Privacy Notice
At CIMB Group, we value your privacy and strive to protect your personal information in compliance with the laws of Malaysia.
If you are reading this Privacy Notice on behalf of a body corporate/business enterprise which maintains/maintained contractual relationship with CIMB Group, this Privacy Notice is intended to be addressed to, without limitation, the individual officers (e.g. authorised signatories/dealer and company secretary), directors, shareholders, beneficial owners (e.g. sole proprietor and partners), guarantor or obligor of the body corporate/business enterprise (the “Relevant Individuals”) and “you”, “your” and “yourself” shall be construed accordingly to mean the Relevant Individuals.
Pursuant thereto, this Privacy Notice is designed to explain and elaborate upon some of our policies and principles pertaining to the privacy of your personal information, all of which we have adopted as a sign of our commitment to respecting, maintaining, protecting and safeguarding the privacy of your personal information.
CIMB Group will only collect, record, hold, use, disclose and store (i.e. "process") use your personal information in accordance with such laws (including the Personal Data Protection Act 2010 and other applicable data protection or privacy laws regulations), this Privacy Notice and the privacy terms in your agreement(s) with any CIMB Group entity that you may have contracted with.
This Privacy Notice explains:
- The type of personal information we collect and how we collect it
- How we use your personal information
- The parties that we disclose the personal information to; and
- The choices we offer, including how to access and update your personal information
Your privacy matters to us, so please take the time to get to know our practices and if you need further information, please call our Consumer Centre at +603 6204 7788.
For the purposes of this Privacy Notice, please note that:
- “CIMB Group” refers to CIMB Group Holdings Berhad and all its related corporations, as defined in section 7 of the Companies Act 2016 and jointly controlled companies, providing financial and other regulated services, excluding companies, branches, offices and other forms of presence operating outside of Malaysia unless and to the extent otherwise stated.
- “Personal information” refers to any information which relates directly or indirectly to you and/or your transactions with us. This information includes your name, address, occupation, contact details, the details of your account(s), the type of products and/or services subscribed to and such other necessary information regarding yourself and your transaction(s) with us. For the avoidance of doubt, please note that this Privacy Notice is applicable only if you are an individual.
What Kind Of Personal Information We Collect And How We Collect It
In order to enable us to deal with your inquiries, open and operate an account/facility for you and/or to generally provide you with our products and services, we may need to and/or may be required to process personal information and financial information about you, including but not limited to:
- your contact detail, for example, your address, telephone number and email address, income tax particulars, your identity card or passport,
- images and biometrics (e.g. fingerprints, facial features, iris/retina patterns, voice) to establish your identity and background;
- specimen signatures, as well as, digital or electronic signatures as defined under the applicable laws and regulations;
- personal information to establish your financial standing, education, employment details, creditworthiness and/or suitability for any of our products/services applied for (if required);
- personal information that you provide when you apply for any of our products and services, including your views or opinions made known to us via feedback or surveys;
- information about your risk profile, investments, tax and insurance/takaful, investment objectives, knowledge and experience and/or business interests and assets;
- information relating to your activities, habits, preferences and interests arising from your use of products and services of CIMB Group, our partners or vendors;
- information about your use of our products and services. For example, your risk profile, preferences, investment objectives, knowledge and experience and/or business interests and assets;
- other electronic data or information relating to you such as IP addresses, cookies, activity logs, online/device identifiers and location data through your usage of our products and services or as part of their delivery to you.
Where We Source Your Personal Information?
We may obtain this information from yourself and from a variety of sources, including but not limited to:
- through your relationship with us, for example information provided by you in application forms, when you operate your account and use our products or services, when taking part in customer surveys, competitions and promotions, and during financial reviews;
- through your verbal and written communications with us and/or our authorised agents via messaging, live chats, voice recordings, phone or mobile device, email, fax, mail, websites or browsers, social media and/or any other appropriate communication channels;
- from an analysis of the way you use and manage your account(s)/facility(ies) with us, from the transactions you make and from the payments which are made to/from your account(s)/facility(ies);
- from third parties connected with you, such as employers, joint account holders, security providers, guarantors and indemnitors, subject to your prior consent;
- If you are a minor (below the age of eighteen), information may be obtained from your parent or legal guardian with their consent. Additionally, if you are unable to manage your own affairs, your information may be provided by a person appointed by a court.
- from such other sources in respect of which you have given your consent to them disclosing information relating to you and/or where they are not otherwise restricted;
- from recordings of Closed Circuit Television (CCTV) installed at our premises;
- from the Malaysia Department of Insolvency, other relevant governmental authorities and/or law enforcement agencies to ascertain inter alia your current and past financial standing;
- from other sources (for example from credit reporting/referencing agencies, including but not limited to CCRIS, FIS and/or any other bureaus or agencies established or to be established by Bank Negara Malaysia or any of its subsidiaries, or by any other authorities and/or from any financial institution);
- information received from insurance/takaful claims or other documents; and/or
- from any information that is supplied and/or collected when you visit our websites and/or download our mobile device applications which may include your device's IP address or from data that is collected via cookies.
We collect two types of personal data: Obligatory and Optional.
- Obligatory data is what we absolutely need to provide you with our products and services. Without this information, we can't fulfil your request.
- Optional data is additional information that helps us improve your experience, but it's not mandatory for us to provide you with our products and services.
Obligatory and optional data collected by us depends on the specific product or service you are interested in.
Mobile App Privacy and Permissions
When you use CIMB OCTO App or any other mobile application offered by CIMB Group, we may collect certain types of information from your device to provide secure, reliable and personalized digital banking services. This section explains how we handle data collected through our mobile applications in accordance with the Personal Data Protection Act 2010 (PDPA) and other applicable Malaysian laws and regulations.
We collect and process only the information necessary to deliver and improve our mobile banking experience, which may include:
- Device and Technical Information – such as your device model, operating system, mobile network, language settings, and unique identifiers. This helps us ensure that the app functions properly, remains secure, and is compatible with your device.
- App Usage Data – information about how you interact with the app (for example, pages viewed, time spent, and crash or error reports). This enables us to analyse performance and continuously enhance our services.
- Location Information – where you have granted permission, we may use your location to help you find nearby branches, ATMs, or promotional offers, or for fraud detection purposes. You can manage or withdraw this permission at any time in your device settings.
- Biometric Information – such as facial recognition or fingerprint data, when you choose to enable biometric login or transaction authentication. These identifiers are securely stored on your device and are not transferred to CIMB Group.
- Camera, Photo, and Media Access - if you use features such as eKYC verification, and document upload, the app will request permission to access your camera or photo library. These permissions are used strictly for the relevant function and only with your consent.
- Notifications and Communication Preferences – the app may send you push notifications about transactions, security alerts, and updates. You can modify these preferences in your notification settings at any time.
We may also use application programming interfaces (APIs), and other secure analytics tools provided by trusted technology service providers (for example, Firebase or similar platforms) to help us monitor app performance, detect security issues, and deliver personalized content. These service providers act on our behalf and are bound by strict confidentiality and data protection obligations consistent with the PDPA.
Any personal information collected through CIMB OCTO App will only be used for legitimate purposes, including but not limited to:
- enabling secure login and transaction processing;
- verifying customer identity and supporting eKYC procedures;
- detecting and preventing fraud or unauthorized access;
- ensuring the app’s operational stability and performance; and
- improving the quality, functionality, and personalization of our services.
You may withdraw your consent or adjust app permissions at any time through your device settings. However, please note that disabling certain permissions may limit or prevent access to some features of CIMB OCTO App.
CIMB Group implements robust security and encryption measures to protect all personal information collected or transmitted via its mobile applications. Our mobile app practices are regularly reviewed to ensure continued compliance with Malaysian data protection, cybersecurity, and financial services regulations.
Cookies and Related Technologies
Cookies are small text files that collect information about users and their visit to the CIMB web site, such as their Internet protocol (IP) address, how they arrived at the web site (for example, through a search engine or a link from another web site) and how they navigate within the web site. Certain cookies may also be used for security monitoring, fraud prevention, and to deliver targeted advertisements or recommendations that are relevant to your interests.
In addition to cookies, we may use pixel tags and similar tracking technologies to better understand user interactions, maintain secure sessions, and measure the effectiveness of our communications and advertisements. We may engage trusted third-party service providers and technology partners, including analytics, advertising and security providers such as Google Analytics, Adobe Analytics, Firebase, or similar providers, who may set and access cookies or similar tools on our behalf. These service providers help us analyse website traffics, measure campaign effectiveness, deliver personalised advertisement and detect security risks.
We ensure that such service provides are subject to appropriate confidentiality and data protection obligations. A current list of our analytics and advertising vendors is available on our website.
We have implemented a cookie management platform that allows you to manage and customise your cookie preferences. Through this platform, you can choose which categories of cookies you wish to allow as well as withdraw or modify your cookie preferences at any time. Your consent preferences will be stored and will expire after a period of time, after which you may be prompted to review and renew your choices.
You may also manage cookies through your browser or device settings, including configuring notifications when cookies are placed or blocking certain cookies altogether. Please note that disabling or blocking certain cookies, particularly those that are strictly necessary, may affect the functionality and performance of our websites or mobile applications. Strictly necessary cookies are required for our digital services to operate properly and cannot be disabled through user preference settings.
Visit our Cookies Usage Guidance website for more information.
How We Use Your Personal Information
Other than as stated above, we may use your personal information for one or more of the following purposes:
- to assess your application(s) /request(s) for our products and services;
- to verify your identity, and to authenticate communication with , and instructions received from you;
- to verify your financial standing;
- to conduct credit checks (including but not limited to upon an application for credit and upon periodic or special review of the credit which normally will take place one or more times each year) and obtaining or providing credit references;
- to contact and to communicate with you in relation to your account and/or services provided to you;
- to manage and maintain your account(s) and facility(ies) with us;
- to better manage our business and your relationship with us;
- to better understand your current and future investment needs and your financial situation;
- to market and to provide you with information on our and selected third parties products, services, offers and/or contests which may be of interest to you, unless you have informed us you do not wish to receive direct marketing communications (in respect of which we may or may not be remunerated) including but not limited to wealth management and related services and products and services and products offered by our co-branding and bancassurance partners (the names of such partners will be provided during the application of the relevant services and products, as the case may be) and in this respect, to contact you via short message service (“SMS”), phone or mobile device, email, fax, mail, websites or browsers, social media or messaging, in person and/or any other appropriate communication channels;
- to improve our products and services and to test, research, analyse and develop new products/ new features of products and/or services;
- to study how you use the products and/or services (analysis for promoting product/service)
- to notify you about benefits and changes to the features of products and services;
- to administer offers, competitions and promotions;
- to respond to your enquiries and complaints and to generally resolve disputes;
- to update, consolidate and improve the accuracy of our records;
- to produce data, reports and statistics which have been anonymised or aggregated in a manner that does not identify you as an individual;
- to conduct research for analytical purposes including but not limited to data mining and analysis of your transactions with us;
- to meet the disclosure requirements of any law binding on CIMB Group;
- to create and maintain credit, behavioural and risk related models for automated credit or suitability scoring and/or any purpose relating to audit, compliance and risk management purposes or functions;
- to analyse your credit and repayment behaviour scoring as part of a lending process;
- to assess financial and insurance/takaful risks;
- to transfer or assign our rights, interests and obligations under any of your agreements with us;
- to protect or enforce our rights to recover any debt owing to us;
- to conduct anti-money laundering checks; for crime detection, investigation, prevention and prosecution;
- to comply with any sanction or law enforcement requirements;
- to enforce and/or defend any of our rights; and/or
- for any other purpose that is required or permitted by any law, regulations, guidelines and/or the order of any court and/or relevant regulatory authorities.
Please be assured that we will ask for your consent before using your personal information for a purpose other than those that are set out in this Privacy Notice and in the privacy terms in your agreement(s) with any CIMB Group entities, and to obtain your explicit consent if we collect, use, maintain or disclose your sensitive personal data.
Use of Automated Processing and Assisted Decision Making Methods
We may automate the processing of your personal information, with limited or without human intervention. We may use the personal data we collect in this processing to conduct data analytics, including profiling and behavioural analysis, to assist or automate decisions in our business operations and to identify and evaluate potential risks. We require that rules followed by such automated systems are designed and tested to make fair and objective decisions.
We may also use specific artificial intelligence and machine learning to help improve our communications and client experience, make our business operational processes safer and more efficient and enable us to provide faster and consistent responses and improve turnaround time. For example, we may use these tools to assist us for the following:
- Chatbots and voicebots for customer engagement – communications and offers to recommend more tailored products and services based on insights from your personal data and interactions with such bots;
- Electronic Know-Your-Customer (eKYC) systems for customer onboarding – systems and algorithms may be used to verify the authenticity of scanned identification documents and photo(s) through image quality, biometric facial recognition and liveliness checks;
- Risk and anti-fraud management tools – monitoring of accounts and transactions to detect unusual activities for risks, unlawful activity, fraud, money laundering, terrorism and other financial crimes (for example, detecting possible misuse of your credit card for fraudulent purposes); and
- Credit-scoring models – to approve financing/loan applications and to facilitate credit decisions.
Disclosure Of Your Personal Information
As a part of providing you with our products and services and the management and/or operation of the same and for the purposes as set out in this Privacy Notice in relation to our use of your personal information, you consent and authorise us to disclose information about you and/or your accounts and/or facilities with us (as well as with other entities within the CIMB Group whether in or outside Malaysia) to:
- other entities within the corporate group of CIMB Group Holdings Berhad, whether in or outside Malaysia;
- companies and persons that act as our agents, contractor, affiliates, service providers, merchant and strategic/ business partners, lawyers, auctioneers, valuers and/or professional advisers (including their sub-agents, sub-contractors, affiliates, service providers, professional advisors), and the employees, directors and officers of all the parties mentioned above, whether in or outside Malaysia);
- companies and/or organisations that assist us in processing and/or otherwise fulfilling transactions that you have requested;
- companies and/or organisations that assist us in providing value added services that you have requested;
- companies and/or organisations that provide services to us in delivering or communicating information about our products and services to you;
- other banks and/or financial institutions, credit reference agencies, credit reporting agencies registered under the Credit Reporting Agencies Act 2010 or credit bureaus (including those established by Bank Negara Malaysia or any of its subsidiaries), any authority, central depository or depository agent in relation to the securities industry; the police; any other governmental or regulatory and authority or body, Cagamas Berhad and/or Credit Guarantee Corporation Berhad, any insolvency department and our appointed debt recovery agents;
- any other person under a duty of confidentiality to us (including any entities within the corporate group of CIMB Group Holdings Berhad) which has undertaken to keep such information confidential;
- any trustees, beneficiaries, administrators or executors;
- your advisers (including but not limited to accountants, auditors, lawyers, financial advisers or other professional advisers) where authorised by you;
- any other person notified by you as authorised to give instructions or to use the account(s)/facility(ies) or products or services on your behalf;
- any third party as a result of any restructuring of facilities granted to you or the sale of debts, or the acquisition or sale of any company by CIMB Group, provided that any recipient uses your information for the same purposes as it was originally supplied to us and/or used by us;
- any guarantors or security providers for the facility(ies) granted by us to you;
- any person intending to settle any moneys outstanding under the facility(ies) granted by us to you;
- any rating agency, insurer/takaful provider or insurance/takaful broker or direct or indirect provider of credit protection;
- any financial institutions, merchants, card scheme operators, electronic-wallet (e-wallet) operators or payment service providers and their networks (including but not limited to VISA International Services Association, MasterCard International Incorporated, Alipay and their affiliates or members, both local and abroad) in relation to any credit card, debit card, e-wallet issued to you or for the remittance, payment or settlement transaction or service utilised by you;
- your intermediaries, correspondent and agent bank, clearing houses, clearing or settlement systems, market counterparties and any company you carry out investment services through us;
- any law enforcement, government, courts, dispute resolution bodies and regulatory bodies including Bank Negara Malaysia and their appointed personnel or party, and/or
- any person connected to the enforcement or preservation of any of our rights under your agreement(s) with us, subject at all times to any laws (including regulations, guidelines and/or obligations) applicable to the CIMB Group (whether in or outside Malaysia). The afore-mentioned third parties may in some instances be located outside of Malaysia.
Further, CIMB Group is permitted to disclose your personal information to third parties in certain circumstances specified below:
- For the purpose declared at the point of the collection of your personal information;
- For the purpose directly related to the purpose declared in this Privacy Notice at the point of collection of your personal information;
- The disclosure is being made to a third party mentioned in this Privacy Notice or to a class or category of third parties identified in this Privacy Notice;
- The disclosure has been consented by you or the individual who is the subject of the personal information;
- The disclosure is necessary for the purpose of preventing or detecting a crime or for the purpose of investigations;
- The disclosure is required or authorised by the Financial Services Act 2013 or Islamic Financial Services Act 2013 or under any other law or by an order of a court;
- With the reasonable belief that it had in law the right to disclose your personal information to the other person;
- Acted in the reasonable belief that it would have had your consent if you had known of the disclosure of your personal information and the circumstances of such disclosure;
- Where determined by the Minister that the disclosure is justified in the public interest; and
- For purposes specified in Schedule 11 or future applicable schedules of the Financial Services Act 2013 and Islamic Financial Services Act 2013.
Marketing
There may be instances where we may share non-Personally Identifiable Information about you to third parties, such as advertising identifiers or one-way coding (e.g. cryptographic hash) of a common account identifier, such as a contact number or e-mail address, to enable the conduct of targeted advertising.
Additionally, the individual entities within the CIMB Group, our merchants and strategic partners may contact you about products, services and offers, which we believe may be of interest to you or benefit you financially. Further, please also be informed that we will only disclose your personal information (which will not include information relating to your accounts) to other entities within the corporate group of CIMB Group Holdings Berhad and/or third parties such as our merchants and strategic partners for marketing and promotional purposes where your express prior consent has been obtained and subject at all times to any laws (including regulations, guidelines and/or obligations) applicable to the CIMB Group (whether in or outside Malaysia).
You may tell us at any time if you do not wish to receive direct marketing communications from us, from individual entities within the CIMB Group and/or from our merchants and strategic. Your latest written instructions to us will prevail. In certain instances where marketing communications from us are sent via browser push to your mobile device, you will have to follow certain prescribed steps to discontinue the receipt of marketing communications from us.
We will treat your personal information as private and confidential and will not disclose your information to anyone outside the CIMB Group except:
- where you have given your express consent as set out in our application form(s) and/or pursuant to your consent and authorisation as contained in this Privacy Notice and/or in the terms and conditions governing the products and services which you have with us;
- where we are required or permitted to do so by law;
- where required or authorised by any order of court, tribunal or authority, whether governmental or quasi-governmental with jurisdiction over CIMB Group;
- where we may transfer rights and obligations pursuant to our agreement(s) with you; and/or where we are required to meet our obligations to any relevant regulatory authority (whether in or outside Malaysia).
Security Of Your Personal Information
Information is our asset and therefore CIMB Group places great importance on ensuring the security of your personal information. We regularly review and implement up-to-date technical and organisational security measures when processing your personal information.
Employees of CIMB Group are trained to handle the personal information securely and with utmost respect, failing which they may be subject to disciplinary action.
Retention Of Your Personal Information
CIMB Group will retain your personal information in compliance with this Privacy Notice and/or the terms and conditions of your agreement(s) with CIMB Group entities for the duration of your relationship with us, or as necessary to perform our obligations to you or to enforce or defend the interests of CIMB Group and/or its customers as may be deemed necessary, or as required by applicable law and CIMB Group’s policies in relation to data retention.
What If Personal Information Provided By You Is Incomplete?
Where indicated (for example in application forms or account opening forms), it is obligatory to provide your personal information to us to enable us to process your application for our products or services. Should you decline to provide such obligatory personal information, we may not be able to process your application/request or provide you with our products or services. You shall update us on any changes to your personal information recorded with us.
Your Rights To Access And Correct Your Personal Information
We can assist you to access and correct your personal information held by us.
Where you wish to have access to your personal information in CIMB Group’s possession, or where you are of the opinion that such personal information held by us is inaccurate, incomplete, misleading or not up-to-date, you may make a request to us via our Data Access Request Form or Data Correction Request Form respectively. These forms are available at our branches.
We will use reasonable efforts to comply with your request to access or correct your personal information within 21 days of receiving your duly completed Data Access Request Form/Data Correction Request Form and the relevant processing fee (if any).
You are entitled to request for selected information in a machine readable format, subject to applicable fees and charges.
Please note that CIMB Group may have to withhold access to your personal information in certain situations, for example when we are unable to confirm your identity or where information requested for is of a confidential commercial nature or in the event we receive repeated requests for the same information. Nevertheless, we will notify you of the reasons for not being able to accede to your request.
We are obligated to retain data under relevant laws and regulations, as well as, for contractual obligations. In this respect, although we do not retain data for longer than necessary, we may not be able to accede to requests to delete data even if you withdraw your consent.
Please also note that CIMB Group may use its discretion in allowing the corrections requested and/or may require further documentary evidence of the new information to avoid fraud and inaccuracy.
Please help us to ensure your personal information (such as your current mailing address(es), e-mail address(es) and telephone number(s) recorded with us are current, complete and accurate by updating us as soon as possible if there are any changes to your personal information recorded with us, as it will ensure that all correspondence and/or communication reach you in a timely manner and enable us to serve you better.
Exercising Choices Over The Disclosure, Retention And Use Of Your Personal Information
Subject always to our contractual rights and obligations and relevant laws and regulations, you may exercise your choice in respect of the disclosure, retention and use of your personal information. Should you wish to do so, kindly contact us at the address/telephone number/ e-mail address given at the end of this Privacy Notice.
Please take note that certain communications such as statements of account and our websites contain standard information regarding our other products and services that cannot be removed without affecting the delivery/provision of our services and/or products, the operation of your account(s) and/or facility(ies) with us, and/or additional costs to you.
This notice is fully compliant with laws (including the Personal Data Protection Act 2010 and other applicable data protection or privacy laws and regulations), and both your rights and our rights are protected under such laws.
Sharing Third Party’s Personal Data
When you provide personal or financial information of third parties to us, including your next-of-kin or dependents, you warrant and represent to us the following:
- You have their consent before sharing their information with us;
- The information you provide about them is accurate;
- To update us in writing if their information changes significantly; and
- You understand that if they withdraw their consent for us to use their information, we may need to terminate your account or service.
Please also ensure that this Privacy Notice is brought to the attention of any such third parties.
Revisions To Privacy Notice
This Privacy Notice may be revised from time to time. Notice of any such revision will be given on CIMB website and/or by such other means of communication deemed suitable by CIMB Group.
Contacting CIMB Group About Your Privacy And How We Handle Your Personal Information
Should you have any query in relation to this Privacy Notice or how we handle your personal information, kindly contact our Consumer Contact Centre or Group Data Protection Officer at the following contact points: