GDPR, Anonymization of Customer Data

In accordance with the directives for GDPRClosed The General Data Protection Regulation is a regulation in EU law on data protection and privacy in European Union and European Economic Area., individual customers' data privacy has to be protected. Data Governance is the process that classifies sensitive data and anonymizes it on request for data protection regulations.

NOTE  
Based on our experience, FintechOS selected which information to be anonymize. The financial institution can validate or add/remove attributes from the anonymization process within Innovation Studio.

There are two scenarios when the data can be anonymized:

  1. Automatically

    After 5 years (not counting the year of closure) from the contractual relationship between a customer and a bank has ended. Certain data is automatically anonymized by the system.

  2. Manually

    Upon user request, the bank can manually select a customer for which the data to be anonymized.

The types of information that are anonymized are username and password and:

   

The anonymization is done based on a rule. Both requests manually and automatically, anonymize the data that have the status Inactive. Manually, the bank representative searches for the user or customer or automatically, the system anonymizes all the records which meet the rule.

IMPORTANT!  
All the records, which will be anonymized, must be in the Inactive state first before anonymization.

Prerequisites

You need an administrator role to perform this action. Additionally, before creating the request, you need to disassociate the users from the customer. Then, you must inactivate the users.

Creating a Sensitive Request and Approving the Records Manually

The following process is done by a back-office employee from the bank:

  1. Log into FintechOS Portal with the credentials given.
  2. Open the main menu, and select Data Anonymization Requests. The Sensitive Requests List is displayed.
  3. Click Insert.
  4. Fill in the following fields:
    FieldDescription
    Request NoInsert a suggestive number.
    Request DateThe system automatically displays the current date.
    Sensitive Context

    Select one from the list:

    • GDPR Account (affects data from more entities)

      The attributes are CNP, Name, Phone, First Name, Last Name, entityStatusID.

    • GDPR User.
    NOTE  
    Two requests must be made, one with each of the contexts above for the anonymization to be complete.
  5. Click Save and reload. The Request Search Attributes grid is displayed. It is time to choose a customer who has those attributes active.
  6. In the grid, in the column named Search Value, insert the corresponding CNP of the customer you are trying to anonymize.

  7. Click Save and reload. The request was created.
  8. On the top right-hand corner, in the Business Workflow widget, the status is Register. Change the status to Requested by clicking on Choose status, and then on Requested from the drop-down.
  9. The system asks you: Are you sure you want to change the business status?

    Click Yes to continue. The data to be anonymized is populated.

    or

    Click No to stop the process.

  10. Click in the section tab Data Found. The Request Entities grid is displayed, it showcases the customer.
  11. On the top right-hand corner, in the Business Workflow widget, the status is Requested. Change the status to Validated by clicking on Validated.

    If the Rule is Approved, then:

  12. The system asks you: Are you sure you want to change the business status?
    • Click Yes to continue. The rule is triggered and the status is Solved.

      or

    • Click No to stop the process.
  13. Click the section tab Data found.
  14. Click on the customer found.
  15. In the page Edit Request Entity, the fields become read-only, and the Request Data Rules grid displays the outcome of the rule in the Message field:
    • success

      It has the status pending approval.

      or

    • fail.
  16. On the top right-hand corner, in the Business Workflow widget, the status is Pending Approval. Change the status to Approved or Rejected by clicking Choose status, and then on Approved from the drop-down if the configuration is as needed.
  17. Click Save and reload. In the Data Found section tab, the Business Status is Anonymized.
  18. If the Rule is Rejected, then:

    The system displays the message: Are you sure you want to change the business status?
    • Click Yes to continue. The rule is triggered and the status is Solved.

      or

    • Click No to stop the process.

    In the page Edit Request Entity, the fields become read-only, and the Request Data Rules grid displays the outcome of the rule:

    • success

      or

    • fail.

      The status is Rule Rejected.

  19. On the top right-hand corner, in the Business Workflow widget, the status is Rule Rejected. Change the status to Approved or Rejected by clicking on Pending Approval, and then on Approved from the drop-down if the configuration is as needed.

For more information, see Data Governance.