Coreal.
Book a working session →
·Compliance · GDPR

GDPR compliance for bank.

General Data Protection Regulation (Regulation (EU) 2016/679). Enforced from 2018-05-25. Supervised by EDPB + national supervisory authorities (CNIL, BfDI, ICO etc.). Coreal generates the evidence pack automatically on every Minctrl build — see /security-compliance for the full posture.

Enforced
2018-05-25
Authority
EDPB…
Penalties
Up to €20M or 4% of annual global turnover, whichever is higher.
Vertical
BANK

What this regulation covers.

Personal data processing, DPIA, breach notification, data-subject rights.

For a bank, the salient angles are: CRR/CRD capital and liquidity ratios; ICAAP / ILAAP annual cycle; Outsourcing concentration limits (EBA guidelines). Primary licence: Banking licence + ECB / national competent authority oversight.

● RELEVANT ARTICLES
  • Art. 5 — Principles relating to processing
  • Art. 25 — Data protection by design and by default
  • Art. 32 — Security of processing
  • Art. 33 — Breach notification (72 hours)
  • Art. 35 — DPIA
● EVIDENCE PACK COREAL GENERATES

What lands in the regulator file.

E01Record of Processing Activities (RoPA)
E02DPIA per high-risk processing (e.g. crypto, biometric)
E03Breach register + 72-hour notification log
E04DSAR (Data Subject Access Request) fulfilment audit

All items journaled, replayable, 7-year retention.

● READ NEXT
·Questions we hear

Which GDPR articles apply to a bank?

Primarily: Art. 5 — Principles relating to processing; Art. 25 — Data protection by design and by default; Art. 32 — Security of processing. The full mapping is in the Coreal compliance posture document — see /security-compliance.

What evidence does Coreal generate per audit?

Record of Processing Activities (RoPA); DPIA per high-risk processing (e.g. crypto, biometric); Breach register + 72-hour notification log. The Minctrl pipeline produces this artefact set automatically on every build — see /company §05 'How we ship'.

What are the penalties for non-compliance?

Up to €20M or 4% of annual global turnover, whichever is higher.

·Working session

Bring the perimeter,
leave with a brief.

Book a working session →Read field notes →
Not ready to book 4 hours?

Read the Wave-1 runbook first.

The full 90-day launch sequence — phases, partner-bank gates, who signs off when. No form to read it.

Read the runbook →

INDICATIVE DATA · Numbers and timelines reflect public regulator filings, vendor documentation and our own delivery experience. Per-engagement values vary with operator profile, BSS vintage and regulatory perimeter. Engage early for a fitted estimate under NDA.