Privacy Policy

Confidentiality Clause & Disclaimer COPYRIGHT

(C) 2021 BY SUNTRUST BANK All rights reserved.

Policy Statement


Who We Are

SunTrust Bank is a privately held Commercial Bank licensed by the Central Bank of Nigeria under the Banks and Other Financial Institutions Act (BOFIA).

SunTrust Bank is poised to create value for its customers by leveraging on our competencies and a team of highly motivated staff, we work tirelessly to develop & provide a broad range of unique financial services and products to consumers, small businesses, corporations, governments and institutions that will positively impact their business.

We strive to create the best outcomes for our clients and customers with financial ingenuity that leads to solutions that are simple, creative and responsible. The Bank focuses its lending activities on SME Finance, Retail/Consumer Banking, and medium to large Corporate Finance and explores other specialized Development/infrastructure financing activities.


What Personal Data Do We Need?

The personal data we would collect and process, depending on the particular processing requirement, are under the following categories:

Personal Data Type –  Sources

Identification Information-   Official identification documents like passports or national ID cards

Contact Information-   Customer details provided during account setup

Financial Information-   Credit applications, transaction information

Transaction Data-  Transaction records

Credit Information-    Credit bureau, loan information

Employment Information-  Employees during onboarding

Communication Records-   Call records, emails, chats

Compliance Data-    AML/KYC records

Digital Data-   Cookies


In certain instances, the personal data we need to collect may fall under a special category of personal data, which includes: race, political opinion, ethnic origin, religion, philosophical beliefs, genetic/biometric data, health record, sex life/sex orientation, criminal records, or alleged criminal activity. In such instances, our lawful basis of processing will be the explicit consent of the data subject, compliance with a legal obligation, or for legal proceedings/advice.


Why Do We Need the Data?

SunTrust Bank ensures that the personal data collected and processed is necessary for the purpose of collection, and SunTrust Bank shall not collect or process more data than is reasonably required for a particular processing activity. In addition, every processing purpose has at least one lawful basis for processing to safeguard the rights of the data subjects, as listed below:

Purpose of Processing:-   Lawful Basis of Processing

Account Management:-  Verifying identities, updating account information, and facilitating transactions.

Credit Assessment:-   To assess creditworthiness when considering loan applications

Regulatory Compliance:-   Comply with legal and regulatory requirements, such as anti-money laundering and KYC

Customer Service:-  To provide customer support, address inquiries, and resolve banking transaction issues

Online Banking :-   To enable secure access to online and mobile banking platforms for better user experience

Internal Analysis and Improvement:-  To improve their services, identify trends, and make data-driven business decisions.


Where Legitimate Interest is considered the legal basis for processing personal data, SunTrust Bank shall follow the steps below in carrying out a Legitimate Interest Assessment.

  1. Determine the Purpose for Processing

In carrying out the purpose test, SunTrust Bank must establish the exact reason for the processing and how it benefits the organization. Answers to the following shall be provided to determine the exact purpose for processing:

  • Description of the processing objective
  • The likelihood of meeting the objective and how to determine if the objective was met
  • The benefit of the processing and the significance to the organisation
  • Description of the possible impact of not processing and any other issues that might be relevant

    1. Determine the Necessity of the Processing

    SunTrust Bank must establish why the processing must take place, how the processing relates to the expected benefits, and any other alternatives and why there were not considered.


    1. Balance the identified interest with the Privacy Interest of the Data Subjects

    The following questions will be addressed under the balance test:

  • Who are the data subjects (category)?
  • What is the relationship between SunTrust Bank and the data subject
  • What personal data is to be processed
  • How will the processing impact the data subject
  • How will the data subject react to the processing

    SunTrust Bank records this information in line with this policy, data protection impact assessment, and data inventory.


    SunTrust Bank requires your explicit consent to process collected personal data. And by consenting to this privacy policy, you are giving us the permission to use/process your personal data specifically for the purpose identified before collection.

    If, for any reason, SunTrust Bank is requesting sensitive personal data from you, you will be rightly notified why and how the information will be used.

    You may withdraw consent at any time by requesting for Withdrawal of Consent form, following the SunTrust Bank Withdrawal of Consent Procedure.



    SunTrust Bank will not pass on your personal data to third parties without first obtaining your consent.

    The following third parties will receive your personal data for the following purpose(s) as part of the processing activities.

    – Foreign Country/International Organization Safeguards in place to protect your personal data

    – Retrieve a copy of the safeguards in place here:


    Where there is a need for a third party to process the personal data of data subjects, SunTrust Bank will enter into a Data Processing Agreement with the third party and be satisfied that the third party has adequate measures in place to protect the data against accidental or unauthorized access, use, disclosure, loss, or destruction.

    In a case where the disclosure is to third parties outside the jurisdiction of the GDPR and NDPR, SunTrust Bank will ensure that the third party meets the core regulatory standards prior to the transfer. This may include transferring the personal data to the third party where SunTrust Bank has satisfied that:

  • the country of the recipient has adequate data protection controls established by legal or self-regulatory regime
  • SunTrust Bank has a contract in place that uses existing or approved data protection clauses to ensure adequate protection
  • SunTrust Bank is making the transfer under approved binding corporate rules
  • SunTrust Bank is relying on approved codes of conduct or certification mechanisms, together with binding and enforceable commitments in the foreign country or international organisation to apply the appropriate safeguards in relation to data subject rights
  • Provisions inserted into administrative arrangements between public authorities or bodies authorised by the competent supervisory authority


    Retention of Records

    In compliance with the GDPR/NDPR data retention policy, SunTrust Bank will process and retain your personal data for 10 years

    This retention period has been established to enable us use the personal data for the necessary legitimate purposes identified, in full compliance with the legal and regulatory requirements. When we no longer need to use your personal information, we will delete it from our systems and records, and/or take steps to encrypt/anonymise it to protect your identity as contained in our media disposal policy.


    Data Subject Rights

    Data subjects, according to the provision of the GDPR/NDPR, have certain rights. At any point while SunTrust Bank are in possession of or processing your personal data, you, the data subject, have the right to:

  • Request a copy of the information that we hold about you
  • Correct the data that we hold about you that is inaccurate or incomplete
  • Ask for the data we hold about you to be erased from our systems/record
  • Restrict processing of your personal data where certain conditions apply
  • Have the data we hold about you transferred to another organisation
  • Object to certain types of processing like direct marketing
  • Object to automated processing like profiling, as well as the right to be subject to the legal effects of automated processing or profiling
  • Judicial review. In the event that SunTrust Bank refuses your request under rights of access, we will provide you with a reason as to why. And you have the right to complain as outlined in clause 3.6 below.
  • All of the above requests will be forwarded on should there be a third party involved in the processing of your personal data.



    If for any reason you wish to make a complaint about how SunTrust Bank (or any of our third parties described in 3.4 above) processes your personal data, or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and the Data Protection Officer of SunTrust Bank.


    Below are the details for


    Data Protection Officer

    Address: SunTrust Bank, 1 OladeleOlashore Street, Victoria Island Lagos.


    Telephone: +234 (01) 2802141


    Privacy statement

    For more information on how we use your personal data and why, please visit [Link to privacy statement on the website]


    Online Privacy Statement


    Personal Data

    Under the EU’s General Data Protection Regulation (GDPR) and the Nigeria Data Protection Regulation (NDPR) personal data is defined as:

    “Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”


    How We Use Your Information

    This privacy notice tells you how we, SunTrust Bank, will collect and use your personal data for relationship management, profiling, business analytics/development, communication, registration, subscription, cookies, and all-round efficient service delivery.


    Why Does SunTrust Bank Need to Collect and Store Personal Data?

    We need to collect your personal data in order for us to provide you with our services. In any event, we are committed to ensuring that the information we collect and use is appropriate for this purpose(s) only, and will in no way invade your privacy. If there is a need to use your personal data for marketing purpose, SunTrust Bank will ensure to seek additional consent from you


    Will SunTrust Bank Share My Personal Data with Anyone Else?

    SunTrust Bank may pass your personal data to third-party service providers contracted by us. Any third parties that we may share your personal data with is under an obligation to secure your details and use them only to fulfil the service for which they were contracted. When they no longer need your details to provide this service, the data will be disposed in line with the SunTrust’s procedures. If we wish to pass your sensitive personal data onto a third party we will only do so once we have obtained your consent, unless we are required to do otherwise, legally.


    How Will SunTrust Bank Use the Personal Data It Collects About Me?

    We will process (collect, use and store) the information you provide in a manner that complies with the EU’s General Data Protection Regulation (GDPR) and the Nigeria Data Protection Regulation (NDPR). We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary. SunTrust Bank is required to retain information in accordance with the law, such as information needed for income tax and audit purposes. The retention period for certain kinds of personal data may also be governed by specific business-sector requirements and agreed practices. Personal data may be held in addition to these periods depending on individual business needs.


    Under what circumstances will the SunTrust Bank contact me?

    We do not intend to be intrusive, and we will not ask irrelevant or unnecessary questions. Moreover, we will subject the information you provide to rigorous measures and procedures to minimize the risk of unauthorized access or disclosure.


    Can I Find Out the Personal Data That SunTrust Bank Holds About Me?

    SunTrust Bank, at your request, can confirm what information we hold about you and how it is processed. If we do hold your personal data, you have the right to request the following information:

  • Contact details of the data protection officer, where applicable.
  • The purpose of the processing as well as the legal basis for processing.
  • Information about interests, if the processing is based on the legitimate interests of SunTrust Bank or a third party.
  • The categories of personal data collected, stored and processed.
  • Recipient(s) or categories of recipients that the data is/will be disclosed to.
  • Information about how we intend to securely transfer the personal data to a third party or international organization. The Attorney General of the Federation will approve sending personal data to some countries because they meet a minimum standard of data protection. In other cases, we will ensure there are specific measures in place to secure your information.
  • How long the data will be stored.
  • Details of your rights to correct, erase, restrict or object to such processing.
  • Information about your right to withdraw consent at any time.
  • How to lodge a complaint with the supervisory authority.
  • Whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether you are obliged to provide the personal data and the possible consequences of failing to provide such data.
  • The source of personal data if you didn’t provide it directly.
  • Any details and information of automated decision-making, such as profiling, and any meaningful information about the logic involved, as well as the significance and expected consequences of such processing.

    What Forms of ID Will I Need to Provide in Order to Access This?

    SunTrust Bank accepts the following (but not limited to) forms of ID when information on your personal data is requested: Passport, driving license, national identity card, permanent voter card.