Data Protection & Information Security
How we implement customer data protection and information security in the Group
Data Protection
In times of increasing digitalisation, the protection of customer data and the preservation of banking secrecy are of utmost importance and a basic prerequisite for the satisfaction of our customers. That is why data security is a key issue for us in terms of responsible banking. Commerzbank AG takes the protection of your personal data very seriously and adheres to the rules of data protection, in particular the provisions of the EU General Data Protection Regulation (GDPR) and our Group Data Protection Policy.
Sustainability and ESG are widely used terms. Sustainability describes a forward-looking perspective in which environmental, social and economic aspects are considered over the long term in order to preserve the foundations of life and business for future generations. In the corporate and financial sectors in particular, these aspects are commonly summarized under the term ESG (Environmental, Social and Governance). Sustainability is defined differently across regulatory, scientific, and economic contexts. Regulatory requirements, such as the EU Taxonomy or the EU Sustainable Finance Disclosure Regulation, provide a framework for individual sustainability aspects while leaving room for company-specific specification.
The specific meaning of sustainability for Commerzbank AG’s products, services, and business activities is set out in the ESG Framework. It defines the relevant criteria and distinguishes, in particular, between the Bank’s own business and external client investment and insurance business, including asset management and securities business (“third-party business”).
Your contact for queries regarding data protection
Responding to cybercrime
With the increasing digital networking of the state, the economy and society, cyber security and resilience are becoming ever more important. In this context, Commerzbank considers not only its own information, premises and IT systems, but also those of customers and service providers. Cyber security is a strong driver of trust and therefore also an important competitive factor. As part of the critical infrastructure, the financial industry is subject to extended legal requirements.
Group Risk Management
We want to take appropriate account of this development and future challenges in managing cyber risks. Cyber and information security risks are managed by the Group Risk Management - Cyber Risk & Information Security (GRM-CRIS) unit. The area is under the responsibility of the Group Chief Information Security Officer. In addition to already established security functions such as the information security management system, the focus is on cyber risk management and strengthening Commerzbank's cyber resilience, including information security incident management capabilities.
Related Topics
- ESG Risk Management
How Commerzbank integrates environmental, social and governance risks into its risk management
- Customer satisfaction
Living transparency and fairness in customer relationships
- Human Rights and Environmental Protection
How we respect human rights and the environment in our supply chain.
