OFBank Security Policy Data Privacy Statement GENERAL STATEMENT This Data Privacy Statement (“Statement”), which has been prepared in relation to R.A. 10173, otherwise known as the Data Privacy Act of 2012, and its implementing rules and regulations, describes how personal information are collected, processed, disclosed, and stored by Overseas Filipino Bank (“OFBank”) and is applicable to all persons who apply for or avail of any of OFBank’s product s and services, or who have established or propose to establish an account with OFBank, or who have provided or propose to provide third party security to OFBank (“Client”). WHAT WE GET FROM YOU To provide the Client with OFBank’s banking/financial products and services and/or to implement Client-requested transactions, OFBank shall collect personal information from the Client which may include, but are not limited to: • Name, Age, Date/Place of Birth, Gender, Civil Status, Nationality • Address and Contact Details • Educational Background • Employment History • Financial Background • SSS/GSIS/TIN • Specimen Signature • Permits, Licenses and Registrations • Status of Pending Civil/Criminal Cases (if any) • Telephone conversion recordings through our Customer Care Center • CCTV footage for security purposes If deemed necessary, OFBank may request to verify the Client’s personal information, or seek additional information from regulatory, judicial, tax authorities, or credit bureaus. PURPOSES OF DATA PROCESSING OFBank shall process the Client’s personal information in connection with any of the following purposes: • Open, maintain, and/or terminate accounts; • Ease of contacting/communication with clients; • To evaluate, approve, provide, or manage applications, financial products and services, and other transactions that the Client has requested; • Maintain know-your-customer information; • Conduct credit and background checks; • Evaluate Client’s eligibility for OFBank’s products and services; • Perform profile and risk analysis ; • Provide extensive and quality support to the Client; • For internal purposes, such as administrative, operational, audit, credit and risk management; or • Comply with its reporting obligation to government authorities under applicable laws, rules and regulations. OUR METHOD OF PROCESSING PERSONAL DATA Processing refers to the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of personal information. OFBank shall collect personal information through, but not limited to, any of the following: • Face-to-face and/or telephone conversation with OFBank personnel • Accomplishment and/or signing of forms/documents • Online enrolment through electronic banking channels and services (e.g., iAccess, Mobile Banking Application, etc.) WHEN DO WE COLLECT PERSONAL INFORMATION OFBank collects information upon the Client’s application for, availment of and/or usage of OFBank’s products and services. This includes, but not limited to, account opening, loan applications, signing-in to e-Banking channels, etc. RECIPIENTS OF INFORMATION Personal information may be processed and shared with various units within OFBank to the extent necessary for any of the purposes herein declared, to credit information bureaus, or to government authorities under applicable laws, rules, and regulations. RETENTION AND DISPOSAL Retention and disposal of personal information shall be made in accordance with the Records Disposal Policy and Records Disposition Schedule of OFBank as approved by the National Archives of the Philippines under RA 9470. HOW WE SAFEGUARD PERSONAL INFORMATION In accordance with the Data Privacy Act, RA 1405 (Bank Secrecy Law), RA 8791 (General Banking Law of 2000), RA 6426 (The Foreign Currency Deposit Act), and BSP Circular 808, series of 2013, OFBank, its employees, agents and representatives, shall handle personal information with utmost care and adhere to appropriate organizational, physical, and technical measures to maintain the confidentiality, integrity and security of all personal information in its possession. THE CLIENT’S RIGHTS In accordance with the Data Privacy Act, the Client has the right to: • Be informed whether their personal information shall or have been processed; • Reasonable access to their personal information; • Require OFBank to update their personal information; and • Suspend, withdraw, or order the blocking, removal, or destruction of personal information of OFBank is not required to retain it by law or for legitimate business purposes. DATA PROTECTION OFFICER Any inquiry or request for information regarding this Statement may be addressed to the following: Data Protection Officer Overseas Filipino Bank, Liwasang Bonifacio 1000 Manila (+632) 8-405-7624 OFB-DPO@mail.ofbank.com.ph