Knowledge Base
Identify the main institutional obligations regarding client confidentiality and data protection
Which article of the Criminal Code sanctions breaches of banking secrecy?
Breaches of banking secrecy are sanctioned by Article 226-13 of the Criminal Code. For individuals, this breach can result in up to one year of imprisonment and a €15,000 fine. For legal entities, the fine can reach €75,000. This sanction reflects the importance placed on the confidentiality of banking information.
What technical and organisational measures are required by Article 32 of the GDPR to ensure appropriate data security?
Article 32 of the GDPR requires technical and organisational measures proportionate to the risks. This includes pseudonymisation, encryption, resilience to incidents, data restoration and implementation of testing procedures. These measures are essential for protecting data against breaches and must be adapted to the specific context of each institution.
What obligations does PSD2 impose regarding open banking?
PSD2 imposes several obligations for open banking: allowing access to account data by authorised third-party providers (PSPs), ensuring the security of shared data and maintaining the confidentiality of information. These obligations aim to foster innovation while protecting consumers.
What is the main legal basis for data processing in the financial sector under the GDPR?
Under Article 6 of the GDPR, the main legal basis for data processing in the financial sector rests on contractual performance (such as loan or account agreements) and legal obligations imposed by regulators. This is crucial because institutions must justify each data processing activity, and these two bases are the most relevant in the financial context.
The Privacy by Design principle (Article 25 of the GDPR) requires that data protection be integrated from the design stage of systems.
Privacy by Design means that data protection must be integrated from the design stage of systems and processes. This requires institutions to anticipate and minimise risks to the rights and freedoms of data subjects from the outset of developing their products or services. This principle is essential for lasting GDPR compliance.
Categorize items by dragging them to the appropriate zones
Items to categorize:
GDPR
Financial sector
Institutional obligations fall into those arising from the GDPR and those specific to the financial sector. For example, banking secrecy is a sector-specific obligation, while appointing a DPO falls under the GDPR. This distinction is crucial for understanding the applicable regulatory framework.
Banking secrecy
Click to see answer
Banking secrecy, enshrined in Article L.511-33 of the Code monétaire et financier, requires all members of the management, board of directors or supervisory board, as well as all employees of a credit institution, not to disclose confidential client information. This obligation is fundamental to maintaining client trust in the financial system.
A data breach must be notified to the CNIL within 48 hours.
Article 33 of the GDPR stipulates that a data breach must be notified to the CNIL within 72 hours of becoming aware of it. This timeframe is crucial for enabling a rapid response to security incidents, while allowing sufficient time to assess the incident.