mBanking Privacy policy
Last updated: October 10, 2026
In accordance with the Law on Personal Data Protection ("Official Gazette of RS", No. 87/2018) and UniCredit Group standards in the field of personal data protection, we hereby inform you, regarding the processing of your personal data when you, as the Data Subject, use the mobile banking application (mBanking expert) of UniCredit Bank, of the following information:
Data Controller
The Personal Data Controller is UniCredit Bank Serbia a.d. Beograd, Rajićeva Street No. 27-29, registration number 17324918 (hereinafter: the Bank).
Data Protection Officer (DPO)
As part of the implementation of personal data protection standards prescribed by the Law on Personal Data Protection and UniCredit Group rules, the Bank has appointed a Data Protection Officer whom you may contact exclusively for questions and requests related to the processing and protection of personal data and the exercise of rights prescribed by the Law on Personal Data Protection, at the following addresses:
- Email: dpo@unicreditgroup.rs
- Address: Jurija Gagarina 12, 11070 Novi Beograd
Purpose and Legal Basis for Processing
The Bank processes personal data based on the law, for the following purposes and in accordance with the legal bases below:
We use your personal data for the purpose of providing payment and other services within the mBanking Expert (mBanking) application, preventing fraud and unauthorized access to the application, communication, and offering Bank products, as well as for improving the performance of the application. For the specified purposes, the Bank must have access to the data of the client using the application. Within the meaning of the Law on Personal Data Protection, this data is considered personal data, and within the meaning of the Law on Banks, it is considered a business (banking) secret. As stated in this Privacy Policy, the data is used for the purposes described above and processed in accordance with the law, for the performance of a contract concluded with the data subject, compliance with legal obligations of the Bank, based on the consent of the data subject, and the pursuit of legitimate interests of the Bank or third parties.
By using the mobile banking application (mBanking), you consent to the collection and processing of data in accordance with this Privacy Policy.
Categories of Personal Data Processed
During the use of the mBanking application, we will collect contact data from you, which is used to contact you or identify you as a user. Personal data falling into this group includes, but is not limited to: email address, phone number, application usage data, etc.
Application Usage Data
Usage data is collected automatically when using the mobile banking application (mBanking).
Usage data may include information such as your device's Internet Protocol address (e.g., IP address), browser type and browser version, information about the pages within the mobile banking application (mBanking) visited by the user, date and time of visit, time spent on those pages, unique device identifiers, and other technical and diagnostic data necessary to protect your account and prevent unauthorized access to the application.
By accessing and using the mobile banking application (mBanking) via a mobile device, we may automatically collect certain data relating to you, including, but not limited to:
- the type of mobile device you use,
- your mobile device's unique ID (MAC address), your mobile device's IP address,
- your mobile device's operating system, technical indicators pointing to the presence of malicious applications installed on the device, the type of mobile Internet browser you use on the device,
- unique device identifiers, other diagnostic data, device location (only with given user permission).
We may also collect data sent by your browser when you visit our mobile banking application (mBanking) or when you access the mobile banking application.
Method of Using Personal Data
The Bank may use your personal data as a user of the mBanking application for:
- managing your account: to manage your registration as a user of the mobile banking application (mBanking). The data provided may enable access to various functionalities of the application available to you as a registered user.
- performance of the contract you have concluded with the bank, primarily in the area of payment services – payment transactions, exchange operations, and other services.
- contacting via communication channels approved by you for contact with the bank, such as email, phone calls, SMS, or push notifications from the mobile application when necessary or reasonable for their execution.
- forwarding news, special offers, and general information about the Bank's products and services, information about the mobile banking application, and other information related to products and services you have already contracted with the Bank, via the selected communication channel for delivering such information, exclusively if you have given consent to receive such messages.
- managing your requests: reviewing, accessing, and managing your requests to the Bank.
- timely detection and prevention of fraud, suspicious activities, and unauthorized access to the application,
- other purposes: e.g., to improve the performance of our mobile banking application (mBanking).
Recipients of Personal Data
The Bank has the right to forward personal data relating to you, as well as other data considered a banking secret, and data on obligations under contracts concluded between the Bank and the Data Subject, as well as the manner of their settlement and adherence to contractual provisions, to:
- employees and engaged persons in the Bank (who, according to the nature of their work, must have access to such data in order to fulfill contractual and legal obligations, as well as achieve the legitimate interests of the Bank and third parties), members of the Bank's bodies, and Bank shareholders;
- Members of the UniCredit Group, whose updated list can be found on the following webpage;
- Competent regulatory authorities and organizations (National Bank of Serbia, Securities Commission, Administration for the Prevention of Money Laundering, tax, judicial, and other authorities e.g., public bailiffs, external Bank auditor, who due to the nature of their work must have access to such data, as well as other organizations e.g., Forum for the Prevention of Credit Abuse at the Serbian Chamber of Commerce);
- Public information systems - e.g., Unique Register of Accounts of natural or legal persons at the National Bank of Serbia, information systems of the Association of Serbian Banks (e.g., Credit Bureau), Business Registers Agency, Real Estate Cadastre;
- in certain cases, depending on the business relationship, to specific third parties with whom the Bank has concluded a Contract governing the handling of confidential data, whose updated and complete list can be found on the Bank's website in the "Personal Data Protection" section.
Personal data may be transferred from the Republic of Serbia to other countries or international organizations only in accordance with the applicable regulations.
Retention Period of Personal Data
The Bank will process personal data collected for the purpose of exercising rights and obligations from the business relationship as long as the Bank's business relationship with the Data Subject lasts, except in cases where the Bank is obliged to retain data even after the termination of business cooperation based on law (e.g., Law on Prevention of Money Laundering and Terrorism Financing prescribes the obligation to retain data and documentation related to the client for at least ten years, or five years from the date of termination of the business relationship, execution of transaction, etc.), consent of the Data Subject, or legitimate interest (e.g., in case of a potential dispute between the Data Subject and the Bank).
Personal data processed solely on the basis of the Data Subject's consent is processed in accordance with the purpose for which it was collected, i.e., until the consent is withdrawn by the Data Subject.
Security of Your Personal Data
The security of your data is important to us, but keep in mind that no method of transmission over the Internet or method of electronic storage is 100% secure. The Bank implements a range of technical, personnel, and organizational security measures to ensure an appropriate level of processing security for your data, in accordance with the Law on Personal Data Protection.
The Bank will take all necessary steps to ensure that your data is treated securely and in accordance with applicable legal regulations and this Privacy Policy, and will not transfer your data unless appropriate controls are in place for such transfer and a clearly defined processing reason exists.
To increase the security of your personal and financial data and prevent potential abuse, the Bank recommends enabling the maximum level of security and protection against access by third parties on the mobile phone used for the mobile banking application (mBanking).
Privacy of Minors
The Bank does not have a regular business need to collect and process data of minors, unless, in accordance with applicable family law regulations, those persons acquire legal capacity before reaching majority and establish a business relationship with the Bank or such relationship is established by their legal guardians on their behalf and for their account. If we determine that we have collected data from minors without parental or legal guardian consent (and in cases where minors do not have the legal capacity necessary to conclude legal transactions with the Bank), that data will be removed from our system.
Rights of the Data Subject Regarding Personal Data Processing
The Data Subject has the right to access personal data processed by the Bank.
In cases provided for by personal data protection regulations, the Data Subject has the right to request rectification, completion, erasure of data, as well as the right to object and restrict processing. The exercise of certain rights may depend on the legal basis and circumstances of the specific processing, and in certain cases may be limited to the extent provided by regulations (e.g., if processing is based on the fulfillment of a legal obligation of the Bank). Under the conditions determined by personal data protection regulations, the Data Subject has the right to data portability, i.e., the right to receive data previously provided to the Bank to transfer it to another controller, as well as the right to have data directly transferred to another controller by the Bank, if technically feasible and if, according to the Bank's assessment, the required data security standard is ensured.
Right to Lodge a Complaint with the Competent Authority
The Data Subject has the right to lodge a complaint with the competent authority (Commissioner for Information of Public Importance and Personal Data Protection) regarding the processing of personal data relating to him/her at the email address: office@poverenik.rs
Changes to this Privacy Policy
Updates or changes to this Privacy Policy will be subject to special notifications in accordance with the defined method and approved communication channels. We will notify you of any changes by posting the new Privacy Policy on this page.
The new version of the Privacy Policy will be available to all users within the mobile banking application (mBanking) at the same location as the previous version. Notifications of changes will be delivered to users in accordance with the authorizations granted for this type of notice. We advise you to review this Privacy Policy periodically for any changes. Changes take effect upon posting.
Contact Us
If you have any questions regarding this Privacy Policy, you can contact us:
- By email: kontakt@unicreditbank.rs
- By visiting our website: https://www.unicreditbank.rs/rs/pi/kontakt/kontakt.html
Bank staff are at your disposal in all Bank branches, as well as the Data Protection Officer who can be contacted in writing at: Jurija Gagarina 12, 11070 Novi Beograd or via email address: dpo@unicreditgroup.rs
For more detailed information on how the Bank processes personal data, please visit the Bank's website in the "Personal Data Protection" section.