← All legal documents Back-office · GDPR Art. 35

Data Protection Impact Assessment (DPIA)

Status: InternalVersion: 1.0Owner: Vanquish AI (dpo@vqs.ai)Reviewed: 22 June 2026

This DPIA assesses the privacy risks of the Vanquish AI platform and the measures that reduce them, in line with Article 35 GDPR and Autoriteit Persoonsgegevens guidance.

1. Why a DPIA

The processing is likely to result in higher risk because it involves: (a) financial data and trading activity; (b) automated processing that places real orders on a user's brokerage account based on user-configured logic; and (c) storage and use of sensitive access credentials (broker API keys). These factors meet several criteria in the WP29/EDPB DPIA guidance, so a DPIA is conducted.

2. Description of processing

3. Necessity & proportionality

Data collected is limited to what is needed to run bots and secure the service (data minimisation). Legal bases are documented in the Privacy Policy. Users retain control: paper-first default, explicit per-bot live consent, kill switch, and broker disconnect. No automated decision-making with legal/significant effect is performed by our profiling of users under Art. 22; the automation acts on the user's own instructions on the user's own account.

4. Risks & mitigations

RiskImpactLikelihoodMitigationsResidual
Compromise of stored broker credentialsHighLowEncryption at rest (envelope/KMS), least-privilege scopes, isolation, secret management, access controls, monitoring, revocation on disconnectLow
Unauthorised account accessHighLowMFA, hashed passwords, session security, anomaly detection, rate limitingLow
Financial harm via erroneous automationHighMediumPaper-first default, explicit live consent, user risk limits, kill switch, monitoring & alerts, clear risk disclosuresMedium
Excessive data retentionMediumLowDefined retention schedule, deletion on account closure, log minimisationLow
International transfer exposure (US sub-processors)MediumLowSCCs, transfer risk assessment, data minimisation to those providersLow
Re-identification via logsMediumLowAccess controls, pseudonymisation where feasible, audit loggingLow

5. Outcome & sign-off

With the measures above, residual risk is assessed as acceptable, subject to DPO confirmation. Prior consultation with the supervisory authority is to be confirmed — confirm with DPO. Review at least annually and on any material change. Sign-off: Vanquish AI (dpo@vqs.ai), date on file.