Privacy Notice
Last Update 8 September 2026
1. Overview and Purpose
GIB Capital (“GIBC”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your Personal Data. This Privacy Policy explains how we collect, use, share, retain and protect your Personal Data, and the rights available to you, in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia issued by Royal Decree No. M/19 dated 09/02/1443H (the “PDPL”) and its Implementing Regulations.
GIB Capital is a company licensed by the Capital Market Authority (CMA), providing a full range of financial services, including the following activities: Dealing as principal, agent, and underwriter, Arranging, Advising, Managing investment funds and clients’ portfolios, and Custody. . This Policy applies to Personal Data that you provide to us, that we collect about you, or that is lawfully provided to us by others (including through referrals), in the course of our business relationship with you or your use of our websites and applications.
2. Scope and Applicability
This Policy applies to the Personal Data of our clients and prospective clients, website and mobile-application visitors, counterparties and other individuals with whom we interact in the course of our business. It applies to Personal Data collected directly from you, through the GIB Capital websites, mobile applications and electronic communications, and through lawful third-party and referral sources.
3. Contact Information
If you have any questions about this Policy or how your Personal Data is processed, or if you wish to exercise your rights under the PDPL and its Regulations, please contact our Data Privacy / Data Protection Team (Data Management Office) at [email protected], through GIB Capital’s official channels, or on 8001240121.
4. Definitions
Capitalised terms have the meaning given to them in the PDPL and its Implementing Regulations. Key terms include:
|
Term |
Meaning |
|
Personal Data |
Any data, of whatever source or form, that would lead to identifying an individual specifically, or make it possible to identify an individual directly or indirectly — including name, personal identification number, addresses, contact numbers, licence numbers, records, personal property, bank-account and credit-card numbers, images of the individual, and other data of a personal nature. |
|
Sensitive Data |
Personal Data revealing ethnic or tribal origin, or religious, intellectual or political belief; membership of non-governmental associations; criminal and security data; biometric or genetic data; credit data; health data; and data indicating that one or both of an individual’s parents are unknown. |
|
Processing |
Any operation carried out on Personal Data by any means, including collection, recording, storage, use, disclosure, transfer and destruction. |
|
Data Subject |
The individual to whom the Personal Data relates. |
|
Controller / Processor |
GIBC determines the purposes and means of processing (Controller); parties processing on our behalf under written agreement act as Processors. |
5. Methods of Data Collection
5.1 Data Collected Directly from You
We collect the minimum Personal Data necessary to deliver our services and meet our legal and regulatory obligations. Depending on your relationship with us, this may include:
• Identity & contact data: name, national ID / Iqama number, date of birth, nationality, and contact details (address, email, telephone);
• Financial & KYC data: employment details, income, source of funds and wealth, tax identification and other information required for Know-Your-Customer (KYC) and Anti-Money-Laundering (AML) purposes;
• Account & transaction data: account holdings, transactions, orders, fees and investment activity;
• Communications data: records of your communications with us, including emails, telephone calls and online chats;
• Sensitive Data: where applicable, Sensitive Data, processed only where permitted under the PDPL and, where required, with your explicit consent.
We also lawfully obtain Personal Data from sources other than you, including:
• Referrals: where you are referred to us, we receive limited contact details — typically your name, email and telephone number — only after your consent to that referral has been obtained, so that we may contact you about our products and services;
• Third-party & public sources: public records, credit-reporting agencies, and custodians holding securities, where lawfully permitted;
• Website & technical sources: IP address, device and browser information, and browsing activity on our websites (see the Cookie Policy in Part B).
6. Purposes of Processing and Legal Basis
We process your Personal Data only where we have a lawful basis under the PDPL. Our principal legal bases are consent; performance of a contract to which you are a party; compliance with a legal or regulatory obligation; and, where recognized under the PDPL and its Regulations, our legitimate interests, balanced against your rights. The table below maps each purpose to its legal basis.
|
Purpose of Processing |
Legal Basis (PDPL) |
|
Opening, administering, updating and closing your accounts; processing your transactions and investments |
Performance of a contract |
|
Meeting KYC, AML, CMA and other legal / regulatory obligations, and preparing and submitting regulatory reports |
Compliance with a legal / regulatory obligation |
|
Issuing account statements, reports and investment-activity information |
Performance of a contract; legal obligation |
|
Providing support and resolving your queries and complaints |
Performance of a contract; legitimate interests |
|
Contacting individuals referred to us about our products and services |
Consent (obtained prior to referral) |
|
Providing personalised investment recommendations |
Consent |
|
Sending marketing communications and market-research material |
Consent |
|
Analysing your investment activity to improve our products, services and websites |
Legitimate interests (or consent where required) |
|
Detecting, preventing and investigating fraud and securing our systems |
Legal obligation; legitimate interests |
Where processing relies on your consent, you may withdraw it at any time (see Section 9). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, nor processing we are required or permitted to continue on another legal basis (for example, to meet AML record-keeping obligations).
7. How We Share Your Personal Data
We share Personal Data only to the extent necessary for the purposes set out in this Policy and in accordance with the PDPL. We may share your Personal Data with:
• Group entities: other entities within the GIB group, for administrative, operational and advisory purposes, within the Kingdom of Saudi Arabia;
• Regulators and authorities: the CMA, SDAIA and other regulatory, supervisory or governmental authorities, where we have a legal or regulatory duty;
• Service providers: acting on our behalf under written agreements (Data Processors) — such as IT, custody and professional-services providers — subject to appropriate safeguards;
• Legal / regulatory disclosure: where required by a competent judicial or regulatory authority, or to establish, exercise or defend legal claims.
We do not sell your Personal Data.
8. Location of Processing and Cross-Border Transfers
Your Personal Data is processed and stored within the Kingdom of Saudi Arabia. Sharing of Personal Data within the GIB group, as described above, takes place within the Kingdom and does not involve any transfer of your Personal Data outside the Kingdom.
If there is ever a requirement to process your Personal Data outside the Kingdom as part of our legal basis for processing, we will transfer it only to third parties or countries considered to provide an adequate level of data protection or, in the absence of such recognition, subject to standard contractual arrangements guaranteeing a sufficient level of protection in accordance with a standard model issued by SDAIA under the PDPL (Art. 29 and the Regulation on the Transfer of Personal Data outside the Kingdom).
9. Your Rights
Subject to the conditions and exceptions in the PDPL and its Implementing Regulations, you have the following rights in respect of your Personal Data:
|
Right |
What it means |
|
Right to know / be informed |
To know our contact details, the legal basis and exact purpose for collecting your data, how it is collected, and whether it will be shared. This Policy is intended to fulfil that right. |
|
Right of access / to obtain a copy |
To access your Personal Data held by us and obtain a copy in a clear, readable format, in conformity with our records, at no cost. |
|
Right to correction |
To request correction of your Personal Data where it is incomplete, inaccurate or out of date. |
|
Right to destruction / deletion |
To request deletion or destruction of your Personal Data where it is no longer needed for the purpose, or where you withdraw consent — subject to our statutory retention obligations, cases where our lawful interest in processing outweighs deletion, and judicial or regulatory requirements. |
|
Right to withdraw consent |
To withdraw consent to processing based on consent at any time, without affecting the lawfulness of prior processing. |
We respond to requests within the period prescribed by the PDPL and its Regulations (as a general matter, within 30 days), and we maintain a record of all Data Subject requests. To exercise any right, withdraw consent, or raise a privacy query or complaint, contact us using the details in Section 3. We may need to verify your identity before acting on a request; if we cannot meet a request in full — for example, where law requires us to retain certain data — we will explain why.
10. Retention of Personal Data
We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy our legal, regulatory, accounting and reporting obligations, and to resolve disputes and enforce our agreements. In setting retention periods we consider:
• statutory and regulatory retention requirements applicable to CMA-licensed persons, including AML and record-keeping obligations;
• the duration of our relationship with you and applicable limitation periods for potential legal claims;
• any specific retention period required or permitted by the PDPL and its Implementing Regulations.
When Personal Data is no longer required for any lawful purpose, we destroy, delete or anonymise it without undue delay, in a secure manner, in accordance with the PDPL and our internal retention and disposal procedures.
11. Security of Your Personal Data
We maintain physical, electronic and procedural safeguards designed to protect your Personal Data against unauthorized access or use, accidental or unlawful alteration, disclosure, loss or destruction. These include access controls, encryption of information in transit in line with standard norms, staff confidentiality obligations, continuous training of our employees in the proper handling of Personal Data, and contractual security requirements on third parties who process Personal Data on our behalf.
12. Personal Data Breaches
We maintain procedures to detect, report, investigate and respond to Personal Data breaches. Where a breach occurs, we will notify SDAIA and, where required, affected individuals, within the timeframes and in the manner prescribed by the PDPL and its Implementing Regulations.
13. Children’s Privacy
Because children cannot provide consent for the processing of their Personal Data, the consent of a child’s guardian must be obtained. Our services are not intended for children under 18 years of age, and we do not knowingly collect or process children’s Personal Data. Where a Data Subject is, in the Kingdom, under 18 (or, elsewhere, below the age of majority in their jurisdiction), this Policy must be reviewed and agreed to by their guardian
14. Automated Processing and Marketing
We do not engage in profiling or automated decision-making that produces legal or similarly significant effects about you, except where necessary for entering into or performing a contract with you, where permitted by law, or where your explicit consent has been obtained. We send marketing and market-research communications only where you have consented, and you may opt out at any time using the contact details in Section 3 or the unsubscribe facility in the relevant communication.
15. Changes to this Policy
The effective date of this Policy is stated on publication. We may update this Policy from time to time in response to legal, regulatory or operational changes; any updated version will be posted on the GIB Capital website with a revised date, which will be the effective date of the changes. We recommend that you review this Policy periodically.
Licensed by the Capital Market Authority No. 07078-37 on July 22, 2007 with a Commercial Registration No. 1010244294 and Unified Number 7001553465 on February 14, 2008, with a paid-up capital of SAR 200 million.