Fundamentals of the GDPR Regulatory Framework in 2026
As the financial services industry responds to an increasingly complex regulatory landscape, GDPR compliance remains a key consideration in 2026. Investment firms and other financial institutions must safeguard the personal data entrusted to them by clients, employees, and third parties while meeting their broader regulatory responsibilities.
In this article, the SALVUS Regulatory Compliance team explores the critical GDPR obligations applicable to investment and financial institutions. Within this article we discuss:
1. GDPR Principles and Key Definitions
2. Consent and Rights of Data Subjects
3. The Role and Responsibilities of the Data Protection (DPO)
4. Privacy and Cookies Policies in Practice
5. How SALVUS can assist
We regularly share bite-sized insights on LinkedIn such as those found in this article
1. GDPR Principles and Key Definitions
GDPR is founded on core data protection principles, including:
- Lawfulness, fairness, and transparency – Personal data must be handled legally, fairly, and openly.
- Purpose limitation – Data should be collected only for clearly defined and legitimate purposes.
- Data minimization and accuracy – Only collect the information they need and ensure that it remains accurate and current.
- Storage limitation – Personal data should not be retained for longer than necessary.
- Integrity and confidentiality – Appropriate safeguards must be used to protect data from unauthorized access, accidental loss, or destruction.
Important GDPR definitions include:
- Personal data – Any information that relates to an identified or identifiable individual.
- Controller and processor – The controller decides why and how personal data is processed, while the processor handles the data on the controller’s behalf.
- Data breach – A security incident involving the unauthorized access, disclosure, alteration, destruction, or loss of personal data.
Investment firms must understand these principles and definitions and incorporate them into their operations, marketing practices, and client service activities.
2. Consent and Rights of Data Subjects
Under the GDPR, consent must be provided voluntarily and must be specific, informed, and clearly expressed. Financial institutions are responsible for maintaining clear records of consent and ensuring that individuals can withdraw it easily at any time.
Key rights of data subjects include:
- Right of access – The right to obtain information about the personal data being processed.
- Right to rectification and erasure – The right to correct inaccurate information or request the deletion of data that is incorrect or no longer required.
- Right to restrict processing and object – The right to limit or oppose certain uses of personal data, particularly for marketing and profiling.
- Right to data portability – The right to receive and transfer personal data to another service provider.
Firms must promptly address data subject requests and notify affected individuals of data breaches when required.
3. The Role and Responsibilities of the Data Protection Officer (DPO)
Financial institutions are required to appoint a Data Protection Officer (DPO) when their principal activities involve the large-scale processing of personal or sensitive data. Under the GDPR, the DPO plays a central role in compliance oversight by helping ensure that personal information is processed lawfully, transparently, and securely.
The DPO must be selected based on professional competence, particularly their knowledge of data protection laws and practices. Whether appointed internally or externally, the DPO must perform their duties independently, remain free from conflicts of interest, and report directly to senior management. The organisation must also provide the DPO with adequate resources and access to all relevant data-processing operations.
Key responsibilities of the DPO include informing and advising the firm on its GDPR duties, monitoring compliance with internal policies, and supporting staff awareness and training programmes. The DPO also supervises Data Protection Impact Assessments (DPIAs), especially when new technologies or processing activities are introduced that could create increased risks to individuals’ rights.
Additionally, the DPO liaises with supervisory authorities and acts as a point of contact for data subjects. A risk-based approach guides the DPO’s daily activities, allowing them to prioritise high-risk processing and help the firm implement appropriate and proportionate measures to maintain continued compliance with the GDPR.
Please contact us at info@salvusfunds.com if you require support with your GDPR compliance or are interested in our CPD course offerings and tailored advisory services.
4. Privacy and Cookies Policies in Practice
Transparency is an essential aspect of GDPR compliance. Financial institutions must publish clear and accessible privacy and cookies policies, which include:
Privacy Policy elements:
- Legal grounds and purposes of data processing
- Categories of data collected (including from marketing activities)
- Data retention periods (e.g., 5 years for CIF under regulatory obligations)
- Rights of data subjects and DPO contact information
- Description of security measures (e.g., encryption, access control)
Cookies Policy components:
- Definition of cookies and their categories, such as essential, marketing, and statistical cookies
- Reasons for using cookies and methods of collecting information
- Guidance on controlling or disabling cookies through browser settings
- Clear user consent for non-essential cookies through banners displayed on the first visit
These policies must be reviewed regularly, updated when necessary, and displayed prominently on the company’s website.
5. How SALVUS can assist
Navigating GDPR compliance can be particularly challenging for investment and financial institutions operating in a highly regulated environment. At SALVUS, we provide tailored support to help firms meet their data protection obligations and strengthen their overall compliance framework.
Our services combine practical advice, staff training, and strategic policy development across several key areas:
- GDPR gap analysis
We assess your current level of compliance, identify potential weaknesses, and highlight areas for improvement. This gives your firm a clear understanding of its strengths and vulnerabilities, providing a strong foundation for a targeted compliance strategy.
- Policies and internal procedures
We help develop and review essential documentation, including privacy policies, cookie policies, and internal data protection procedures. We also ensure these documents align with the GDPR and relevant sector-specific requirements, such as MiFID II.
- Data Protection Officer support
If your firm is required to appoint a Data Protection Officer, we can help structure the role, identify qualified personnel, or determine whether outsourcing is appropriate. We also support firms in ensuring that the DPO has the independence, resources, tools, and access needed to perform the role effectively.
- Staff training and professional development
We deliver awareness sessions and specialised CPD courses in collaboration with the Institute for Professional Excellence (IforPE). These include our course, “Fundamentals of the GDPR Regulatory Framework in 2026.” Each programme focuses on practical application and addresses the real-world challenges faced by compliance, legal, and operational teams.
Final Thoughts
GDPR compliance is not simply a regulatory obligation. It is essential for maintaining client trust, protecting sensitive information, and safeguarding a firm’s reputation.
By regularly reviewing privacy practices, data-handling procedures, and DPO arrangements, investment and financial firms can identify risks early and respond effectively. With expert guidance and proactive planning, firms can meet GDPR requirements with confidence and strengthen their overall compliance culture.
Please contact us at info@salvusfunds.com if you require support with your GDPR compliance or are interested in our CPD course offerings and tailored advisory services.
#StayAhead
If you’re interested in exploring related topics such as CIF regulated entities and Areas of EU Regulatory Compliance, visit our other SALVUS articles:
- Establishing a CySEC Investment Firm in Cyprus in 2026
- The 6 Areas of EU Regulatory Compliance
- The Role of the Data Protection Officer (DPO)
The information provided in this article is for general information purposes only. You should always seek professional advice suitable to your needs.