Knowledgebase

Data Protection in Financial Services Print

  • fintechpaymentsystems, fintech, guide, howto, solution, zillionkinghost, hosting, support
  • 0

Handling customer information.

WHAT MAKES IT SENSITIVE

Financial data reveals behaviour, relationships, health and circumstances.

WHAT IS TYPICALLY HELD

Identity documents and identifiers Transaction history Contact details Device and location data Credit information

WHAT PRINCIPLES APPLY

Collect only what is needed Use it only for stated purposes Retain only as long as required Protect it appropriately Allow access and correction

WHAT THE TENSION IS

Retention required for anti-money-laundering purposes against deletion rights.

WHAT THAT MEANS

Deletion requests may be lawfully refused for records subject to retention obligations.

WHAT TO DOCUMENT

Which data is retained under which obligation, and for how long.

WHAT TO ENCRYPT

Data at rest and in transit, without exception.

WHAT TO RESTRICT

Access to customer data, by role, with logging.

WHY LOGGING SPECIFICALLY

Internal access to financial records is a recognised risk.

WHAT TO NEVER DO

Use customer transaction data for purposes they were not told of.

WHAT TO PREPARE

A breach response plan, including notification obligations and timelines.

WHAT TO VERIFY

Current data protection requirements, which are actively developing here.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot