GDPR Art. 35 · Regulation (EU) 2016/679
Data Protection Impact Assessment (sample)
Northwind Bank · synthetic tenant · Financial Services
DEMO DATA · SAMPLE — NOT A COMPLETED DPIA
Is a DPIA required? Yes. A DPIA is required (GDPR Art. 35): 4 of 4 systems involve high-risk or high-risk-indicator processing (Account Opening Agent, KYC Verification Agent, Account Servicing Agent, Account Review Agent) — systematic evaluation/profiling of natural persons with potentially significant effects and, in several cases, decisions affecting access to an essential service. Conducted here ahead of any reliance.
Processing activities & risk to data subjects
Per Art. 35(7): a description of processing, an assessment of necessity and proportionality, the risks to data subjects, and the measures to address them.
01
Account Opening Agent
account-opening-agent · Onboarding · Origination · risk class: Indeterminate
RESIDUAL: MEDIUM
Data subjects & data GDPR Art. 35(7)(a)
Applicants for new customer accounts. Personal data processed includes standard identification and contact details, financial suitability information, Politically Exposed Person (PEP) status, and potentially data related to criminal convictions or offences via sanctions screening (GDPR Art. 10).
Risk to data subjects Art. 35(7)(c)
Solely automated decision-making (GDPR Art. 22) with a significant effect, as it can lead to the denial of access to essential financial services. Risk of unfair exclusion or discrimination based on potentially inaccurate risk scores or sanctions data. Exposure of sensitive financial information and Art. 10 data to security and confidentiality risks.
Necessity & proportionality Art. 35(7)(b)
Processing is necessary for the financial institution to onboard customers and fulfil legal obligations for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) regulations. Data minimisation is addressed by processing only data directly relevant to applicant identity, risk assessment, and regulatory screening. Data retention policies for financial records would govern the storage of this information, ensuring proportionality.
Mitigating measures Art. 35(7)(d)
Automated decisions are limited: auto-approval is restricted to low-risk applications with zero sanctions hits; other cases likely trigger human review (HITL gate). Mandatory verification and screening: identity verification and sanctions/PEP screening are mandated before any account opening, acting as critical controls. Auditability: all computed risk scores and sanctions results are recorded in a decision snapshot, providing an audit trail (Witness audit trail). Robust 'MUST NOT' rules: automatic rejection for sanctions hits or incomplete identity verification prevents processing under high-risk or non-compliant conditions.
02
KYC Verification Agent
kyc-agent · KYC · Compliance · risk class: Indeterminate
RESIDUAL: MEDIUM
Data subjects & data GDPR Art. 35(7)(a)
The data subjects are applicants for financial services undergoing Know Your Customer (KYC) verification. The agent processes personal data including risk flags, adverse media screening results, existing customer status, relationship duration, and transaction history. While 'adverseMedia' could indirectly contain references to criminal convictions, no explicit GDPR Article 9 or Article 10 data is directly processed by the agent's inputs.
Risk to data subjects Art. 35(7)(c)
There is a significant risk of solely automated decision-making impacting data subjects, potentially leading to exclusion from financial services or denial of applications. Incorrect high-risk flagging based on adverse media or other data could result in reputational damage, financial exclusion, or discrimination, even if triggering enhanced due diligence (EDD). The indeterminate EU AI Act risk class reflects this elevated potential for harm.
Necessity & proportionality Art. 35(7)(b)
The processing is necessary and proportionate to meet legal and regulatory obligations for Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) compliance. The data fields handled are directly relevant to assessing customer risk and ensuring due diligence. Data minimisation is addressed by limiting inputs to KYC-specific data, and retention periods should align with statutory requirements.
Mitigating measures Art. 35(7)(d)
Mitigating measures include platform controls such as Human-in-the-Loop (HITL) gates, particularly for Enhanced Due Diligence triggers, and a fail-open ESCALATE mechanism for uncertain outcomes. A comprehensive Witness audit trail ensures accountability and transparency of decisions. Schema-bounded inputs enforce data quality. Agent-specific rules mandate EDD for high-risk customers and verification of source-of-funds for elevated-risk applicants, embedding human oversight at critical junctures. The agent is also required to record the due-diligence tier applied.
03
Account Servicing Agent
servicing-agent · Servicing · Operations · risk class: High
RESIDUAL: MEDIUM
Data subjects & data GDPR Art. 35(7)(a)
Data subjects are customers of the financial institution requesting account changes or credit limit adjustments. The concrete categories of personal data processed include financial data such as current credit limits and requested credit limits, alongside authentication status and implicit customer identity associated with the request. No GDPR Art. 9 special-category or Art. 10 criminal-conviction data is indicated for processing by this agent.
Risk to data subjects Art. 35(7)(c)
The agent poses a risk of solely-automated decision-making with significant effect under GDPR Art. 22, specifically for credit limit increase requests below €10,000 where autonomous approval is permitted. This could lead to financial detriment, exclusion from enhanced services, or missed financial opportunities if decisions are erroneous or discriminatory. The processing of sensitive financial data also carries inherent security and confidentiality risks, potentially leading to reputational damage if compromised.
Necessity & proportionality Art. 35(7)(b)
Processing customer requests for account changes and limit adjustments is necessary for the financial institution to deliver its core services and manage customer accounts efficiently. The data fields handled (request, currentLimitEur, customerVerified, requestedLimitEur) appear proportionate and directly relevant to fulfilling the agent's charter, aligning with data minimisation principles. Data retention should comply with relevant financial regulations and legal obligations.
Mitigating measures Art. 35(7)(d)
Mitigating measures include platform controls such as schema-bounded inputs for financial data and a Witness audit trail for all decisions and actions. Agent-specific controls mandate a HITL (Human-in-the-Loop) gate and ESCALATE mechanism for all credit-limit increases or transactions above €10,000. Furthermore, the agent MUST re-authenticate the customer before any limit change and MUST NOT action any change without successful re-authentication, enhancing security. Transparency is ensured by recording critical decision parameters.
04
Account Review Agent
account-review-agent · Review · Assurance · risk class: Indeterminate
RESIDUAL: MEDIUM
Data subjects & data GDPR Art. 35(7)(a)
Account holders or clients of the financial institution undergoing periodic review. Concrete categories of personal data processed include account-related information, financial risk profiles (riskScoreChange), and potentially highly sensitive data such as adverse financial findings or allegations (adverseFindings) and information derived from public sources, which may include criminal convictions or offences (adverseMediaChange, indicating GDPR Art. 10 data processing).
Risk to data subjects Art. 35(7)(c)
There is a risk of solely automated decision-making where the agent auto-completes reviews detecting no adverse change, potentially missing critical information that could lead to financial harm or compliance breaches. The agent performs profiling based on risk scores and adverse media, which carries a risk of inaccuracy, bias, and discrimination, potentially leading to unfair exclusion from services, increased scrutiny, or reputational damage. Processing of Art. 10 data via adverse media and findings increases confidentiality and security risks, and the impact of erroneous detection is significant.
Necessity & proportionality Art. 35(7)(b)
The processing is necessary to meet regulatory obligations in financial services, such as Anti-Money Laundering (AML) and Know Your Customer (KYC) requirements, ensuring financial stability and preventing illicit activities. The automation aims to enhance efficiency and consistency. Proportionality is addressed by mandating human oversight for any adverse findings and by strictly limiting auto-completion to cases with no detected adverse changes; however, the scope of 'adverse media' must be minimised to only relevant and necessary data, and robust retention policies for sensitive data are crucial.
Mitigating measures Art. 35(7)(d)
The agent includes a HITL gate by explicitly requiring escalation of any newly detected adverse change to a compliance officer. A fail-open mechanism ensures reviews are not closed with unresolved adverse findings. All review outcomes are recorded in a decision snapshot, serving as a Witness audit trail for accountability and transparency. Further agent-specific measures should include regular fairness and bias testing of risk scoring and adverse media detection models, strict data minimisation for information extracted from adverse media, and clear protocols for data subject rights requests concerning automated decisions.
Measures & outcome
•Human oversight: HITL gates enforced by the Compliance Guard (ACP §2.1) on out-of-authority decisions; ESCALATE routes to a named human reviewer.
•Fail-open default: where governance context cannot be evaluated, the agent ESCALATES rather than silently permitting — no unreviewed automated decision.
•Auditability: every decision sealed to the Witness trail (clause applied, files consulted, data snapshot) — Evidence-as-Code for data-subject rights requests.
•Data minimisation: each agent's inputs are bounded by its SKILL.md schema; special-category and protected-attribute inputs are excluded by policy where not strictly necessary.
•Transparency: consumer-facing agents carry an Art. 50 AI-interaction disclosure and a human-review route.
Outcome. With the platform mitigations applied (human oversight, fail-open ESCALATE, audit trail, minimisation, transparency), residual risk is assessed Low-to-Medium across the processing activities. DPO and Compliance Officer sign-off required before reliance.
Data Protection Officer — signature & date
Compliance Officer — signature & date
Controller representative — signature & date
DISCLAIMER. This is a SAMPLE Data Protection Impact Assessment (GDPR Art. 35) auto-generated by the ACP Governance Module from in-process journey governance state and the Witness decision trail. It is a template/working document, not a completed DPIA: it requires the Data Protection Officer's and Compliance Officer's review, the controller's confirmation of data flows and retention, and consultation with the supervisory authority where residual high risk remains (Art. 36). In DEMO DATA state the deployer and records are synthetic and must not be relied upon.