GDPR consulting for asset managers and fund management companies

Records of Processing Activities and Data Inventory under Art. 30 GDPR

Art.

  • 01Complete data inventory of all personal data in the financial sector
  • 02Records of processing activities under Art. 30 GDPR with retention periods and legal bases
  • 03Technical and organisational measures (TOMs) under Art. 32 GDPR
  • 04Retention policy reconciling regulatory obligations (MiFID, commercial law) with GDPR deletion requirements
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

Why asset managers need a structured data inventory

Without a complete data inventory, asset managers cannot fulfil data subject rights under Art. 15-22 GDPR within required timeframes or report data breaches within 72 hours. Records of processing activities under Art. 30 document all processing activities — from client master data and transaction histories to risk profiles. They form the foundation for retention policies, data protection impact assessments and cooperation with the data protection officer.

6 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

Data Inventory and Data Classification

Systematic identification of all personal data assets in your organisation. We map data sources, processing purposes, legal bases and storage locations — as the foundation for records of processing activities and retention policies.

02

Records of Processing Activities (Art. 30 GDPR)

Creation and maintenance of records of processing activities as required by Art. 30 GDPR. Documentation of all processing activities including purpose, legal basis, recipient categories, retention periods and technical-organisational measures.

03

Technical and Organisational Measures (TOMs)

Design and implementation of TOMs under Art. 32 GDPR: encryption, access controls, pseudonymisation, backup strategies and incident response processes — aligned with financial industry requirements.

04

Retention Policies and Deletion Concepts

Development of industry-specific retention policies balancing GDPR storage limitation with regulatory retention obligations (e.g. MiFID, national commercial codes). Definition of deletion rules, deletion protocols and automated deletion routines.

05

Data Protection Impact Assessment (DPIA)

Conducting data protection impact assessments under Art. 35 GDPR for high-risk processing in asset management — such as automated investment decisions, profiling or cross-border data transfers.

06

Data Subject Rights and Request Handling

Implementation of efficient processes for access, rectification, erasure and portability requests under Art. 15-20 GDPR. Setup of internal workflows with defined timelines, responsibilities and documentation.

5 phases

How we support your GDPR project in asset management

From initial assessment to audit-ready documentation, we support asset managers, fund management companies and investment firms in achieving full GDPR compliance.

  1. Assessment

    identification of all IT systems, data flows and processors

  2. Data inventory

    classification of personal data by category, legal basis and retention period

  3. Records of processing

    creation under Art. 30 GDPR with all mandatory information

  4. TOM documentation

    technical and organisational measures under Art. 32 GDPR

  5. Retention policy

    reconciliation of GDPR deletion requirements with regulatory retention periods

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Strategic GDPR asset management excellence is the foundation for future-proof data asset governance, combining comprehensive asset transparency with operational compliance innovation. Modern asset management frameworks not only create regulatory security but also enable strategic data asset optimization, operational synergies, and sustainable competitive differentiation. Our integrated asset governance approaches transform complex compliance challenges into strategic business enablers that ensure long-term business success and operational excellence.

7 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about GDPR Asset Management

What are records of processing activities under Art. 30 GDPR?

Records of processing activities (RoPA) are a mandatory documentation requirement under Art. 30 GDPR. They list all processing activities involving personal data, the respective purpose, legal basis, recipient categories, retention periods and a description of technical-organisational measures. For asset managers and fund management companies, RoPA forms the basis of any data protection audit by supervisory authorities.

What data must asset managers include in a data inventory?

Asset managers typically process client master data, financial data, risk profiles, transaction histories, identity verification documents and communication records. All these categories must be captured in the data inventory — including storage location, access permissions, legal basis and retention period. Data of employees, business partners and service providers must also be included.

What TOMs does the GDPR require from financial services firms?

Art. 32 GDPR requires technical and organisational measures appropriate to the risk. For financial services firms, this includes: encryption of data at rest and in transit, role-based access control systems, pseudonymisation of sensitive data, regular security assessments, backup and recovery procedures, and documented incident response processes.

When is a DPIA required in asset management?

A data protection impact assessment under Art. 35 GDPR is required when processing is likely to result in a high risk to data subjects. In asset management, this particularly applies to automated investment decisions, client scoring and profiling, systematic monitoring of large datasets, and cross-border data transfers to third countries.

How do you build a GDPR-compliant retention policy for financial services?

A retention policy defines when which data must be deleted. The challenge in financial services: regulatory retention obligations (e.g. 10 years under commercial law, 5 years under MiFID) often override the GDPR deletion requirement. The policy must address both — with clear deletion rules per data category, automated deletion routines and documented reviews after retention periods expire.

What happens in a data breach in asset management?

In the event of a personal data breach, the controller must notify the competent supervisory authority within 72 hours (Art. 33 GDPR). Data subjects must be informed where there is a high risk (Art. 34). Fines can reach up to EUR 20 million or 4% of global annual turnover. A documented incident response process is therefore essential for asset managers.

How does ADVISORI support GDPR implementation in asset management?

ADVISORI supports asset managers, fund management companies and investment firms from initial assessment to audit-ready documentation. We create data inventories, records of processing activities, retention policies and TOM documentation. Our consultants understand the industry-specific requirements from financial regulation and connect data protection with existing compliance structures.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance