Skip to content
Last updated: Sep 25, 2026

Data Protection Impact Assessment — Finni LLM Processing ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. Assesses the data-protection and AI risk of transmitting tenant data to a large language model.

Required:

  • before a material change to Finni's data flows, and
  • where GDPR, DPDP, or the EU AI Act obliges an assessment.

Scope and method ​

Processing assessed: Finni narration and Layer-2 judges transmitting financial and personal data to an external model.

Method:

  1. Describe the processing.
  2. Assess necessity and proportionality.
  3. Identify risks to data subjects.
  4. Define mitigations.
  5. Record residual risk.

Source material is held in the Compliance Readiness document.

Assessment ​

ElementSummary
Processing descriptionData categories, purpose, recipients, retention — to be completed
Necessity and proportionalityTokenise identity, retain semantics; enterprise no-train endpoint
RisksRe-identification, cross-tenant exposure, log leakage, automated-decision effect (Article 22)
MitigationsTokenisation, tenant scoping, redaction, human oversight, DPA / zero-data-retention
Residual risk and sign-offTo be completed

Actions and owners ​

The items folded from the compliance-readiness assessment (pending F-number assignment).

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial structure.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.