This page was last updated on November 10, 2025.
Please select a language to view the Global Privacy Notice for Institutional Clients. To view the notice in English, please scroll down.
At Citi we value and protect the privacy of our clients and their service recipients.
This Privacy Notice describes how Citigroup affiliates collect and use (or ‘process’) personal information in connection with global markets, investment banking and financial services for corporate entities, including governments and financial institutions.
Depending on how else you interact with us, other Privacy Notices may also apply. For example: notice applies when you visit our websites, customer/ US personal banking privacy notices apply to retail banking, and wealth and private banking clients have their privacy notices. Citi also has specific notices for non-client activities, Citi Careers (for job applicants), HR for our global workforce and for Suppliers and Contractors.
This Privacy Notice does not replace privacy notices related to any other interactions with us, nor does it override Privacy Notices issued for specific purposes.
This Privacy Notice applies to the processing of personal information by Citi legal entities in general in regard to corporate banking and financial services in the following business areas:
Our Markets business serves corporates, institutional investors and governments from trading floors around the world. The strength of our Sales & Trading, Underwriting and Distribution capabilities span currencies and asset classes including Rates, Equities, Spread Products and Commodities.
Banking is organized around three lines of business: our Investment Bank, which meets clients’ capital raising needs and provides merger and acquisition and equity and debt capital markets-related strategic financing solutions; our Corporate Bank, which serves as the conduit of Citi’s full product suite to clients; and our Commercial Bank, which helps mid-sized companies address the challenges of rapid growth and international expansion. The unified Banking & International organization oversees the local delivery of the full firm to clients in
markets where Citi has an on-the-ground presence.
Our suite of Services encompasses treasury, cash and trade banking services, and investor, as well as issuer services. Within this offering Cash and Trade deliver an integrated suite of innovative and customized cash management and trade finance services to meet the needs of multinational corporations, financial institutions and public sector organizations. Our Investor Services arm supports banks, institutional investors, asset managers, and asset owners with local market expertise, innovative post-trade technologies and data solutions. In Issuer Services, Citi provides end-to-end capital market services through its Agency and Trust and Depositary Receipt Services businesses.
a) The Country Supplemental Provisions that may be applicable to your country of residence/domicile
b) The Digital Platforms Schedule, which covers CitiDirect and CitiVelocity; and
c) Citi Research
In this Privacy Notice we use the following terms:
“You” means any individual or natural person whose information or personal data we process in relation to financial services that we provide to Your Organization, or other service recipients.
“Your Organization” is the corporation or institution you are associated with as an employee, authorized representative, director, shareholder or client.
“Personal Information” or “Personal Data” are equivalent terms to mean any information or data:
“Sensitive Personal Information” or “Special Categories of Personal Information” are interchangeable terms that refer to categories of Personal Information that require special handling due to their inclusion of certain elements such as racial and ethnic origin, religion, medical information, political or philosophical positions and biometric data. Personal information that has been aggregated and anonymized data is not considered Personal Information for purposes of this Privacy Notice. In some US jurisdictions, sensitive personal information includes Social Security Numbers, Passports, Drivers Licenses or State IDs.
We will only process Sensitive Personal Information with your consent, unless applicable law contains exceptions or allows us to process it under a different legal basis (for example to comply with our legal obligations). In order to prevent its involuntary processing please do not share Sensitive PI or Special Categories of PI about yourself or anyone else unless you have been asked. If we receive that information directly from you or from a third party, by accident or happenstance, we may remove and dispose of it. We remind data subjects that we have an authorization, not an obligation to receive personal information (including its protected categories) from you or a third party.
1. Entity responsible for processing your Personal Information
2. Sources of Personal Information
3. Categories of Personal Information we collect and process
4. Purposes and Uses of Personal Information
5. Lawful Bases for Data Processing
6. Consequences of Not Providing Personal Information if required
7. Your Privacy and Data Protection Rights
8. Disclosures and Recipients of Personal Information
9. International Transfers of Personal Information
10. Storage and Retention (Archiving) of Personal Information
(1) Supplemental Provisions for Countries and Territories
(2) Information for Digital Platforms (CitiDirect and CitiVelocity)
(3) Citi Research
Contact Information for Complaints
The Citi legal entity that provides the accounts, products and services to Your Organization, whether as a client or a service recipient, or makes a payment to you acts as an independent business and is responsible for determining how your Personal Information is collected, the purposes that information is collected for, and how it will be processed. This is the “Data Controller,” also known as Principal. Responsible Party, Data Custodian or Data User under the laws of certain countries.
Please refer to the list of Data Controllers for the Country or Territory relevant to the services you receive. For geographies without a specific Supplement, please refer to the global list of Citi branches and affiliate available here.
In certain cases, Citi entities act as intermediaries, and consequently as Data Processors, or service providers (and not as Data Controllers): for example, where Citi entities are links a payment chain and are neither the institution originating a payment instruction, nor the final link that processes a payment to the beneficiary); when executing card payments on behalf of banks and merchants, and in transfer agency and payment agency agreements. This Privacy Notice is not intended for activities where Citi is an intermediary and a data processor. (the relevant privacy notice will be issued by the Data Controllers in those operations). Please note that Data Processors are sometimes required to comply with legal obligations, for example, scrutinizing payment beneficiaries names for international sanctions, fraud, money laundering or combating terrorism financing and undertake these discrete activities in a special capacity as Data Controller.
INDIRECTLY: From Your Organization and other entities
Your Organization
We obtain most of our information about you indirectly from Your Organization or from other third parties, including financial institutions, government entities, credit reference agencies, recognized anti-fraud data sharing from domestic and international organizations, and from companies specialized in background checks. This includes your name, place and date of birth, nationality, account routing information, nationality and business and/or home contact address and phone numbers, and certain information required for Know-Your-Client (KYC), Anti Money Laundering (AML) and Countering Terrorism Financing information, and for sanctions-checking purposes. In some countries we require a form of government ID.
To uphold the security, integrity and legality of our operations we obtain personal information from company or commercial registers, insolvency lists, and registers of persons that have been bankrupted or banned temporarily or permanently from holding directorships. Our contracted subscription services also review estimated wealth, court listings, court judgments, and press articles (mainly on allegations of corruption and other red flags) on senior government figures and politically exposed persons, and our security and information services review international sanctions lists and anti-fraud cooperation mechanisms.
We also obtain (to a lesser degree) personal information from international and domestic payment infrastructures, financial and currency markets, investment and settlement infrastructures including clearing houses, securities depositories, stock exchanges, OTC or private exchanges and similar sources.
As required and/or permitted by law, we also monitor and record telephone, email, instant messaging, and other online communications with us have resulted or may result in a banking or financial transaction.
DIRECTLY: From You
We obtain information directly from You from various sources:
General Categories of Personal Information
Citi collects personal information about you, for purposes indicated in this Global Privacy Notice.
The categories of personal information that we process, with their elements include:
Sensitive Personal Information or “Special Categories of Data”
Where required by law (to comply with legal obligations) or as appropriate to protect a substantial public interest, we process sensitive information (or special categories of personal data), including information such as your Social Security and other national identity. We have systems that compartmentalize such information, and operational, technical and governance measures, including access controls that protect the confidentiality and security of all information.
We only collect and process the amount of personal information that is necessary to provide our services, and as required by business, legal, and regulatory aims. We will offer detailed information and additional disclosures if appropriate where we collect or otherwise process sensitive or “special categories of personal data”, including biometric or behavioral data that we obtain from your interactions with our systems and applications, including by way of example your mouse speed and movements, your keyboard usage, and voice pattern recognition for telephone banking, which we use to detect threat actors, or demonstrate that you are not being impersonated (‘prove you are human’ tests). When we use the built-in biometric authentication technology in your mobile device, we do not have access to the data, that remains locked in your mobile device.
Digital Personal Information
For details on the information we collect from your device, and your use of digital resources consult :
We use your Personal Information for the following purposes:
Certain countries and territories require Citi to offer to individuals the options and means to limit their use or disclosure of personal information. Please refer to the Special Provisions for your country or territory for information on these additional rights and how to exercise them. Citi corporate businesses do not sell or share your Personal information with third parties for cross-contextual advertising or other commercial purposes. We also do not disclose the Personal Information of persons under the age of 16 (see ‘Minors and Children’ further below).
Citi does not delegate control or decision-making functions to automated processing means (including Artificial Intelligence) and does not engage in profiling that may result in legal or similarly significant effects. Nevertheless, we use artificial intelligence to monitor transaction data, to ensure the consistency and correctness of outputs, detect and prevent illegal activities, for risk management and investment analysis, as an information assistance tool for our personnel. We use fully automated means for example in algorithmic securities trading solely where all information is de-personalized.
If Your Organization is a Citi client, depending on your digital marketing choices, we may create AI profiles to offer you products targeted to your organization. Our marketing communications have ‘unsubscribe’ links to change your preferences or suppress further notifications.
We do not use your personal data to train third party models. However, when processing involves machine learning or statistical models, it may not be always technically feasible to remove all traces of an individual’s data; however, we will take reasonable steps to ensure rights are respected to the extent required by law.
The lawful bases that we rely on for data processing do vary, depending on the applicable law in the location where data is collected. These include as the case may be:
When we collect and process sensitive personal information, or ‘Special Categories of Information’, we will request your consent unless the law allows us to rely on prescribed exceptions based on a substantial public interest:
If we request you to provide consent, we will make clear to you if it is our legal basis at the point of gathering. For example, your consent may be needed to: (a) initiate any contract or transaction between us, that will subsequently enable us to use other lawful basis (e.g. contract necessity); (b) to send you commercial communications or marketing about Citi services, that can be of interest to you and your organization, (c) where we use certain technologies such as online trackers (e.g. to determine your location); (d) where we record and/or monitor service chats, and voice or video conversations, for service quality, security, fraud monitoring, staff training, and to deal with complaints, disputes and to prevent criminal activity’ To the extent permitted by law, these recordings are our sole property.
If you choose not to agree or provide this personal information we will be unable to it may impact our ability to provide you or your organization with our services. For example:
You have rights over your personal information that are protected by law in many countries. Most countries grant 4 basic rights: Access, Rectification, Cancellation and Objection (by their initials, the so-called ARCO rights). Citi responds to these rights globally in order to provide a consistent standard to corporate clients.
You can CONTACT US to request any of the following rights:
Citi may not always be able to provide requested information or fulfil other rights where certain exceptions apply to a rights request. In our reply, if we need to withhold certain information or cannot fulfil your request we will explain the rationale for our decision, and the subsequent steps you can take.
We will always respond to your request within the timeframes provided under applicable law.
To ensure your safety and given the confidentiality of financial information, we must verify your identity before disclosing any personal data related to financial or banking operations. If you are making a request on behalf of someone else (as an attorney or a friend or relative) we may require further information to ensure that you are duly authorized to make that request.
For the purpose of providing banking and financial services, we disclose personal information to third parties confidentially, and where necessary, as follows:
We will only share your information for the purposes outlined in the Section 4 (“Purposes and Use of Personal Information”) in this Global Privacy Notice.
Where required by applicable law, we shall add to Country or Territory Supplemental Provisions, and to our client terms, details of third parties we share information with, their locations, and the categories of information that we share.
We provide services to corporations and institutions in more than 120 countries and territories. Your personal information is stored and processed where Your Organization opens a product or receives a service, and backed up and further processed (unless your country or territory has data localization laws) in global service centres, for operational and regulatory purposes. The Supplemental Provisions indicate their location.
We transfer personal data in outgoing payment orders and other cross-border instructions to correspondent banks. Where there is an incoming payment or any other transaction, we will transfer beneficiary account information to our correspondent bank if the payment is processed through our WorldLink ® service, or if the funding account is held in another Citi affiliate, or if we are required by statutory obligations.
Citi and its service providers transfer your personal information to countries and territories that may not provide legal protection that is equivalent to that offered in the place of business or establishment of Your Organization. For this reason, we take steps to ensure that your personal information receives an optimal level of protection wherever we process it, by using our own affiliate organizations, or if otherwise, by introducing appropriate contractual and technical and operational means, including standard contractual clauses, complemented with transfer impact assessments (TIA) and specific measures to resolve any issues detected in a TIA. Where transferring data is an essential pre-requisite for executing a banking instruction, carried out as mandated, and with the knowledge and in the interest of the client, we may rely in legal exceptions or derogations for international data transfers in countries that have no formal declaration of data equivalence or ’adequacy’.
We process personal information only for the length of time that is necessary to carry out the purposes for which personal data was collected, and retain your data during the time Your Organization’s accounts and products are open, or a transaction is underway, and for a certain length pf time after its closure. Our retention periods vary in accordance with applicable law in the country where we collect personal information, including under commercial banking and securities and anti-money laundering legislation, and, in accordance with statutory limitation periods. When the retention of your personal information is no longer necessary, we will securely dispose of it by destroying the data, or we will irreversibly anonymize it, so that it is no longer personal data. The Country and Territory Supplements indicate the applicable retention terms. Please note that retention periods for sensitive personal information, or protected categories of personal information are significantly constrained: if we do not need the information for a protected function any further we will erase or destroy it.
Citi takes all steps required by law to preserve the security of personal information.
All personal information is held in a protected environment with sufficient organizational and technology measures appropriate to a professional financial organization.
We have put in place and implemented appropriate technical and organizational measures to provide an high information security level that is appropriate to the risks associated with a large financial institution, and in accordance with recognized international standards including ISO/IEC 27001:2013 to prevent your personal information being accidentally lost, used¸ altered disclosed or accessed in an unauthorized way.
In addition, we apply appropriate safeguards, including strict role-based access, encryption in transit and at rest, operational and logical separations, need-to-know approvals and data deletion once the processing of your personal information is no longer necessary.
Our products and financial services are intended for corporate, government and institutional clients, and are not designed for persons that cannot enter into business transactions in their own name, including children.
We do not knowingly collect without consent from their parents or guardians, personal information from persons under the age of 16, other than for executing payments. We do not sell, share, or use their data for social media and we do not have targeted advertising directed to children.
We may process personal information relating to minors with prior consent from their parents or guardians, if they are named beneficiaries of trusts, wills or insurance policies, and for similar uses permitted by law. If you have reason to believe that information about a child has been provided to us in error, please contact us.
NORTH AMERICA
CALIFORNIA
ASIA-PACIFIC
LATIN AMERICA
EUROPE, MIDDLE EAST AND AFRICA
| European Union Countries (EU) | European Economic Area (EEA) (+EU Countries) | OTHER EUROPEAN COUNTRIES WITH SIMILAR OR EQUIVALENT LAWS | |||
| Austria | Estonia | Italy | Portugal | Iceland | United Kingdom |
| Belgium | Finland | Latvia | Romania | Liechtenstein | Jersey |
| Bulgaria | France | Lithuania | Slovakia | Norway | Guernsey |
| Croatia | Germany | Luxembourg | Slovenia | Monaco | |
| Cyprus | Greece | Malta | Spain | Isle of Man | |
| Czech Republic | Hungary | Netherlands | Sweden | San Marino | |
| Denmark | Ireland | Poland | The Vatican | ||
Please click here to review our Digital Platforms supplement, which apples to Citi’s online banking and trading portals, and mobile Apps including CitiVelocity and CitiDirect.
Please click here to review the Citi Research supplement.
Please use the Contact Us links provided under Section 6 (“Your Privacy or Data Protection Rights”) to exercise your data subject rights, or refer to the Supplemental Provisions for the location were we provide services. You may also contact our Data Protection Officers as indicated in the Supplements, including:
State of California Residents If you have any questions about this Supplement, the ways in which Citi collects and processes your Personal Information described in this Supplement, your choices and rights regarding such use, or wish to exercise your rights under the CPRA, please visit Citi California Privacy Hub or call | Residents in other Countries and Territories Please review the Country Supplement applicable to your country or territory |
If you feel that your data has not been handled correctly by Citi, or you are unhappy with our response or have concerns regarding the use of your data, you have the right to lodge a complaint with a data protection authority in the country where the alleged infringement of data protection law occurred. Contact details for data protection authorities can be found here, and as otherwise indicated in any country or territory-specific supplemental provisions:
EU/EEA: http://ec.europa.eu/justice/article-29/structure/data-protection- authorities/index_en.htm
United Kingdom: Information Commissioner’s Office (ICO): www.ico.org.uk
Jersey: Office of the Information Commissioner: https://jerseyoic.org