← All posts
AI & Email Compliance

Client confidentiality in private banking: the four moments it breaks

September 16, 2026 · 7 min read

A relationship manager sends a warm introduction. “You should speak to my colleague in Geneva, he looks after a family in a similar position to yours after their business sale.”

It is a helpful email. It is also, in most European private banking contexts, a disclosure. Nobody was named, and the sentence still narrows the field considerably: a family, a recent business sale, Geneva coverage. For a reader who knows the market, that is often enough.

Confidentiality in private banking behaves differently from confidentiality in most other businesses, and the difference is worth stating precisely, because it changes which sentences carry risk.

The identity is the confidential fact

In most industries, the protected thing is the content: the pricing, the specification, the strategy. The existence of the relationship is ordinary commercial information, and firms publish client logos on their websites.

In private banking the relationship itself is protected. That a particular individual is a client, at this institution, in this segment, is confidential before anything about their affairs is mentioned. It carries an inference about their wealth, which is exactly the inference clients are paying to keep private.

This produces a category of exposure that does not exist elsewhere. A message can breach confidentiality while containing no financial data at all. A calendar invitation with two names on it, a colleague copied into an introduction, a reply that confirms a person is known to the desk, all of these disclose the fact of the relationship.

Four moments where it goes

The referral. Growth in this business runs on introductions, and an introduction requires context to be useful. The context is the disclosure. This is the most common route because the commercial incentive and the confidentiality obligation point in opposite directions.

The family member. A spouse, an adult child, or a family office representative asks about an account or a structure. They are close to the client and are often present in meetings. Whether they are entitled to information is a question of mandate rather than relationship, and the mandate is rarely in front of the person replying.

The co-adviser. Lawyers, tax advisers and trustees are legitimate participants in a client’s affairs. Each of them is authorised for a scope, and the scope is narrower than the full picture. A reply that answers the question asked plus the context around it exceeds the scope without anyone noticing.

The departing relationship manager. When a manager moves firms, the client list is the asset in dispute. Messages written in the weeks before a departure, to a personal address or to the new employer, are examined closely afterwards. This is the route that produces litigation rather than a regulatory finding.

What the obligations actually stack up to

Three separate duties operate at once, and they have different triggers, which is why a single mental model tends to fail.

Duty What triggers it What it protects
Professional secrecy or banking confidentiality The client relationship itself The existence of the relationship, and everything learned through it
Data protection Processing personal data Identified or identifiable individuals, including by inference
Contractual confidentiality The terms of the mandate Whatever the mandate defines, which may be wider than the first two

The second row deserves attention because of the word identifiable. Removing a name does not remove the personal data if the remaining details allow the person to be picked out. The introduction at the top of this piece is a worked example: no name, and a small enough population that identification is realistic.

A wording reference

These are the patterns that recur. The principle in the right column is more useful than the specific rewrite, because the sentence will be different every time.

If the draft says The principle
“a family in a similar position after their business sale” Remove the identifying combination. Describe the service you provide rather than the client you provide it to.
“attaching the full portfolio and account numbers” Send the minimum the question requires. Summarise and strip identifiers.
“as you know, we also act for his brother” Never confirm another client relationship, including to a family member.
“copying in the tax adviser so everyone has the background” Give each adviser the scope their mandate covers, and check the mandate before widening the list.
“sending this to my personal address so I can work on it” Client information stays on firm systems. This pattern is the one examined most closely after a departure.

The cross-border complication

One further layer applies to most private banks and rarely to their clients’ other suppliers.

A single relationship routinely spans jurisdictions: the client resident in one country, the booking centre in another, the family office in a third, and advisers spread across all of them. Each jurisdiction attaches its own confidentiality duty to the same facts, and the strictest one governs any message that touches it.

The practical effect is that a sentence which is unremarkable between two colleagues in one office can carry a different weight the moment it crosses to a second booking centre, even inside the same group. Internal is not a safe category here. Group entities are separate legal persons, and information sharing between them runs on a legal basis rather than on org-chart proximity.

The failure this produces is quiet. Nobody thinks of an email to a colleague in another office as an external disclosure, and in confidentiality terms it sometimes is.

Why training alone does not close it

Everyone in a private bank knows the duty. It is covered at induction, it is in the handbook, and it is a matter of professional identity rather than a rule people resent.

The four routes above happen anyway, for a reason worth understanding. Each of them is a moment where being helpful and being confidential pull apart, and the pull happens under time pressure, inside a relationship the person is trying to maintain. Knowing the rule and applying it to the sentence you are currently writing, to this recipient, are different cognitive acts, and the second one is the one that fails.

The other reason is that the deciding fact is often not in front of the writer. Whether this family member is on the mandate, whether this adviser’s scope covers structures as well as tax, whether this contact is inside the agreement, all of that lives in the file rather than in the mail client.

Where a pre-send check fits

A check at the point of writing addresses both problems. It evaluates the sentence and the recipient list together, which is the combination that decides confidentiality, and it brings the agreement and mandate register into the moment the message is composed.

Our recipient-aware check flags the combination of client-identifying content and a recipient outside the covered scope, at phrase level, before the message goes. It records that the check ran, at department level, with no message content stored and no individual attribution, which matters in a business where the compliance function is watched as closely as the front office.

The takeaway

Brief your desks on the identity point specifically. The rule most people carry is about financial information, and the exposure that produces complaints is usually about the existence of a relationship. Take the five rows in the wording reference to your next desk meeting and ask how many were written this month. For the wider pattern of confidential information leaving in ordinary messages, see our piece on the four routes it takes.

See how VerbaPulse flags risk before an email is sent, right inside Gmail and Outlook.

See VerbaPulse in action →
← How to stop confidential information leaving in an email Is a pre-send writing check employee monitoring? GDPR, works councils, and what actually decides it →