Corporate and investment banking
Privacy regulation, implemented inside a corporate bank
A data governance capability built from concept to delivery, then reused to meet a second regulatory regime without being rebuilt.
Two regulatory regimes
Context
A corporate bank needed to establish a data governance capability to meet its privacy obligations under GDPR. Every serious privacy regime asks the same underlying questions: what personal data do you hold, where does it live, why do you hold it, and how do you act on it. Most banks discover they cannot answer any of them on demand.
The problem
Personal data was distributed across systems, spreadsheets and departments with no central record. Responding to a data subject request meant a manual hunt with no guarantee of completeness — which is both a regulatory exposure and an operational cost every single time one arrives.
What we did
- 01Designed and built an Information Asset Register from conception through to final product, covering the data warehouse architecture and the user interface staff would actually work in.
- 02Built an interrogation tool aligned to the regulation and to internal procedure, so data subject requests could be answered from a system of record rather than from memory.
- 03Established a standard framework for classifying and storing personal data, so new systems joined the register by default instead of by exception.
- 04Carried the same framework into a second regulatory regime for another group entity, adapting it to the differences rather than rebuilding from scratch — which is the test of whether governance work was designed or improvised.
- 05Coordinated Open Banking API implementation alongside the governance work, where data sharing and data protection requirements meet directly.
Outcome
- A repeatable framework for locating, classifying and responding on personal data.
- Deployed successfully across two distinct regulatory regimes without a rebuild.
- Data subject requests answerable from a system of record rather than a manual search.