CBE Super App

Privacy Policy

How the Commercial Bank of Ethiopia collects, uses, stores, shares, and protects your personal data across the CBE SuperApp and all integrated Mini Apps.

Effective Date: May 01, 2026

1. Introduction

This Privacy Policy establishes how the Commercial Bank of Ethiopia CBE collects, uses, stores, shares, and protects the Personal Data of customers who use the CBE SuperApp.

2. Definitions

Personal Data: Any information relating to an identified or identifiable individual as per defined under Personal Data Protection Proclamation No. 1321/2024.

Sensitive Personal Data: Biometrics, health data, criminal records, or other categories defined under Ethiopian law.

Processing: Any operation performed on Personal Data, including collection, storage, use, sharing, or deletion.

Controller: The entity that determines why and how data is processed (CBE).

Processor: Any third party processing data on behalf of CBE.

Mini-Apps: Third-party or CBE-owned functional applications integrated within the SuperApp.

3. Scope

All users of the SuperApp and Mini-Apps, all digital services linked to the SuperApp, all data processed through the SuperApp, including payments, onboarding, customer support, and third-party integrations.

4. Categories of Personal Data CBE Collects

Contact Information: Name, address, phone numbers, and email addresses.

Financial Information: Account numbers, card numbers, transaction records, loan data, repayment history, income information.

Identification Information: Fayda ID, passport, driver's license, date of birth, nationality, biometrics (fingerprint/face ID), account verification details.

Sensitive Personal Data: Health information, disability data, criminal records only where required by law or for regulated banking services.

Technical & Device Information: Device ID, IMEI, MAC address, IP address, geolocation, app usage logs, browser type, cookies.

Demographic & Professional Data: Occupation, employer, marital status, etc.

Mini-App Transactional Data: Data generated through the use of integrated Mini-Apps.

5. Lawful Basis for Processing

Contract performance: To provide banking and digital financial services.

Legal obligations: As required by NBE directives, AML/CFT laws, KYC requirements, and other regulatory mandates.

Legitimate interest: Fraud prevention, service enhancement, security monitoring.

Consent: For marketing communications, location tracking, and optional features.

Public interest: Where required for financial sector stability or regulatory reporting.

6. Sources of Personal Data

  • Information you provide directly through the app or at branches.
  • Your transactions and interactions with our services.
  • National ID and government authorities.
  • Credit reporting agencies.
  • Regulated third-party service providers.
  • Device and system logs generated automatically.

7. Purpose of Processing Personal Data

Service Delivery: Opening and managing accounts, processing payments, transfers, deposits, and withdrawals. Supporting Mini-App functions.

Service Improvement: Customer analytics and product development, performance monitoring.

Marketing & Communication: Sending promotional offers with your consent, service alerts and important notifications.

Security & Fraud Prevention: Preventing unauthorized access and monitoring suspicious activity.

Risk Management & Regulatory Compliance: KYC/AML checks, fraud monitoring, credit scoring and loan assessment, and reporting to NBE and other regulators.

8. Data Sharing

Internal Sharing within CBE: Data is shared only with authorized departments that require the information to deliver services.

Third-party service providers: To assist in providing our services, such as data processing, marketing, and customer support, for the limited purpose needed.

Financial institutions: Shared only for transaction processing, settlement, and regulatory compliance.

Law enforcement & regulatory authorities: Shared only where legally required by law.

Corporate Transactions: In the event of a merger, acquisition, or sale of assets, information may be disclosed subject to confidentiality agreements.

9. Data Security

Encryption: Strong encryption technologies to protect data in transit and at rest.

Access controls: Strict access controls limiting access to authorized personnel only.

Regular security assessments: Periodic security audits and vulnerability assessments to identify and address potential risks.

10. Data Retention

CBE retains Personal Data only for as long as required by law or business needs. After expiry, data is securely deleted or anonymized.

KYC documents: 10 years (NBE requirement)

Transaction data: 10 years

Log files: 2 years

Marketing data: Until consent is withdrawn

11. Your Data Protection Rights

Right to Access: Request access to your Personal Data.

Right to Rectification: Request correction of inaccurate or incomplete Personal Data.

Right to Erasure: Request deletion of your Personal Data, subject to legal and regulatory retention obligations.

Right to Object: Object to the processing of your Personal Data in certain circumstances.

Right to Restriction: Request restriction of processing of your Personal Data in certain circumstances.

Right to Data Portability: Request transfer of your Personal Data to another organization or to you directly.

Right to Withdraw Consent: Withdraw consent to processing at any time without affecting prior lawful processing.

12. Location Data Collection

  • Collected only with your explicit consent via in-app permission request
  • Used for services such as branch/head office locator, delivery services, or verification
  • You can manage or revoke location permissions anytime through your device settings
  • Retained only as long as necessary for the service session unless regulatory purposes require otherwise
  • There is an option to allow account creation both for resident and non resident customers. As per the National Bank of Ethiopia directives, as of December, 2025, any customers living in Ethiopia who want to open an account are required to present National ID. So, to detect their location whether they are in Ethiopia or not, we will request their location while processing Online account opening requests.

14. Contact Us

If you have any questions or concerns about this Privacy Policy, please contact us by calling 951 or visiting your nearest CBE branch.

15. Changes to this Privacy Policy

CBE may update this policy from time to time. Material changes will be communicated through the SuperApp or official channels.

16. Effective Date

This Policy enters into force effective from May 01, 2026.