Introduction to Customer Data Protection
The Customer Data Protection (CDP) module provides tools and functionalities to help certain data protection related to processing.
The module allows the user to do the following:
- Identify personal data within the system.
- Define a central store of personal data fields and tag these fields with specific properties that determine their processing.
- Determine the customers in scope for data protection related processing.
- Store and record data protection related requests from customers in relation to the use of their personal data.
- Provide specific personal data reports based on request.
- Monitor a customer’s activity status.
- An erasure process, which erases or anonymises data within the system after the completion of retention periods for holding the data.
The CDP module has two menus:
- Admin Menu – Used for configuration
- User Menu − Helps with day-to-day processing
Configuring Customer Data Protection
The bank is responsible for configuring the Customer Data Protection module.
The below outlines the module components that are to be configured by the bank.
This configures the high-level rules and settings for the module.
| Application | Description |
|---|---|
CZ.CDP.PARAMETER
|
|
Read Parameter user guide for more information.
This helps in the analysis of personal data fields within the bank’s own system.
| Application | Description |
|---|---|
CZ.CDP.PDD.SEARCH.REQUEST
|
Defines the search criteria to identify likely personal data fields |
CZ.CDP.PDD.SEARCH.RESULTS
|
Provides the output of the search request |
| Service | Description |
|---|---|
| BNK/PDD.SEARCH.UTILITY | Selects the trigger created by the Search Request and generates an output based on the search criteria |
Read Search Utility user guide for more information.
| Application | Description |
|---|---|
CZ.CDP.DATA.DEFINITION
|
Allows the client to define the Personal Data fields available in the system and processing of such fields |
CZ.CDP.PURPOSE
|
Allows the client to define the following:
|
CZ.CDP.ERASE.OPTION
|
Allows the client to define the mechanism of anonymising data. |
Read Data Definition, Purpose and Erase Option user guide for more information.
| Application | Description |
|---|---|
ST.CUSTOMER.ACTIVITY.PARAMETER
|
|
ST.CUSTOMER.ACTIVITY
|
Maintains the list of Active and Completed contracts and other linked applications for an individual |
CZ.CUSTOMER.ACTIVITY
|
Maintains additional details related to an individual’s activity and Customer Data Protection details such as:
|
CZ.CUSTOMER.ACTIVITY.CAPTURE
|
Confirms whether the customer is blocked for erasure and the customer remain active because of an externally held product with the bank |
| Service | Description |
|---|---|
| BNK/ST.TAKEOVER.CUS.ACTIVITY | Builds the original customer activity records for the module. Without this, the CDP processing cannot occur. The full configuration of the module should be set up correctly before this service is run. |
| BNK/ST.BUILD.CUS.ACTIVITY |
|
| BNK/ST.WATCHOUT.COMPLETED.CONTRACTS | Identifies whether a customer is removed from a contract and moves the contract to Completed. |
Read Customer Activity user guide for more information.
Applications
| Application | Description |
|---|---|
CZ.CDP.REQUEST.TYPE
|
|
CZ.CDP.REQUEST.CAPTURE
|
Allows a mechanism to log data protection related requests for customers |
| Service | Description |
|---|---|
| BNK/CDP.BUILD.ACCESS.RESULT | Generates the report for a Subject Access Request |
| BNK/CDP.BUILD.PORTABLE.REQUEST | Generates the report for a Data Portability request. |
| BNK/CZ.ERASURE.PROCESS | Provides an anonymisation process which pseudonymises personal data within the system – as per the set up of the Personal Data Definition. |
Read Rights Management user guide for more information.
A high-level visual representation of the module is shown below.
Illustrating Model Parameters
This section covers the following Model parameters.
| Parameters | Description | ||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
CZ.CDP.PARAMETER
|
This application defines the following:
|
||||||||||||||||||||
CZ.CDP.PURPOSE
|
This table defines the purpose of holding or processing the data. Additionally, it enables the user to define how long the data should be held before it is erased.Based on the underlying lawful basis, the bank processes the data and the following values are defined:
Erasure of personal data can be requested for customers who are still active, by setting the Allow Active Erasure field to Yes. The default value is No. |
||||||||||||||||||||
CZ.CDP.ERASE.OPTION
|
It allows the user to define how the data should be erased within the erasure process. The following values can be defined in the Erase Action field:
|
||||||||||||||||||||
CZ.CDP.DATA.DEFINITION
|
As part of the General Data Protection Regulation (GDPR) regulation, it is important to know the personal data which is stored in the system and how it is processed. It is important to have central metadata store, where the personal data is held within the system and allow specific processing to be exercised on the data that is identified.
System defined fields are based on initial analysis of fields that may contain personal data within the database. These fields are pre populated based on an initial analysis of the database and are no input. It enables the user to exclude by populating the field within the user fields section and setting the Exclude field as Yes. It allows the user to record their own definition of personal data. Field names and additional properties can be attached here. If a field has both a system and user defined field, the user field’s properties takes precedence during all CDP processing. User can define their own definition of personal data, where core and local fields can be added. The User Field Name is multi-valued so multiple fields can be added within each application.
Include for Prospect field defines whether the given application is required to consider for prospect data erasure processing. This field allows the below values:
|
||||||||||||||||||||
CZ.CDP.REQUEST.TYPE
|
It defines the request type and expiry days. Valid request types are:
Delink Pty Rln Api field is input only if the request type is Erasure. This field accepts an |
Illustrating Model Products
Model Products are not applicable for this module.
In this topic