Report rpt_northline_privacy
Northline Neo-Bank Privacy Policy
Completed Jul 21, 2026, 10:05 AM · 1/1 pages scanned
High risk
0
Review
1
OK
6
Findings
7
International transfers lack documented safeguards
1 source · 1 clause
Finding
Cross-border transfers are contemplated; confirm SCCs/IDTA and transfer risk assessment are explicit and current.
Recommendation
Name the transfer mechanism (SCCs/IDTA), commit to a transfer impact assessment, and list destination countries.
Regulation
Articles 44–46 GDPR
Transfers to third countries require an adequacy decision or appropriate safeguards such as SCCs plus transfer risk assessment.
Source document · Approx. p. 5
“…rketing communications. International transfers When we transfer personal data outside the UK/EEA we use UK International Data Transfer Agreements or EU Standard Contractual Clauses and complete a transfer risk as…”
Documented lawful basis for processing
1 source · 1 clause
Finding
The document identifies a lawful basis for processing personal data.
Recommendation
No immediate action required for this control.
Regulation
Article 6 GDPR
Processing is lawful only if and to the extent a legal basis applies.
Source document · Approx. p. 2
“…is the controller of personal data processed through our consumer banking app. Legal bases We process personal data to perform our contract with you, to meet legal obligations under applicable financial regulat…”
Special category data handled without Article 9 condition
1 source · 0 clauses
Finding
No special category processing language detected.
Recommendation
No immediate action required for this control.
Regulation
Article 9 GDPR
Processing of special categories of personal data is prohibited unless an Article 9 condition applies.
Source document
“Control language present in policy body.”
Sub-processor changes without prior notice
1 source · 0 clauses
Finding
No unrestricted sub-processor appointment language detected.
Recommendation
No immediate action required for this control.
Regulation
Article 28(2) GDPR
The processor shall not engage another processor without prior specific or general written authorisation of the controller.
Source document
“Control language present in policy body.”
Breach notification window is conditional or weak
1 source · 0 clauses
Finding
No weak breach-notification hedge detected.
Recommendation
No immediate action required for this control.
Regulation
Article 33 GDPR
Personal data breaches must be notified to the supervisory authority without undue delay and, where feasible, not later than 72 hours.
Source document
“Control language present in policy body.”
Audit rights limited to summary reports only
1 source · 0 clauses
Finding
No restrictive audit-only-summary language detected.
Recommendation
No immediate action required for this control.
Regulation
Article 28(3)(h) GDPR
The processor must make available all information necessary to demonstrate compliance and allow for and contribute to audits.
Source document
“Control language present in policy body.”
Deletion/return timeline is open-ended
1 source · 0 clauses
Finding
No open-ended deletion timeline detected.
Recommendation
No immediate action required for this control.
Regulation
Article 28(3)(g) GDPR
At the end of services the processor must delete or return personal data at the choice of the controller.
Source document
“Control language present in policy body.”