Privacy and Data Protection
Summary: NEFE deployments should use only the data needed for defined commercial purposes and protect it throughout its lifecycle.
#Core principles
- Define the purpose before collecting or receiving data.
- Identify the responsible parties and lawful basis where required.
- Minimize fields, precision, audience, and retention.
- Provide appropriate notice and meaningful choices.
- Protect data in transit, at rest, and in use according to risk.
- Support correction, deletion, objection, or access rights as applicable.
- Document sharing, processors, and cross-border considerations.
#Data categories
Deployments may handle:
- Business profile data.
- User account data.
- Campaign configuration.
- Operational events.
- Aggregated commercial measures.
The exact data inventory must be documented per deployment.
Important: Do not place payment credentials, government identifiers, sensitive verification evidence, or unnecessary personal data into general-purpose profile, campaign, or analytics fields.
#Retention and deletion
Retention should reflect:
- Purpose.
- Contractual and legal obligations.
- Security needs.
- Customer expectations.
Pilot closeout must include an explicit retention or deletion decision.
#Related guidance
See security overview, roles and permissions, consumer onboarding, and verification.

