In one sentence. GDPR and AML (Anti-Money Laundering) regulations pull in opposite directions: AML mandates 5-10 year retention of identity and transaction data, sanctions screening of every customer, and information-sharing across borders — while GDPR mandates data minimization, storage limitation, and purpose limitation. The resolution is Article 6(1)© GDPR (legal obligation) as the lawful basis, Article 23 GDPR restrictions on data subject rights where tipping off is a risk, and clear segregation of AML data from marketing/commercial processing. The launch of the EU Anti-Money Laundering Authority (AMLA) in mid-2026 further harmonises the AML side, raising the stakes for getting the GDPR interface right.
Key takeaways
- AML retention floor is 5 years under the 6th AMLD (extendable to 10 in many Member States) — GDPR storage limitation does not override this.
- Lawful basis for AML processing is Art. 6(1)© (legal obligation), not consent — customers cannot opt out of KYC.
- AMLA (operational mid-2026) directly supervises ~40 EU credit/financial institutions, harmonising obligations across the bloc.
- Article 23 GDPR allows restricting access, erasure, notification rights when needed to prevent tipping off a suspicious transaction subject.
- Penalty stacking risk: a single failure (e.g., over-retained KYC data leaked) can trigger both GDPR (up to €20M/4%) and AML directive (up to €5M for individuals, €10M for legal entities) fines.
For related reading: legitimate interest GDPR, storage limitation, data minimization, supervisory authority GDPR.
Here is the recorded presentation “GDPR & AML — what can go wrong”:
1. The structural conflict between AML and GDPR
The two regimes share an objective — protect against harm — but optimise opposite variables. AML maximises data collection to detect money laundering, terrorism financing, and sanctions evasion. GDPR minimises data collection to protect fundamental rights to privacy and data protection. Both are EU regulations of equal hierarchical standing. Neither defaults to overriding the other.
The result is a per-processing analysis: for every data point an obligated entity collects under AML (a passport scan, a beneficial-ownership declaration, a transaction screening result), the GDPR analysis must run in parallel. Lawful basis, retention period, transfer mechanism, data subject rights — all apply.
The EBA Guidelines on customer due diligence (EBA/GL/2021/02, revised 2024) explicitly require credit and financial institutions to document this dual analysis and to provide it to supervisors on request. The lawful-basis analysis itself flows from Article 6 GDPR, and the EDPB has repeatedly stressed that a legal obligation basis does not exempt controllers from the storage-limitation and minimisation principles.
2. The 5 main conflict points
| # | AML requires | GDPR principle | Resolution |
|---|---|---|---|
| 1 | Retain KYC + transaction data 5-10 years | Storage limitation (Art. 5(1)(e)) | Art. 6(1)© legal obligation supersedes; document the retention schedule per AMLD requirement |
| 2 | Collect extensive identity + source-of-funds data | Data minimisation (Art. 5(1)©) | The “minimum necessary” benchmark is set by AMLD, not by the controller’s preference |
| 3 | Sanctions screening against EU/UN/OFAC lists (third-country data flows) | Cross-border transfer rules (Chapter V) | Use Art. 49(1)(d) public interest derogation OR SCC with adequate safeguards |
| 4 | Report suspicious transactions to FIU (Tracfin, FIU-NL, BaFin, etc.) without informing customer (“no tipping off”) | Transparency (Art. 13/14), access (Art. 15) | Art. 23 restriction; document the criteria for invoking it |
| 5 | Share STR/SAR data within financial group across borders | Joint controllership / cross-border transfer | Joint-controller agreement (Art. 26) + transfer mechanism per Chapter V |
3. AMLA — the 2026 game-changer
The EU Anti-Money Laundering Authority (AMLA) was established by Regulation (EU) 2024/1620 and becomes operational in mid-2026 (headquartered in Frankfurt). AMLA’s responsibilities include:
- Direct supervision of ~40 high-risk credit and financial institutions across the EU
- Indirect supervision of national AML supervisors (the network includes BaFin, ACPR, DNB, CNMV)
- Harmonised technical standards via Regulatory Technical Standards (RTS)
- Cross-border investigation coordination under the 6th AMLD
For obligated entities, the practical impact is higher consistency of AML expectations across Member States, and consequently less room for divergent national interpretations of how GDPR interacts with AML. The first AMLA-led supervisory inspections are expected from Q4 2026.
4. Lawful basis under GDPR Art. 6
The lawful basis for AML/KYC processing is almost always Art. 6(1)© — legal obligation. The 6th AMLD (Directive (EU) 2024/1640) and national transposition acts are the source of the obligation. This means:
- No consent required — customers cannot opt out of KYC
- No legitimate interest balancing test required (Art. 6(1)(f) does not apply)
- No contract necessity test (Art. 6(1)(b) does not apply directly to KYC)
For fraud prevention activities that go beyond AML legal obligations (e.g., proprietary behavioural-analytics on transaction patterns), the lawful basis shifts to legitimate interests (Art. 6(1)(f)), requiring a documented Legitimate Interest Assessment (LIA).
For sanctions screening of third-country nationals where the screening involves third-country data flows, the lawful basis remains Art. 6(1)© (sanctions regulation is itself a legal obligation), but the transfer mechanism must be addressed separately.
5. Special categories of data — Article 9
KYC frequently involves special categories of personal data under Art. 9(1) — particularly:
- Biometric data (facial recognition for remote onboarding, fingerprint at branch)
- Political opinions (PEP screening reveals political exposure)
- Health data (source-of-funds explanations may reveal medical conditions)
The applicable Art. 9(2) exception is (g) substantial public interest based on EU/Member State law — namely the AMLD-transposing act. Some Member States (Germany via BDSG §22, France via LIL Art. 9) explicitly cite AML as a substantial public interest ground.
6. Retention periods — the precise rules
| Data category | Minimum retention | Maximum retention | Source |
|---|---|---|---|
| Customer identification records | 5 years from end of business relationship | 10 years (extendable in some MS) | 6th AMLD Art. 56 |
| Transaction records | 5 years from transaction date | 10 years | 6th AMLD Art. 56 |
| Suspicious transaction reports (STR/SAR) | 5 years from report date | Indefinite if pending investigation | National FIU rules |
| Beneficial ownership data | Duration of business relationship + 5 years | 10 years | 6th AMLD Art. 30 |
| Sanctions screening logs | 5 years per AMLD | 7 years (BaFin guidance for DE) | National guidance |
At the end of the retention period, data must be deleted or anonymised per Art. 5(1)(e) GDPR. The CJEU C-470/21 (La Quadrature du Net, October 2024) ruling confirmed that even AML retention cannot be open-ended.
7. Article 23 restrictions — when to invoke them
Art. 23 GDPR permits Member States to restrict the scope of data subject rights when necessary for important public interests, including prevention of money laundering. The restrictions allowed:
- Right of access (Art. 15) — may be refused if disclosure would tip off a subject of investigation
- Right to erasure (Art. 17) — does not apply to AML-retained data during retention period
- Right of notification (Art. 19) — may be deferred during active investigation
- Right to information about processing (Art. 13/14) — may be deferred where notice would compromise an investigation
To invoke Art. 23, the controller must:
- Identify the legal basis in national law (e.g., France LIL Art. 23, Germany BDSG §32)
- Document the specific risk justifying the restriction
- Inform the data subject of the restriction reasoning (where doing so does not itself tip off)
- Allow the data subject to lodge a complaint with the supervisory authority even when access is restricted
8. Real enforcement landscape
| Year | Entity | Fine | Issue |
|---|---|---|---|
| 2024 | BNP Paribas (CNIL) | €1.5M | KYC data retained beyond legal period, weak segregation |
| 2023 | N26 Bank (BaFin) | €4.25M | AML monitoring failures + GDPR data quality issues |
| 2022 | Caixa Geral de Depósitos (CNPD Portugal) | €1.25M | Indefinite KYC retention without basis |
| 2021 | Credit Suisse (Garante Italy) | €1.5M | Sanctions screening of third-country nationals without GDPR transfer mechanism |
| 2020 | Various Spanish banks (AEPD) | €3.5M total | KYC data used for marketing without consent |
The pattern: regulators sanction when AML data leaks into commercial processing, retention exceeds legal period, or sanctions screening creates undocumented cross-border transfers.
9. Practical implementation checklist
- ☐ Document Art. 6(1)© as lawful basis in your ROPA for all KYC + transaction monitoring processing
- ☐ Maintain separate storage for AML data vs marketing/commercial data (no shared databases)
- ☐ Document retention schedule citing the exact AMLD article + national transposition
- ☐ Implement automated deletion at retention expiry (not “delete on request”)
- ☐ Document the Art. 9(2)(g) exception for special category data
- ☐ Document criteria for Art. 23 restrictions + decision log per refused DSR
- ☐ Sign Joint Controller Agreement (Art. 26) with group entities sharing STR/SAR data
- ☐ Implement Standard Contractual Clauses for cross-border transfers in sanctions screening
- ☐ Annual review of the AML×GDPR interface in your data protection impact assessment
10. AMLA — what to do before mid-2026
For credit and financial institutions in scope of direct AMLA supervision:
- Map every AML-related processing operation against AMLA’s draft RTS (published Q1 2026)
- Update ROPA to reflect the new harmonised obligations
- Renegotiate intra-group AML data-sharing agreements to align with AMLA cross-border investigation powers
- Train DPO and MLRO jointly on the AML×GDPR interface
- Conduct a dual DPIA (covering both GDPR Art. 35 risks and AMLD operational risks) for any AI-based AML monitoring system — also triggering EU AI Act compliance for the AI component
For SMEs that fall under indirect AMLA supervision (via national supervisors): expect tightening of national AML guidance from 2026, with consequent updates to data-protection practice required.
11. Tooling
Legiscope maintains a registry of AML+GDPR processing operations with automated retention scheduling, Art. 23 restriction decision logs, and DPIA templates calibrated for KYC, sanctions screening, and transaction monitoring use cases.
Conclusion
The GDPR/AML interface is not a conflict to resolve once — it is a permanent operational tension to manage continuously. AMLA’s launch in 2026 raises the bar on AML harmonisation; obligated entities that have treated GDPR alignment as an afterthought will be exposed.
FAQ
Does GDPR apply to AML (Anti-Money Laundering) processing?
Yes, in full. AML obligations require retaining transaction and identity data for 5-10 years under EU AML Directives. GDPR storage limitation principles still apply, but the AML legal obligation (Art. 6(1)© GDPR) provides the lawful basis for processing and supersedes consent requirements. The retention period must be documented citing the specific AMLD article and national transposition.
Can AML screening results be shared with other entities?
Only under strict conditions. Sharing between group entities for consolidated AML monitoring may be permissible under legitimate interests, but requires a documented Joint Controller Agreement (Art. 26 GDPR), a documented transfer mechanism if crossing borders (Chapter V), and clear technical and organisational measures to prevent the data being used for non-AML purposes. Sharing with non-obligated third parties requires a separate legal basis.
What data subject rights can be restricted for AML purposes?
Article 23 GDPR permits restricting rights (access, erasure, notification of breach) when necessary to prevent tipping off under AML law. A subject access request from a person under suspicious transaction investigation can be lawfully refused if disclosure would prejudice the investigation. The restriction must be grounded in national law (e.g., LIL Art. 23 in France, BDSG §32 in Germany) and documented per refused request.
What retention period applies to AML records under GDPR?
EU AMLD Article 56 requires 5-year retention of customer identification records and transaction data from the end of the business relationship or transaction date. Some Member States extend to 10 years (Germany, Italy). This provides the legal basis for retention under GDPR Art. 6(1)©. At the end of the retention period, data must be deleted or anonymised under storage limitation principles — confirmed by CJEU C-470/21 (October 2024).
What is AMLA and when does it become operational?
AMLA is the EU Anti-Money Laundering Authority established by Regulation (EU) 2024/1620, headquartered in Frankfurt. It becomes operational in mid-2026. AMLA directly supervises ~40 high-risk EU credit and financial institutions and coordinates national AML supervisors. For data protection, AMLA brings harmonised cross-border investigation powers and consistent technical standards, reducing national divergence in how AML interacts with GDPR.
Can KYC data be used for marketing?
No. KYC data collected under AML legal obligation cannot be repurposed for marketing without violating purpose limitation (Art. 5(1)(b) GDPR). Spanish banks have been fined €3.5M collectively (AEPD 2020) for this exact issue. Marketing requires a separate lawful basis (consent or legitimate interest) and separate storage from AML systems. The two processing activities must be segregated technically and organisationally.
What’s the maximum fine if AML and GDPR are both breached?
The fines stack. A single failure — e.g., over-retained KYC data leaked in a breach — can trigger GDPR fines up to €20M or 4% of global turnover (Art. 83(5)) AND AMLD fines up to €5M for individuals, €10M for legal entities under the 6th AMLD enforcement framework. National supervisors can issue both. In the BNP Paribas 2024 case, CNIL imposed €1.5M for the data protection side while ACPR also took separate AML supervisory action.
Legiscope automates this for you
Stop doing compliance manually. Legiscope's AI handles ROPA creation, DPA audits, and gap analysis — in minutes, not weeks.
Start free trial





