Privacy Policy
Privacy Statement
National Bank of Malawi plc recognizes the importance of the personal data entrusted to us. We are committed to protecting the privacy and security of your personal information in accordance with applicable data protection laws and regulations.
A. Who We Are
National Bank of Malawi plc (“We”, “Us”, “Our”) provides banking and payment services through our website, mobile apps, and online banking platforms (“Our Services”).
Registered Office: NBM Towers, 7 Henderson Street, P.O Box 945, Blantyre, Malawi
B. Scope of this Statement
This statement explains how we collect, use, store, share, update, safeguard, and delete your personal data when you interact with our services. It also outlines your rights. This statement does not apply to third-party services.
C. Personal Information We Collect
- Name, age, gender, and identification details
- Contact details (address, email, phone number)
- Employment and financial information
- Online identifiers (IP address, cookies)
- Service requests, preferences, and feedback
- Marketing preferences and consents
- Sensitive data (biometric, health, beliefs where applicable)
D. How We Collect Information
We collect data:
- Directly from you
- Automatically through system usage
- From third parties such as credit bureaus, regulators, and partners
Automatically Collected Data Includes:
- Device information (IP, browser, OS)
- Usage data (pages visited, session duration)
- Location data
- Cookies and tracking technologies
E. Why We Process Your Information
1. Contractual Requirements
- Providing banking services
- Processing transactions
- Customer communication
- Credit assessments
2. Legal Obligations
- Fraud prevention and crime detection
- Compliance with laws and regulations
- Identity verification
3. Legitimate Interests
- Business operations and risk management
- Legal claims and advisory services
4. Consent
Where required, we process your data based on your explicit consent.
F. Sharing Your Information
We may share your data with:
- Service providers and advisors
- Business partners
- Regulatory authorities and law enforcement
- Financial institutions and credit agencies
We ensure appropriate safeguards are in place when transferring data across jurisdictions.
G. Data Retention
We retain personal data only as long as necessary to meet legal, regulatory, and business requirements.
H. Security
We implement appropriate security measures to protect your data against unauthorized access, loss, or misuse.
I. Automated Decision-Making
We may use automated systems (including profiling) for fraud detection and service improvement. You have the right to request human review.
J. Marketing
We may use your data to inform you about our products and services. You can opt out at any time.
K. Your Rights
- Access your personal data
- Correct inaccurate data
- Request deletion
- Restrict or object to processing
- Data portability
- Withdraw consent
L. Third-Party Links
Our services may contain links to third-party websites. We are not responsible for their privacy practices.
M. Changes to this Statement
We may update this policy periodically. Continued use of our services means acceptance of changes.
N. Contact Us
If you have any questions or complaints, contact us:
- Toll Free: 626
- Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
- Visit any Service Centre
You may also contact the Data Protection Authority:
Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
Phone: +265 991802180
Effective Date
1 October 2025

