Knowledge Base
Apply GDPR and CNIL rules to ensure personal data protection
Which GDPR principle requires that only strictly necessary data be collected?
The principle of data minimization, set out in Article 5 of the GDPR, stipulates that personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. This means that organizations must collect only the data that is strictly necessary.
Which article of the GDPR requires maintaining a record of processing activities?
Article 30 of the GDPR stipulates that every organization must maintain a record of processing activities, documenting the purposes, categories of data, recipients, retention periods, and security measures. This record is essential for demonstrating GDPR compliance and must be regularly updated.
What is the most common legal basis for data processing in the banking sector under Article 6 of the GDPR?
Under the GDPR, the legal bases for data processing include consent, performance of a contract, legal obligation, etc. In the banking sector, the most common bases are performance of the contract for the client relationship and legal obligation for AML/CFT (Anti-Money Laundering and Combating the Financing of Terrorism) requirements.
What is the maximum time allowed to respond to a data access request under Article 15 of the GDPR?
Article 15 of the GDPR grants data subjects the right to access their personal data. Organizations must respond to these requests within one month. This period may be extended by two months if necessary, but this must be justified and the requester must be notified.
True or False: The right to data portability (Article 20) is less important in the context of Open Banking.
The right to data portability (Article 20) is crucial in the context of Open Banking and PSD2 (Payment Services Directive). It allows clients to transfer their data to another financial institution, thereby promoting competition and innovation in the banking sector.
True or False: A bank may use KYC data for commercial prospecting purposes without a separate legal basis.
The principle of purpose limitation (Article 5 of the GDPR) requires that data be collected for specified and explicit purposes. Therefore, a bank cannot use KYC (Know Your Customer) data for commercial prospecting purposes without a separate legal basis, as this would fall outside the original scope of data collection.
Data Protection Officer (DPO)
Click to see answer
The Data Protection Officer (DPO) is a person designated to oversee GDPR compliance within an organization. Under Articles 37 to 39 of the GDPR, the DPO must be involved in all matters relating to data protection and may be an employee or an external appointee. In the financial sector, their appointment is mandatory for institutions conducting large-scale processing.
Categorize items by dragging them to the appropriate zones
Items to categorize:
Breach of information duty or fairness
Failure to secure data
CNIL sanctions illustrate the importance of GDPR compliance. For example, Carrefour Banque was fined €800,000 in November 2020 for breach of the duty to inform and the principle of fairness. American Express Carte France was sanctioned €1.5 million in November 2025 for non-compliance with applicable rules, while NS Cards France received a fine of €105,000 for failure to secure banking data.