Data-minimisation principles
The public assessment should request only non-sensitive facts necessary for preliminary routing. Sensitive KYC and identity records should not be submitted through ordinary public forms.
Future authenticated portal functions should implement encryption in transit and at rest, role-based access, access logging, retention limits, secure deletion and appropriate backup controls.
Final privacy notices, consent wording, retention periods and regulatory/legal statements require approval by the firm’s responsible legal reviewer before publication.
