Daiwa Capital Markets Tackles GDPR Using Multi-Layer Encryption Tools
Investment bank is anonymizing data to meet cross-border data protection and cybersecurity regulations.
Daiwa Capital Markets is leveraging multi-layer encryption mechanisms to anonymize data to comply with new data protection and cybersecurity laws globally. The investment bank is reviewing the potential of using ARX’s open-source technology to anonymize client data and support various international risk models.
Speaking on the sidelines at the Asia Pacific Financial Information Conference (Apfic) on June 12, Huayi Dong, global head of electronic trading solutions at Daiwa Capital Markets, told WatersTechnology that the bank is looking at using the anonymization tool for various use cases, such as regulatory reporting. One example is the use of ARX’s double-layer encryption system, where the first layer can only be accessed by regulators, who can decrypt the layer using a specialized key.
As financial institutions are having to comply with multi-faceted data privacy and protection laws—most notably the EU’s General Data Protection Regulation (GDPR), which went into effect on May 25, 2018— they need to implement more robust and specialized data governance strategies. While encryption has always been key to the process, firms are now having to experiment with new tools and techniques to better combat information leakage or hacks.
Dong explains that firms need to understand what data should be anonymized, such as client-identifying data flowing to, from and through their IT systems. The bank’s legal and compliance department works with tech teams to identify what data needs to be encrypted for regulatory purposes, and where they also want to add extra attention. According to Dong, the firm implements a more restrictive internal policy for managing client data and believes that the industry should work towards a common framework for data protection.
“We not only obey [jurisdictional laws], but set ourselves one level higher to say we need a common standard [across the organization],” he adds. “For example, for a country such as South Africa, which doesn’t have very strong personal data protection or cybersecurity rules, we will apply, for example, Japanese cybersecurity rules on top of that so that we have a similar standard.”
Dong believes that the EU’s GDPR is one example of a regulation that is a move in the right direction, but admits that its implementation required major effort and drained resources at banks complying with the rule. As for a true global data security standard, Dong believes we’re still a long way away from something so all-encompassing, as many sovereign nations don’t see eye to eye on data privacy and protection.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Data Management
New working group to create open framework for managing rising market data costs
Substantive Research is putting together a working group of market data-consuming firms with the aim of crafting quantitative metrics for market data cost avoidance.
Off-channel messaging (and regulators) still a massive headache for banks
Waters Wrap: Anthony wonders why US regulators are waging a war using fines, while European regulators have chosen a less draconian path.
Back to basics: Data management woes continue for the buy side
Data management platform Fencore helps investment managers resolve symptoms of not having a central data layer.
‘Feature, not a bug’: Bloomberg makes the case for Figi
Bloomberg created the Figi identifier, but ceded all its rights to the Object Management Group 10 years ago. Here, Bloomberg’s Richard Robinson and Steve Meizanis write to dispel what they believe to be misconceptions about Figi and the FDTA.
SS&C builds data mesh to unite acquired platforms
The vendor is using GenAI and APIs as part of the ongoing project.
Aussie asset managers struggle to meet ‘bank-like’ collateral, margin obligations
New margin and collateral requirements imposed by UMR and its regulator, Apra, are forcing buy-side firms to find tools to help.
Where have all the exchange platform providers gone?
The IMD Wrap: Running an exchange is a profitable business. The margins on market data sales alone can be staggering. And since every exchange needs a reliable and efficient exchange technology stack, Max asks why more vendors aren’t diving into this space.
Reading the bones: Citi, BNY, Morgan Stanley invest in AI, alt data, & private markets
Investment arms at large US banks are taken with emerging technologies such as generative AI, alternative and unstructured data, and private markets as they look to partner with, acquire, and invest in leading startups.