Privacy Notice
At Banque Saudi Fransi ("BSF"," Bank", "us", "we", "our") we value your privacy and the trust you place in us when you share your Personal Data. Privacy Notice (the “Notice”) outlines how we collect, process, use, manage, disclose and protect your personal data. This Notice is framed according to the applicable regulations including the Personal Data Protection Law and Regulations in the Kingdom of Saudi Arabia (“PDPL”).
Why We Collect, Process, and Use Your Personal Data
We collect and use your Personal Data to Provide you with our services including:
- Recruitment and Hiring: to assess qualifications, skills, and experience to make hiring decisions.
- Employee Management: to manage employment records, contracts, performance review, promotions, absence management..., etc.
- Payroll and Benefits: to administrate salaries, benefits, GOSl and Muddad administrations and others.
- Legaland Regulatorycompliance: to adhere to and comply with Labor law, government regulations and any other regulatory/legal requirement (SAMA, HRSD,GOSl, ...etc).
- Training and Development: to provide you with professional development programs and career progression.
- Disciplinary and grievance Procedures: to handle grievances and disciplinary actions in case of misconduct.
- Security and Safety purpose: to provide and manage access to BSF premises, and to ensure the security of our premises and our employees by monitoring through surveillance system such as CCTV.
- Benefits: to provide you with BSF benefit including, but not limited to provide the employees with the insurance policy for them and their families, saving plan, education allowance, child care and marriage allowance, loans, and business mission.
- Informed decision-making: to make accurate and informed decisions, whether it's related to hiring or business strategies.
- Performance Measurement: to track and measure performance across various functions, allowing better performance management.
Lawful Basis for Processing your Personal Data
At BSF, we prioritize transparency in our dealings, especially when it comes to managing and utilizing the Personal Data you entrusted us with. We gather and use your data based on the following legal basis:
- Contractual Obligation: To Process your Personal Data to fulfill our obligations under your employment contract.
- Legitimate Interest: To protect us (including the protection of relevant third party’s inerets, including without limitations, our shareholders, our directors, and our customers’s interest), and our employee's legitimate interest.
- Actual interest: To achieve moral or material interest to you.
- Legal Obligation: To meet our regulatory and legal requirements.
- Consent: When we Process your Personal Data based on your Consent.
What Personal Data We Collect, Process, and Use
When employed by us, the following data may be collected:
| Personal Data Type | Description |
|---|---|
| Personal Data | Full name, gender, nationality, citizenship, National/Residency ID number and soft copy, passport, mobile number, personal email address, relative data, telephone number, age, emergency contact, birth date, birth place, marital status, national address, emergency contact number and name, your family data including name and ID, personal assets, account number, GOSI number, account balance, account transaction data, health status fit or not fit, education level, any relationship with politically exposed person and relevant data, your relatives' information in our custody, and any personal data related to conflicting interests. |
| Credit Data | SIMAH report. |
| Biometrics Data | Signature, handwriting, fingerprints, voice, and face recognition data. |
| Health Data | In some conditions we may collect medical reports, health condition, whether physical, mental or psychological conditions. |
| Other Data | Personal Data for compliance with laws and regulations and regulatory requirements, or for delivering online services. Such as, location (including geographic location and network IP address), cookies, communication records (including video or audio records).Personal data arising from employee investigation, e.g., Personal Data collected during customer due diligence, sanction or anti-money laundering checks. |
How We Collect Your Personal Data
- When you directly provide us your Personal Data
- When we collect and verify your Personal Data from other sources such as, licensed credit bureaus, public entities, financial and regulatory bodies, external sevice providers acting on our behalf, or based on our instructions, including but not limited to GOSI, QIWA, MUDDAD, General Directorate of Passports, medical providers, etc.
- In some cases, we Collect and Process certain data based on your explicit consent, which ensures that we use your data only in ways that you agreed to.
Data Retention, Storage, and Destruction
Your Personal Data will be stored and retained indigital or physical forms securely at BSF data centers in the Kingdom of Saudi Arabia, or at a cloud computing services provider in the Kingdom of Saudi Arabia. We will retain your data to the extent necessary or as required by the applicable and relevant laws, and for the duration necessary to fulfill the outlined purposes in this Notice, suchduration might be changed or extended based on regulatory requirements for the retention of Personal Data or connected information. At the lapse of such duration(s) or upon your request, to the extent technically applicable and legally permissible, such data will be destructed securely through secured deletion mechanism, or such data will be anonymized whenever deletion would not be possible. In case your Personal Data is being transferred outside the Kingdom of Saudi Arabia for legitimate purposes, it will be done in compliance with PDPL and SAMA’s approval, as applicable.
Data Protection
Your Personal Data security is important to us. We deploy both organizational and technical measures, including periodic audits, staff training, and strict policies and procedures for protection against unauthorized data access or processing. Rest assured, BSF stores your Personal Data with appropriate security measures, such as encryption, masking, and restricted access mechanisms.
Although we do our due diligence, we make no warranties, towards the security of third-party links in our websites. BSF assumes no liability or responsibility for the completeness, accuracy, reliability, nor the protection from third-parties (including without limitation software, websites, etc.), if any, which may be linked to our websites. You are responsible to review the terms, notices, and agreements of such third parties, are your discretion and independently agree or reject such.
How We May Share Your Personal Data
Your Personal Data may be shared:
- Within BSF's affiliates, subsidiaries and sister companies to enable seamless administration of employee-related processes across affiliated entities in compliance with legal and internal data protection requirments.
- With competent authorities, agencies and regulatory bodies, whether for verification purposes, to fulfil regulatory compliance obligations, or for other legal requirements.
- With third party who assist in providing service on behalf of BSF.
- Where there is a legitimate interest, public interest or legal obligation.
BSF maintains the utmost confidentiality of all collected data. Data disclosure occurs only under legal mandates or to enhance our services, in accordance with this Notice.
In the case of transferring Personal Data outside the Kingdom, or sharing it with external entities, it is carried out judiciously, adhering to the Personal Data Protection Law (PDPL) or any other applicable laws of the Kingdom of Saudi Arabia.
Individual Who Lacks Legal Capacity
For employees who fully or partially, lack or become lacking of legal capacity, we require legal guardian consent before Processing any Personal Data.
Your Rights as an Employeeor a Candidate
- Right to be Informed.
- Right to Access
- Right to Access Personal Data
- Right to Request Correction
- Right to Destruction
- Right to Withdraw Consent
You have the right to be informed about the legal basis and the purpose of the Collection and Processing of your Personal Data.
You have the right to access your Personal Data through the channels provided by The Bank.
You have the right to access or receive a copy of your Personal Data through the channels provided by BSF in a structured, commonly used, and readable soft or hard copy format if possible.
You have the right to request correction, completion or updating your Personal Data available with BSF.
As long as there is no legal requirement or legitimate Interest to Process or retain the data, you have the right to request Destruction of your Personal Data available with BSF, if it is no longer needed for the purpose it was originally collected.
You have right to withdraw your Consent whenever it is given as long as there is no legal requirement to Process the data.
Privacy Notice Amendments
BSF may update this notice occasionally, especially to comply with new laws. Always refer to this section for the latest version. The current version was last updated on November, 2025.
Contacting Us
Maintaining the privacy and trust of your personal data is of utmost importance to Banque Saudi Fransi, and for any queries or to exercise any of the rights mentioned, please contact our Data Privacy Office at DPO@bsf.sa
Explanation of Key Terms
| Term | Explanation |
|---|---|
| PDPL | Personal Data Protection Law |
| Processing | The collection of Personal Data by BSF, either from the Data Subject directly, a representative of the Data Subject, any legal guardian over the Data Subject, or any other party. |
| Destruction | Any action taken on Personal Data that makes it unreadable and irretrievable, or impossible to identify the related Data Subject. |
| Processing | Any operation carried out on Personal Data by any means, whether manual or automated, including collecting, recording saving, indexing, organizing, formatting. storing, modifying updating, consolidating, retrieving, using disclosing, transmitting, publishing, sharing, linking, blocking, erasing and destroying data. |
| Consent | Consent is a crucial concept that refers to the Data Subject's freely given. specific, informed, and unambiguous agreement to the Processing of their Personal Data. It's a fundamental requirement for organizations to collect, use, or share Personal Data lawfully and transparently. |
| Data Subject | The individual to whom the Personal Data relates (also referred to as "you" or "employee (s)" in this notice). |
| BSF | Banque Saudi Fransi |
| Personal Data | Any element of data, regardless of its source or form, that independently or when combined with other available information could lead to the identification of an individual specifically, or that may directly or indirectly make it possible to identify an individual, including but not limited to name, personal identification number, addresses, contact numbers, license numbers, records, personal assets, bank and credit card numbers, photos and videos of an individual, and any other data of personal nature. |