Privacy Policy

We're big on privacy and we do not take your trusting us with your information lightly. So we have developed this Privacy Policy to help you understand what data we collect, why we collect it, and what we do with it.

Privacy Policy

PRIVACY NOTICE

Effective Date: 1 July 2026

1. Introduction

Zenith Bank (Ghana) Ltd (Zenith, we, our, us), a subsidiary of Zenith Bank Plc, was incorporated in April 2005 under the Companies Code, 1963 (Act 179) as a private limited liability company and licensed by the Bank of Ghana in September 2005 under the Banking Act, 2004 (Act 673) as amended by the Banking (Amendment) Act, 2007 (Act 738) to provide financial services under a Universal Banking Licence.

Our registered Address is Zenith Heights, No. 37 Independence Avenue, Accra, Ghana.

We are a Data Controller under the Ghana Data Protection Act, 2012 (Act 843)

Zenith Bank promises to treat all your personal information carefully and responsibly.

This Privacy Notice explains how we collect, use, store, share, and protect personal data relating to:

Customers/Prospective customers

Website users

Employees and job applicants

Vendors and service providers

Visitors to our premises

2. Definitions

"Data Controller" means the person or organisation that determines the purposes and means of processing personal data.

“Data Subject” means a person whose personal data is collected, stored and processed by the bank. The data subject for a record containing personal data is the person whom the data is about.

"Personal Data" means data about an individual who can be identified from that data, or from that data and other information in the possession of the data controller.

“Personal Data Breach” means an event or occurrence (including but not limited to a breach of security) leading to the accidental or unlawful destruction, loss, alteration, disclosure of, or access to personal data.

“Processing” means any operation carried out on personal data, whether by automated means or otherwise. This includes the collection, receipt, recording, organisation, storage, updating, retrieval, use, disclosure, transmission, sharing, alignment, restriction, erasure, destruction, or degradation of personal data.

3. The Personal Data We Collect

Depending on your relationship with us, we may collect, use, store, and transfer different kinds of Personal Data about you:

Data Type

Description

Identity Information

Includes name, date of birth, nationality, marital status, photograph, government ID, biometric data (where required by law), username or similar identifier, and any other similar information.

Contact Information

Includes residential address, postal address, email address, and telephone number.

Financial Information

Includes account details, transaction history, credit information, income details, card information, and other electronic and non-electronic payment details.

Transaction Information

Includes payment history, product usage, international transfers (including SWIFT-related data), location data of transactions where you may have used your debit card, and other details of products and services you have acquired from us.

Technical Information

Includes IP address, browser type, device identifiers, login data, browser plug-in types and versions, platforms, and other technology such as geolocation, model, and user agent on the devices used to access the Bank’s website.

Usage data

Includes information about how you use our website, products, and services.

Marketing and communication data

Includes information we collect when you communicate with us and your preferences regarding the receipt of marketing e-mails.

Employment Information

Includes CVs, references, background checks, and any personal information you provide as part of the recruitment process.

Special Category information

Includes data on persons with disabilities.

CCTV Footage

Images captured at our branches and offices for security purposes.

 

4. How We Collect Your Data

We collect personal data:

·       Directly from you (through means such as account opening forms, applications, website, mobile application, email, telephone, or when you give us feedback or contact us)

·       Through transactions you conduct

·       From third parties (credit bureaus, regulators, fraud databases, etc.)

·       From public sources

·       Automatically via cookies and website technologies

·       Through CCTV systems at our premises

5. Why We Process Your Personal Data

Zenith will only use your personal data where we have your consent or a legal basis to process. Most commonly, we process your personal data for:

·       To enter into a contract with you or perform a contract we have entered into with you

·       Account opening and management

·       Identity verification (KYC)

·       Risk management

·       Anti-money laundering compliance

·       Fraud detection and prevention

·       Regulatory reporting

·       Credit assessment and scoring

·       Transaction processing

·       Customer service

·       Website administration

·       Security monitoring

·       Recruitment and employment management

·       Comply with a legal or regulatory obligation

6. Legal Basis for Processing

We rely on the following lawful bases:

Contract – 

·       To provide banking services and manage accounts

·       To onboard and manage service provider/vendor relationships

·       Recruitment and employment management

Legal Obligation –

To comply with:

·       Anti-Money Laundering laws

·       Tax laws

·       Banking sector regulations

·       Court orders and regulatory directives

·       Law enforcement

Legitimate Interests – 

For fraud prevention, IT security, service improvement, internal reporting, and risk management.

Vital Interests – 

Where necessary to protect life or safety.

Consent –

·       For direct marketing communications (where required).

·       We will require the explicit consent of a parent/guardian when processing the data of a child (under the age of 18 years).

We do not rely on consent where processing is necessary for contractual or legal reasons.

7. Withdrawal of Consent

Irrespective of the initial consent given, an individual may withdraw their consent at any time by submitting a request to withdraw consent. Upon receipt of such a request, we will cease processing the personal data that was based on consent, unless there is another lawful basis that permits continued processing under the Ghana Data Protection Act, 2012.

Please note that where the withdrawn consent relates to processing that is necessary for the provision of certain products or services, we may be unable to continue to provide those services, or certain features of those services may become unavailable. In such circumstances, the withdrawal of consent may result in the suspension, limitation, or termination of the relevant service, where the processing is integral to its delivery.

8. Change of Purpose

We will use your Personal Data only for the purposes for which it was collected, as described in this Privacy Policy or explained to you at the time of collection.

If we need to use your Personal Data for a purpose that is not related to the original reason for collection, we will inform you and obtain your consent where required.

However, in certain circumstances, we may process your Personal Data without your knowledge or consent where this is required or permitted by law.

9. Automated Decision-Making 

To provide our products and services, we may use tools that allow us to automate the processing of your personal information to make decisions about you.  Where such processing produces legal or significant effects, you have the right to request human review.

10. Sharing of Personal Data

We may share personal data with:

·       Regulators and supervisory authorities

·       Credit reference bureaus

·       Other financial institutions

·       Correspondent banks

·       Card schemes

·       SWIFT network providers

·       Service providers (including IT, cloud, audit, legal)

·       Law enforcement agencies

We do not sell personal data.

We have put in place, to the best of our ability and in line with standard global practices, physical, technical, and organisational measures (including secure encryption, anonymisation, and contractual confidentiality and data protection obligations) to ensure the optimum protection of personal data when transferred or shared with third parties.

11. Cross-Border Transfers

Due to the international nature of banking services, your personal data may be transferred outside Ghana. These transfers are necessary for us to perform our contract with you and to comply with our legal obligations.

Where this occurs, we ensure:

·       The recipient country has adequate data protection safeguards; or

·       Appropriate contractual protections are in place.

·       The transfer is covered by provisions included in administrative arrangements between public authorities or bodies

Transfers of your personal data outside of Ghana may occur in the following situations:

·       International funds transfers – when you initiate or receive an international payment, your data may be shared with Money Transfer Operators (MTOs), correspondent banks, or processed through the SWIFT or PAPSS network.

·       Card payments – when you use your debit or credit card, your transaction data is processed through international card schemes (such as Visa or Mastercard), which operate global processing centres.

·       Service providers – we may engage third-party service providers (including cloud hosting, etc.) that are located outside Ghana.

·       Regulatory obligations – in certain cases, we may share your data with foreign regulators or authorities to comply with applicable laws and anti-money laundering requirements.

 

12. Data Retention

Zenith Bank stores a broad spectrum of personal information. All information Zenith Bank holds is stored and retained or stored and destroyed in compliance with DPA’s guidelines on the retention of records and personal data.

Zenith Bank will retain your personal data as long as the information is active on the bank’s systems and necessary for the bank’s service delivery purposes. This retention period is verified and established with special consideration to the following areas:

  • The requirements of the bank
  • The type of personal data
  • The purpose of processing
  • Lawful basis for processing
  • The categories of data subjects

As a regulated financial services institution, the bank will retain your personal data for ten (10) years after the exit of the relationship by the data subject, or as may be required by regulation. When the personal data is no longer needed, or beyond the stipulated retention period, Zenith Bank will delete it from its systems and records or take steps to securely archive it while protecting your identity and privacy rights.

13. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

·       Encryption of sensitive data, including payment and transaction information

·       Strong access controls

·       Secure banking systems and infrastructure, with physical and environmental safeguards at our facilities and data centres

·       Staff confidentiality obligations

·       Continuous monitoring of systems and transactions to detect and respond to suspicious or unauthorised activity

·       Robust incident management procedures to promptly address and contain data security incidents

·       Regular vulnerability assessments, penetration testing, and timely system updates to address security risks

·       Data minimisation and strict controls over the use and sharing of customer information

·       Oversight of third-party service providers to ensure they maintain appropriate data protection and security standards

·       Ongoing staff training and confidentiality obligations to ensure responsible handling of customer information

Despite these measures, please note that no system is completely secure. However, we continuously review and enhance our security practices to protect your personal data and maintain the integrity of our banking services.

In the event of a personal data breach, we will notify the regulator and affected individuals where legally required.

14. Your Rights

Under the Ghana Data Protection Act, 2012, you have the right to:

·       Request access to your personal data

·       Request correction of inaccurate or incomplete data

·       Object to certain types of processing like direct marketing and automated profiling

·       Request restriction of processing

·       Request deletion where applicable

·       Have your data transferred to another organisation

·       Withdraw consent (where processing is based on consent)

·       Lodge a complaint

Requests to exercise your data subject rights should be submitted to dataprotectionsupervisor@Zenithbank.com.gh

We will respond within the statutory timeframe.

We may ask you to provide specific information to confirm your identity and verify your right to access your Personal Data or exercise any of your other rights. This is a security measure to ensure that Personal Data is not disclosed to anyone who is not authorised to receive it. We may also contact you to request additional information where necessary to process your request.

15. Cookies

Our website uses cookies to:

·       Improve functionality

·       Analyse usage

·       Enhance user experience

You may disable cookies via browser settings; however, some website functionality may be affected.

16. Complaints

If you wish to make any enquiries regarding your personal data, or are dissatisfied with our handling of your personal data, you may contact:

Data Protection Supervisor

Zenith Bank (Ghana) Ltd (Ghana) Limited

Telephone: +233 531100068

Email: dataprotectionsupervisor@Zenithbank.com.gh

If we do not handle your enquiry/complaint to your satisfaction, you also have the right to lodge a complaint with the regulator:

Data Protection Commission Ghana

East Legon, Accra

Telephone: +233 256301533

Email: info@dataprotection.org.gh

17. Changes to this Notice

We may update this Privacy Notice from time to time. Material changes will be published on our website. We will alert you to changes by, for example, placing a notice on our website and/or by sending you an email.

Send this to friend