Consent for Data Processing
Personal data is processed only after obtaining explicit and informed consent, which can be withdrawn.
🌐 www.karnatakabank.bank.in
Explicitly mentions collection of sensitive data (biometrics, financial info) and outlines security measures, but lacks detailed safeguards for specific data types.
References DPDPA 2023, RBI guidelines, and outlines user rights (access, correction, erasure), but lacks specific GDPR/CCPA alignment details.
Provides user rights and grievance mechanisms, but includes broad data sharing clauses and potential service restrictions on consent withdrawal.
Uses structured sections and plain language, but embedded in lengthy website markup, reducing readability for non-lawyers.
The provided document is a webpage for a bank's privacy policy, but it is heavily intermixed with extensive website navigation, menus, and unrelated content. The actual privacy policy text is buried within this structure.
Problematic aspects of the privacy policy content itself, extracted from the document, are:
The policy states it applies to the collection and processing of Personal Information "as per the above-mentioned laws," but the introductory paragraph references "applicable governing laws in India," creating initial ambiguity before specific acts are named later.
It defines a "Child" as under eighteen, but a later section on protecting children's data states the bank does not knowingly collect data from individuals under 18, which seems to contradict the definition by not acknowledging processing for minors with parental consent within that age bracket.
The section on the lawful basis for processing cites the Digital Personal Data Protection Act, 2023 (DPDPA) and lists "Consent" and "Legitimate Uses." However, it does not specify what these legitimate uses are, only giving vague examples like "compliance with legal requirements," which lacks transparency for the user.
The consent clause states that providing consent agrees to the collection and processing "in accordance with this Privacy Notice." It also states that providing wrongful data is the user's responsibility, which could be interpreted as shifting undue burden onto the user.
The policy states that withdrawal of consent may restrict access to online services, which is a potential negative consequence for exercising a right, though it notes it does not affect prior lawful processing.
The types of Personal Information collected are listed as "including but not limited to," which is an open-ended clause that does not clearly define the limits of collection.
The use of personal information includes "Marketing and promotional services (with consent)" but also "Research, analytics, audits, and reporting" without explicitly linking these to consent or anonymization, potentially allowing broad usage.
The sharing and transferring section mentions cross-border transfers may occur with "contractual safeguards" but does not specify what these safeguards are or to which jurisdictions data may be transferred, lacking specific detail.
The policy states that in the event of a personal data breach, timely notification will be provided to affected individuals via email or SMS per legal requirements, but it does not define what "timely" means, which could be subjective.
The retention section states data is kept as long as necessary for legal, regulatory, and business purposes, and then securely deleted. However, it also states a minimum retention period of one year is required by the DPDPA, even after purposes are fulfilled, and mentions retention for KYC, AML, etc., which could conflict with the principle of deletion when no longer necessary.
The policy is stated to be subject to change, with material changes being notified. Continued use of services implies acceptance unless consent is withdrawn. This could mean users must proactively monitor for changes and withdraw consent to avoid being bound by new terms they have not actively accepted.
The document structure itself is problematic as the privacy policy is not presented in a clear, standalone, and easily readable format but is embedded within extensive website code and navigation elements, making it difficult for a user to review.
Personal data is processed only after obtaining explicit and informed consent, which can be withdrawn.
Collects name, financial details, government IDs, biometric data, and other voluntarily shared information.
Information may be shared with affiliates, partners, and regulators; cross-border transfers occur with safeguards.
Data retained as long as necessary for legal and business purposes, with a minimum one-year retention.
Provides a grievance officer contact for data concerns; internal mechanism must be exhausted first.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free