Privacy Statement

What is personal data?

Personal data, is any information relating to you or can be used to identify you.

As a client of DEGIRO you provide us with some of your personal data, this includes your name, telephone number, email address. It can also include IP addresses which in some circumstances can be used to identify you.

In the event that a corporate or professional party intend on becoming a client, we will also collect personal data which relates to the interested individuals of the company for example, directors, UBO, authorised representatives etc.

What do we mean by processing?

Processing is a concept from law. It is very broad concept which covers actions taken in respect to your personal data such as: collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Whenever DeGiro carries out any processing of personal data, we do so in line with the relevant privacy regulation.

Why do we collect personal data?

DeGiro collect personal data for the following reasons:

  • To comply with the law;
  • Marketing activities; and
  • Execution of contractual obligations.

DeGiro as an investment firm has a number of regulatory obligations which require the processing of client data; customer identification is one of the main reasons we collect and process personal data. Next to this, when people contact DeGiro to ask for additional information or to become a client of DeGiro, DeGiro needs to be able to contact that client or potential client or you request us to send you our periodical newsletters. DeGiro may also have contractual obligations which mean that they need to process the data of their clients to fulfil these obligations.

But rest assured, when DeGiro process the personal data of its clients, it does so by using the minimal amount of data possible to ensure that aim is met.

What do we use personal data for?

DeGiro may for example do the following with your personal data:

Client acceptance

It is required by law for us to verify the identity of our clients, and without this information DeGiro could not provide its services to you. With your personal data we can for example,

  • Contact you.
  • Perform the relevant checks to ensure that you are eligible to become a client of DeGiro.
  • Review and check your request to become our client or to change your profile.
  • Keep your details in our administration and update them when there are changes.
  • Manage your profile(s).

Reduce risks

We share the responsibility for the safety and stability of the financial sector. We also have a responsibility to you and all our clients. We will therefore use your personal data to reduce risks.

You might notice for example:

  • If the risk on your account breaches the allowed limits we will contact you to allow you to bring this back into the allowed limits.

You might not notice much of the below but it is also done to protect you:

  • We keep your IP address when you visit our site. This can be used in the event that there is a dispute as to who accessed your account or for the security of the company for example preventative measures against DDoS attacks.
  • Ensure good levels of security and invest in resources that protect both you and ourselves against all kind of crimes.
  • Internal quality checks, to ensure determine possible issues, risks and testing to ensure that legislation has been properly implemented.
  • Carry out the relevant regulatory reporting.
  • Ensure that we remain a healthy company (risk management).

Legal obligations

There are a variety of legal obligations which DeGiro as an investment firm must follow.

  • Identification of clients: we check who you are and ensure that we have enough knowledge to allow us to offer our services.
  • Provide your personal data to specific organisations which are authorised to request this information, for example the tax authorities, financial supervisors, or when we are legally obliged to share this information for example during a criminal investigation.
  • We also have a number of obligations under anti money laundering legislation.

Marketing activities

At DeGiro we like to keep you informed. For example, with emails, newsletters, offers or updates to our WebTrader or Mobile App.

  • We can for example collect your searches within the website of DeGiro to ensure that our FAQ are up to date with the information clients need. This information is anonymised, so no one is able to ascertain which client is asking the question.
  • We use anonymised data to ensure that our marketing campaigns are effective.

If you would prefer not to receive some of this information, please feel free to contact the Service desk or unsubscribe via the button within the email.

Improve and innovate

We may also use personal data for analytical research, this allows us to find better solutions and ensure that we continue to be innovative.

When we are carrying out these research activities, we use the minimal data required and do this in a way where your information is either pseudonymised or anonymised.

Google analytics

In order to ensure that the website of DEGIRO is easy to use for clients, and to assess the success of campaigns DEGIRO make use of Google Analytics. DEGIRO have signed an agreement for the use of this service and ensures that the data is anonymised as much as possible, this includes masking some of the IP address.

Who do we have personal data from?

We can have (some) personal data of anyone who has contact with DeGiro. If you request additional information we will store the information which is provided during that request.

We are required by law to have personal information surrounding all of our clients. This information is gathered during the registration and requested when necessary.

What personal data is collected?

Data about you

This includes your name, address, telephone number and email address. In the event you are a corporate client we will also collect information surrounding your company or foundation. If you open a minor account or a joint account, the information surrounding the secondary account holders will also be collected. We will also ask for copies of your ID and personal numbers such as your tax identification number or relevant identifiers.

Transaction history

In addition to personal data which DeGiro have in relation to clients, we also keep a historic log concerning transaction and order history.

Contact history

We keep record of the times when you have contacted DeGiro, this includes telephone recordings, emails or other ways you have communicated with us.

Website visits and app use

In the event that you visit the website of DeGiro, we will also collect the IP address which is used. Should your IP address be used, for example via Google Analytics this will be done in an anonymised way.

External data sources

There are times where DeGiro will use external data provides, such as checking with the relevant chamber of commerce or in the event a credit check is required.

In the event that DeGiro carry out credit checks (BKR) they apply the strictest confidentiality on this information. Any individual who has access to this information does so only in the performance of their duty and the relevant data protection regulation is fully complied with. In the event you have questions of when BKR checks are carried out please contact the service desk of DeGiro.

Sensitive personal data

Sensitive personal data include things such as tax identification number, criminal history, biometric data, political beliefs, sexuality or ethnic origin, etc. If processing sensitive personal data is necessary, there are stricter rules applied to this.

At DeGiro we never use sensitive data related to health, religious beliefs, political or philosophical beliefs, sexual orientation or ethnic origin.

We have a legal obligation to identify our clients, therefore we require the tax identification number to do this.

Who do we share your personal information with?

In principle we do not share your information with others. It is possible that we may share personal data within the Group which DeGiro is a part of. All members of the Group which DeGiro is a part of have the same strict Privacy Policy. The police, judiciary, regulators and the tax authority can also request information from us on the grounds of law. However, we follow procedures which ensure that any sharing of information is both legitimate and proportionate.

Service providers

In the event we use a service provider to assist DEGIRO, we will aim to inform you about the use of a third party and limit the sharing of personal information strictly to what is required for that specific assignment.

With other companies when you ask

There are times when we will only share your personal data with other companies when you specifically ask. When this is done, we will specify this in the agreement to share the information.

Government and regulatory bodies

As an investment firm regulated within the Netherlands, there are times when we receive requests for information surrounding our clients. We are obliged under law to provide the regulators with this information. Additionally, we have legal obligations which require us to share information with governmental bodies and competent legal authorities. The data protection regulations which cover DeGiro are also applicable to these bodies.

How do we protect your personal data?

Security

We spend a lot of time and resources to ensure our systems and your personal data have the relevant security measures in place. In the case that there is a breach of our systems we will report this to the relevant authorities and ensure that our clients are aware.

Confidentiality

Our employees have all signed a confidentiality agreement and agreed to an internal code of conduct and follow the Dutch Banker’s Oath. Further to this, only authorised personnel may view and process your personal data.

Supervision

  • We are supervised by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) to ensure we comply with the Personal Data Protection Act.
  • DEGIRO operates under behavioural supervision of The Netherlands Authority for Financial Markets (AFM) and the prudential supervision of the Dutch Central Bank (DNB).

Viewing, erasure, portability or modification of your personal data

If you want to know what personal data DeGiro has recorded about you, it is possible to contact us to exercise your ‘Right of access’. Please contact the Service Desk of DeGiro and they will respond with the relevant information within 4 weeks of the request.

If you want to modify your personal data, it is possible to contact the Service Desk of DeGiro and they will inform you about how to modify this information.

We are a financial institution which have legal obligations which require us to store the data of our clients for 5 years, under Dutch law. This 5-year period begins when you terminate the client agreement. Should you request your data to be erased, we will firstly check if this is possible given the applicable legal requirements. If we have an obligation to keep this data we will inform you about this and that we are unable to erase it at this time and let you know when this will be erased. In the event it is possible to erase this data we will do so and inform you that it has been done.

In the event that you would like to request a restriction to your personal data being processed, please contact the Service Desk of DEGIRO who will be able to deal with this request or provide you with further information.

Control of communication

Naturally we want to keep all our clients and interested parties up to date with DeGiro and any changes we have upcoming. If you would prefer not to have these emails it is possible to change this by following the unsubscribe link at the bottom of the email. Please be aware that for some communication we are required to inform you and for these it will not be possible to unsubscribe while you are a client, this includes changes to the client agreement for example.

Our view on privacy

At DeGiro, our clients trust is fundamental to our relationship. We therefore strive to ensure that our clients have faith in the way we deal with their personal data. We take great care in ensuring that your data is safe and only processed when authorised to do so.

Our privacy policy is updated regularly, as law and regulations are continuously subjected to change, we will review the policy to ensure that it is kept up to date.

Questions about privacy

In the event you have some additional questions in relation to privacy or your personal data you can contact the service desk of DeGiro where they will answer all questions.

In the event that you wish to complain about the way we have handled your personal data please contact the data protection officer via privacy@degiro.co.no. Please note when contacting the data protection officer this communication will be answered in Dutch or English. The DPO will then look into your complaint and work towards a resolution.

If you still feel that your personal data has not been handled appropriately according to the law, you can contact Autoriteit Persoonsgegevens and file a complaint with them.

Generelt

DEGIRO respekterer og beskytter ditt privatliv. Du kan besøke denne nettsiden anonymt. DEGIRO er ikke interessert i navn eller annen informasjon som avslører identiteten på de som besøker denne nettsiden. Informasjon om deg og din datamaskin kommer kun til å bli registrert hos DEGIRO i tilfeller med tekniske problemer, eller i forbindelse med en kunde. Dette gjøres ved hjelp av en såkalt «cookie» (informasjonskapsel) eller på andre måter.

Cookies

Hva er en cookie?

Cookies er små filer som lagres på datamaskinens harddisk. Cookies sørger for at DEGIROs webserver gjenkjenner din nettleser.

Hvorfor bruker DEGIRO cookies og web bugs?

Nettsider har ikke noe minne. En person som blar gjennom sidene på nettsiden anses som en ny besøkende hver gang. Cookies gjør det mulig for en nettside å gjenkjenne din nettleser. Web bugs oppfører seg på omtrent samme måte som cookies.

Er alle cookies de samme?

Nei. Det finnes forskjellige typer cookies. De skilles mellom funksjon, varighet og hvem som legger til cookien.

Funksjon:

En teknisk cookie er nødvendig for at en nettside og bestemte funksjoner skal fungere på riktig vis (teknisk). For eksempel, for å gi tilgang til beskyttende eller sikrede deler av en nettside. Uten denne typen cookie, kommer en antall tjenester, slik som pålogging, handlekurv og elektronisk betaling ikke til å fungere.

En analyse-cookie samler inn informasjon på hvordan besøkende bruker en nettside. For eksempel, hvilken side som besøkes mest og hvor feil oppstår. Formålet med denne type cookie er å gi nettsideleverandøren innsikt i hvordan nettsiden fungerer og hvordan den kan forbedres. Denne cookien bidrar derfor også til brukervennligheten av nettsiden.

En funksjonell cookie husker valgene som foretas av brukeren. Dette kan være valg slik som brukernavn, valuta, språk eller land. Dette betyr at en bruker ikke trenger å spesifisere sine preferanser på nytt. Den funksjonelle cookien bidrar derfor også til brukervennligheten av nettsiden.

En reklame-cookie brukes til å vise reklame som er rettet mot besøkende av nettsiden for å sikre at den samme reklamen ikke vises hver gang, og for å måle effektiviteten av reklamekampanjer. Disse legges vanligvis til av reklamenettverk med samtykke fra administratoren av nettsiden. De registrerer at en nettside besøkes.

Varighet:

En sesjon-cookie installeres på brukerens datamaskin og samler inn data så lenge den besøkende er på nettsiden. Når du lukker din nettleser, vil cookien bli fjernet.

En permanent cookie installeres på brukerens datamaskin i en bestemt (lengre) periode.

Parter:

En førsteparts cookie (first party cookie) er en cookie som er knyttet til nettsiden som den besøkende besøker. Det kan være en cookie fra DEGIRO som legges ut når man besøker www.degiro.nl eller relaterte underdomener.

En tredjeparts cookie (third party cookie) er en cookie som er lagt ut av en annen part, og ikke DEGIRO (leverandøren av nettsiden som besøkes). For eksempel, reklameleverandører og (eksterne) programleverandører som har integrert sine annonser og programmer på nettsiden som besøkes.

Hva er en web bug?

En web bug er et elektronisk bilde av én enkelt piksel (1 x 1) eller en såkalt «fargeløs GIF» i nettsidens koding. Web bugs fungerer akkurat på samme måte som cookies. Web bugs brukes til å følge med på trafikken på nettsiden for hver side som besøkes, slik at den kan optimalisere trafikkflyten på nettsiden.

Hva kan jeg gjøre hvis jeg ikke ønsker (bestemte) cookies?

Du kan spesifisere i nettleserinnstillingene (f.eks. Internet Explorer, Safari, Firefox, Mozilla eller Chrome) om du tillater cookies eller ikke, og hvilken cookies du aksepterer. Innstillingene kan være forskjellige fra nettleser til nettleser. Du kan få informasjon om hvor du finner denne innstillingen og metoden under «Hjelp» i nettleseren din.

Du bør være klar over at du kanskje ikke vil kunne bruke funksjonene på nettsiden hvis du ikke godtar (bestemte) cookies.

Hvis du ikke ønsker å motta reklame-cookies, kan du aktivere «spor ikke» i din nettleser.

Du kan angi på www.youronlinechoices.eu at du ikke ønsker å motta cookies fra reklamebyrå.

Hva DEGIRO bruker dine personopplysninger til?

DEGIRO registrerer kun personopplysninger som du ble bedt om å oppgi da du ble et medlem av DEGIRO og kun etter din eksplisitte tillatelse. Uten disse kan og må DEGIRO ikke utøve sine bedriftsaktiviteter. DEGIRO og DEGIROs konsernselskaper bruker dine opplysninger til å gi deg tjenester som holder deg oppdatert om (nye) produkter og tjenester fra DEGIRO og konsernselskapene, anonyme statistiske analyser og overholde juridiske forpliktelser.

Alle telefonsamtaler mellom kunden og DEGIRO er tatt opp på bånd. Disse opptak er lagret og kan brukes til:

  • levering av dokumenter, slik som ved forskjell i tolkning eller med hensyn til innholdet i en telefonsamtale;
  • (svindel) avsløring og etterforskning;
  • evaluering av kvaliteten på tjenesten;
  • opplæringen, trening, og evalueringsformål

Ansvar

DEGIRO ser det som viktig at behandlingen av dine (personlige) opplysninger utføres på en måte som er i samsvar med de eksisterende sikringstiltak for å beskytte dine personopplysninger. DEGIRO handler i samsvar med Data Protection Act (personopplysningsloven) og Act on Financial Supervision (kredittilsynsloven) i all sin virksomhet. Dine (personlige) opplysninger kommer ikke til å utleveres til tredjeparter utenfor DEGIRO og DEGIROs konsernselskaper uten ditt samtykke, med mindre juridiske forpliktelser krever dette fra DEGIRO.

Nettsider fra tredjeparter

DEGIRO og konsernselskapene er ikke ansvarlige for andre nettsiders brukervilkår, selv om de er forbundet med DEGIRO og konsernets nettsider via hyperkoblinger eller på andre måter.

Utøvelse av rettigheter

Du har rett til å se dine opplysninger og dersom mulig forbedre dem. For å gjøre dette, ta kontakt med DEGIRO via denne nettsiden.

Vi holder deg oppdater angående (nye) produkter og tjenester fra DEGIRO og konsernselskapene via e-post. Hvis du ikke ønsker dette, kan du angi dette ved å sende en e-post til: kunder@degiro.co.no

Endringer

DEGIRO forbeholder seg retter til å foreta endringer av denne erklæringen. Det anbefales derfor at du besøker denne personvernserklæringen regelmessig når du besøker nettsiden.

Mener du at noe er feil ved denne erklæringen eller er du ikke fornøyd med bestemte aspekter av vår tjeneste? Sørg da for at du tar kontakt med oss. Klagen vil bli behandlet av DEGIROs compliance officer. Hvis du ikke er fornøyd med DEGIROS vurdering, ta kontakt med Klachteninstituut Financiële Dienstverlening, PO Box 93257, 2509 AG, Haag, i Nederland (www.kifid.nl).