Data processing

Privacy policy of SIA Citadele Leasing Estonian branch

Valid from 01.02.2021

In this policy on the webpage you will find out what information we collect about you, what we do with it and in when do we disclose it to others. We always protect your information and regularly improve this privacy policy. We will inform you about any changes to the privacy policy on our  webpage section About us > News.

  • 1 . How do we collect information about you?

    We collect information about you in three ways:

    • You use our website or enter information in it;

    • You apply for a lease, credit or insurance or are repaying it;

    • You fail to repay us your lease.

    1.1. Information provided by you:

    • given name, surname, personal identity number;

    • postal address;

    • mobile phone number;

    • employer;

    • occupation;
    • e-mail address;

    • net monthly income;

    • monthly expenses;

    • additional income and sources of additional income;

    • details about other financial obligations;

    • bank account number;

    • bank account statement for the last 6 months;

    • relations to politically exposed persons.

     1.2. Information we receive about you

    1.2.1. Credit history

    According to the Creditors and Credit Intermediaries Act and Law of Obligations Act, we are obliged to evaluate your creditworthiness at the time we receive a lease application. We receive information from credit bureaus to evaluate your creditworthiness.

    1.2.2. Information provided by Citadele Group companies

    As a company of Citadele Group, we may receive lease applications from other Citadele Group companies and review them in accordance with the terms of this privacy policy for processing of your personal data.

    We may receive information from other Citadele Group companies to restrict or prevent money laundering, terrorism and proliferation financing, violations of international and national sanctions, fraudulent activity and other risks of the Citadele Group. Here again, your personal data will be processed in compliance with the requirements of regulatory enactments and the conditions provided for in this privacy policy for processing of your personal data.

    1.2.3. Net salary

    According to the Creditors and Credit Intermediaries Act and Law of Obligations Act, we are obliged to evaluate your creditworthiness at the time we receive a lease application. We receive information from the funded pension register held by AS Pensionikeskus about your last 6 months 2nd pillar pension contributions.

    1.2.4. Number on dependants (minors)

    According to the Creditors and Credit Intermediaries Act and Law of Obligations Act, we are obliged to evaluate your creditworthiness at the time we receive a lease application. We receive information from population register.

    1.2.5. Relations with politically exposed persons

    According to the Money Laundering and Terrorism Financing Prevention Act, we are obliged to identify your potential relationship with politically exposed person. We receive information from the register held by the FICO TONBELLER.

    1.2.6. Activity on our website

    To improve the quality of our services and the speed of our website and the lease process, we, together with our cooperation partners, collect anonymous cookies and store them it for maximum 12 months. This information is anonymous.


  • 2 . Why do we collect information about you?

    What information and for what purposes we collect it, see here

  • 3 . How do we analyze your data?

    We make sure you are acting in good faith and evaluate your creditworthiness by automated means to issue a lease to you as soon as possible. That allows us to decide if we will lend you money, how much and under what conditions. This is beneficial to you, as we can consider individual information about you and adjust the lease terms for your needs. The process described below takes about 2 working days. Unfortunately, if you do not agree with the automated decision-making procedure described below, we will not be able to evaluate your creditworthiness, calculate lease conditions and lend you money.

    In the process of issuing a lease and determining the lease conditions, we use an algorithm by which we analyze your information according to the internal credit scoring rules.

    If you would like to know what information we have received from credit registers and debtor's databases, please contact them:

    Creditinfo Eesti AS
    +372 665 9600

    If we need to refuse granting you a lease, you can ask for an explanation of the refusal as described in section 6.

  • 4 . Who do we disclose your information to?

    We have implemented various tools and services that facilitate our cooperation and make our communication faster. Therefore, we disclose:

    • personal data related to your agreement incl. contact details to the dealer in the necessary capacity and scope to fulfill terms of the agreement and its related annexes;

    • your contract and contact information to car dealers, who submitted your application with us;

    • your given name, surname, personal ID code to vehicle registration bodies like Transpordiamet, Autoregistrikeskus and Liikluskindlustuse Fond;

    • your given name, surname, personal ID code to insurance company Smart Kindlustusmaakler AS if you consented to receiving an insurance quote for the vehicle subject to the lease;

    • information about you in the lease file to archiving and debt collection services provider;

    • your contact information to communication and IT services providers for administering the lease;

    • information about your requests and claims to our parent company JSC “Citadele banka”;

    • information on various types of incidents (e.g., if we have established violations of the law) to our parent company JSC “Citadele banka”;

    • information on the verification of your data in accordance with the Creditors and Credit Intermediaries Act, Law of Obligations Act and Money Laundering and Terrorist Financing Prevention Act to JSC “Citadele banka” and its other subsidiaries for verification or mitigation or prevention of the identified risks;

    • if you have agreed to receive advertisements, then we may transfer your personal data to our parent company JSC "Citadele banka".

    Entities to whom we may transmit your data for the reasons listed above have been indicated in the list of data processors of SIA Citadele Leasing Estonian branch available on our website at

    If you do not repay a lease in accordance with the lease agreement terms, we will consider the need to involve experts to recover your debt. In this case, we will process your personal data to ensure our legitimate interest of getting the money back. If we decide to transfer your debt to a debt recovery service provider, we will give them your given name, surname, all contact details, a copy of the lease agreement and any amendments thereto, and information about all previous payments.

  • 5 . How do we protect your information?

    We deploy strict IT infrastructure use and access policies, which are based on the need-to-know and less-privileged access principles. We encrypt personal data, deploy firewalls, intrusion detection and prevention systems to ensure that all your personal data is confidential and safe. We regularly test our systems and review applicable policies to make sure that our IT safety measures are one step ahead of any threat.

    We delete your personal data according to the rules in Section 2 of this Privacy Policy. If you have not reached the age of 13, but have filled out a lease application, our system will reject any information about you and will not store it. If you decline to sign a lease agreement with us, we will delete your data in 5 years based on AML laws.

  • 6 . What are your rights?

    We process your data; therefore, you can find out what we do with it and how, and in some cases ask us to process it to a lesser extent. You can:

    • receive your personal data that is in our possession, find out the purpose and basis of the data processing (free of charge);

    • refuse from receiving ads (free of charge);

    • change your contact information (free of charge);

    • submit current information about your income or expenses (free of charge);

    • ask us not to use certain information about you (free of charge);

    • retrieve information about yourself (free of charge);

    • request to delete your data on our database (free of charge);

    • get an explanation for refusal to grant a lease.

    SIA Citadele Leasing Estonian branch registered in the Republic of Estonia, address Liivalaia 13, 10118, Tallinn, Estonia, is responsible for processing your data. A personal data protection officer, will answer all your questions regarding the use of your information by Citadele Leasing. You can reach by sending an e-mail to Please describe the problem in as much detail as possible. We will respond to you within 30 days.

    Our activities in the field of personal data protection are monitored by the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon,, +372 627 4135). Before you turn to the inspectorate for advice or with a complaint, we encourage you to contact our personal data protection specialist to ensure your request is addressed as quickly as possible.