AI KYB Merchant ScreeningPrivacy by Design
Prototype engines onlineResidency: Indonesia profile+ New Screening
KSI
Privacy engineering

Privacy by Design

Privacy controls are embedded as system requirements rather than treated as a policy appendix. The prototype includes 34 design controls spanning collection, AI processing, third parties, decisioning, retention and data-subject operations.

34Design requirements
6HITL / source / cross-border / deletion
42Linked register
36Linked risk register
IDControlEngineering requirementStatus
PBD-01Field-level minimizationDefine required data fields per module; reject or mask unused fields.Designed
PBD-02Raw-document segregationStore raw images/documents in more restricted encrypted zone.Designed
PBD-03Identifier tokenizationUse case tokens instead of direct identifiers in downstream analytics where possible.Designed
PBD-04Source allowlistOnly approved external data sources/connectors may be invoked.Designed
PBD-05Source-policy enforcementRecord permitted access method, ToS/robots policy and contract status.Designed
PBD-06Evidence minimizationRetain specific decision evidence, not unnecessary full-source copies.Designed
PBD-07TTL & freshnessEach derived finding has source timestamp and expiry/re-screen policy.Designed
PBD-08Entity thresholdAmbiguous identity match is not treated as confirmed.Designed
PBD-09Human review gateHigh-impact probabilistic findings require analyst review.Designed
PBD-10Reason codesEvery risk-driving output has human-readable reason code.Designed
PBD-11No opaque auto-declineFinal adverse decisions cannot be based solely on uninterpretable model output.Designed
PBD-12No secondary trainingCase data excluded from vendor/model training unless separately approved.Designed
PBD-13Telemetry minimizationLogs avoid raw documents, images, tokens and unnecessary personal data.Designed
PBD-14Model bias testingTest materially affected groups/language patterns where relevant and legally appropriate.Designed
PBD-15RBAC/ABACRole and purpose-based authorization for analyst/admin access.Designed
PBD-16PAMPrivileged access controlled and monitored.Designed
PBD-17EncryptionTLS in transit and strong encryption at rest.Designed
PBD-18Key separationSeparate key control for raw sensitive document store.Designed
PBD-19Cross-border gateNo offshore processor/subprocessor until legal and security review passes.Designed
PBD-20Deletion propagationDeletion covers primary store, derived cache, search index and supported backups.Designed
PBD-21Correction propagationCorrected identity data invalidates stale findings and triggers re-score.Designed
PBD-22DSR engineeringSearch/export/correct/delete capabilities mapped to data stores.Designed
PBD-23Dispute / reconsiderationMerchant can request review of incorrect risk-driving data.Designed
PBD-24Processor controlsInstructions, confidentiality, security, audit and deletion obligations.Designed
PBD-25Subprocessor inventoryMaintain approved subprocessor and data-location list.Designed
PBD-26Retention by data classDifferent retention for raw evidence vs derived decision records.Designed
PBD-27Purpose-bound re-screeningOngoing monitoring only when policy/legal basis allows.Designed
PBD-28Change assessmentNew connector/model/category triggers privacy/security impact review.Designed
PBD-29Secure exportAnalyst exports watermarked/logged and minimized.Designed
PBD-30Evidence integrityHash/sign evidence snapshots where applicable.Designed
PBD-31Audit completenessWho/what/when/model/source/reason captured for decision reconstruction.Designed
PBD-32Incident containmentConnector tokens, raw stores and model endpoints separately isolatable.Designed
PBD-33Privacy metricsTrack minimization, deletion SLA, DSR SLA, false positive disputes.Designed
PBD-34Go-live privacy gateDPIA, ROPA, processor review and control test complete before production.Designed

Privacy Gate 1 · Design

Confirm purpose, data subjects, categories, source, legal basis candidate, minimization, recipients and residency before development.

Privacy Gate 2 · PoC

Use controlled test data, validate source ToS, measure false positives and verify no uncontrolled model-training reuse.

Privacy Gate 3 · Go-Live

DPIA residual risks accepted, ROPA complete, processor terms signed, retention/deletion tested, DSR and audit reconstruction tested.