Skip to content

GDPR and data protection

The General Data Protection Regulation (GDPR) governs how a financial institution collects, uses, shares, secures, retains, and deletes personal data. Finsaku supplies controls for handling that data, but the organisation remains responsible for deciding why processing is lawful and how each obligation is fulfilled.

The controller, processor, joint-controller, and subprocessor roles depend on the service and contracts in use. Confirm those roles in the applicable data-processing agreement rather than inferring them from a Finsaku screen.

What GDPR requires

From the financial institution

The organisation must:

  • identify a lawful basis and a specific purpose for each use of personal data;
  • collect only the data needed for that purpose and keep it accurate;
  • explain the processing to data subjects and handle their requests within the applicable deadline;
  • restrict access, protect the data, and demonstrate that its safeguards are appropriate to the risk;
  • define retention periods and erase or restrict data when required, subject to legal retention duties;
  • maintain records of processing, assess high-risk processing, and govern processors and international transfers;
  • detect, investigate, document, and, where required, report personal-data breaches;
  • remain accountable for automated decisions and any required human review.

From the software and service

GDPR does not certify a software product as compliant. The financial institution must choose and configure systems that support data protection by design and by default, appropriate security, traceability, data-subject rights, retention, and processor oversight.

For Finsaku, this means the assessed solution includes more than the application screens. Review the tenant configuration together with hosting, backups, support access, enabled integrations, subprocessors, data locations, security measures, and contractual assistance. Deployment-specific evidence must come from the applicable service and security documents.

Traceability matrix

The classification describes product coverage:

  • Out of the box — Finsaku provides the application control without custom development. The customer must still configure and operate it correctly.
  • Customer action required — Finsaku provides supporting controls or evidence, but the customer must complete the legal, procedural, contractual, or deployment-level work.
Important requirement GDPR reference Coverage How the requirement is addressed
Lawfulness, fairness, transparency, and purpose limitation Articles 5, 6, 12–14 Customer action required Finsaku stores the configured application, customer, loan, payment, document, and communication data. The customer must establish and document the lawful basis and purpose, issue the required notices, and ensure that screens, templates, integrations, and staff use match them.
Data minimisation and protection by default Articles 5(1)(c) and 25 Customer action required Finsaku lets administrators configure collected fields, mandatory values, product versions, saved queries, templates, and integrations. The customer must decide which data is necessary, remove excessive fields and outputs, and test the resulting journey before use.
Accuracy and rectification Articles 5(1)(d) and 16 Out of the box Authorised users can correct supported customer and lending data, while history records supported changes. The customer must verify the correction, consider downstream documents and providers, and preserve earlier evidence where law or audit duties require it.
Confidentiality and least-privilege access Articles 5(1)(f), 25, and 32 Out of the box Unique users, user status, permission groups, affiliations, tenant scope, separate export and history permissions, and controlled impersonation restrict application access. The customer must design roles, approve membership, review cumulative access, block leavers, and test both allowed and prohibited operations.
Accountability and evidence of processing Articles 5(2) and 24 Customer action required Finsaku audit history records supported actors, events, times, references, and stored value changes. The customer must maintain the wider accountability record, including policies, approvals, lawful-basis decisions, training, disclosures, exceptions, and evidence held outside Finsaku.
Records of processing activities Article 30 Customer action required Tenant configuration, products, fields, templates, integrations, and audit history help identify processing performed through Finsaku. The customer must maintain the authoritative processing register with purposes, data subjects, recipients, transfers, retention, security measures, owners, and all connected systems.
Data-subject access and portability Articles 15 and 20 Customer action required Search, related-record views, saved queries, documents, messages, enrichments, history, and controlled exports help locate and retrieve data. The customer must verify identity, define the complete scope, gather provider-held copies, apply exemptions, choose the response format, approve the disclosure, and meet the deadline. A single query export is not a complete response.
Erasure and restriction Articles 17 and 18 Customer action required Finsaku exposes supported edit, status, access, document, and configuration actions, but it does not provide one action that erases or restricts every related copy. The customer must decide whether erasure or restriction applies, reconcile statutory retention duties, and coordinate the outcome across Finsaku, generated files, backups, integrations, and subprocessors.
Automated decisions and human review Article 22 Customer action required Finsaku decisions, workflow actions, enrichment results, and history make configured processing visible. The customer must determine whether Article 22 applies, establish a lawful basis and safeguards, provide required information, define human intervention and contest routes, and test the decision process for the intended use.
Processor selection, contracts, and subprocessors Articles 28 and 29 Customer action required Finsaku identifies enabled integrations and the workflows that use them; applicable service documents can describe the Finsaku processing arrangement. The customer must complete due diligence, execute the required agreements, approve subprocessors where applicable, control instructions and credentials, and verify deletion, assistance, audit, and incident terms.
International transfers Articles 44–49 Customer action required Finsaku configuration helps identify external providers receiving data. The customer must determine where data is processed, select a lawful transfer mechanism, complete any required transfer assessment, and maintain supplementary safeguards and evidence.
Security of processing Article 32 Customer action required Finsaku provides application-level authentication integration, granular authorisation, tenant scoping, audit history, and controlled integration configuration. The customer must combine those controls with deployment evidence for encryption, availability, resilience, restoration, monitoring, vulnerability management, access reviews, and regular testing appropriate to risk.
Data-protection impact assessment Article 35 Customer action required Product versions, field definitions, decisions, enrichments, integrations, and access configuration provide inputs to an assessment. The customer must screen the processing for high risk, conduct and approve the DPIA where required, record mitigations, consult the authority where applicable, and review the assessment after material change.
Personal-data breach handling Articles 33 and 34 Customer action required Audit history, event-action execution history, record state, provider references, and service logs can support an incident timeline. The customer must operate the breach process, preserve evidence, assess risk, maintain the breach register, coordinate processor notifications, and notify the authority or affected people when required.

The matrix is a control map, not a legal conclusion. Use the official GDPR text, current regulatory guidance, the applicable contracts, and qualified advice for the organisation and jurisdiction being assessed.