Financial Services AI and GDPR
Financial institutions process vast amounts of personal data for AI: transaction histories, behavioural patterns, credit data, employment information, and increasingly, alternative data sources (social media, device fingerprints). GDPR constrains how this data can be collected, processed, and used for AI model training — and financial regulators (ECB, EBA, national authorities) are increasingly scrutinising GDPR compliance of AI systems.
Lawful Basis for Financial AI
Article 6 Options
- Contract (Art. 6(1)(b)): Processing necessary for the performance of a contract. Applies to credit scoring for a loan application, fraud detection for a transaction, KYC for account opening. Limited to what's necessary for the specific contract.
- Legitimate interest (Art. 6(1)(f)): Most common basis for AI model training. Requires a balancing test: your legitimate interest vs the individual's rights. Document the assessment. Provide opt-out mechanism.
- Legal obligation (Art. 6(1)(c)): AML/CFT screening — you're legally required to monitor transactions. Strong basis, but limited to what the law requires.
- Consent (Art. 6(1)(a)): Rarely appropriate for financial services AI. Consent must be freely given — difficult when the alternative is "no financial service." Use only for optional, non-essential processing (e.g., personalised product recommendations).
Article 22: Automated Decision-Making
Article 22 prohibits "solely automated" decisions with legal or similarly significant effects, unless:
- Necessary for a contract: Automated credit decisions for online lending — but must provide human review on request
- Authorised by law: AML automated screening — authorised by AMLD
- Based on explicit consent: Rarely used in finance
Practical impact: Most financial AI operates as "semi-automated" — the AI provides a recommendation, a human makes the final decision. This avoids Art. 22 but requires that the human review is genuine (not rubber-stamping).
Data Minimisation for ML
- Feature selection: Only use features necessary for the model's purpose. More features ≠ better model, and each feature is a data processing operation that needs justification.
- Training data retention: Define retention periods for training data. Don't keep customer data indefinitely "because the model might need retraining."
- Pseudonymisation: Train models on pseudonymised data where possible. Direct identifiers rarely improve model performance.
- Purpose limitation: Data collected for one purpose (e.g., transaction processing) cannot automatically be repurposed for AI model training without a compatible lawful basis.
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →DPIA Requirements
A DPIA is mandatory for financial AI when:
- Large-scale profiling: Credit scoring, behavioural analysis, customer segmentation
- Automated decisions with significant effects: Lending, insurance, account management
- Innovative technology: New AI/ML applications in financial services
- Sensitive data processing: Financial data combined with other personal data for AI
The DPIA must be completed before processing begins, reviewed when processing changes significantly, and made available to supervisory authorities on request.
Related Solution
Need GDPR-compliant AI infrastructure? We design architectures that satisfy data residency, DPIAs, and right-to-erasure from day one.
Learn about our GDPR-compliant AI infrastructure →
Luca Berton