Scenarios · Financial services

A payments and lending business with automated decisions

Aurelia Finance is a licensed payments institution with a consumer lending arm across four member states. It decides loan applications automatically, screens transactions for fraud with a bought model, keeps records for anti money laundering purposes, and outsources arrears collection. Its difficulty is that two bodies of law pull in opposite directions: the Regulation limits retention and grants erasure, while financial law requires records to be kept and identities to be verified.

Who and what appears in this scenario

Each kind of record keeps the same mark throughout, so the same name always means the same thing.

Entity

  • Aurelia Finance NVThe controller, with both supervisors recorded.
  • Vigilant AnalyticsThe fraud model vendor, a processor.
  • Meridian CollectionsThe arrears agent, a processor on limited instructions.
  • Credit bureauA separate controller receiving a disclosure.

Business unit

  • Lending, Payments, Fraud, Collections, ComplianceOne unit per function, each with an owner.

Data subject set

  • Loan applicantsSubject to an automated decision.
  • Payment customersScreened for fraud on every transaction.
  • Borrowers in arrearsHandled by the collections agent.

Processing activity

  • Automated loan decisionArticle 6(1)(b) with the Article 22(2)(a) exception and its safeguards.
  • Transaction fraud screeningSplit basis: obligation, and legitimate interests beyond it.
  • Anti money laundering recordsArticle 6(1)(c), with the statutory retention period named.
  • Arrears collectionOutsourced on instruction.

Assessment

  • Automated decisions and profilingArticle 35(3)(a), with accuracy and bias as risks.

Transfer

  • Model hosting outside the UnionClauses and supplementary measures.

Risk

  • Model refuses credit inaccuratelyAccuracy under Article 5(1)(d) is a compliance duty.

Measure

  • Retention schedule with evidenced disposalBy activity and category, with proof of each run.

Document

  • Partial refusal letterThe reasoned explanation required by Article 12(4).

Person

  • Elena RossiData Protection Officer, approver on assessments.
  • Tom WillemsHead of lending, owner of the automated decision.
  • Nadia HaddadFinancial crime officer, owner of the screening activity.

How it gets built

The shape of the organisation

A regulated business already holds an obligations register. The data protection register has to agree with it, so the legal obligations are named on the activities that rest on them.

The entity register, with each party's role and state.
The entity register, with each party's role and state.

Entity: Aurelia Finance NV

What is held
The controller, with the Data Protection Officer and the financial supervisor both recorded.
Why
Two supervisors ask different questions about the same activity. Recording both means an answer prepared for one is findable by the other.

Business units: Lending, Payments, Fraud, Collections, Compliance

What is held
One unit per function, each with an owner.
Why
The units are how ownership becomes real. Fraud and lending both score customers, and giving each its own owner prevents one model being justified by the other's assessment.

Entity: Collections agent

What is held
A processor acting on instructions, with the agreement and the instruction limits recorded.
Why
An agent that only collects on instruction is a processor. The record states what it may not do, such as reporting to a credit bureau on its own initiative.
Alternative
Selling the debt makes the buyer a controller and requires a notice to the borrower, not a processor agreement. Which one applies follows the contract, so the contract is attached to the record.

Automated decisions on creditworthiness

Article 22 is the centre of this scenario. A decision made solely by automated means, with a legal or similarly significant effect, is prohibited unless one of three exceptions applies, and each exception carries obligations.

The assessment page of a processing activity, where screening and the assessment sit together.
The assessment page of a processing activity, where screening and the assessment sit together.

Processing activity: Automated loan decision

What is held
The decision, on Article 6(1)(b) with the Article 22(2)(a) exception, plus the safeguards: meaningful information about the logic, human intervention on request and the ability to contest.
Why
Refusing credit is a similarly significant effect, so the activity records the exception relied upon and the safeguards actually in place. A register that names Article 22 without naming the safeguards fails the first inspection.
Alternative
Explicit consent under Article 22(2)(c) is available, and is a poor fit here: consent cannot be freely given where refusing it means no loan. Adding a genuine human review before the decision issues takes the activity out of Article 22 altogether, at the cost of speed. State which route was taken and price it honestly.

Processing activity: Transaction fraud screening

What is held
Screening on Article 6(1)(c) where financial law requires it, and Article 6(1)(f) for the part that goes beyond the requirement.
Why
Splitting the basis is what allows the voluntary part to be objected to while the mandatory part continues. One combined basis would overstate the obligation.

Assessment: Automated decisions and profiling

What is held
An impact assessment covering Article 35(3)(a), with accuracy, bias and contestability as risks in their own right.
Why
Accuracy under Article 5(1)(d) is a data protection duty, so an inaccurate model is a compliance failure and not only a commercial one. The assessment cites the risk records and the measures that test them.

Where retention and erasure collide

This is the question a lending business is asked most often, and the register answers it by holding the obligation, not by refusing the right.

The register of technical and organisational measures, with the state of implementation and how effectiveness was tested.
The register of technical and organisational measures, with the state of implementation and how effectiveness was tested.

Processing activity: Anti money laundering records

What is held
Identification and transaction records, on Article 6(1)(c), with the statutory retention period and the law that sets it.
Why
Article 17(3)(b) disapplies erasure where processing is necessary for compliance with a legal obligation. Naming the law on the record is what turns a refusal into a reasoned one.

Request: erasure refused in part

What is held
The request, the part granted, the part refused and the reason for the refusal.
Why
A partial refusal is lawful and has to be explained under Article 12(4). Recording it as a partial answer, rather than a blanket refusal, is both correct and easier to defend.
Alternative
Restriction under Article 18 is the middle path where the obligation ends soon: the data stops being used for anything but the obligation, and is deleted when the period expires. It is more work to operate and much easier to justify.

Measure: retention schedule with evidenced disposal

What is held
The schedule by activity and category, with the disposal method and the evidence of each run.
Why
A schedule nobody executes is worse than none, because it documents the breach. The evidenced run is what closes the loop.

What the finished register answers

With the above in place, the record of processing lists every activity in use, each with its basis, its safeguards and its retention. The gaps view shows what is outstanding, ordered so each step is possible when it is reached. The exports carry the evidence in the form a supervisory authority reads.

The record of processing activities, produced from the activities in use.
The record of processing activities, produced from the activities in use.

How it gets maintained

A register is not finished when it is built. Three changes arrive at every organisation, and each one is absorbed the same way.

A new risk arrives

A quarterly test shows the credit model refuses applicants from one postcode band at three times the rate, without a lending reason.

  1. 01Set the context band to Aurelia Finance NV and the Lending unit.
  2. 02Open Risks, press the plus button, and name the risk Model refuses credit inaccurately.
  3. 03State the source, the affected set Loan applicants, and the effect on individuals in the Details tab.
  4. 04Move to Under assessment and rate both lenses. Harm to individuals is severe because credit is refused; the effect on the organisation carries a regulatory dimension as well.
  5. 05Link the assessment Automated decisions and profiling and the measure that tests the model, then record the treatment and the residual rating.
  6. 06Send the record to Elena Rossi for approval and set a quarterly review, because the model retrains.

Accuracy is now a tracked risk with a dated review, not a line in a model card.

The risk register, with the review dates that keep a retrained model honest.
The risk register, with the review dates that keep a retrained model honest.

A new processing activity starts

The business launches instant income verification by reading bank transaction data with the applicant's authorisation.

  1. 01Open Processing activities in the Lending context and press the plus button.
  2. 02State the purpose, the basis and whether the output feeds the automated decision. If it does, say so on the record.
  3. 03Cite the existing data subject set Loan applicants with Link a record.
  4. 04Open the Assessment tab. The activity feeds an Article 22 decision, so screening asks for an assessment: extend the existing one rather than starting a parallel document.
  5. 05Record the safeguards on the Accountability tab: the human intervention route and the ability to contest.
  6. 06Move to In use and read the new line in the record of processing.

A new source of data is attached to the decision it feeds, and the assessment covers both.

The accountability page, where the owner, the approver and the safeguards are held.
The accountability page, where the owner, the approver and the safeguards are held.

A new data processor is engaged

Collections is moved from one agent to another, and the new agent hosts its case system outside the Union.

  1. 01Open Entities, create the new agent as a processor, and record the instruction limits, including that it may not report to a credit bureau on its own initiative.
  2. 02Create the data processing agreement in Documents and link it to the entity.
  3. 03Link the new agent to the activity Arrears collection, and unlink the outgoing agent, then move that entity to its closed state rather than deleting it.
  4. 04Open Transfers and create the record for the hosting destination, with the clauses and the transfer impact assessment.
  5. 05Re-rate the risk on unauthorised further use, and confirm the retention measure still applies to the new system.

The change of supplier is visible as a change, with the old party retained as history and the new party fully evidenced.

The entity register, with each party's role and state, including the parties no longer used.
The entity register, with each party's role and state, including the parties no longer used.

Try it

The demo site builds a register from a sentence. Describe an organisation like this one and it will draft the records, then leave you the gaps to close.