GDPR-Conscious Reconciliation Workflow
Use local browser processing to reduce unnecessary product access to raw financial rows while keeping governance responsibilities explicit.
Try with sample files | View sample report
Problem statement
A reconciliation can include customer names, payment references, account identifiers, and transaction descriptions. EU teams must decide what is necessary, who receives it, and how long it is kept.
Example minimization decisions
| Line item | Amount |
| Account scope | One account only |
| Date scope | One review month |
| Unused columns | Excluded before handoff |
| Raw rows uploaded by product | No |
| Compliance guaranteed | No — organizational controls still apply |
Where local processing can support data minimization
- A scoped export can exclude accounts, periods, and columns that are not needed.
- Raw financial rows are processed in the browser session.
- No standing bank connection is created for future account activity.
- The organization still owns the legal, security, transfer, and retention decisions.
Define the data package
- A minimal bank export with only the account, period, and necessary fields.
- A minimal source export with only the rows needed to support the review.
- A final report, open-item list, owner, and retention decision.
Data-minimization review
- Document the purpose, data owner, reviewer, and retention period.
- Limit exports to the necessary account, range, currency, and fields.
- Use the approved transfer channel and open files in the local workflow.
- Export only the evidence required for review and follow-up.
- Delete or retain source files according to policy.
Governance checks
- Confirm a lawful basis and purpose before sharing exports.
- Remove unnecessary columns and date ranges.
- Define access to source files, the report, and notes.
- Set retention and deletion rules before distribution.
What the product does and does not do
- Keeps raw uploaded file rows in the browser processing path.
- Avoids a product-side bank OAuth connection.
- Exports a structured report that can be retained separately from source rows.
What still needs manual review
- Local processing does not control how files are exported, transferred, stored, backed up, or retained outside the session.
- This workflow description is not legal advice or a certification of GDPR compliance.
Do not want to connect a bank account?
Compare a browser-local exported-file workflow with a typical connected reconciliation tool.
Content review and sources
Written and reviewed by the Reconcile Locally product team. Last reviewed June 7, 2026.
Guidance is checked against current product behavior and first-party documentation where available. Reconciliation results still require human review.
Frequently asked questions
Is Reconcile Locally GDPR-compliant?
Local processing can support data minimization, but compliance depends on the full organizational workflow and obligations.
Do raw financial rows go to Reconcile Locally servers?
No. Raw CSV/XLSX rows used for reconciliation are processed inside the browser session.
Should I remove personal data before reconciliation?
Remove fields that are not necessary and keep only references needed for matching and follow-up under your policy.