Privacy policy
Last updated April 10, 2025
About us
The London Foundation for Banking & Finance (LFBF) is a registered charity incorporated by Royal Charter. We are dedicated to the advancement of knowledge of and awareness in, financial services and to carrying out research for the benefit of the public.
We also recognise the highest level of professional competence by awarding Chartered status to individuals who have demonstrated professional excellence in financial education and financial services.
LFBF is a Data Controller registered in the UK with the Information Commissioner’s Office, Registration Ref Z585966X.
-
Our use of your personal data
We attach great importance to personal data and use a range of measures to protect it. This notice sets out how we may collect, process, share and dispose of your data and the individual rights that are available to you.
We aim to make our use of your personal data as transparent as possible and use and protect your data in accordance with relevant legislation, including the General Data Protection Regulation (GDPR) and the UK Data Protection Act (2018).
This privacy policy relates to any data you share with us through:
- visiting our website at http://www.lfbf.org.uk, or any website of ours that links to this Privacy Notice;
- engaging with our staff and representatives, including any sales, marketing, or events.
2. Lawful use of your personal data
Data protection legislation requires organisations to have a lawful basis for collecting and processing your personal data. Below are the six lawful bases that can be used and information about how they apply to our use of your data:
- Consent – where you have advised us that you are happy to be contracted in relation to our activities and services. This is used to ensure we are marketing our services in line with legislation.
- Contract – where you have applied for a bursary, scholarship or chartered status, attended one of our events or made a purchase from us. This contract will only apply to the interaction or service you have requested.
- Legal obligation – where there is a legal requirement on us, as the Data Controller, for us to use your data in certain ways. This may include providing statistical information to regulatory agencies and information for the prevention, detection or prosecution of crimes.
- Vital interests – this is only used where we feel it is necessary for the protection of life. For example, should you be taken ill when on our premises, or when attending one of our events.
- Public task – this is only used by public authorities and therefore does not apply to our use of your data.
- Legitimate interests – where we determine that you would reasonably expect us to process your data in this way, and where it has minimal impact on your privacy. For example, we may believe it necessary to communicate changes in regulation relevant to the services we provide, including updates to policies such as this one, or to advise you of any change which may impact on the consent you have previously supplied.
3. Processing personal data
We seek only to collect the personal data we require to respond to your request, deliver a product or service or meet a statutory reporting obligation.
Personal data is collected when you first contact us, and we create a record on our central database to maintain the security of your data. Any information you give us, or we generate (such as email conversations) are subsequently added to your record.
We do not normally collect information related to your health, racial or ethnic origins, sexual orientation, or religious beliefs as these are considered special category data, and sensitive personal information. We would only process this if it was necessary for the fulfilment of the service you have requested from us, and where you have given your explicit consent. For example, if you needed reasonable adjustments to access an event venue.
4. Use of personal data
Depending on the service you have requested from us, we may use your personal data in the following ways:
- To process any application for a grant, bursary, scholarship or Chartered status
- To provide you with the service you have requested, for example access to an online learning component or an event.
- To process payments related to membership, events or learning, and to undertake fraud prevention.
- To provide third parties with relevant information to enable them to fulfil their obligations. (See section 7. Data Sharing.)
- To provide information about additional services and products that may be of interest to you.
- To undertake research to improve our services, in line with our charitable purpose of carrying out research for the benefit of the public.
- To provide information to any government or statutory body, as required.
5. Data retention
We regularly review the data we hold, and will only keep your personal data for as long as is necessary to fulfil the purpose for which it was collected. We are legally obliged to keep a record of all financial transactions for six years.
6. Data sharing
We will share your personal data with third parties where necessary to deliver our products and services, including with:
- The Walbrook Institute London (formerly “The London Institute of Banking & Finance” and “LIBF”), with regard to Chartered applicants and members;
- event venues and event management partners;
- Government and other regulatory departments
Where we share personal data with third parties, we will ensure we have an appropriate agreement in place that specifies how the data may be used, and that they have appropriate technical and organisational measures in place to protect your personal data. We will only share as much information as is required to deliver the specified service and will ensure that your personal data is securely disposed of when it is no longer required.
We will not share your personal data with third parties unless you have consented for us to do so.
7. Your rights
Under the General Data Protection Regulation, you can exercise the following rights over your personal data:
- To be informed about how we will use your data
- To access your data
- To correct your personal data
- To have your data deleted – We will consider all requests for deletion and endeavour to fulfil the request where possible. We may be legally obliged to retain some personal data such as financial transactions for a specified period to meet statutory reporting requirements. We will highlight as far as possible the implications of deleting any personal data but may not be able to foresee all circumstances and the final decision to accept the deletion will be yours. We will hold a record to be able to confirm we have processed a deletion request.
- To have your personal data provided in a portable format
- To restrict the processing of your data – you can request that we restrict how we process your data. This may be used as an alternative to having data deleted, allowing us to store your personal data but not process it. This may affect the products or services we can provide to you and there may be some limitations where we have a legal obligation to still process.
- To object to the processing of your personal data – you have the right to object to direct marketing at any time. You can do this by clicking the link included at the bottom of all marketing emails we send. This will not affect transactional emails we send that are necessary for delivering any product or service.
8. Recruitment
You can read our recruitment privacy statement policy here.
Further information
If you are unhappy with how we have used your personal data, or how we have responded to a request, you have the right to complain to the Information Commissioner’s Office (ICO). If you are based outside of the UK, you may have the right to lodge a complaint with the data protection supervisory authority in your country of residence.
If, having read this Privacy Policy, you have any questions, please contact us at [email protected].
Updates to our policy
We may update this policy from time to time but will communicate any changes in advance where they have a material effect on your privacy rights. The date the policy was last updated can be found at the top of the page.