This page was last updated on March 5, 2025.
Please select a language to view the Global Privacy Notice for Institutional Clients. To view the notice in English, please scroll down.
At Citi we value, respect and protect the privacy of our clients and service recipients.
This Privacy Notice describes how we collect and use (or ‘process’) personal information in connection with global markets, investment banking and financial services for corporate entities, including governments and financial institutions.
Depending on how else you interact with us, other Privacy Notices may apply additionally to this Global Privacy Notice. For example: Our online privacy notice applies when you visit Citigroup.com, while customer privacy notices apply to retail , wealth and private banking clients. We also have specific notices for non-client activities, such as Citi Careers (for job applicants), for our permanent global workforce and for our contingent workforce (‘Non Employees and Suppliers’).
This Privacy Notice does not replace privacy notices related to any other interactions with us, nor does it override Privacy Notices issued for specific purposes.
This Privacy Notice covers the processing of personal information (also referred to as ‘personal data’) in the following business areas:
Markets provides customized solutions that support the diverse investment and transaction strategies of corporations, governments, investors and intermediaries globally. The strength of our sales and trading, distribution capabilities span asset classes and currencies, sectors and products including Equities, Spread Products, Commodities, Rates and Currencies.
Banking is organized around three lines of business: our Investment Bank, which meets clients’ capital raising needs and provides merger and acquisition and equity and debt capital markets-related strategic financing solutions; our Corporate Bank, which serves as the conduit of Citi’s full product suite to clients; and our Commercial Bank, which helps mid-sized companies address the challenges of rapid growth and international expansion. The unified Banking & International organization oversees the local delivery of the full firm to clients in
markets where Citi has an on-the-ground presence.
Our suite of Services encompasses treasury, cash and trade banking services, and securities services. Within this offering Cash and Trade deliver an integrated suite of innovative and customized cash management and trade finance services to meet the needs of multinational corporations, financial institutions and public sector organizations. Similarly, our Securities Services arm provides cross- border support for clients with extensive on-the-ground local market expertise, innovative post-trade technologies, customized data solutions and a wide range of securities services that can be tailored to meet the requirements of our clients.
a) Country Supplemental Provisions that may be applicable to
b) Digital Platforms Schedule,
c) Citi Research Schedule
In this Privacy Notice we use the following terms:
“You” means any individual or natural person whose information or personal data we process in relation to financial services that we provide to Your Organization, or other service recipients.
“Your Organization” is the corporation or institution you are associated with as an employee, authorized representative, director, shareholder or client.
“Personal Information” or “Personal Data” are equivalent terms to mean any information or data:
“Sensitive Personal Information” or “Special Categories of Personal Information” are interchangeable terms that refer to categories of Personal Information that require special handling due to their inclusion of certain elements such as racial and ethnic origin, religion, medical information, political or philosophical positions and biometric data. Personal information that has been aggregated and anonymised data is not considered Personal Information for purposes of this Privacy Notice. In some US jurisdictions, sensitive personal information includes Social Security Numbers, Passports, Drivers Licenses or State IDs.
We will only process Sensitive Personal Information with your consent, unless applicable law contains exceptions or allows us to process it under a different legal basis (for example to comply with our legal obligations). In order to prevent its involuntary processing please do not share Sensitive PI or Special Categories of PI about yourself or anyone else unless you have been asked. If we receive that information directly from you or from a third party, by accident or happenstance, we may remove and dispose of it. We remind data subjects that we have an authorization, not an obligation to receive personal information (including its protected categories) from you or a third party.
1. Entity responsible for processing your Personal Information
2. Sources of Personal Information
3. Categories of Personal Information we collect and process
4. Purposes and Uses of Personal Information
5. Lawful Bases for Data Processing
6. Consequences of Not Providing Personal Information if required
7. Your Privacy and Data Protection Rights
8. Disclosures and Recipients of Personal Information
9. International Transfers of Personal Information
10. Storage and Retention (Archiving) of Personal Information
(1) Countries and Territories
(2) Information for Digital Platforms
(3) Citi Research
The Citi legal entity that provides the accounts, products and services to Your Organization, acts as an independent business and is responsible for determining how your Personal Information is collected, the purposes the information is collected for, and how it will be processed. This is the Data Controller, also known as Data User under the laws of certain countries.
Please refer to the Country or Territory Supplement relevant to your services for a list of Data Controllers where these are provided. A global list of Citi branches and affiliate is available here.
In certain operations, Citi entities act as a Data Processors, that is to say as service providers or operators (and not as Data Controllers): for example, where processing international payments, when executing commercial payments and transactions on behalf of banks and merchants and other institutions, in transfer agency and payment agency agreements, and where we explicitly indicate that we are acting as service providers or data processors. This Privacy Notice does not apply to activities where we are processors, service providers or operators (the relevant privacy notice will be issued by the Data Controllers in those operations). If, when acting as a Data Processor we are also required to comply with a legal obligation, for example, conducting age verification, scrutinizing payment beneficiaries names for international sanctions, fraud, money laundering or combating terrorism financing, or for our internal compliance and transaction reporting, we will undertake these discrete activities in the capacity of a Data Controller.
INDIRECT: From Your Organization and other entities
Your Organization
We obtain information from Your Organization or third parties, such as financial institutions, government entities, credit reference agencies, recognised fraud data sharing mechanisms, both from domestic and international organizations, and from companies specialised in fraud detection and background checks.
To uphold the security, integrity and legality of our operations we obtain personal information from company or commercial registers, insolvency lists, and registers of persons that have been bankrupted or banned temporarily or permanently from holding directorships. Our contracted subscription services also review estimated wealth, court listings, court judgments, and press articles (mainly on allegations of corruption and other red flags) on senior government figures and politically exposed persons, and our security and information services review international sanctions lists and anti-fraud cooperation mechanisms.
We also obtain (to a lesser degree) personal information from international and domestic payment infrastructures, financial and currency markets, investment and settlement infrastructures including clearing houses, securities depositories, stock exchanges, OTC or private exchanges and similar sources.
As required and/or permitted by law, we also monitor and record telephone, email, instant messaging, and other online communications with us have resulted or may result in a banking or financial transaction.
DIRECTLY: From You
We obtain information directly from You from various sources:
General Categories of Personal Information
Citi collects personal information about you, for purposes indicated in this Global Privacy Notice.
The categories of personal information that we process, with their elements include:
General Categories of Sensitive Personal Information or “Special Categories of Data”
Where required by law, we process sensitive information (special categories of personal data), your Social Security and other national identity indicators. We have systems that compartmentalize such information, and operational, technical and governance measures, including access controls that protect the confidentiality and security of all information.
We only collect and process personal information that is necessary for us to provide our services and as required by business, legal, and regulatory aims. We will offer detailed information and additional disclosures if appropriate where we collect or otherwise process special categories of personal data, such as biometric or behavioural personal data that we obtain from your interactions with our systems and applications, including by way of example your mouse speed and movements, your keyboard usage, and voice pattern recognition for telephone banking. When we use the built-in biometric authentication technology in your mobile device, we do not have access to your biometric data, which remains stored in your mobile device.
Digital Personal Information
For details on the information we collect from your device, and your use of digital resources please consult :
We use your Personal Information for the following purposes:
Certain countries and territories require Citi to offer to individuals the options and means to limit their use or disclosure of personal information. Please refer to the Special Provisions for your country or territory for information on these additional rights and how to exercise them. Citi does not sell or share your Personal information with third parties for their advertising or other commercial purposes. We also do not disclose the Personal Information of persons under the age of 16 (see ‘Minors and Children’ further below).
Citi does not delegate control or decision-making functions to automated processing means (including Artificial Intelligence) and does not engage in profiling that may result in legal or similarly significant effects. Nevertheless, we use artificial intelligence to monitor transaction data, to ensure the consistency and correctness of outputs, detect and prevent illegal activities, for risk management and investment analysis, as an information tool for our personnel. We use fully automated means on securities markets (for example in algorithmic trading) solely where all information is de-personalised. If Your Organization is our client, depending on your digital marketing choices, we may create user profiles to offer you products targeted to Your Organization. Our marketing communications have links to change your preferences or supress further notifications.
The lawful basis that we rely on for data processing vary, depending on the applicable law in the location where we provide our services. These include as the case may be:
When we collect and process sensitive personal information, or Special Categories of Information, we will do so by obtaining your explicit consent unless the law allows us to rely on prescribed exceptions:
We may require certain data to fulfil our contractual obligations or to comply with legal obligations. If you choose not to provide this required data, it may impact our ability to provide you with our services effectively. For example:
You have rights over your personal information that are protected by law in many countries. Most countries grant 4 basic rights: Access, Rectification, Cancellation and Objection (by their initials, the so-called ARCO rights). Citi extends these, and other rights set out in the EU General Data Protection (GDPR), beyond the requirements under local law, in order to provide a consistent standard across our operations globally.
You can CONTACT US to request any of the following rights:
Citi may not always be able to provide all requested information or fulfil other rights where certain exceptions apply to a privacy rights request. In our reply, if we need to withhold certain information or fulfil your request we will explain the rationale for our decision, and the subsequent steps.
We will always respond to your request within the timeframes provided under applicable law.
To ensure your safety and given the confidentiality of financial information, we must verify your identity before disclosing any personal data. If you are making a request on behalf of someone else (as an attorney or a friend or relative) we may require further information to ensure that you are duly authorised to make that request.
For the purposes providing banking and financial services, we disclose personal information to third parties (including our affiliates) confidentially, and where necessary, as follows:
We will only share your information for the purposes outlined in the Section 4 (“Purposes and Use of Personal Information”) in this Global Privacy Notice.
Where required by applicable law, we shall add to Country or Territory Supplemental Provisions, and to our client terms, details of third parties we share information with, their locations, and the categories of information that we share.
We provide services to corporations and institutions in more than 120 countries and territories. Your personal information is stored and processed where Your Organization opens a product or receives a service, and backed up and further processed (unless your country or territory has data localization laws) in global service centres, for operational and regulatory purposes. The Supplemental Provisions indicate their location.
We transfer personal data in outgoing payment orders and other cross-border instructions to correspondent banks. Where there is an incoming payment or any other transaction, we will transfer beneficiary account information to our correspondent bank if the payment is processed through our WorldLink ® service, or if the funding account is held in another Citi affiliate, or if we are required by statutory obligations.
Citi and its service providers transfer your personal information to countries and territories that may not provide legal protection that is equivalent to that offered in the place of business or establishment of Your Organization. For this reason, we take steps to ensure that your personal information receives an optimal level of protection wherever we process it, by using our own affiliate organizations, or if otherwise, by introducing appropriate contractual and technical and operational means, including standard contractual clauses, complemented with transfer impact assessments (TIA) and specific measures to resolve any issues detected in a TIA. Where transferring data is an essential pre-requisite for executing a banking instruction, carried out as mandated, and with the knowledge and in the interest of the client, we may rely in legal exceptions or derogations for international data transfers in countries that have no formal declaration of data equivalence or ’adequacy’.
We process personal information only for the length of time that is necessary to carry out the purposes for which personal data was collected and retain your data during such time Your Organization’s accounts and products are open, or a transaction is active, and for a certain time after their closure. Our retention periods vary in accordance with applicable law in the country where we provide services, including under relevant commercial codes, banking and securities acts, anti-money laundering and external legislation, and lastly, in accordance with statutory limitation periods. When the retention of your personal information is no longer necessary, we will securely dispose of it by destroying the data, or we will irreversibly anonymize it, so that it is no longer personal data. The Country and Territory Supplements indicate the applicable retention terms.
Citi stakes reasonable steps to preserve the security of personal information.
All personal information is held in a protected environment with sufficient organizational and technology measures appropriate to a professional financial organization. We have implemented security controls, procedures and protocols across our different business lines, physical premises, and IT networks to minimize loss, misuse, unauthorized access, modification, or disclosure of personal information. All information shared with external third parties is encrypted during transmission and in storage, and all information held internally is protected using security passwords and logons or other security procedures. However, due to the inherent nature or electronic communications, we cannot guarantee the security of personal information outside our networks.
Our products and financial services are intended for corporate, government and institutional clients, and are not designed for persons that cannot enter into business transactions in their own name, including children.
We do not knowingly collect without consent from their parents or guardians, personal information from persons under the age of 16, other than for executing payments. We do not sell, share, or use their data for social media and we do not have targeted advertising directed to children.
We may process personal information relating to minors with prior consent from their parents or guardians, if they are named beneficiaries of trusts, wills or insurance policies, and for similar uses permitted by law. If you have reason to believe that information about a child has been provided to us in error, please contact us.
NORTH AMERICA
CALIFORNIA
ASIA-PACIFIC
LATIN AMERICA
EUROPE, MIDDLE EAST AND AFRICA
European Union Countries (EU) | European Economic Area (EEA) (+EU Countries) | OTHER EUROPEAN COUNTRIES WITH SIMILAR OR EQUIVALENT LAWS | |||
Austria | Estonia | Italy | Portugal | Iceland | United Kingdom |
Belgium | Finland | Latvia | Romania | Liechtenstein | Jersey |
Bulgaria | France | Lithuania | Slovakia | Norway | Guernsey |
Croatia | Germany | Luxembourg | Slovenia | Monaco | |
Cyprus | Greece | Malta | Spain | Isle of Man | |
Czech Republic | Hungary | Netherlands | Sweden | San Marino | |
Denmark | Ireland | Poland | The Vatican |
Please click here to access out Digital Platforms supplement, which apples to Citi’s online banking and trading portals, and mobile Apps.
Citi Research activities are covered by a separate document, accessible here.
Please use the Contact Us links provided under Section 6 (“Your Privacy or Data Protection Rights”) to exercise your data subject rights, or refer to the Supplemental Provisions for the location were we provide services. You may also contact our Data Protection Officers as indicated in the Supplements, including:
California Residents If you have any questions about this Supplement, the ways in which Citi collects and processes your Personal Information described in this Supplement, your choices and rights regarding such use, or wish to exercise your rights under the CPRA, please visit Citi California Privacy Hub or call us at 833-981-0270 (TTY: 711) | |
Citibank Europe plc Data Protection Officer 1 North Wall Quay Dublin, Ireland D01 T8Y1 | Citi UK and European Chief Privacy Officer ( Data Protection Officer) 40 Bank Street, 9th Floor London E14 5AB United Kingdom |
If you feel that your data has not been handled correctly by Citi, or you are unhappy with our response or have concerns regarding the use of your data, you have the right to lodge a complaint with a data protection authority in the country where the alleged infringement of data protection law occurred. Contact details for data protection authorities can be found here, and as otherwise indicated in any country or territory-specific supplemental provisions:
EU/EEA: http://ec.europa.eu/justice/article-29/structure/data-protection- authorities/index_en.htm
United Kingdom: Information Commissioner’s Office (ICO): www.ico.org.uk
Jersey: Office of the Information Commissioner: https://jerseyoic.org