Data Privacy Statement
This page sets out how we handle personal data in the performance of our functions, and how we protect the privacy of the individuals whose data we process. By visiting our website, you confirm that you are over 18 years of age and confirm that we can process your personal data as provided below. If you do not agree to the terms of this Privacy Policy, please do not use the website.
1. What Personal Datai do we collect?
EADB may processii or use data that relates to natural persons with whom it has direct or indirect dealings. Such Personal data may include a person’s name; identification card number; phone number; location data; online identifiers e.g., email address; screen names; IP address; device IDs; etc
2. How do we collect your data?
The Bank receives most Personal data directly from the Data Subjectiii through information provided to us for purposes of obtaining our services, providing us with goods and services, applying for employment etc. The Bank also obtains personal data indirectly for instance, through information collected automatically e.g. through cookies when you visit and use the Bank’s website or, in certain instances where Personal data is received from at third party. Such third party must however ensure that it has obtained your prior consent authorizing the sharing of and processing of the personal data with us.
Some of the instances when EADB will collect, and process personal data include when you:
• Register, apply for or use any of our products or services or submit your Personal data or that of your related parties as you participate in the foregoing activities;
• Use or view our channels including our website, send or receive an email to an employee of the Bank or through the Bank’s server; or call or receive a call through the Bank’s switch board;
• Visit our premises and provide such data;
• Participate in our recruitment process;
• Supply or bid to supply EADB with any goods or services;
• Voluntarily complete a customer survey or provide feedback through any channel availed by us or via email;
• When you get in touch with us or provide Personal data to us for any envisaged purposes including requests to participate in EADB arranged events, etc
3. Why do we collect your personal data?
We collect your Personal data in order to meet our business objectives and to ensure compliance with the applicable regulatory framework. Personal data is only used to the extent necessary for the Bank to provide our services, to comply with our legal obligations or meet our legitimate interests. Typically, the Bank uses the Personal data it collects to undertake due diligence on its counterparties, this includes identifying the person the Bank is dealing with together with its related persons. Personal data also serves other purposes like understanding which counterparties interact with our channels and for which reasons.
The decision on whether or not to disclose your personal data is your choice. However, should you choose not to provide some of the required information, this may limit the ability of the Bank to provide certain services to you or may limit your access to certain functions on our website. Whenever you are requested to provide information, please limit your disclosure to what is requested and do not provide more personal information than is required.
4. When and how do we share your data?
In certain instances, the Bank will share your Personal data with third parties, but only to the necessary extent. Examples include:
• Instances in which you take up any of the Bank’s products or services : EADB may share your data with its development partners / funders for that product; internally within the Bank’s staff and agents in any of its country offices; and externally with its professional advisers;
• The Bank may share personal data with service providers for instance companies that send or receive information on its behalf;
• EADB may send your data to, and use the information from, credit reference bureaus for purposes of assessing credit worthiness and preventing fraudulent practices;
• The Bank may use your personal information to undertake background checks with relevant government agencies, for instance land or company registries; security agencies like Interpol etc. prior to the process of entering a contract with you or during the subsistence of a contract; and
• With Government Authorities in order to comply with the relevant laws.
5. How do we store your data?
The Bank securely stores your data at its head office, its regional offices, through electronic means and such other places as deemed necessary. EADB will keep your data for as long as the purpose for which it was collected and other purposes that are not incompatible with the purpose continue. Generally EADB will only maintain your personal data for as long as is necessary. EADB shall delete, erase, anonymize or pseudonymize personal data whose retention is no longer necessary.
The Bank has in place appropriate measures to ensure the confidentiality and integrity of personal data provided to us. Such measures include having appropriate technical and organizational measures that ensure that only authorised personnel have access to the data necessary for their processing tasks among others.
The Bank identifies and assesses internal and external risk to personal information in its possession and adopts appropriate mitigating strategies and safeguards against the identified risks; regularly interrogates the effectiveness of adopted safeguards; continuously updates its responses as new risks emerge or deficiencies are identified. We have due regard to generally accepted information security practices and procedures as per industry, professional rules and regulations as well as those enshrined in the Bank data policy documents.
6. What are your data protection rights?
The Bank would like to make sure that you are aware of your data protection rights. Every Data Subject is entitled to the following rights that may be exercised under certain conditions:
The right to access – You have the right to request EADB for copies of your personal data. We may charge you a small fee for this service.
The right to rectification – You have the right to request the Bank to correct any information you believe is inaccurate. You also have the right to request EADB to complete the information you believe is incomplete.
The right to erasure – You have the right to request us erase your personal data.
The right to withdraw consent – where we process data based on your consent, you have the right to withdraw your consent but this shall not affect the lawfulness of processing based on prior consent before such withdrawal.
The right to restrict processing – You have the right to request that EADB restricts the processing of your personal data.
The right to object to processing – You have the right to object to the Bank’s processing of your personal data.
The right to data portability – You have the right to request us to share the Personal data that we have collected with another organization, or directly with you. The Bank may charge a fee for this service.
If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, our contacts are stated in section 12 of this statement.
7. Cookies
Cookies are text files placed on your computer to collect standard Internet log information and visitor behaviour information. When you visit our website, we may automatically collect information from you through cookies or similar technology.
8. How do we use cookies?
The Bank uses cookies in a range of ways to improve your experience on our website, including:
• Keeping you signed in
• Understanding how you use our website
9. How to manage cookies
You can set your browser not to accept cookies. However, some of our website features may not function as a result.
10. Privacy policies of other websites
The EADB website contains links to other websites. Our privacy policy applies only to our website, so if you click on a link to another website, you should read their privacy policy.
11. Changes to our privacy policy
The Bank keeps its privacy policy under regular review and places any updates on this web page.
12. How to contact us/ Contacts for the Data Protection Officer
If you have any questions about the Bank’s privacy policy, your Personal data that we hold, would like to exercise one of your data protection rights or make a complaint, please do not hesitate to contact us.
Email us at: enquiry@eadb.org
Call us: +256417112900
Or write to us at: The East African Development Bank
P.O. Box 7128, Kampala Uganda
(Attention: Data Protection Officer)
i Personal Data means information that relates to, identifies or that can be used directly or indirectly to identify a Data Subject.
ii Data processing mean any operation or sets of operations which is performed on Personal data or on sets of personal data whether by automated means, such as –
• Collection, recording, organizing, structuring;
• Storage, adaptation or alteration;
• Retrieval, consultation, use;
• Disclosure by transmission, dissemination, or otherwise making available;
• Alignment or combination, restriction, erasure, or destruction
iii An identified or identifiable natural person who is the subject of Personal data. For purposes of the EADB Data Protection and Privacy Policy, Data Subjects do not include legal persons, e.g. a company. Data Subjects include past and present EADB customers, individuals associated with institutional and business customers, applicants for EADB products or services, Third Party’ personnel, present and past staff and their dependents, applicants for EADB jobs, users / visitors to the Bank’s website and any other individual whose personal data is acquired pursuant to actual or prospective contractual arrangements or other dealings with the EADB




