Security and incident management
Incident management
We may be required to process personal data both before and if a crisis situation or incident occurs in DNB. This will be personal data that is related to an incident such as violence, threats, unwanted behaviour or an accident.
Personal data processed in this context relates to the event itself. The incidents may contain both general personal data.
DNB Finans AS, a branch of DNB Finans AS, Norway, CVR no. 45909522 (“DNB Finans Denmark”), is a branch of DNB Finans AS.
DNB Finans AS is therefore the controller and is responsible for the processing of your personal data.
We store events in access-controlled internal information systems and retain the personal data for as long as necessary to fulfil the purpose of the processing. Some logs are kept 10–15 years in accordance with our internal archiving routines.
When we collect and process information about you, you have several rights under data protection rules and legislation. This includes the right of access, the right to data portability, the right to rectification of any errors and the right of erasure, which means that we must, on our own initiative, delete information that is no longer necessary for the purpose of the processing.
We will always consider any objections you may have to the processing of your personal data, and we will follow up when you opt out of direct marketing. Read about how you can exercise your data protection rights in our privacy notice under ‘Your rights’.
The purpose of the processing is to detect and handle a crisis situation.
We are legally obliged to process personal data for this purpose, and the legal basis is the regulatory statutory requirements that apply to the financial industry regarding security and incident management.
- Identification data
- Special categories of personal data collected from the data subject during incident management, including health data
We may share personal data within the Group for internal processing purposes. In addition, we may share information with external authorities such as the police. We may also share data with suppliers who process personal data on our behalf.
IT Security
Security in DNB primarily relates to protecting the bank against crime and other intentional and undesirable incidents, but also unintentional incidents as a result of errors and accidents.
It is very important for us to protect our equipment, systems and information from damage, misuse, unauthorized access, alteration and vandalism. In this regard, a number of different security measures and systems are needed to detect and prevent unwanted incidents and damage to our assets and services, as well as to handle incidents that do occur.
We process personal data to achieve this purpose. This will typically be personal data such as your user identity and IP address. The information is processed by analyzing internet activities on our secure networks and the use of our systems. We continuously seek to ensure that your personal data is protected against loss, destruction, corruption or unauthorized access.
DNB Finans AS, a branch of DNB Finans AS, Norway, CVR no. 45909522 (“DNB Finans Denmark”), is a branch of DNB Finans AS.
DNB Finans AS is therefore the controller and is responsible for the processing of your personal data.
We retain your personal data as long as is necessary to achieve the purpose. This is up to a maximum of three years, unless the purpose entails a special need to keep the data longer.
When we collect and process information about you, you have several rights under data protection rules and legislation. This includes the right of access, the right to data portability, the right to rectification of any errors and the right of erasure, which means that we must, on our own initiative, delete information that is no longer necessary for the purpose of the processing.
We will always consider any objections you may have to the processing of your personal data, and we will follow up when you opt out of direct marketing. Read about how you can exercise your data protection rights in our privacy notice under ‘Your rights’.
The purpose of the processing is prevention, detection and handling of IT security incidents in DNB.
DNB is legally obliged to process personal data for this purpose, and the legal basis is the regulatory statutory requirements that apply to the financial industry regarding security and incident management, as well as data protection rules and legislation.
- Identification data
- IP address
- Digital behaviour data
We may share personal data within the Group for internal processing purposes. In addition, we may share information with external authorities such as the police. We may also share data with suppliers who process personal data on our behalf.