The guidelines for implementing the GDPR in banks, published in November 2017, provide a detailed overview of the responsibilities and roles involved, emphasizing the importance of data protection and information governance. The principle of accountability and the significance of the Data Protection Officer (DPO) are discussed. Additionally, the requirements for implementing adequate security measures and the approach to Data Protection Impact Assessments (DPIA) for high-risk processing are highlighted. The adoption of codes of conduct and certification mechanisms is encouraged to enhance compliance and user trust. The guidelines also offer a framework for managing incidents and data breaches, with specific deadlines for notification to competent authorities.