Data Protection Impact Assessment — Finni LLM Processing
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. Assesses the data-protection and AI risk of transmitting tenant data to a large language model.
Required:
- before a material change to Finni's data flows, and
- where GDPR, DPDP, or the EU AI Act obliges an assessment.
Scope and method
Processing assessed: Finni narration and Layer-2 judges transmitting financial and personal data to an external model.
Method:
- Describe the processing.
- Assess necessity and proportionality.
- Identify risks to data subjects.
- Define mitigations.
- Record residual risk.
Source material is held in the Compliance Readiness document.
Assessment
| Element | Summary |
|---|---|
| Processing description | Data categories, purpose, recipients, retention — to be completed |
| Necessity and proportionality | Tokenise identity, retain semantics; enterprise no-train endpoint |
| Risks | Re-identification, cross-tenant exposure, log leakage, automated-decision effect (Article 22) |
| Mitigations | Tokenisation, tenant scoping, redaction, human oversight, DPA / zero-data-retention |
| Residual risk and sign-off | To be completed |
Actions and owners
The items folded from the compliance-readiness assessment (pending F-number assignment).
Related
- → LLM Compliance Readiness — the findings this assessment formalises
- → Tokenization — the primary mitigation
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial structure. |
Finaisse Internal — Confidential. Not for external distribution.