AML vs GDPR: how to verify a customer's identity without risking compliance breaches?

Violetta Matusiak | Data Protection Inspector   | Crowe Poland
9/17/2026
AML vs GDPR

Customer identity verification is one of the core obligations imposed on obliged entities under AML regulations. At the same time, every stage of collecting, copying, storing, and updating personal data must comply with the GDPR.

This requires organisations to strike a balance between their obligation to prevent money laundering and terrorist financing and the GDPR principles of data minimisation, purpose limitation, and processing security.

AML and GDPR do not conflict, but they require a conscious approach


In many organisations, customer verification is still treated as a purely administrative exercise: obtain an identity document, verify the data, save a copy, and complete the KYC form. From a legal and compliance perspective, however, the process is far more complex.

On the one hand, AML legislation requires obliged entities to apply customer due diligence measures, including customer identification, identity verification, identification of beneficial owners, and assessment of the purpose and nature of the business relationship. The Polish AML/CFT framework is primarily based on the Act of 1 March 2018 on Anti-Money Laundering and Counter-Terrorist Financing, which defines the responsibilities of obliged entities, the role of the General Inspector of Financial Information (GIIF), and rules for reporting suspicious transactions.

On the other hand, the GDPR requires every personal data processing activity to have a valid legal basis, be proportionate to its purpose, properly documented, and adequately secured. In practice, it is not sufficient to say, "We process the data because AML regulations require it." Organisations must know what data they collect, why they collect it, how long it is retained, who has access to it, and how privacy risks are mitigated.

The key principle is simple: AML regulations justify data processing, but they do not exempt organisations from GDPR obligations. In a typical AML compliance process, the legal basis for processing will be Article 6(1)(c) GDPR in conjunction with the relevant AML provisions. The recent decision of the President of the Polish Personal Data Protection Office (UODO) concerning identity document copying also assessed such processing through the lens of Article 6(1)(c) GDPR.

What data can be processed during customer verification?


The scope of data processed within a KYC process should primarily result from AML regulations, while the extent and intensity of customer due diligence measures should reflect the identified risk level, customer type, nature of the business relationship, and other circumstances specified by law.

Such data may include:

  • full name,
  • nationality,
  • PESEL number or date of birth,
  • identity document series and number,
  • address details,
  • identification data of the customer's representative,
  • beneficial ownership information,
  • ownership structure information,
  • source of funds information, where enhanced due diligence measures require it.

The new EU AML framework promotes greater harmonisation, digitalisation, and a risk-based approach. Among other things, the EU AML package emphasises proportionality, digital identification, and tailoring the scope of collected information to the actual level of risk, rather than mechanically collecting excessive data from every customer.

From a GDPR perspective, however, the key requirement is that the obliged entity must be able to demonstrate that the specific scope of data collected was necessary to fulfil AML obligations. In other words, being subject to AML regulations does not automatically grant an organisation the right to collect "everything, just in case."

Read more
Data anonymisation: when does data stop being subject to the GDPR?

Can a customer's identity document be copied?


This is one of the most common questions in both AML and data protection practice. The answer is not always straightforward.

Copying an identity document may be permissible where it is necessary to fulfil AML obligations and falls within the scope of customer due diligence measures being applied. However, this does not mean that every organisation should automatically copy the documents of all customers in every situation. Under Article 34(4) of the Polish AML Act, obliged entities may process information contained in customers' identity documents and may create copies of such documents for customer due diligence purposes.

The key word is "may." Article 34(4) does not impose a general obligation to copy identity documents.

Importantly, this approach has also been confirmed by the President of the UODO, who pointed out that the possibility of creating copies of identity documents constitutes a right available to obliged entities rather than a universal obligation applicable in all cases.

From a GDPR perspective, organisations should assess:

  • whether a copy of the document is genuinely necessary;
  • whether recording the information contained in the document would be sufficient;
  • whether the scope of data captured on the copy can be limited, for example through technical measures, provided such measures do not prevent compliance with AML obligations or the ability to document them;
  • who will have access to the copy;
  • how long the document will be retained;
  • whether storage systems provide an adequate level of security.

The greatest risk arises when organisations routinely collect scans of identity documents without assessing necessity, without a retention policy, and without access restrictions. Such practices may violate the principle of data minimisation and increase the impact of any security incident.

A risk-based approach: the common denominator of AML and GDPR


AML and GDPR pursue different objectives. However, both frameworks rely on a risk-based approach, although the subject and purpose of the risk assessment differ.

Under AML regulations, organisations must assess risks associated with customers, products, transactions, countries, distribution channels, and ownership structures. The intensity of verification measures should correspond to the level of money laundering or terrorist financing risk. Within both the Polish and EU AML frameworks, the risk-based approach is one of the fundamental principles of customer due diligence.

Under the GDPR, a risk-based approach means that controllers should assess risks to the rights and freedoms of individuals and implement appropriate technical and organisational safeguards.

A properly designed KYC process should therefore answer two questions simultaneously:

  1. What AML risk is associated with this customer?
  2. What privacy risk arises from the customer verification process?

Only by combining these two perspectives can an organisation create a procedure that is both regulatory-compliant and data protection-compliant.

The most common organisational mistakes


The most common customer identity verification mistakes include:

  • collecting excessive information "just in case"; ,
  • copying identity documents without assessing necessity;
  • failing to align the scope and intensity of customer due diligence measures with the identified risk level;
  • failing to keep customer information up to date;
  • retaining AML documentation longer than legally required;
  • failing to restrict access to KYC documentation;
  • not providing customers with clear information about data processing;
  • inconsistencies between AML procedures, privacy notices, and records of processing activities.

Another significant issue is treating AML and GDPR as separate processes managed by different teams. Effective compliance requires consistency. AML procedures, data protection documentation, IT systems, and operational practices should work together.

How to verify customer identities safely


To minimise compliance risks, organisations should implement several practical measures.

1. Define the legal basis for processing

In most cases, processing personal data for AML purposes will be based on a legal obligation imposed on the controller. However, organisations should clearly identify which legal provisions justify specific processing activities.

2. Limit data collection to what is necessary

Do not collect information that is unnecessary for customer identification, beneficial owner verification, or risk assessment.

3. Adapt the process to the risk level

The scope and intensity of customer due diligence measures should reflect the identified risk level. Higher risk levels may justify, or in some cases require, enhanced due diligence measures.

4. Establish clear rules for copying documents

Procedures should clearly specify when a document may be copied, who can approve the decision, whether data masking is permitted, and how copies must be secured.

5. Ensure appropriate retention periods

AML documentation should be retained for the period required by law. Under Article 49 of the Polish AML Act, documents and information obtained through customer due diligence measures must generally be stored for five years from the first day of the year following the year in which the business relationship ended or the occasional transaction was completed. In certain cases, this period may be extended by law. Once the retention period expires, the data should be securely deleted.

6. Train employees

Even the best procedure will fail if employees responsible for customer onboarding do not understand how to apply it. Training programmes should cover both AML obligations and personal data protection requirements.

AML vs GDPR: conflict or shared responsibility?


Customer identity verification does not have to create a conflict between AML and GDPR. Problems arise only when organisations act automatically, without risk assessment, without documentation, and without control over the scope of processed data.

A well-designed KYC process should be:

  • compliant with AML requirements,
  • proportionate from a GDPR perspective,
  • tailored to the identified risk level,
  • properly documented,
  • technologically secure,
  • easy for employees and customers to understand.

In practice, the safest organisations are those that view AML and GDPR not as competing obligations but as two components of the same compliance framework.

Learn more
Discover Crowe Poland's data protection services

Personal data protection

Summary


Customer identity verification is required under AML regulations, but it must also comply with GDPR principles. The key challenge is finding the right balance between effective anti-money laundering measures and personal data protection.

Key takeaways

  • AML and GDPR are not contradictory. They complement one another. AML obligations provide the legal basis for processing personal data, but they do not remove the need to comply with GDPR requirements.
  • Organisations should process only the information necessary to fulfil AML obligations, in line with the principle of data minimisation.
  • The type of data collected should result from AML requirements, while the scope and intensity of customer due diligence measures should reflect the identified level of risk.
  • The AML Act allows obliged entities to create copies of identity documents for customer due diligence purposes, but it does not impose a general obligation to do so. Each organisation should assess whether making a copy is justified and necessary in the specific circumstances.
  • Both AML and GDPR rely on a risk-based approach. Organisations should assess not only money laundering risks but also privacy risks affecting individuals.

Frequently asked questions (FAQ)


Does AML allow organisations to process a customer's personal data?

Yes. Obliged entities may process personal data to fulfil AML obligations, particularly for customer and beneficial owner identification and verification. However, processing must still comply with GDPR principles, including data minimisation, purpose limitation, and security.

Is it always necessary to copy a customer's identity document?

No. The AML Act permits obliged entities to create copies of identity documents for customer due diligence purposes, but it does not require automatic copying in every case. Organisations should assess whether making a copy is justified and necessary while considering both AML obligations and GDPR requirements.

How can AML obligations be reconciled with the principle of data minimisation?

Organisations should collect only the data necessary to fulfil AML obligations and appropriate to the customer's risk profile. It is also important to distinguish between data required for standard, simplified, and enhanced due diligence measures.

Who is responsible for ensuring that the KYC process complies with the GDPR?

The obliged entity, acting as the data controller, is responsible for GDPR compliance. Responsibilities should be appropriately distributed among AML/compliance functions, legal teams, IT departments, and business units. The Data Protection Officer should participate within their advisory and monitoring role while maintaining the independence required under the GDPR.

Violetta Matusiak
Violetta Matusiak
Data Protection Inspector

See also: