Enterprise deployments should follow privacy-by-design principles and clearly distinguish Member data from enterprise administrative data.
Member data
Sensitive Member financial, profile, communication, and account data should be used only for authorized purposes and should not be disclosed to an employer, sponsor, or enterprise customer merely because that organization facilitates access to DIY Finance.
Enterprise data
Enterprise administrative information may include authorized contacts, eligibility files, entitlement status, aggregated usage reporting, support records, and contractual data. Reporting should minimize identifiable Member financial information unless disclosure is expressly authorized and legally permitted.
Processing controls
- Use purpose limitation and data minimization.
- Apply least-privilege access and role separation.
- Use appropriate contractual safeguards with subprocessors and service providers.
- Maintain retention and deletion controls appropriate to the data and relationship.
- Document cross-border or jurisdiction-specific processing where applicable.
- Separate analytics/aggregate reporting from sensitive Member-level financial data.
The operative Privacy Policy, enterprise agreement, data-processing terms, and applicable law control where more specific obligations apply.