Last updated : 11/05/2026
1. Preamble
Banca Popolare di Sondrio (Suisse) SA, Monaco Branch (hereinafter "BPS (SUISSE) MONACO" or the "Institution") attaches particular importance to the protection of personal data and is committed to ensuring its confidentiality, integrity and security, in accordance with Monegasque Law No. 1.565 of 3 December 2024 on the protection of personal data and its implementing texts.
This policy aims to provide clear and transparent information to all data subjects – existing and prospective clients, employees, applicants, subcontractors, external service providers, visitors and partners – on how their personal data is collected, processed, stored and protected in the context of the Institution's banking activities.
The Institution provides information on multiple levels. Specific information notices are given for certain interactions (e.g. account opening, online forms, recruitment, video surveillance, professional messaging).
2. Definitions
Personal data
Any information that directly or indirectly identifies a natural person (such as name, account number, address, bank details, etc.).
Processing of personal data
Any operation or set of operations performed on personal data, regardless of the method used (collection, recording, organisation, storage, adaptation, alteration, extraction, consultation, use, disclosure by transmission or dissemination, matching, restriction, erasure or destruction, etc.).
Data Controller
BPS (SUISSE) MONACO, who determines the purposes and means of processing the personal data of its clients and contacts.
Data Subject
Any natural person whose data is collected or processed by BPS (SUISSE) MONACO (existing and prospective clients, job applicants, etc.).
Processor
Any natural or legal person who processes personal data on behalf of BPS (SUISSE) MONACO and on its express instruction.
Recipient
Any natural or legal person authorised to receive personal data processed by BPS (SUISSE) MONACO (including regulatory authorities and authorised technical service providers).
3. Security and confidentiality
BPS (SUISSE) MONACO attaches great importance to the security and confidentiality of your personal data. Because of this, the Bank implements appropriate technical and organisational measures to protect your data against any loss, alteration, disclosure, misuse or unauthorised access.
These measures include, in particular:
4. Personal data processing activities
As part of its banking, regulatory and operational activities, BPS (SUISSE) MONACO carries out a number of personal data processing activities.
Each processing activity corresponds to a specific use of the data (such as account management, regulatory compliance, security or human resources management) and is subject to specific information notices.
In accordance with Law No. 1.565 of 3 December 2024, for each processing activity, the following notices specify the purposes pursued, the categories of data concerned, the data subjects, the applicable retention periods and the recipients of the data.
4.1 Banking relationship management
Purpose
Opening, managing and monitoring accounts, loans, financial instruments, online banking services (GO-Banking) and the execution of banking transactions.
Categories of data processed
Data subjects
Clients, authorised representatives, legal representatives, beneficial owners, administrators, company directors and managers, cardholders.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Authorised employees, technical service providers, competent authorities.
4.2 Regulatory obligations (AML/CFT, CRS, FATCA)
Purpose
Compliance with legal obligations relating to anti-money laundering, counter-terrorist financing, anti-corruption, and international tax reporting requirements.
Categories of data processed
Data subjects
Clients, authorised representatives, legal representatives, beneficial owners, administrators, company directors and managers, cardholders, beneficiaries.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Local and head-office compliance teams, specialised service providers, competent authorities.
4.3 Security (video surveillance, access checks, IT security)
Purpose
Protection of individuals, property, premises and information systems.
Categories of data processed
Data subjects
Employees, visitors, clients, service providers.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Authorised personnel, security service providers, authorities in the event of an incident.
4.4 Communication and telephony
Purpose
Management of professional communications, service-quality monitoring and evidence of communications.
Categories of data processed
Data subjects
Existing and prospective clients, employees, and any person sending or receiving emails.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Authorised employees and, where applicable, competent authorities.
4.5 Human Resources
Purpose
Recruitment, administrative management of staff, payroll, access rights, training, career management and offboarding.
Categories of data processed
Data subjects
Employees, candidates.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Local and head-office HR teams, management, social-security and IT service providers, and competent authorities where applicable.
4.6 Archiving (paper and electronic documentation)
Purpose
Retention of documents for legal, evidential and auditing purposes.
Categories of data processed
Client files, HR files, tax, accounting and legal documents.
Data subjects
All persons affected by the processing operations.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Authorised departments, archiving service providers, competent authorities where applicable.
4.7 Complaints, litigation and whistleblowing
Purpose
Management of complaints, disputes, defence of rights and professional whistleblowing mechanisms.
Categories of data processed
Data subjects
Clients, employees, whistleblowers.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Legal teams, management, competent authorities where applicable.
4.8 Data protection (rights and breaches)
Purpose
Managing requests to exercise rights and managing personal data breaches
Categories of data processed
Data subjects
Data subjects affected by the processing operations.
Retention period
Data is retained for the period necessary to achieve the purposes of the processing, then archived where applicable in accordance with legal, regulatory, tax, accounting and prudential obligations, as well as applicable limitation periods.
Recipients
Data Protection Officer (DPO), relevant internal departments, APDP where applicable.
5. Origin of the data
The personal data processed by the Institution may come from:
In this context, certain searches or checks may generate technical traces (logs) on the part of these bodies or service providers, in accordance with applicable legal obligations.
The Institution undertakes to process this data in compliance with the principle of minimisation and to inform the data subjects of any specific collection in accordance with the applicable regulations.
6. Retention principle
Personal data is retained by BPS (SUISSE) MONACO for a period not exceeding that strictly necessary for fulfilling the purposes for which it is processed, in accordance with the requirements of Law No. 1.565 of 3 December 2024 and with legal, regulatory, prudential, accounting, tax and anti-money-laundering and counter-terrorist-financing obligations.
The applicable retention periods are determined in particular according to:
Certain data may be subject to intermediate archiving when its retention is necessary to meet legal or regulatory obligations, or for the defence of the Institution's rights and interests, before its final deletion or anonymisation.
More detailed information on the retention periods applicable to certain processing operations may be provided in specific information notices or at the request of the Data Protection Officer.
7. Legal bases for processing
Depending on the nature of the processing carried out, the collection and use of your personal data by BPS (SUISSE) MONACO has one or more of the following legal bases:
8. Recipients and data transfers
The personal data processed by BPS (SUISSE) MONACO is accessible only to:
As part of its due-diligence and regulatory compliance obligations (notably in the areas of anti-money-laundering, counter-terrorist-financing, anti-corruption, international sanctions and client due diligence), the Institution may be required to disclose certain personal data to specialised service providers (e.g. client information research).
Some of these service providers may be located outside Monaco or the European Union. In such cases, the Institution implements all appropriate safeguards required by the applicable regulations to ensure an adequate level of protection for personal data, in particular through the use of standard contractual clauses or equivalent mechanisms.
9. Your rights
In accordance with Monegasque regulations on the protection of personal data, you have the following rights:
To exercise any of these rights, you are free to contact the Data Protection Officer (DPO) by email at dataprotection@bps-suisse.mc or by post at the following address: [BPS (SUISSE) MONACO, 3, rue Princesse Florestine B.P. 416, MC - 98011 Monaco Cedex]. Proof of identity may be requested to ensure the confidentiality of your information.
If, after contacting us, you consider that your rights are not being respected, you may refer the matter to the Monegasque Personal Data Protection Authority (APDP) to lodge a complaint.
10. Cookies and trackers
When you browse our website, cookies that are strictly necessary for the operation of the site may be placed on your device.
These cookies make it possible, in particular, to manage your session, display information banners and ensure the proper functioning of the site's features.
The cookies used by BPS (SUISSE) MONACO are exclusively technical cookies (such as session cookies or consent-management cookies) and are not used for advertising purposes or to track your browsing for profiling purposes.
You can configure your browser to block or delete these cookies. However, refusing certain technical cookies may result in a deterioration of the site's functioning.
For more information, please see our Cookies Policy below.
11. Changes and updates
This personal data protection policy may be amended at any time to take into account legal, regulatory or organisational developments in the field of personal data protection. We invite you to consult this page regularly to take note of any updates or changes made to this policy.
12. DPO contact/complaints
If you have any questions relating to this personal data protection policy or to the processing of your personal data, or if you wish to exercise your rights or lodge a complaint, please contact our Data Protection Officer (DPO):
In the event of the DPO's absence or unavailability, a deputy DPO is appointed to ensure continuity in handling requests and communications with data subjects and with the Personal Data Protection Authority (APDP).