A support document to help clients' GDPR teams conduct a Data Protection Impact Assessment (DPIA) when deploying the Convier platform.

Contents of this page


Version: 1.0 Last updated: 12. september 2025


1. Purpose of this document

This document is provided to help Convier clients and their GDPR, legal, and compliance teams perform their own Data Protection Impact Assessment (DPIA) when using the Convier platform.

Convier itself does not act as a data controller or processor for client data when the platform is deployed in the client’s own infrastructure. Clients remain responsible for performing a DPIA under GDPR Article 35. This guide outlines the types of data that may be processed, the risks involved, and the safeguards built into Convier to support privacy by design.


2. Scope

The Convier platform is an analytics and investigation tool used by financial institutions and regulated entities to comply with Anti-Money Laundering (AML) requirements.


3. Categories of personal data that may be processed

The types of personal data processed in Convier depend entirely on client configuration and data sources. Typical examples include:

Clients decide which categories of personal data to process in Convier and remain responsible for ensuring that processing is lawful under GDPR. In practice, the processing carried out in Convier typically mirrors and supports the workflows clients already use for KYC and AML compliance (e.g., customer due diligence, transaction monitoring, and alert investigation).


4. Processing activities supported by Convier

The platform enables clients to:


5. Risks identified

The main risks in relation to personal data processing when using Convier are:


6. Safeguards and privacy by design features

Convier is built to minimize risks through privacy by design and by default:


7. Residual risks

While Convier reduces many risks, some responsibilities remain with the client:


8. Conclusion and recommendations

The Convier platform is designed to support GDPR compliance by minimizing data storage, integrating with existing client systems, and giving clients full control of their environment.

When conducting their own DPIA, clients should: