Overall LowGDPR

Report rpt_northline_privacy

Northline Neo-Bank Privacy Policy

Completed Jul 21, 2026, 10:05 AM · 1/1 pages scanned

High risk

0

Review

1

OK

6

Findings

7

ReviewArticles 44–46 GDPR

International transfers lack documented safeguards

1 source · 1 clause

Finding

Cross-border transfers are contemplated; confirm SCCs/IDTA and transfer risk assessment are explicit and current.

Recommendation

Name the transfer mechanism (SCCs/IDTA), commit to a transfer impact assessment, and list destination countries.

Regulation

Articles 44–46 GDPR

Transfers to third countries require an adequacy decision or appropriate safeguards such as SCCs plus transfer risk assessment.

Source document · Approx. p. 5

“…rketing communications. International transfers When we transfer personal data outside the UK/EEA we use UK International Data Transfer Agreements or EU Standard Contractual Clauses and complete a transfer risk as…”

OKArticle 6 GDPR

Documented lawful basis for processing

1 source · 1 clause

Finding

The document identifies a lawful basis for processing personal data.

Recommendation

No immediate action required for this control.

Regulation

Article 6 GDPR

Processing is lawful only if and to the extent a legal basis applies.

Source document · Approx. p. 2

“…is the controller of personal data processed through our consumer banking app. Legal bases We process personal data to perform our contract with you, to meet legal obligations under applicable financial regulat…”

OKArticle 9 GDPR

Special category data handled without Article 9 condition

1 source · 0 clauses

Finding

No special category processing language detected.

Recommendation

No immediate action required for this control.

Regulation

Article 9 GDPR

Processing of special categories of personal data is prohibited unless an Article 9 condition applies.

Source document

“Control language present in policy body.”

OKArticle 28(2) GDPR

Sub-processor changes without prior notice

1 source · 0 clauses

Finding

No unrestricted sub-processor appointment language detected.

Recommendation

No immediate action required for this control.

Regulation

Article 28(2) GDPR

The processor shall not engage another processor without prior specific or general written authorisation of the controller.

Source document

“Control language present in policy body.”

OKArticle 33 GDPR

Breach notification window is conditional or weak

1 source · 0 clauses

Finding

No weak breach-notification hedge detected.

Recommendation

No immediate action required for this control.

Regulation

Article 33 GDPR

Personal data breaches must be notified to the supervisory authority without undue delay and, where feasible, not later than 72 hours.

Source document

“Control language present in policy body.”

OKArticle 28(3)(h) GDPR

Audit rights limited to summary reports only

1 source · 0 clauses

Finding

No restrictive audit-only-summary language detected.

Recommendation

No immediate action required for this control.

Regulation

Article 28(3)(h) GDPR

The processor must make available all information necessary to demonstrate compliance and allow for and contribute to audits.

Source document

“Control language present in policy body.”

OKArticle 28(3)(g) GDPR

Deletion/return timeline is open-ended

1 source · 0 clauses

Finding

No open-ended deletion timeline detected.

Recommendation

No immediate action required for this control.

Regulation

Article 28(3)(g) GDPR

At the end of services the processor must delete or return personal data at the choice of the controller.

Source document

“Control language present in policy body.”