Money and personal data.
WHY IT IS DIFFERENT
Financial data enables fraud, and sector regulation adds obligations.
WHAT OBLIGATIONS OVERLAP
Data protection law Financial sector regulation Anti-money-laundering requirements Payment card security standards
WHAT THAT MEANS
Requirements can conflict, and the stricter usually governs.
WHAT EXAMPLE LOOKS LIKE
Retention: data protection favours deletion, while regulation may require retention.
WHAT TO DO
Identify the retention obligation, and delete when it expires.
WHAT IDENTITY VERIFICATION COLLECTS
Identification documents Proof of address Sometimes biometric data
WHAT TO DO WITH THOSE
Retain only as required, securely, with restricted access.
WHAT TO NEVER DO
Store full payment card numbers unless equipped for that obligation Store card security codes, ever
WHY THE SECOND ONE ABSOLUTELY
It is prohibited, and it is checked.
WHAT TO USE INSTEAD
A payment provider, so details never reach your systems.
WHAT TO BE CAREFUL WITH
Screenshots of transactions shared internally Statements sent by unencrypted email Spreadsheets of customer financial details
WHAT TO IMPLEMENT
Strong access control and logging.
WHAT TO ASSESS
An impact assessment, for scoring or automated decisions.
WHAT TO TAKE ADVICE ON
The interaction between the regimes.