AML and data protection
AML and data protection

The following Risk & Compliance guidance note provides comprehensive and up to date legal information covering:

  • AML and data protection
  • The data protection regime
  • Lawful ground for processing
  • Restriction on processing personal data for non-AML/CTF purposes
  • Information requirements
  • Protecting and retaining CDD data
  • Data sharing
  • Subject access requests and tipping-off

Forthcoming changes: The UK has voted to leave the EU and this will take place on exit day as defined in section 20 of the European Union (Withdrawal) Act 2018. This has implications for organisations. This Practice Note is likely to be affected. It will be updated as and when relevant implementing legislation is published. For more on Brexit, see subtopic: Brexit—compliance and risk management.

The provisions of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA 2018) creates some challenges under the anti-money laundering (AML) and counter-terrorist financing (CTF) regime, including:

  1. complying with information requirements

  2. the requirement not to use personal data collected for AML/CTF reasons for other purposes

  3. protecting the customer data you collect during the customer due diligence (CDD) process

  4. sharing customer data with law enforcement agencies, eg by making suspicious activity reports (SARs) or responding to enquiries, and

  5. data subject access requests (DSARs) and tipping-off offences

This Practice Note begins with a brief overview of the data protection regime and its principles and then explains these challenges, providing practical guidance on how to approach them. It reflects the requirements of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), SI 2017/692 which came into force on 26 June 2017. It provides guidance which is of general