Commentary

Top 5 GDPR Challenges for Financial Institutions

Ever since the General Data Protection Regulation (GDPR) came into force on 25th May 2018, data privacy laws in the European Union (EU) have undergone a quantum jump. Under the new rules, organizations across industries are now accountable for protection of personal data of customers and employees.GDPR empowers the customer and puts them in control of their personal information. It applies to all EU citizens and EU organizations. It also encompasses institutions outside the EU serving individuals within the EU.When it comes to banks and financial entities, clients’ data go through various levels during customer onboarding, accounting, relationship management and other banking processes. At each of these stages, sensitive data is handled by numerous people and computing systems. This necessitates a structured plan to safeguard customer data against possible breaches. Hence, the GDPR.Today we are going to take a look at the challenges faced by financial institutions while implementing GDPR. But first, a few definitions. Data subject: A data subject is a customer or employee who shares their personal data with a bank. Data controller: A data controller is a bank or financial entity which collects, holds and manages the personal information of its clients and employees. Data processor: A data processor is an organization that processes and analyzes customer data. It can be a bank or a third party service provider.Now let us get to the challenges which are the excerpt from the webinar conducted by Payjo, a leading conversational AI banking software provider. Customer consent The first thing banks need to ensure under GDPR is customer consent. Personal data of clients have to be strictly processed under the 6 lawful bases enshrined in the GDPR. Personal data is anything that can be used to identify a client. Name, age, sex, email address, residential address, phone number, social security number and information shared on social media, all come within the ambit of personal data. Under the new regulations, it is now mandatory for data controllers to seek the customers’ consent before collecting their personal information. They also need to explain why they are gathering the said data and how they are going to use it. Sharing the data with a third party also requires approval, and customers can hold the data controller accountable for any unauthorized use of their data. In short, banks need to be fully prepared to lawfully handle customer data. Right to data erasure Under GDPR, data subjects can request data controllers to permanently erase and remove their personal data from their records without any external authorization. The data subject has full right to data erasure. The bank might retain some data for complying with other laws, but apart from that, the customer has the right to be forgotten. For this, data controllers need to overhaul their data management system to execute the new rules.Breach of data GDPR mandates every bank to employ a Data Protection Officer to ensure adherence to the new laws. In case of a data violation, the GDPR governing authority needs to be notified within 72 hours. The data controller has to furnish all the details of the breach including nature, extent and criticality. Impacted data subjects must also be intimated without undue delay. In this regard, financial institutions need to gear up and put in place an efficient data breach reporting system. A rethinking in their approach towards customer data is imperative. They need to redefine how they, and the service providers they outsource the processing to, handle customer data. Data sharing GDPR requires data controllers to take responsibility for data shared across platforms. Due to the nature of operations, banks often have to outsource to third party service providers jobs beyond their core competency, like human resources and IT. In doing so, a lot of sensitive data moves across borders and get exposed to external agencies. Under the new regulations, data controllers need to ensure the information is safe and ethically handled by data processors. In other words, GDPR imposes end-to-end accountability on banks for total protection of personal data.Privacy by design One of the pillars of GDPR is the ‘privacy by design’ tenet. It calls on data controllers to list all the possible risks to privacy before a project involving personal data commences. It also requires them to set up organizational and technical checks and balances to preempt violations and implement data protection rules. This is where Psudonymisation comes in. It is defined as ‘the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person’. To this end, data controllers need to revamp their data security measures to ensure GDPR compliance. 

Top 5 GDPR Challenges for Financial Institutions

Ever since the General Data Protection Regulation (GDPR) came into force on 25th May 2018, data privacy laws in the European Union (EU) have undergone a quantum jump. Under the new rules, organizations across industries are now accountable for protection of personal data of customers and employees.GDPR empowers the customer and puts them in control of their personal information. It applies to all EU citizens and EU organizations. It also encompasses institutions outside the EU serving individuals within the EU.When it comes to banks and financial entities, clients’ data go through various levels during customer onboarding, accounting, relationship management and other banking processes. At each of these stages, sensitive data is handled by numerous people and computing systems. This necessitates a structured plan to safeguard customer data against possible breaches. Hence, the GDPR.Today we are going to take a look at the challenges faced by financial institutions while implementing GDPR. But first, a few definitions. Data subject: A data subject is a customer or employee who shares their personal data with a bank. Data controller: A data controller is a bank or financial entity which collects, holds and manages the personal information of its clients and employees. Data processor: A data processor is an organization that processes and analyzes customer data. It can be a bank or a third party service provider.Now let us get to the challenges which are the excerpt from the webinar conducted by Payjo, a leading conversational AI banking software provider. Customer consent The first thing banks need to ensure under GDPR is customer consent. Personal data of clients have to be strictly processed under the 6 lawful bases enshrined in the GDPR. Personal data is anything that can be used to identify a client. Name, age, sex, email address, residential address, phone number, social security number and information shared on social media, all come within the ambit of personal data. Under the new regulations, it is now mandatory for data controllers to seek the customers’ consent before collecting their personal information. They also need to explain why they are gathering the said data and how they are going to use it. Sharing the data with a third party also requires approval, and customers can hold the data controller accountable for any unauthorized use of their data. In short, banks need to be fully prepared to lawfully handle customer data. Right to data erasure Under GDPR, data subjects can request data controllers to permanently erase and remove their personal data from their records without any external authorization. The data subject has full right to data erasure. The bank might retain some data for complying with other laws, but apart from that, the customer has the right to be forgotten. For this, data controllers need to overhaul their data management system to execute the new rules.Breach of data GDPR mandates every bank to employ a Data Protection Officer to ensure adherence to the new laws. In case of a data violation, the GDPR governing authority needs to be notified within 72 hours. The data controller has to furnish all the details of the breach including nature, extent and criticality. Impacted data subjects must also be intimated without undue delay. In this regard, financial institutions need to gear up and put in place an efficient data breach reporting system. A rethinking in their approach towards customer data is imperative. They need to redefine how they, and the service providers they outsource the processing to, handle customer data. Data sharing GDPR requires data controllers to take responsibility for data shared across platforms. Due to the nature of operations, banks often have to outsource to third party service providers jobs beyond their core competency, like human resources and IT. In doing so, a lot of sensitive data moves across borders and get exposed to external agencies. Under the new regulations, data controllers need to ensure the information is safe and ethically handled by data processors. In other words, GDPR imposes end-to-end accountability on banks for total protection of personal data.Privacy by design One of the pillars of GDPR is the ‘privacy by design’ tenet. It calls on data controllers to list all the possible risks to privacy before a project involving personal data commences. It also requires them to set up organizational and technical checks and balances to preempt violations and implement data protection rules. This is where Psudonymisation comes in. It is defined as ‘the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person’. To this end, data controllers need to revamp their data security measures to ensure GDPR compliance. 

Asia to lead the 21st century through financial inclusion and data-driven banking

With over $3.8b invested in Asia’s fintech ecosystem in 2017 and the emergence of a bouquet of services such as insurtech, Internet of Things (IoT) in wealth management, consumer-centric targeted services, amongst others, the region is well-poised to emerge as the leader of next generation fintech applications. Asia is also home to one of the largest peer-to-peer (P2P) lending, crowd funding, and e-commerce markets which complement its growing fintech base.

An Asia perspective: A bank branch for the digital age

The bank branch as we know it, with tellers behind windows and bankers huddled in cubicles with desktop computers, needs reinvention. Most customers now carry a bank in their pockets in the form of a smartphone and only visit an actual branch to get advice or buy complex products. Across Asia, digital transactions are 1.6 to 5 times as frequent as branch transactions.

The IBOR transition: A certainty, not a choice

As the pace of global regulatory change increases, it is clear that the Inter-Bank Offered Rates (IBORs) of major currencies will evolve or that alternate nearly risk-free reference rates (ARRs) will soon be introduced. These changes will have an impact across a wide range of organisations, including banks, buy-side, sell-side and corporates. In this environment, organisations in Asia-Pacific with IBOR exposures should be taking active steps to understand the scale of the transition and the associated risks in order to prepare for the changes ahead.

Riding the waves of opportunities: Asia to spur infrastructure growth

Urbanisation, together with population growth, is expected to add another 2.5 billion people to urban areas around the world by 2050, according to a United Nations report launched earlier this year. The potential challenges this will bring will be far-reaching, particularly in Asia and Africa where nearly 90 percent of the increase is set to take place.

How to approach open APIs: Threats and oppotunities

Returning to a global perspective, both US and European open API trends, as well as regulatory and market participant responses, are valuable reference points for Japanese market players looking for insight. While Japan was mulling advancements related to open APIs, we continued to find best practices in each industry including banking, insurance, securities, and wealth management in the pioneering European market and the US market. We also continued to offer strategic advice to financial institutions engaging in individual projects and technology vendors.

Time for Hong Kong to embrace higher rates, and perhaps lower asset prices

With HKMA and major Hong Kong banks increased their base lending rate on September 27, Hong Kong has finally embraced higher rates after twelve years of muted low rate environment. The abundant liquidity in Hong Kong and the seemingly decoupled rate cycle with the US has been the trending question in the market. Not only during the era of the global quantitative easing, rates in Hong Kong have stayed at an ultra-low level even after the FED started its hiking cycle. But the recent sudden appreciation of the HKD seems to be a wakeup call to carry trade participants.

Time to go back to basics for the Australian banking industry

Stirring beneath the Banking Royal Commission and amplified by the recent interest rate hikes is a sense of agitation amongst the Australian public that things can be better when it comes to banking in Australia.

The future of financial crime compliance

The global financial services industry including Asia is being plagued with the pervasive nature of financial crime and the ever-changing typology of threats. These threats include money laundering, tax evasion, bribery and corruption, and fraud – and financial institutions are grappling to find the right balance to ensure that their compliance programmes are able to adapt and respond.

Why risks remain for Asia's top banks

Asia’s banks have been in a sweet spot this year: operating performances, asset quality, and credit quality are all relatively stable, and macroeconomic and financing conditions continue to be favorable. But some threats loom. 

Pricing, discounting, and negotiation to maximise profitability

Increased competition and rising costs are forcing private banks globally and in Asia to focus more on profitability and less on volume growth. In an evolving and competitive landscape, innovation will require smart pricing strategies to protect margins, as the effect of pure price adjustment is limited. Maximising profitability all comes down to improving management of individual client conditions through more effective pricing, discounting practices and negotiation approaches.

How banks can prepare for the worst

Why do banks in Asia and the rest of the world have so much trouble managing operational risk?

Goodbye deleveraging: Fiscal and monetary expansion to support growth in China

Against very clear headwinds due to the trade war and decelerating investment, China's State Council has unveiled plans to take a more aggressive fiscal policy in 2018 with a reduction of corporate and household burden by RMB 1.1 trillion. In the whole year, tax reduction will amount to RMB 800 billion for enterprises and individuals, which is equivalent to 5.5% of total tax revenue in 2017. This includes the adjustment in value added tax, the reduction in corporate tax rate of manufacturing, transportation, and other industries, and the rebate from research and development expense. Another RMB 300 billion will come from reducing non-tax burden on costs in logistics and utilities. The total amount is roughly equivalent to the reduction in corporate burden from the US tax reform of $150 billion (RMB 1 trillion).

Paths to overcoming the trap: Digital transformation as an opportunity

The topic being discussed most nowaday is “Opportunities and Challenges of Digital Transformation in Southeast Asia”. OECD-SEARP has been engaged in active discussions on policies to make digitalisation work for better lives and inclusive growth. Japan has actively lead those discussions. OECD has been working on a horizontal project to assess the potential and impact of digitalisation on various aspects of human lives. It is essential to recognise digital transformation as an opportunity, not as a problem.

Human-machine collaboration could be a big boon for financial firms, if only they fully embrace it

Artificial intelligence has been a topic of conversation and a part of business for years, from rogue robots in movies to neural networks that detect fraud at credit card companies, but only recently have companies really started experimenting with and implementing it more widely.

Alternative payment providers position for growth in Indonesia

When it comes to growth opportunities for digital payments, Indonesia is in a league of its own. The prospect of tens of millions of new digital payment customers is too much for digital companies and investors to ignore. The likes of SoftBank, Alibaba’s Ant Financial, and Chinese ride hailing giant Didi-Chuxing are injecting billions of dollars into companies with a chance of gaining a foothold in the market.

Open API is just the beginning

It might seem as though vertical division of labor and horizontal disintegration have already proliferated enough.