Information about personal data protection and data processing when using the S-Portal.

Home

Sparkasse Bank AD Skopje, as part of the Steiermärkische Sparkasse Group, is a legal entity that, in accordance with the Personal Data Protection Law and the provisions of the General Data Protection Regulation (GDPR) and applicable regulations, is defined as the Controller that collects, processes, uses, and analyzes the personal data of its clients.

The bank, as an employer and controller of your personal data, is highly aware of the importance of personal data for each individual. Therefore, it fully respects the privacy rights of its clients when processing their personal data in accordance with the Personal Data Protection Law and the provisions of the General Data Protection Regulation (GDPR).

The purpose of the Personal Data Protection Law

The purpose of the Personal Data Protection Law is the protection of personal data and the right to privacy in relation to the processing of personal data of individuals.

Definitions

„Personal data“ means any information relating to an identified or identifiable natural person (data subject), particularly based on an identifier such as name and surname, personal identification number, location data, an online identifier, or based on one or more specific characteristics related to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

„Processing of personal data“ means any operation or set of operations performed on personal data, or a set of personal data, whether automated or not, such as: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

„Controller“ means a natural or legal person, public authority, governmental body, or legal entity established by the state to exercise public powers, agency, or other body, which alone or jointly with others determines the purposes and means of processing personal data.

„Processor of a personal data set“ means a natural or legal person, public authority, governmental body, or legal entity established by the state to exercise public powers, agency, or other body which processes personal data on behalf of the controller.

Controller of a personal data set

Sparkasse Bank AD Skopje Vasil Iljoski 14, 1000 Skopje
Tel.: +389 2 15 050 Fax: +389 2 3200 515 Email: contact@sparkasse.mk

Authorized Person for Personal Data

Personal Data Protection Officer
Gjorgji Rajchinoski Tel.: +389 2 3200 507 Email: privacy.protection@sparkasse.mk

Personal data processed by the Bank and the sources from which it is obtained

The Bank processes personal data that it receives directly from you in its original form when logging in and using the S-Portal.

Your personal data processed by the Bank when using digital channels are:

  • Name and Surname
  • Personal Identification Number
  • Email address
  • IP address
  • Home address
  • Contact phone number
  • Account number
  • Username

*The mobile application offers the possibility to log in and authorize accounts through Fingerprint/Face ID/Touch ID features on the client's mobile device. The Bank does not collect, store, or process biometric data and does not have access to it.

For what purposes are personal data and information used?

Your personal data is processed by the Bank for the authentication of client data in order to enable access to the S-Portal.

Legal basis for processing personal data in the Bank

The Bank processes your personal data based on:

  • Fulfillment of contractual obligations, as well as for the purpose of taking actions at the request of the data subject before entering into a contract
  • Legal obligation based on the Law on Payment Services and Payment Systems

Users of personal data

Access to personal data is granted to authorized personnel employed in the organizational units of the Bank, as well as engaged individuals for the purpose of fulfilling contractual and legal obligations, or those who have a legitimate interest.

The Bank may provide information about its clients only if it represents a legal obligation, a contractual obligation, or if the client has given consent for it, as well as for the purposes and goals of auditing, if necessary for reservation activities.

Retention period of personal data in the Bank

Personal data is not stored on the website portal. Upon client request, access to documents and notifications is provided in accordance with the Law on Payment Services and Payment Systems. According to the Law on Prevention of Money Laundering and Financing of Terrorism, the Bank is required to retain data for 10 years from the moment of termination of the business relationship with the Bank.

The Bank retains personal data no longer than necessary for the purposes for which it is processed, i.e., as long as there is a contractual obligation with the client. The Bank needs to protect its rights before judicial or other authorities and as long as there is a legal obligation to retain the data. After this period, in an internally determined procedure, the Bank destroys the data and documents, including data processed by third parties on behalf and for the account of the Bank.

Transfer of personal data to third countries

Your personal data will be transferred to third countries (EU countries, as well as countries outside the EU) only if this is required by law/regulation, contract, the legitimate interest of the bank, or based on your consent, including transfers within the Group to which the bank belongs, outside of the home country.

Rights of data subjects for the protection of personal data

The principle of accountability and transparency is a fundamental principle of any personal data protection system.

The Bank, as the data controller, has established principles and mechanisms for transparent information and the exercise of the rights of data subjects in accordance with the law.

The Bank informs the data subject about their rights and obligations at the time of collecting the data or establishing the business cooperation.

According to the Law on the Protection of Personal Data, the basic rights for the protection of personal data are:

  • Right to transparency and information;
  • Right to access personal data;
  • Right to rectify inaccurate personal data and to complete incomplete personal data by providing an additional statement;
  • Right to erasure of personal data when the legal conditions for this are met;
  • Right to restrict the processing of personal data;
  • Right to data portability, where the bank transfers your personal data to another controller, if the conditions are met in accordance with the Law on the Protection of Personal Data;
  • Right to object;
  • Right not to be subject to a decision solely based on automated processing, including profiling;
  • Right to withdraw previously given consent.

For any questions and to exercise their rights, the data subject can submit a Request/Objection and contact the Bank through:

  • The email address contact@sparkasse.mk - with a reference to the Data Protection Officer,
  • Directly to the email of the Data Protection Officer: privacy.protection@sparkasse.mk,
  • By mail to the Bank’s address: Vasil Iljoski 14, 1000 Skopje – with a reference to the Data Protection Officer.

Template for Request/Objection

The template for the Request/Objection can be downloaded from the website of Sparkasse Bank.

After verifying the identity of the requester, the Bank will provide information regarding the actions taken based on Articles 16 to 26 of the Law on the Protection of Personal Data, without undue delay, within the legally prescribed period of 30 days. If necessary, this period may be extended up to three months, taking into account the complexity and number of requests. In such cases, the controller will inform the data subject about each extension within one month from the day the request was received, along with the reason for the delay.

Objections can also be addressed directly to the regulatory body, the Agency for Personal Data Protection (for more information www.azlp.mk).

For additional information, please contact our Data Protection Officer, Gjorgji Rajchinoski, at +38923200507, e-mail: privacy.protection@sparkasse.mk.