizations, subject to safeguards; medical treatment by a practitioner or institution, subject to confidentiality; or the establishment, exercise, or defense of legal claims, or disclosure to a government or public authority.
We process personal data for purposes connected to establishing, maintaining, and servicing our relationship with you, and to meeting the obligations that come with operating a BSP-supervised bank. In practical terms, this means we use your personal data to open and administer your accounts, deliver the products and services you have applied for, and process your transactions and instructions accurately and on time.
Because we are a bank, a substantial part of our processing exists to satisfy regulatory requirements that exist to protect the financial system and its participants, including you. This includes performing Know Your Customer checks and ongoing Customer Due Diligence, monitoring transactions and reporting suspicious activity under the Anti-Money Laundering Act, complying with tax information exchange obligations such as FATCA where applicable, and submitting reports required by the BSP, the Anti-Money Laundering Council, and other regulators. We also use personal data to assess creditworthiness and manage credit risk, including through credit scoring, and to manage the Bank's overall risk exposure.
We process personal data to protect you and the Bank from harm, including detecting and preventing fraud, securing our digital channels against unauthorized access, and maintaining the resilience and integrity of our information systems. Internally, we use personal data for legitimate business management purposes such as internal audit, financial and regulatory reporting, product development, service quality improvement, and analytics that help us understand how our products are used so that we can serve customers better.
Subject to the consent requirements described in the next section, we may also use your personal data for marketing and promotional communications about products and services that may interest you. Where you are an employee, applicant, vendor, or contractor, we process personal data for employee administration, recruitment, and vendor management purposes consistent with our obligations as an employer and business. Finally, we may process personal data as necessary to establish, exercise, or defend legal claims, and to comply with any other legal or contractual obligation that applies to us.
We also process personal data in furtherance of our obligations under the Financial Products and Services Consumer Protection Act, which requires us to treat customers fairly, resolve complaints effectively, and ensure that our products are suitable for the customers to whom they are offered. This means that some of the personal data we collect, including information about your financial circumstances and objectives, is used specifically to assess whether a product is appropriate for you before we offer or approve it, rather than solely to support our own commercial interests. Where we decline to open an account or approve a product based in part on information we have processed about you, our consumer protection obligations require us to be able to explain the basis for that decision if you ask us to.
When you visit our website or use our mobile application, we and our authorized service providers use cookies, pixels, software development kits (SDKs), and similar tracking technologies to make our digital channels work properly and to understand how they are used. Some of these technologies are strictly necessary, for example to keep you logged into online banking securely or to remember your language preference, and cannot be disabled without affecting core functionality. Others support analytics, allowing us to see which features are used most and where customers encounter difficulty, so that we can improve our platforms over time.
Where our digital channels use cookies for purposes beyond what is strictly necessary, such as personalizing content or measuring the effectiveness of marketing campaigns, we will seek your consent in accordance with applicable guidance, and we provide mechanisms, such as browser settings or in-app preference controls, that allow you to manage or withdraw that consent. Please note that disabling certain cookies may limit your ability to use some features of our website or mobile application, including features related to security and personalization.
As a digital-centric bank, Own Bank may use data analytics, machine learning models, and, in certain cases, artificial intelligence to support functions such as fraud detection, transaction monitoring under our anti-money laundering program, credit scoring and lending decisions, and customer segmentation for the purpose of tailoring our products and communications. These tools help us serve customers more efficiently and protect the Bank and its customers from financial crime, but we recognize they also carry risks that deserve careful governance.
Before we deploy a model or automated system that has a material impact on customers, we subject it to internal review by our risk, compliance, and technology governance functions, consistent with our AI governance framework, to assess accuracy, fairness, and potential impact before it is used in production. Where feasible, we design these systems with explainability in mind, so that our staff can understand and, where necessary, explain the basis for a material outcome that affects you.
Where a decision that produces legal effects or similarly significant consequences for you, such as a loan decline, is made solely through automated means without meaningful human involvement, you have the right to request human review of that decision, and our staff will assess your case individually rather than relying solely on the automated output. We do not use automated decision-making for purposes that are not disclosed in this Policy, and we periodically review our models to identify and correct issues such as inaccuracy or unintended bias.
Our approach to artificial intelligence is overseen through a dedicated governance structure that brings together our risk, compliance, technology, and data protection functions before any material AI-enabled system is approved for production use. This governance extends to systems we build ourselves and to artificial intelligence capabilities we procure from third-party vendors, including any provider used to support identity verification, fraud screening, or customer service. We require vendors offering AI-enabled services to disclose how their models are trained, what safeguards exist against inappropriate use of customer data for model training, and what audit or explainability capabilities are available to us, and we factor these disclosures into our due diligence before onboarding any such provider. We do not permit customer personal data to be used to train third-party AI models beyond the specific service we have contracted for, unless we have obtained your explicit consent to that additional use.
Own Bank does not sell personal data. We disclose personal data only where we have a lawful basis to do so, whether that is your consent, a contractual necessity, or a legal or regulatory obligation, and we limit each disclosure to what is reasonably necessary for the purpose.
We share personal data within the Bank among authorized personnel who need it to perform their functions Where we share personal data with another entity that independently determines the purpose or manner of processing that arrangement is a data-sharing relationship between controllers, and we document it through a Data Sharing Agreement specifying the recipient, purpose, categories of data, and lawful basis, consistent with NPC guidance on data sharing agreements. We engage service providers and outsourcing partners, including technology vendors, cloud service providers, and business process outsourcers, to help us deliver our products and services; unlike the data-sharing arrangements above, these providers act solely as Personal Information Processors on our documented instructions, not as independent controllers, and are bound by contractual obligations described in Section 13 below. We work with payment networks, correspondent banks, and clearing houses to process transactions, and with credit bureaus and the Credit Information Corporation to support credit assessment and reporting, consistent with the Credit Information System Act.
As a regulated bank, we are required to disclose personal data to government and regulatory bodies in defined circumstances, including the BSP, the Anti-Money Laundering Council, the National Privacy Commission, the Bureau of Internal Revenue, courts, and law enforcement agencies, and other competent authorities, when they act within their lawful authority to request such information. We may also share personal data with insurers and insurance brokers in connection with deposit or credit protection products, with external auditors and legal counsel in connection with audits, investigations, or legal proceedings, and, in the context of a merger, acquisition, or similar corporate transaction, with prospective investors or acquiring entities, subject to confidentiality obligations that protect your information throughout the process. All such disclosures, and our disclosures generally, remain subject to and qualified by the confidentiality requirements applicable to a Philippine bank, including the Bank Secrecy Law (RA 1405), the Foreign Currency Deposit Act (RA 6426), the Credit Information System Act (RA 9510), the Anti-Money Laundering Act and its implementing rules, and other applicable confidentiality laws; we disclose covered account information only through the specific exceptions those laws provide, such as a valid court order, your written consent, or another statutory exception, and not as a matter of general discretion.
Where the law imposes specific disclosure obligations on the Bank, such as under the Anti-Money Laundering Act, the National Internal Revenue Code, the Anti-Graft and Corrupt Practices Act, or directives from the BSP or other regulators, we comply with those obligations even without your separate consent, because the law itself provides the lawful basis for disclosure. In every case, we extend particular care to the personal data of minors, and we do not disclose their personal data except as strictly necessary and, where required, with parental or guardian consent. We also take particular care when processing the personal data of minors. We limit the collection, use, disclosure, and retention of a minor's personal data to what is necessary and proportionate for the relevant lawful purpose and, where consent is the applicable lawful basis, obtain consent from a parent or legal guardian in accordance with applicable law.
Before we disclose personal data to any external party, we consider whether the disclosure is genuinely necessary for the purpose at hand, whether a more limited or anonymized disclosure could achieve the same result, and whether the recipient is bound by obligations that will protect your personal data to a standard consistent with this Policy. This means that a request for information, even from a party with a legitimate interest in your account, does not automatically result in a wholesale transfer of your file; we disclose only the specific data elements reasonably required for the stated purpose. We also maintain records of significant disclosures so that we can respond fully if you exercise your right to access and ask us who has received your personal data and why.
When we engage a third party to process personal data on our behalf, whether as a processor of customer data, a cloud hosting provider, or an outsourced business function, we conduct due diligence before onboarding them, assessing their information security posture, financial stability, regulatory standing, and privacy practices. We document the relationship through Data Sharing Agreements, Outsourcing Agreements, or Data Processing Agreements, as appropriate to the nature of the engagement, and these agreements impose confidentiality, security, and data protection obligations consistent with our own responsibilities under the Data Privacy Act, its IRR, and other applicable NPC issuances, and BSP outsourcing regulations.
Our agreements with service providers require them to implement appropriate technical and organizational safeguards, to process personal data solely for the purposes we authorize, to support us in responding to data subject requests and Personal Data Breach investigations, and to cooperate with compliance reviews and audits that we or our regulators may conduct. We monitor our service providers on an ongoing basis, commensurate with the risk associated with the data they process, and we retain the right to terminate arrangements that fail to meet our standards.
We classify our service providers according to the sensitivity of the data they process and the criticality of the function they perform, and we apply proportionately deeper due diligence and more frequent monitoring to providers handling large volumes of customer data or performing functions material to our operations, consistent with BSP guidance on technology risk management and outsourcing. Providers that fall within the scope of BSP outsourcing regulations are subject to the additional approvals, notifications, and contractual requirements that the regulations prescribe, on top of the privacy and security obligations described in this section. We also require our material service providers to carry appropriate insurance or demonstrate financial capacity to remediate an incident, and to maintain their own sub-processor oversight where they, in turn, rely on further vendors to deliver services to us. Subcontracting by a service provider requires our prior consent as a standard contractual term; a vendor record stating that no subcontracting is involved reflects a contractual prohibition, not merely the current arrangement.
Some of the service providers we engage, including certain cloud infrastructure and specialized technology providers, may process or store personal data outside the Philippines. We recognize that cross-border processing introduces additional considerations, and we do not take this lightly.
Before personal data is transferred outside the Philippines, whether to a cloud provider's data center or an offshore service provider, we assess the receiving jurisdiction and the specific safeguards available, and we put in place contractual protections designed to ensure that personal data continues to receive a level of protection consistent with Philippine law, regardless of where it is processed. These protections typically include data processing agreements incorporating standard contractual clauses or equivalent mechanisms, restrictions on further transfer or sub-processing without our authorization, obligations to notify us promptly of any Personal Data Breach, and, where appropriate, requirements that data be encrypted in transit and at rest. Where feasible and consistent with service requirements, we prefer arrangements that keep core customer data within Bank-approved environments and apply additional safeguards, such as data residency controls or heightened contractual assurances, to any processing that occurs abroad.
We conduct a transfer impact assessment as part of our due diligence and Data Privacy Impact Assessment process for any new arrangement involving cross-border processing, considering factors such as the nature of the data involved, the purpose and duration of the transfer, and the legal and regulatory environment of the receiving country. If you would like more information about a specific cross-border transfer relevant to your data, you may contact our Data Protection Officer using the details in Section 28.
Own Bank remains accountable for personal data even after it has been transferred to a service provider located outside the Philippines. Engaging an offshore provider does not reduce our obligations under the Data Privacy Act or BSP regulations, and we do not treat cross-border processing as a way to place customer data beyond the reach of Philippine oversight. Where a proposed arrangement would involve transferring personal data to a jurisdiction or provider that cannot offer safeguards consistent with this Policy, we will not proceed with that arrangement, or we will limit the scope of data involved until appropriate protections can be put in place.
Protecting personal data against loss, misuse, and unauthorized access is a continuous discipline at Own Bank, not a one-time project. We maintain a layered program of organizational, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of the personal data entrusted to us, consistent with BSP information security expectations and internationally recognized standards such as ISO/IEC 27001.
On the organizational side, we maintain information security and privacy governance structures with clear accountability, supported by policies, standards, and procedures that our employees are trained to follow, and we conduct regular privacy and security awareness training across the organization. On the physical side, we control access to our facilities and to the physical records and infrastructure that store personal data, using measures such as restricted access areas, visitor management, and secure storage facilities for physical documents.
On the technical side, we deploy access controls and to limit system access to authorized personnel, firewalls and anti-malware protections to defend our network perimeter, and to detect unusual activity. We conduct regular vulnerability assessments, penetration testing, and security audits to identify and remediate weaknesses before they can be exploited, and we maintain incident response and business continuity procedures so that we can respond quickly and effectively if something goes wrong. Remote connectivity to Bank systems is secured through approved technologies such as virtual private networks, and access to personal data is granted strictly on a need-to-know basis tied to legitimate business functions.
Because much of our infrastructure depends on outsourced technology and cloud services, our security program extends beyond our own network perimeter. We assess the security posture of our critical vendors before onboarding them and on a periodic basis thereafter, consistent with BSP expectations on technology risk management and outsourcing, and we require material vendors to maintain their own incident response capabilities and to notify us promptly of any event that could affect our customers' personal data. Our operational resilience planning considers not only cyberattacks and system failures but also the possibility that a key vendor becomes unavailable, and we maintain contingency arrangements designed to keep essential banking services running, and your personal data protected, even under adverse conditions.
Before we launch a new product, system, or process, we conduct a Data Privacy Impact Assessment for every processing system involving personal data, consistent with NPC Circular No. 2023-06, and not only where we consider the processing significant or high-risk; the assessment is updated whenever a material change is made to the system. Processing that carries heightened privacy risk, such as the introduction of automated decision-making, artificial intelligence, large-scale data processing, cross-border transfers, or new data sharing arrangements, receives correspondingly deeper review. This assessment allows us to identify privacy risks before they materialize, evaluate whether the intended processing is necessary and proportionate, and put in place safeguards or, where appropriate, redesign the initiative to reduce risk. Findings and recommendations from these assessments feed directly into our enterprise risk management framework and inform decisions made by our Data Protection Officer and, where relevant, our AI Governance Committee.
Personal data is stored only in systems and repositories that the Bank has approved following appropriate information security, legal, compliance, and privacy assessments. Physical documents containing personal data are kept in controlled, secure storage facilities, while electronic records are protected through the access controls, encryption, and monitoring described in Section 15.
Access to personal data is limited to authorized Bank personnel who require it to perform a legitimate business function, and access is granted and reviewed on a need-to-know basis. Where our staff or authorized third parties need to connect to Bank systems remotely, that connectivity is secured through approved technologies that enforce the same security controls that apply within our premises.
Own Bank retains personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with applicable legal and regulatory requirements, or to establish, exercise, or defend legal claims. We do not apply a single, universal retention period to all personal data, because different categories of information are subject to different legal and operational requirements.
As a bank, we are subject to specific regulatory retention requirements that are determined by the type of record and the regulation that applies to it, not by whether it is held in physical or digital form. For example, records relevant to a taxable transaction are generally retained for five years under Bureau of Internal Revenue rules pursuant to Republic Act No. 11976 (Ease of Paying Taxes Act); customer due diligence and transaction records relevant to anti-money laundering are retained for at least five years under Anti-Money Laundering Council rules; and BSP regulations applicable to rural banks prescribe longer periods for certain accounting and transaction records, including a ten-year retention period for specified categories. Where a specific law or regulation requires a longer retention period than would otherwise apply, we observe the longer period. Beyond these regulatory minimums, we may retain personal data for as long as needed for legitimate business purposes consistent with standard banking industry practice, such as maintaining a complete customer relationship history, or for as long as necessary to resolve a dispute, respond to a regulatory inquiry, or support ongoing litigation.
Once personal data is no longer needed for any of these purposes, we take steps to securely dispose of or anonymize it, as described in the following section.
When personal data reaches the end of its retention period and is no longer required for any legitimate purpose, Own Bank disposes of it securely to prevent unauthorized recovery, reconstruction, or disclosure. Physical documents are destroyed through methods such as shredding that render the information permanently unreadable, while electronic records are securely deleted or rendered irrecoverable using industry-accepted data destruction techniques appropriate to the storage medium involved. Where retaining data in fully identifiable form is no longer necessary but the underlying information retains statistical or analytical value, we may anonymize it in a manner that prevents re-identification, consistent with guidance from the National Privacy Commission.
The Data Privacy Act gives you meaningful control over your personal data, and Own Bank is committed to honoring these rights in practice, not just in principle.
You have the right to be informed about how your personal data is being or has been processed, including whether automated decision-making or profiling is involved, and this Policy is one of the ways we fulfill that right. You have the right to access your personal data upon written request, including the contents of the data we hold, how it has been and is being processed, the sources from which it was obtained, and the recipients to whom it has been or will be disclosed. If you believe any of your personal data is inaccurate, you have the right to dispute it and to have it corrected, and we will investigate and act on legitimate disputes promptly.
You have the right to object to certain processing, including the right to withdraw consent for processing that is based on consent, such as marketing communications, and the right to opt out of your data being used for direct marketing purposes; withdrawing consent does not affect processing we carry out on other lawful bases, such as compliance with legal obligations. Based on reasonable grounds, you have the right to erasure or blocking of your personal data from our filing system, without prejudice to our continued processing of information we are required to retain for legal, regulatory, or legitimate business purposes. You have the right to data portability, allowing you to obtain a copy of your personal data in an electronic or structured format that is commonly used and allows for further use, where this is technically feasible.
Where you have suffered damage because of an inaccurate, unlawfully obtained, or unauthorized use of your personal data, you have the right to be indemnified for that damage under the Data Privacy Act. You also have the right to request human review of any decision made solely through automated processing that significantly affects you, as described in Section 11. Finally, you have the right to file a complaint with our Data Protection Officer or with the National Privacy Commission if you believe your privacy rights have been violated.
To exercise any of these rights, you may write to our Data Protection Officer using the contact details in Section 28. We will respond to legitimate requests within thirty (30) working days from receipt of a complete request, consistent with National Privacy Commission guidance, which may be extended by up to an additional fifteen (15) working days for requests that are complex or numerous, with notice to you of the extension and the reason for it; where we are unable to grant a request, we will explain the legal basis for our decision.
We will ask you to verify your identity before acting on a request that relates to your personal data, both to protect you from someone else impersonating you and to satisfy our own obligations around information security and know-your-customer controls. Where a request comes from someone acting on your behalf, such as a lawyer, guardian, or attorney-in-fact, we will ask for appropriate documentation establishing their authority before proceeding. There is generally no charge for exercising your rights under the Data Privacy Act, although we may charge a reasonable fee to cover the direct costs of providing further copies of information you have already received, consistent with applicable NPC guidance.
Own Bank recognizes that minors require special protection when it comes to personal data. Where our products or services involve the processing of a minor's personal data, we require the consent of a parent or legal guardian before that data is collected, processed, or disclosed, except where the law provides an exception. We limit the collection, processing, and disclosure of a minor's personal data strictly to what is necessary for the specific service being provided, and we apply enhanced security measures to safeguard this category of information. If you believe we have collected a minor's personal data without appropriate consent, please contact our Data Protection Officer so that we can investigate and address the matter.
From time to time, and where permitted by law, Own Bank may wish to send you information about products, services, or promotions that may be of interest to you, whether by SMS, email, phone, or other channels. Where this processing is based on your consent, we will only send you marketing communications after you have given that consent, and you may withdraw it at any time by contacting our Data Protection Officer, using the opt-out mechanism provided in the communication itself, or updating your preferences through our digital channels. Withdrawing your consent to marketing communications will not affect our ability to send you service-related communications necessary to administer your account or comply with our legal obligations, and it will not affect the lawfulness of any marketing communications sent before your withdrawal.
Because this Policy covers the full range of our processing activities, we also maintain a shorter notice provided at the point we collect your information, such as at account opening or on a specific form, which summarizes what is collected and why for that particular interaction and refers back to this Policy for complete detail. Where our website, mobile application, or a specific product involves employees, job applicants, vendors, cookies and SDKs, children, or AI-assisted decisions, we may also provide a further targeted notice for that context. Where a shorter notice and this Policy appear to differ, this Policy governs unless the shorter notice states otherwise for its specific context.
We take reasonable steps to keep the personal data we hold accurate and up to date, but we also rely on you to help us do so. Please notify us promptly of any changes to your personal data, such as a new address, contact number, or employment status, so that we can update our records and continue to serve you effectively. Keeping your information current also helps us meet our regulatory obligations, including those related to Know Your Customer requirements, and reduces the risk of communications or transactions being misdirected.
Despite our safeguards, no organization can guarantee that a security incident will never occur, and we believe in being direct with you about how we would respond if one did. A Personal Data Breach occurs when there is a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data.
If we know, or have reasonable belief, that a Personal Data Breach has occurred that involves information capable of enabling identity fraud, that the information may have been acquired by an unauthorized person, and that the breach is likely to give rise to a real risk of serious harm to affected individuals, we will notify the National Privacy Commission and affected data subjects within seventy-two hours of our knowledge of, or reasonable belief that, the breach occurred — this clock runs from that knowledge or reasonable belief, not from a later internal determination or the conclusion of an investigation, in accordance with the Data Privacy Act and NPC regulations on breach notification. Where we notify you of a breach, we will explain, through a secure means of communication, the nature of the breach, the personal data that may have been affected, the measures we have taken or will take to address the breach and mitigate its impact, recommended actions you can take to protect yourself, and how to reach our Data Protection Office for further assistance.
Internally, we maintain incident response procedures that allow us to detect, contain, investigate, and remediate security incidents promptly, and we conduct post-incident reviews to strengthen our controls and prevent recurrence. Where a service provider processing personal data on our behalf experiences a breach, our contracts require them to notify us without undue delay so that we can meet our own notification obligations.
Not every security incident rises to the level of a notifiable Personal Data Breach, and we assess each event against the criteria set out above rather than treating every anomaly as a reportable breach. That said, we would rather investigate a false alarm thoroughly than dismiss a genuine incident prematurely, and our staff are trained to escalate any suspected compromise of personal data to our Data Protection Officer and information security team immediately upon discovery, so that the seventy-two hour clock, where applicable, is never at risk of being missed due to internal delay.
This Policy applies not only to our customers but also to our own workforce and the businesses we work with. When you apply for a position at Own Bank, we collect personal data such as your educational background, employment history, references, and, where relevant to the role, results of background checks, and we use this information solely to evaluate your candidacy and, if you join us, to administer your employment. Personal data of current and former employees is processed for purposes including payroll and benefits administration, performance management, regulatory reporting required of us as an employer, and workplace security, and is protected using the same organizational, physical, and technical safeguards described in Section 15, with access restricted to human resources personnel and other staff who need it to perform their functions.
Where we engage suppliers, contractors, and other business partners, we collect and process the personal data of their authorized representatives, such as names and contact details, for purposes of contract management, vendor accreditation, and due diligence. We expect our vendors to handle any personal data we share with them, or any personal data they process on our behalf, in accordance with the contractual obligations described in Section 13, and we extend the same expectation of accountability to our supply chain that we hold for our own operations.
Responsibility for data privacy at Own Bank begins with our Board of Directors and Senior Management, who exercise oversight over our data privacy management program, approve this Policy, and ensure that privacy risk is integrated into our enterprise risk management framework. The Board supports the independence of our Data Protection Officer, who is empowered to escalate concerns directly to the Board or its appropriate committee, and monitors the implementation of privacy controls and the Bank's ongoing compliance with the Data Privacy Act and related regulations. Our Data Protection Officer reports periodically on privacy risks, compliance status, and significant incidents, so that governance over your personal data rests with people who are accountable for outcomes, not just for paperwork.
Privacy governance at Own Bank does not sit in isolation. It is coordinated with our broader risk governance structure, including the committee responsible for overseeing the use of artificial intelligence across the Bank, so that new technology initiatives are evaluated for privacy and security implications alongside their operational and financial merits before they are approved. This coordinated approach reflects our view that data privacy, information security, and responsible technology adoption are facets of the same underlying commitment: using your personal data only in ways that are lawful, necessary, and worthy of the trust you place in us.
If you have questions about this Policy, wish to exercise any of your rights as a data subject, or have concerns about how your personal data has been handled, please contact our Data Protection Officer at:
Data Protection Officer
Own Bank, The Rural Bank of Cavite City, Inc.
505 P. Burgos Avenue, Caridad, Cavite City, 4100 Cavite Email: dpo@ownbank.com.ph
We take every inquiry seriously and will respond as promptly as we can.
If, after contacting our Data Protection Officer, you remain unsatisfied with our response, or if you believe your rights under the Data Privacy Act have been violated, you may file a complaint with the National Privacy Commission through www.privacy.gov.ph. We encourage you to reach out to us first, as we are committed to resolving concerns directly wherever possible, but your right to escalate a complaint to the National Privacy Commission is one we fully respect.
We review this Policy at least annually, and more frequently where necessary, to ensure it continues to reflect changes in law, regulation, technology, and our business operations. When we make material changes to this Policy, we will publish the updated version on our official website and, where appropriate, notify you through other communication channels. We encourage you to check this page periodically so that you remain informed about how we protect your personal data.
This Privacy Policy takes effect on the date indicated at the beginning of this document and remains in force until it is amended, updated, or superseded by a subsequent version published by Own Bank.

