Data Protection Impact Assessment (DPIA)
This DPIA assesses the privacy risks of the Vanquish AI platform and the measures that reduce them, in line with Article 35 GDPR and Autoriteit Persoonsgegevens guidance.
1. Why a DPIA
The processing is likely to result in higher risk because it involves: (a) financial data and trading activity; (b) automated processing that places real orders on a user's brokerage account based on user-configured logic; and (c) storage and use of sensitive access credentials (broker API keys). These factors meet several criteria in the WP29/EDPB DPIA guidance, so a DPIA is conducted.
2. Description of processing
- Nature: collection, storage, encryption, transmission and automated use of account, strategy, trading and credential data to operate user bots.
- Scope: all platform users; data categories per the RoPA.
- Context: self-directed, invite-only B2C/B2B SaaS; users connect their own broker; live trading is opt-in per bot.
- Purposes: provide the service, execute user-authorised automation, secure the platform, bill, and comply with law.
3. Necessity & proportionality
Data collected is limited to what is needed to run bots and secure the service (data minimisation). Legal bases are documented in the Privacy Policy. Users retain control: paper-first default, explicit per-bot live consent, kill switch, and broker disconnect. No automated decision-making with legal/significant effect is performed by our profiling of users under Art. 22; the automation acts on the user's own instructions on the user's own account.
4. Risks & mitigations
| Risk | Impact | Likelihood | Mitigations | Residual |
|---|---|---|---|---|
| Compromise of stored broker credentials | High | Low | Encryption at rest (envelope/KMS), least-privilege scopes, isolation, secret management, access controls, monitoring, revocation on disconnect | Low |
| Unauthorised account access | High | Low | MFA, hashed passwords, session security, anomaly detection, rate limiting | Low |
| Financial harm via erroneous automation | High | Medium | Paper-first default, explicit live consent, user risk limits, kill switch, monitoring & alerts, clear risk disclosures | Medium |
| Excessive data retention | Medium | Low | Defined retention schedule, deletion on account closure, log minimisation | Low |
| International transfer exposure (US sub-processors) | Medium | Low | SCCs, transfer risk assessment, data minimisation to those providers | Low |
| Re-identification via logs | Medium | Low | Access controls, pseudonymisation where feasible, audit logging | Low |
5. Outcome & sign-off
With the measures above, residual risk is assessed as acceptable, subject to DPO confirmation. Prior consultation with the supervisory authority is to be confirmed — confirm with DPO. Review at least annually and on any material change. Sign-off: Vanquish AI (dpo@vqs.ai), date on file.