Terms of Use of CMB Wing Lung Bank Open API
 
Effective Date: 11 October 2019
 
These Terms of Use of CMB Wing Lung Bank Open API (“Open API Terms of Use”) are a legal agreement between you and CMB Wing Lung Bank Limited (“our”, “us”, “we”) where API is an application programming interface and related software, excluding information/data called by such application programming interface so we encourage you to read these Open API Terms of Use carefully. By checking the box indicating your acceptance to these Open API Terms of Use and the Terms of Use of the Exchange, you  warrant that you are not a minor (but if you are a minor, then you have obtained parental consent to agree to these Sandbox Terms of Use), and you agree to be bound by these Sandbox Terms of Use in relation to your use of the sandbox developer portal operated by JETCO (“Sandbox”) on the information exchange platform currently known as “APIX”. If you are accepting these Open API Terms of Use on behalf of a legal entity, by checking the box indicating your acceptance to these Open API Terms of Use, you represent that you have the authority to legally bind such entity to these Open API Terms of Use. If you do not accept these Open API Terms of Use, you may not use our services or access CMB Wing Lung Bank Open API.
 
We work constantly to improve our services and develop new features. As a result, we may need to update these Open API Terms of Use from time to time to accurately reflect our services and practices. Unless it is not permitted by law, we will notify you before we make any changes to these Open API Terms of Use. Once any updated Open API Terms of Use are in effect, you will be bound by them if you continue to use our services.
 
  1. OUR SERVICES
 
CMB Wing Lung Bank Open API provides you production data for your Apps (defined below).
Use of Information and Materials
The products and services referred to in the CMB Wing Lung Bank Open API are offered only in jurisdictions where and when they may be lawfully offered by us. Nothing in these CMB Wing Lung Bank Open API should be regarded as an offer or solicitation to sell the products or services to person in any jurisdiction in which it would be unlawful for us to make such offer or solicitation. It is the responsibility of those accessing these CMB Wing Lung Bank Open API to ensure that they are aware of all relevant restrictions which apply to them.
The information contained in the CMB Wing Lung Bank Open API is provided for reference only. It should not be treated as a substitute for specific advice concerning individual situations and professional advice. It is strongly recommended that appropriate professional advice should be sought where necessary.
No Warranties
The information and materials contained on this CMB Wing Lung Bank Open API are provided "as is" and "as available" basis without warranty or representation of any kind, express or implied. Also, no warranty or representation regarding non-infringement, security, accuracy, fitness for a particular purpose or freedom from computer virus, Trojan horse, worms, software bombs or similar items is given in conjunction with these information and materials. We expressly disclaims any liability whatsoever for any loss howsoever arising from or in reliance upon the whole or any part of such information.
The information in the CMB Wing Lung Bank Open API does not constitute any representations, warranties or obligations binding on us who shall have absolute discretion to withdraw, vary or amend the services and products at any time with or without advance notice to users.
System Communications
Messages sent over the system cannot be guaranteed to be completely secure. We will not be responsible for any damages incurred by users as a result of any delay, loss, diversion, alteration or corruption of any message either sent to or received from us at the users' request, over the system. We are not responsible in any manner for direct, indirect, special or consequential damages arising out of the use of this web site.
Communication over the system may be subject to interruption, transmission blackout, delayed transmission due to system traffic or incorrect data transmission due to the public nature of the system or otherwise.
 
   
 You agree that the APIs contained therein, will only be used for commercial purpose only and not be used for any fraudulent or unauthorised transactions/purposes. You agree that we can at our sole and absolute discretion suspend/terminate your access or revoke your rights to use CMB Wing Lung Bank Open API without notice and that we shall have no liability or obligation to you thereto or for any loss or damage whatsoever arising from or in connection with such suspension or termination
 
  1. CHARGES
Use of CMB Wing Lung Bank Open API is currently free of charge subject to the API call limit set by JETCO.
 
  1. PRIVACY
We may need to collect and use your personal data when providing our services in CMB Wing Lung Bank Open API. We detail our practices in Privacy Policy regarding our use of your personal data, which you must agree to before you use CMB Wing Lung Bank Open API.
 
  1. FEEDBACK AND ENQUIRIES
Your user experience is important to us. If you have any feedback or enquiries about our services in using CMB Wing Lung Bank Open API, please do not hesitate to contact us at +852 3508-0193 (7x24 hours hotline) or email us at itoperator@cmbwinglungbank.com.
 
You agree that by providing us with your feedback, we are also entitled to use and publish such information in any publicity or advertising materials, or to help us improve our services, without need to notify you or obtain your consent in advance.
 
  1. OTHERS
By using APIX and/or its functionalities, you agree to comply with the Terms of Use of the Exchange  (https://sandboxportal.apix.com.hk/jetco/sb/terms-and-conditions) issued and modified by JETCO from time to time.”  Jetco will use the attached version upload to OneTSP and Bank Live portal for UAT acceptance.  Thanks.

- End of Document –



CMB WING LUNG BANK LIMITED
Privacy Policy Statement
As a CMG member (as defined below), it is the policy of CMB Wing Lung Bank Limited ("the Bank") and its subsidiaries (collectively referred to as the "Bank Group") to respect the privacy of their customers and keep the information relating to a customer secure and confidential. The Bank Group is committed to protecting the privacy, confidentiality and security of personal data the Bank Group holds by complying with the requirements of Personal Data (Privacy) Ordinance (the “Ordinance”) with respect to the management of personal data. The Bank Group is equally committed to ensuring that all its employees and agents uphold these obligations.
Statement of Practices and Kinds of Personal Data Held by the Bank Group
There are different kinds of personal data and sensitive personal data held by the Bank Group. There are mainly two broad categories of personal data held by the Bank Group, namely:
(a)    data of potential and existing customers; and
(b)    data of employees.

However, personal data may be provided by other individuals, including but not limited to agents and business partners.
The kinds of personal data held by the Bank Group may include (but are not limited to) name, title, address, e-mail address, employment information, contact details, date of birth, nationality, financial information, credit information, marital status, identity card or passport numbers and other personal information in the public domain.
It is necessary for the Bank Group to hold such data for various purposes including, without limitation, the opening or continuation of accounts, the establishment or continuation of banking/credit facilities, and the provision of securities and futures trading, credit card, insurance, tenancy and property management, concierge services and other banking and financial services.
Personal Data Collection and Usage
The Bank Group collects personal data through fair and lawful means on a voluntary basis. The data is used by the Bank Group or CMG for the purposes indicated in the respective screens in which customers are invited to provide personal data and in the Notice to Customers relating to the Personal Data (Privacy) Ordinance (the "Notice"). The Bank Group will provide the Notice on or before the collection of personal data in an appropriate format and manner. For details, please refer to the Notice, including the consequences of failure to provide such data.
Personal information held by the Bank Group is kept confidential and the Bank Group does not use customers' personal information for any purpose other than that already specified in this Privacy Policy Statement or in the Notice or unless such usage is permitted or required by law.
Information is collected from the Bank Group's customers, which include the Bank Group's web portal visitors.
In addition, information is collected on the use of the Bank Group’s smartphone app (the "APP") from the Bank Group's customers, which include the APP users. When an individual visits the Bank Group’s web portal (without logging in to NET Banking), the Bank Group records the visit only as a "hit" or records such use only as a “hit” but does not capture any personal identifiable information about the visitor or user. The Bank Group gathers and analyzes this information to compile general statistics about usage of the Bank Group's web portal. The Bank Group also collects information about the visit or use by means of cookies files (cookies are small pieces of data transmitted to and stored in the visitor's local hard drive). The data obtained would be used for web portal personalization and marketing. Cookies cannot retrieve information stored in the visitor's hard disk. Should you wish not to be tracked by cookies, you may change your browser settings. However, you may not be able to take full advantage of our website because certain functionalities may not be available if you do not accept cookies.
Similarly, when an individual uses the APP, the Bank Group uses behavioural tracking tools to: The information gathered may include time and duration of a customer’s use of the APP and the pages viewed by customers while using the APP. As behavioural tracking is integral to the operation of the APP and the provision of a quality service to customers, the APP’s design does not permit behavioural tracking to be disabled. Any individuals who do not consent to the use of behavioural tracking tools should access the Bank’s services using NET Banking instead.
The Bank Group generally has closed circuit television systems (“CCTV”) installed at the Bank Group’s premises (e.g. branches). Information collected is mainly used for security, management and other related purposes as stated in the Notice.
Personal Data Disclosure Restrictions
The Bank Group follows strict privacy procedures in regard to protection of personal data. No disclosure of personal identifiable information to third parties is allowed unless the related customer has already been informed or has provided the consent (where required) or the disclosure is permitted or required by any law binding on the Bank Group or any of its branches. For possible transferees (whether within or outside Hong Kong), please refer to the Notice.
Personal Data Retention
The Bank Group retains all records of transactions for validation and auditing purposes. Appropriate retention periods apply and the Bank Group takes all practicable steps to ensure that personal data are not kept longer than is necessary for the fulfilment of the intended purpose.
Under applicable circumstances, customers may have the right to ask the Bank Group to delete their personal data or not to transfer or share their personal data.
Personal Data Security
All personal data provided to the Bank Group is secured with restricted access by authorized personnel with relevant training provided. The Bank Group has security measures in place to protect personal data. Encryption technology is employed for sensitive data to protect customers' privacy during data transmission.
Data Access Requests and Data Correction Requests
The Bank Group processes all Data Access Requests (“DARs”) and Data Correction Requests in accordance with the Ordinance. Requestors for access are advised to use the form prescribed by the Office of the Privacy Commissioner for Personal Data, Hong Kong. However, the Bank Group has the right to charge a reasonable but not excessive fee to comply with DARs. In addition, the Bank Group will check the identity of the requestor to ensure that the requestor is the person legally entitled to make the data access or correction request.
Outsourcing Arrangement
If the Bank Group engages outsourcing service providers or data processors (whether within or outside Hong Kong), outsourcing service providers or data processors are required to adhere to specific standards to prevent any loss, unauthorised access, use, modification or disclosure, either by contractual provisions or other means.
Direct Marketing
The Bank Group may use your data in direct marketing and the Bank Group requires your consent (which includes an indication of no objection) for that purpose. However, you may exercise your opt-out right by notifying the Bank Group.
Debt Collection
The Bank Group may use your personal data if you are in default of payment for debt collection purposes, including the transfer of your appropriate personal data to debt collection agencies for debt collection purposes.
Changes to Privacy Policy Statement
This Privacy Policy Statement is subject to review and change from time to time. Please approach the Bank Group or visit the Bank Group’s website for the Bank Group’s latest Privacy Policy Statement.
Contact Us
Request for access to data or correction of data or for information regarding policies and practices and kinds of data held should be addressed to:
Data Protection Officer
CMB Wing Lung Bank Limited
CMB Wing Lung Bank Building
45 Des Voeux Road Central, Hong Kong

Interpretation
In this Privacy Policy Statement:
"CMG" means:
(a) the Bank or its successor;
(b) any subsidiary undertaking, related company, associated company, direct and/or indirect parent undertaking of the Bank;
(c) any subsidiary undertaking of any such parent undertaking;
(d) any related company of (a), (b) and (c) above; and
(e) any associated company of (a), (b) and (c) above;

and “CMG member” shall mean any of them; and
the expressions "subsidiary undertaking", "parent undertaking" and "undertaking" bear the meanings under the Companies Ordinance (Cap.622).
In case of any discrepancy between the English and Chinese versions of this Privacy Policy Statement, the English version prevails.
September 2019
 
 
CMB WING LUNG BANK LIMITED
Notice to Customers relating to the Personal Data (Privacy) Ordinance (the “Ordinance”) (the “Notice”)In compliance with the Ordinance, CMB Wing Lung Bank Limited (“the Bank”) would wish to inform you of the following:
1.From time to time, it is necessary for customers, potential customers and various other individuals (including without limitation applicants for banking/financial services and banking/credit facilities, sureties, referees, guarantors, providers of security, shareholders, directors, officers and managers of corporate customers or applicants, and sole proprietors or partners of applicants and other contractual counterparties) (collectively, “data subjects”) to supply the CMG (as defined in paragraph 17 below) with data in connection with various matters including without limitation the opening or continuation of accounts and the establishment or continuation of banking/credit facilities or provision of securities and futures trading, credit card, insurance, tenancy and property management and other banking and financial services.
2.Failure to supply such data may result in the CMG being unable to open or continue accounts or establish or continue banking/credit facilities or provide securities and futures trading, credit card, insurance, tenancy and property management and other banking and financial services for its customers.
3.It is also the case that data are collected from data subjects in the ordinary course of the continuation of the CMG’s business relationship with such data subjects, including without limitation, when payments are made to data subjects’ accounts, when data subjects instruct the Bank to enter into transactions, when data subjects write cheques, deposit money, repay loans, conduct securities and futures trading, apply for credit cards, request the Bank to provide tenancy and property management services or purchase insurance or other banking and financial products and services.
4.The purposes for which data relating to a data subject may be used will vary depending on the nature of the data subject’s relationship with the CMG, which may comprise all or any one or more of the following purposes:-(i)the daily management and operation of the services and credit facilities provided by the CMG to the data subject, including determining whether to provide or continue with the provision of, banking and financial services to the data subject;
(ii)provision of bankers’ references;
(iii)conducting credit checks (including without limitation upon applications for consumer credit and periodic or special reviews of such consumer credit) which normally take place one or more times each year and, subject to the requirements set out in the Ordinance, carrying out matching procedures (as defined in the Ordinance);
(iv)creating and maintaining the CMG’s credit or behaviour scoring models;
(v)assisting other financial institutions, credit or charge card issuing companies and debt collection agents to conduct credit checks and collect debts;
(vi)ensuring ongoing credit worthiness of data subjects;
(vii)conducting market, service or product analysis or researching, designing, developing or improving financial services or related products of the CMG for data subjects’ use;
(viii)marketing services, products and other subjects (in respect of which the CMG may or may not be remunerated) (please see further details in paragraph 7 below);
(ix)determining the amount of indebtedness owed to or by data subjects;
(x)the enforcement of data subjects’ obligations, including but without limitation the collection of amounts outstanding from data subjects and those providing security or guarantee for data subjects’ obligations;
(xi)complying with the obligations, requirements or arrangements for disclosing and using data that apply to or is expected to be complied with by the CMG or any CMG member or any service provider of the CMG or any CMG member according to:
 (1)any law binding or applying to it within or outside the Hong Kong Special Administrative Region existing currently and in the future (e.g. the Inland Revenue Ordinance and its provisions including those concerning automatic exchange of financial account information);
 (2)any guidelines or guidance given or issued by any legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers within or outside the Hong Kong Special Administrative Region existing currently and in the future (e.g. guidelines or guidance given or issued by the Inland Revenue Department including those concerning automatic exchange of financial account information);
 (3)any present or future contractual or other commitment with local or foreign legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers that is assumed by or imposed on the CMG or any CMG member by reason of its financial, commercial, business or other interests or activities in or related to the jurisdiction of the relevant local or foreign legal, regulatory, governmental, tax, law enforcement or other authority, or self-regulatory or industry bodies or associations;
(xii)complying with any obligations, requirements, policies, procedures, measures or arrangements for sharing data and information within the CMG and/or any other use of data and information in accordance with any group-wide programmes for compliance with sanctions or prevention or detection of money laundering, terrorist financing or other unlawful activities;
(xiii)enabling an actual or proposed assignee of the CMG (including their legal, accounting and/or commercial advisers), or participant or sub-participant of the CMG’s rights in respect of the data subjects (including legal, accounting and/or commercial advisers to such participant or sub-participant) to evaluate the transaction intended to be the subject of the assignment, participation or sub-participation;
(xiv)comparing data of data subjects or other persons for credit checking, data verification or otherwise producing or verifying data, whether or not for the purpose of taking adverse action against the data subjects;
(xv)maintaining a credit history of data subjects (whether or not there exists any relationship between data subjects and the CMG) for present and future reference;
(xvi)exchanging information with merchants accepting credit cards issued by the CMG and entities with whom the CMG provides affinity/co-branded/private label credit card services (each a “merchant” or an “affinity entity”) (the names of such affinity entities can be found in the application form(s) for the relevant services and products);
(xvii)verifying data subjects’ identities with the bank of any merchant in connection with any credit card payment or transaction;
(xviii)for reasonable internal management purposes (including without limitation, security controls, investigations, risk management, fraud prevention, the defence of claims and the monitoring of the quality and efficiency of services offered or provided by the CMG); and
(xix)purposes relating thereto.
5.The data of a data subject may be processed, kept and transferred or disclosed in and to any country (in or outside Hong Kong, e.g. Mainland of China) as the CMG or any of the transferees contemplated in paragraph 4 may consider appropriate for the purposes set out under paragraph 4. Such data may also be released or disclosed in accordance with the local practices and laws, rules and regulations (including any governmental acts and orders) to which the CMG and/or such contemplated transferees are subject to the applicable jurisdiction (inside or outside Hong Kong, e.g. Mainland of China). Data held by the CMG relating to data subjects will be kept confidential but the CMG is authorized to provide the data of a data subject to the following parties whether inside or outside Hong Kong (e.g. Mainland of China) for the purposes set out in paragraph 4:-(i)any agent, contractor, claim adjuster or third party service provider (including any CMG member as an outsourcing service provider) who provides administrative, management, telecommunications, computer, payment or securities clearing, underwriting, depository, custodian, registration, anti-money laundering, customer contact centre, credit card authorization, card embossing process or other services to the CMG in connection with the operation of its business;
(ii)any other person under a duty of confidentiality to the Bank including a CMG member which has undertaken to keep such information confidential;
(iii)the drawee bank providing a copy of a paid cheque (which may contain information about the payee) to the drawer;
(iv)credit reference agencies; and, in the event of default, to debt collection agencies;
(v)any person to whom the CMG or CMG member is under an obligation or otherwise required to make disclosure under the requirements of any law binding on or applying to the CMG or CMG member, or any disclosure under and for the purposes of any guidelines or guidance given or issued by any legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers with which the CMG or CMG member is expected to comply, or any disclosure pursuant to any contractual or other commitment of the CMG or CMG member with local or foreign legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers, all of which may be within or outside the Hong Kong Special Administrative Region and may be existing currently and in the future;
(vi)any actual or proposed assignee of the CMG (including their legal, accounting and/or commercial advisers) or participant or sub-participant or transferee of the CMG’s rights (including their legal, accounting and/or commercial advisers) in respect of the data subject;
(vii)any insurance company or agent, and securities and futures broker, merchant or other business partners of the CMG;
(viii)any financial institution and charge card or credit card issuing companies with which the data subjects have or propose to have dealings;
(ix)any party giving or proposing to give a guarantee or third party security to guarantee or secure the data subjects’ obligations;
(x)Joint Electronic Teller Services Limited (“JETCO”), operators or participants of the JETCO network and other issuers of ATM cards;
(xi)the Bank of any merchant in connection with any credit card payment or transactions for the purpose of verifying the identity of the cardholder;
(xii)any CMG member in Hong Kong or other jurisdiction(s);
(xiii)(1)third party financial institutions, insurers, credit card companies, securities and investment services providers;
 (2)third party reward, loyalty, co-branding and privileges programme providers;
 (3)co-branding partners of the CMG (the names of such co-branding partners can be found in the application form(s) for the relevant services and products, as the case may be);
 (4)charitable or non-profit making organisations; and
 (5)external service providers (including but not limited to mailing houses, telecommunication companies, telemarketing and direct sales agents, call centres, data processing companies and information technology companies) that the CMG engages for the purposes set out in paragraph 4(viii); and
(xiv)any other person (x) where public interest requires; or (y) with the express or implied consent of the data subject.
6.With respect to data in connection with mortgages applied by a data subject (whether as a borrower, mortgagor or guarantor and whether in the data subject’s sole name or in joint names with others) on or after 1 April 2011, the following data relating to the data subject (including any updated data of any of the following data from time to time) may be provided by the CMG, on its own behalf and/or as agent, to a credit reference agency:(i)full name;
(ii)capacity in respect of each mortgage (as borrower, mortgagor or guarantor, and whether in the data subject’s sole name or in joint names with others);
(iii)Hong Kong Identity Card Number or travel document number;
(iv)date of birth;
(v)correspondence address;
(vi)mortgage account number in respect of each mortgage;
(vii)type of the facility in respect of each mortgage;
(viii)mortgage account status in respect of each mortgage (e.g. active, closed, write-off (other than due to a bankruptcy order), write-off due to a bankruptcy order); and
(ix)if any, mortgage account closed date in respect of each mortgage.
The credit reference agency will use the above data supplied by the CMG for the purposes of compiling a count of the number of mortgages from time to time held by the data subject with credit providers in Hong Kong, as borrower, mortgagor or guarantor respectively and whether in the data subject’s sole name or in joint names with others, for sharing in the consumer credit database of the credit reference agency by credit providers (subject to the requirements of the Code of Practice on Consumer Credit Data approved and issued under the Ordinance).
7.USE OF DATA IN DIRECT MARKETING
The CMG intends to use a data subject's data in direct marketing and the CMG requires the data subject's consent (which includes an indication of no objection) for that purpose. In this connection, please note that:
(i)the name, contact details, products and services portfolio information, transaction pattern and behaviour, financial background and demographic data of a data subject held by the CMG from time to time may be used by the CMG in direct marketing;
(ii)the following classes of services, products and subjects may be marketed:
 (1)financial, insurance, credit card, banking and related services and products;
 (2)reward, loyalty or privileges programmes and related services and products;
 (3)services and products offered by the CMG’s co-branding partners (the names of such co-branding partners can be found in the application form(s) for the relevant services and products, as the case may be); and
 (4)donations and contributions for charitable and/or non-profit making purposes;
(iii)the above services, products and subjects may be provided or (in the case of donations and contributions) solicited by the CMG and/or:
 (1)the CMG member;
 (2)third party financial institutions, insurers, credit card companies, securities and investment services providers;
 (3)third party reward, loyalty, co-branding or privileges programme providers;
 (4)co-branding partners of the CMG and the CMG member (the names of such co-branding partners can be found in the application form(s) for the relevant services and products, as the case may be); and
 (5)charitable or non-profit making organisations;
(iv)in addition to marketing the above services, products and subjects itself, the CMG also intends to provide the data described in paragraph 7(i) above to all or any of the persons described in paragraph 7(iii) above for use by them in marketing those services, products and subjects, and the CMG requires the data subject's written consent (which includes an indication of no objection) for that purpose;
(v)The CMG may receive money or other property in return for providing the data to the other persons in paragraph 7(iv) above and, when requesting the data subject's consent or no objection as described in paragraph 7(iv) above, the CMG will inform the data subject if it will receive any money or other property in return for providing the data to the other persons.
If data subject does not wish the CMG to use or provide to other persons his/her data for use in direct marketing as described above, the data subject may exercise his/her opt-out right by notifying the CMG.
8.Under and in accordance with the terms of the Ordinance and the Code of Practice on Consumer Credit Data approved and issued under the Ordinance, any data subject has the right:-(i)to check whether the CMG holds data about him and of access to such data;
(ii)to require the CMG to correct any data relating to him which is inaccurate;
(iii)to ascertain the CMG’s policies and practices in relation to data and to be informed of the kind of personal data held by the CMG;
(iv)in relation to consumer credit data, to request to be informed which items of data are routinely disclosed to credit reference agencies or debt collection agencies, and be provided with further information to enable the making of a data access and correction request to the relevant credit reference agency or debt collection agency; and
(v)in relation to any account data (including, for the avoidance of doubt, any account repayment data) which has been provided by the CMG to a credit reference agency, to instruct the CMG, upon termination of the account by full repayment, to make a request to the credit reference agency to delete such account data from its database, as long as the instruction is given within five years of termination and at no time was there any default of payment in relation to the account, lasting in excess of 60 days within five years immediately before account termination. Account repayment data include amount last due, amount of payment made during the last reporting period (being a period not exceeding 31 days immediately preceding the last contribution of account data by the CMG to a credit reference agency), remaining available credit or outstanding balance and default data (being amount past due and number of days past due, date of settlement of amount past due, and date of final settlement of amount in default lasting in excess of 60 days (if any)).
9.In the event of any default of payment relating to an account, unless the amount in default is fully repaid or written off (other than due to a bankruptcy order) before the expiry of 60 days from the date such default occurred, the account repayment data (as defined in paragraph 8(v) above) may be retained by the credit reference agency until the expiry of five years from the date of final settlement of the amount in default.
10.In the event any amount in an account is written-off due to a bankruptcy order being made against a data subject, the account repayment data (as defined in paragraph 8(v) above) may be retained by the credit reference agency, regardless of whether the account repayment data reveal any default of payment lasting in excess of 60 days, until the expiry of five years from the date of final settlement of the amount in default or the expiry of five years from the date of discharge from a bankruptcy as notified by the data subject with evidence to the credit reference agency, whichever is earlier.
11.The CMG may have obtained a credit report on a data subject and any of its sureties from a credit reference agency in considering any application for credit. In the event the data subject or any of its sureties wishes to access the credit report or to request to have any personal data of the data subject held by the credit reference agency corrected pursuant to the Ordinance, the CMG will advise the contact details of the relevant credit reference agency.
12.The CMG may access the database of a credit reference agency for the purpose of credit review of any data subject from time to time. In particular, the CMG may access the consumer credit data of any data subject held by a credit reference agency for the purpose of the review of their existing consumer credit facilities which may involve the consideration by the CMG of any of the following matters:(i)an increase in the credit amount;
(ii)the curtailing of credit (including the cancellation of credit or a decrease in the credit amount); or
(iii)the putting in place or the implementation of a scheme of arrangement with the data subject.
13.In accordance with the terms of the Ordinance, the CMG has the right to charge a reasonable fee for the processing of any data access or correction request.
14.The person to whom requests for access to data or correction of data or for information regarding policies and practices and kinds of data held are to be addressed is:-

The Data Protection Officer
CMB Wing Lung Bank Limited
45 Des Voeux Road Central, Hong Kong
Telephone: 230 95555

15.You may, at any time and without charge, choose not to receive our promotional material. You must inform us in writing at the address specified in paragraph 14 or such other updated address as we may notify you from time to time if you do not wish to receive such material.
16.Nothing in this Notice shall limit the rights of data subjects under the Ordinance.
17.In this Notice, the following terms shall have the following meanings:
“CMG” means the Bank or its successor, any subsidiary undertaking of the Bank, any related company of the Bank, any associated company of the Bank, any direct and/or indirect parent undertaking of the Bank, any subsidiary undertaking of any such parent undertaking, any of their related companies, any of their associated companies including, for the avoidance of doubt, undertakings within the group of China Merchants Group Ltd (and “CMG member” shall be construed accordingly); and
The expressions “subsidiary undertaking”, “parent undertaking” and “undertaking” bear the meanings under the Companies Ordinance (Cap.622).

18.In case of any discrepancy between the English and Chinese versions, the English version prevails.

Effective Date: 31st January 2019

You may be subject to an earlier version of this Notice if you have established a relationship with the Bank before the Effective Date.