This requires organisations to strike a balance between their obligation to prevent money laundering and terrorist financing and the GDPR principles of data minimisation, purpose limitation, and processing security.
In many organisations, customer verification is still treated as a purely administrative exercise: obtain an identity document, verify the data, save a copy, and complete the KYC form. From a legal and compliance perspective, however, the process is far more complex.
On the one hand, AML legislation requires obliged entities to apply customer due diligence measures, including customer identification, identity verification, identification of beneficial owners, and assessment of the purpose and nature of the business relationship. The Polish AML/CFT framework is primarily based on the Act of 1 March 2018 on Anti-Money Laundering and Counter-Terrorist Financing, which defines the responsibilities of obliged entities, the role of the General Inspector of Financial Information (GIIF), and rules for reporting suspicious transactions.
On the other hand, the GDPR requires every personal data processing activity to have a valid legal basis, be proportionate to its purpose, properly documented, and adequately secured. In practice, it is not sufficient to say, "We process the data because AML regulations require it." Organisations must know what data they collect, why they collect it, how long it is retained, who has access to it, and how privacy risks are mitigated.
The key principle is simple: AML regulations justify data processing, but they do not exempt organisations from GDPR obligations. In a typical AML compliance process, the legal basis for processing will be Article 6(1)(c) GDPR in conjunction with the relevant AML provisions. The recent decision of the President of the Polish Personal Data Protection Office (UODO) concerning identity document copying also assessed such processing through the lens of Article 6(1)(c) GDPR.
The scope of data processed within a KYC process should primarily result from AML regulations, while the extent and intensity of customer due diligence measures should reflect the identified risk level, customer type, nature of the business relationship, and other circumstances specified by law.
Such data may include:
The new EU AML framework promotes greater harmonisation, digitalisation, and a risk-based approach. Among other things, the EU AML package emphasises proportionality, digital identification, and tailoring the scope of collected information to the actual level of risk, rather than mechanically collecting excessive data from every customer.
From a GDPR perspective, however, the key requirement is that the obliged entity must be able to demonstrate that the specific scope of data collected was necessary to fulfil AML obligations. In other words, being subject to AML regulations does not automatically grant an organisation the right to collect "everything, just in case."
This is one of the most common questions in both AML and data protection practice. The answer is not always straightforward.
Copying an identity document may be permissible where it is necessary to fulfil AML obligations and falls within the scope of customer due diligence measures being applied. However, this does not mean that every organisation should automatically copy the documents of all customers in every situation. Under Article 34(4) of the Polish AML Act, obliged entities may process information contained in customers' identity documents and may create copies of such documents for customer due diligence purposes.
The key word is "may." Article 34(4) does not impose a general obligation to copy identity documents.
Importantly, this approach has also been confirmed by the President of the UODO, who pointed out that the possibility of creating copies of identity documents constitutes a right available to obliged entities rather than a universal obligation applicable in all cases.
From a GDPR perspective, organisations should assess:
The greatest risk arises when organisations routinely collect scans of identity documents without assessing necessity, without a retention policy, and without access restrictions. Such practices may violate the principle of data minimisation and increase the impact of any security incident.
AML and GDPR pursue different objectives. However, both frameworks rely on a risk-based approach, although the subject and purpose of the risk assessment differ.
Under AML regulations, organisations must assess risks associated with customers, products, transactions, countries, distribution channels, and ownership structures. The intensity of verification measures should correspond to the level of money laundering or terrorist financing risk. Within both the Polish and EU AML frameworks, the risk-based approach is one of the fundamental principles of customer due diligence.
Under the GDPR, a risk-based approach means that controllers should assess risks to the rights and freedoms of individuals and implement appropriate technical and organisational safeguards.
A properly designed KYC process should therefore answer two questions simultaneously:
Only by combining these two perspectives can an organisation create a procedure that is both regulatory-compliant and data protection-compliant.
The most common customer identity verification mistakes include:
Another significant issue is treating AML and GDPR as separate processes managed by different teams. Effective compliance requires consistency. AML procedures, data protection documentation, IT systems, and operational practices should work together.
To minimise compliance risks, organisations should implement several practical measures.
In most cases, processing personal data for AML purposes will be based on a legal obligation imposed on the controller. However, organisations should clearly identify which legal provisions justify specific processing activities.
Do not collect information that is unnecessary for customer identification, beneficial owner verification, or risk assessment.
The scope and intensity of customer due diligence measures should reflect the identified risk level. Higher risk levels may justify, or in some cases require, enhanced due diligence measures.
Procedures should clearly specify when a document may be copied, who can approve the decision, whether data masking is permitted, and how copies must be secured.
AML documentation should be retained for the period required by law. Under Article 49 of the Polish AML Act, documents and information obtained through customer due diligence measures must generally be stored for five years from the first day of the year following the year in which the business relationship ended or the occasional transaction was completed. In certain cases, this period may be extended by law. Once the retention period expires, the data should be securely deleted.
Even the best procedure will fail if employees responsible for customer onboarding do not understand how to apply it. Training programmes should cover both AML obligations and personal data protection requirements.
Customer identity verification does not have to create a conflict between AML and GDPR. Problems arise only when organisations act automatically, without risk assessment, without documentation, and without control over the scope of processed data.
A well-designed KYC process should be:
In practice, the safest organisations are those that view AML and GDPR not as competing obligations but as two components of the same compliance framework.
Customer identity verification is required under AML regulations, but it must also comply with GDPR principles. The key challenge is finding the right balance between effective anti-money laundering measures and personal data protection.
Key takeaways
Yes. Obliged entities may process personal data to fulfil AML obligations, particularly for customer and beneficial owner identification and verification. However, processing must still comply with GDPR principles, including data minimisation, purpose limitation, and security.
No. The AML Act permits obliged entities to create copies of identity documents for customer due diligence purposes, but it does not require automatic copying in every case. Organisations should assess whether making a copy is justified and necessary while considering both AML obligations and GDPR requirements.
Organisations should collect only the data necessary to fulfil AML obligations and appropriate to the customer's risk profile. It is also important to distinguish between data required for standard, simplified, and enhanced due diligence measures.
The obliged entity, acting as the data controller, is responsible for GDPR compliance. Responsibilities should be appropriately distributed among AML/compliance functions, legal teams, IT departments, and business units. The Data Protection Officer should participate within their advisory and monitoring role while maintaining the independence required under the GDPR.