Financial services organisations rarely struggle to take data protection seriously; they struggle to reconcile it with obligations that pull the other way. Anti-money-laundering rules require retention, fraud prevention requires profiling, and regulators require records long after a customer relationship ends.
The practical work is therefore about precision: which obligation justifies which retention period, which decisions are automated in a way that triggers safeguards, and which outsourced arrangements have been assessed properly.
Where personal data flows
- Onboarding and KYC
- Identity documents, biometric verification, sanctions and PEP screening results, and adverse media checks.
- Transactions and behaviour
- Payment records, device signals, location and behavioural analytics used for fraud and risk scoring.
- Credit and underwriting
- Bureau data, affordability models, and internal scoring that informs decisions about individuals.
- Servicing and complaints
- Call recordings, chat transcripts, complaint files and vulnerability indicators.
- Outsourced processing
- Core banking platforms, cloud providers, collections agencies, and offshore operations centres.
Priority risks
- Retention conflict
- Legal retention obligations applied to entire datasets rather than the specific fields required, keeping far more personal data than the rule demands.
- Automated decisioning
- Scoring models influencing outcomes for individuals without documented human oversight, explanation routes or accuracy monitoring.
- Special-category creep
- Health and vulnerability data captured in servicing notes without a condition for processing or access restriction.
- Third-country access
- Offshore support teams with production access, creating transfers that were never assessed.
- Call recording
- Recording and speech analytics applied without a clear basis, notice or exclusion for sensitive conversations.
Practical controls
- Map retention obligations at field level, not dataset level, and separate regulatory archives from operational stores.
- Maintain a register of decisions that are wholly or partly automated, with the oversight mechanism and explanation route for each.
- Restrict and monitor access to vulnerability and health indicators recorded during servicing.
- Assess outsourcing and offshore access as transfers, with documented mechanisms and technical restrictions.
- Give the complaints function a defined route for privacy issues that reaches the DPO, not just customer service.
- Test rights request handling against archived, offline and third-party-held records — not only the CRM.
- Review model inputs periodically for proxies that create unfair outcomes and for data no longer necessary.
Worth measuring
- Proportion of retained records held under a documented field-level obligation rather than a blanket period.
- Number of automated decision types with an active oversight and explanation procedure.
- Rights requests fulfilled within the statutory clock, split by channel.
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.