Compliance
Data Protection Impact Assessment
A DPIA is a UK GDPR requirement (Article 35) when processing is likely to result in high risk to individuals. This template documents the AdviserFlow platform's own DPIA and provides a starting point for your firm's DPIA.
1. Description of processing
Nature: AdviserFlow captures lead enquiries, seminar registrations and referrals for UK financial advice firms; segments contacts; sends compliance-approved follow-up emails; and stores CRM notes, tasks and pipeline data.
Scope: Personal data of prospective and existing clients of participating firms (name, email, phone, enquiry notes, IP address, consent state) and of firm staff (name, email, role).
Context: B2B SaaS; each firm is data controller for its own customer records; Pinnacle Reach Limited is the processor.
Purpose: Client acquisition, compliance-aware follow-up, regulatory recordkeeping.
2. Necessity and proportionality
- Lawful basis: consent for marketing follow-up; legitimate interests for operational messages and enquiry response; legal obligation for financial recordkeeping.
- Data minimisation: only name, email, phone, enquiry text and consent state captured by default.
- Retention: 12 months post-termination for account data; firm-configurable for customer records.
- Data subjects can exercise rights at /privacy/request.
3. Risks to individuals
- Unauthorised access to prospect data → mitigated by row-level security scoped to firm membership, encrypted transport, audit log.
- Sending marketing without consent → mitigated by explicit consent capture (IP + timestamp) and financial-promotion approval gate on every send.
- Cross-firm data leakage → mitigated by mandatory
firm_idscoping and policy tests. - Data retention beyond purpose → mitigated by documented retention schedule and firm-level export/delete tooling.
- Third-country transfers → data stored in UK/EEA managed cloud; sub-processors listed on request.
4. Measures to reduce risk
- UK GDPR compliant consent capture (lawful basis, IP, user agent, timestamp).
- PECR-compliant one-click unsubscribe on every marketing email.
- Financial-promotion approval gate on every sequence step.
- Row-level security in the database with firm-scoped policies.
- Immutable audit log for all write operations on customer data.
- Regular automated backups (see internal Backup & Restore Runbook).
- Access to production data is role-scoped and logged.
- Data subject request flow at /privacy/request.
5. Sign-off
This DPIA is reviewed at least annually and whenever the processing changes materially. Firms using AdviserFlow should complete their own DPIA covering their end-client processing.
Controller (platform): Pinnacle Reach Limited · Contact: privacy@pinnaclereach.co.uk