When Two Rulebooks Collide: Data Protection and Financial Crime Regulation

Written by Mark Farrell

When data protection and financial crime rules collide, financial services firms need joined-up governance for data collection, retention and supplier risk.

When Two Rulebooks Collide Navigating the Tension Between Data Protection and Financial Crime Regulation

When Two Rulebooks Collide: Data Protection and Financial Crime Regulation

Financial services firms are often expected to do two things at once: know more about their customers and collect less data about them.

This is the practical tension between financial crime regulation and data protection law. Both carry serious regulatory consequences, but they ask different questions of the same customer record.

Financial crime rules focus on whether a firm knows enough to identify and manage risk. Data protection law asks whether each item of personal data is necessary, lawful, secure and retained for no longer than needed.

The challenge affects customer onboarding, transaction monitoring, retention, technology, supplier management and the evidence a firm can produce when challenged. Firms that treat data protection and financial crime compliance as separate workstreams often only address the overlap when something goes wrong.

The Core Challenge

The practical question is whether a firm can show that each item of customer data has a defined regulatory purpose, a proportionate risk trigger, a controlled access route and a clear retention outcome.

This means considering where the two regimes overlap and where they create tension, particularly around collection, retention, outsourcing, governance and emerging technology.

Collection: Need to Know vs Just in Case

The first point of friction is collection.

The Money Laundering Regulations 2017 require customer due diligence and, in higher-risk situations, enhanced due diligence. In practice, this can mean collecting detailed information about source of funds, source of wealth, beneficial ownership, corporate structures and transaction behaviour.

At the same time, the UK GDPR requires organisations to collect personal data that is adequate, relevant and limited to what is necessary. This is known as data minimisation.

Data minimisation does not mean collecting as little information as possible in every situation. It means being able to explain why each data point is needed for a defined purpose.

Problems arise when firms collect more information simply because they can, or because teams are worried about getting anti-money laundering requirements wrong. This can lead to data being collected just in case without a clear risk-based reason.

A stronger approach is to apply the risk-based logic already built into the Money Laundering Regulations. Enhanced information gathering should be linked to a genuine, documented risk trigger. Standard-risk customers should not automatically be subject to the same level of collection.

For each category of data, firms should be able to explain:

  • Which legal or regulatory obligation supports collection
  • What risk factor triggered the request
  • Who can access the information
  • When the need for the information will be reviewed

Retention: Delete Less, Delete More

Retention is another area where financial crime obligations and data protection expectations can appear to conflict.

The UK GDPR requires personal data to be kept in an identifiable form for no longer than necessary. However, the Money Laundering Regulations require relevant records to be retained for five years after the end of a business relationship or the completion of an occasional transaction, subject to the detailed requirements of the Regulations.

This does not mean anti-money laundering obligations automatically override data protection law. It means firms need a precise retention analysis.

The lawful basis for retaining anti-money laundering records will often be compliance with a legal obligation under Article 6(1)(c) UK GDPR. However, a robust retention schedule should distinguish between different record types, including:

  • Customer identification records
  • Verification evidence
  • Risk assessments
  • Transaction monitoring alerts
  • Suspicious activity escalation material
  • Sanctions screening results
  • Call recordings
  • Suitability files and advice records

Each category may have a different legal basis, retention trigger and deletion point. Some records may need to be retained because anti-money laundering law requires it. Others may be retained because FCA rules, limitation periods or advice obligations apply. Others should be deleted, anonymised or access-restricted once their purpose has expired.

Delete records too early and the firm may be unable to evidence adequate due diligence or monitoring. Keep everything indefinitely and the firm risks unlawful over-retention, greater breach impact and weaker accountability.

Outsourcing, Suppliers and Operational Resilience

A single supplier can create several overlapping compliance requirements.

A cloud provider, KYC screening tool, transaction monitoring platform or credit reference relationship may require an Article 28 processor assessment, international transfer analysis where relevant, an information security review, financial crime due diligence, an outsourcing assessment and an operational resilience assessment.

These reviews overlap, but they are not the same.

Data protection asks about processing instructions, sub-processors, security, deletion, audit rights and international transfers. Financial crime asks whether a tool supports effective due diligence, screening, monitoring and escalation. Operational resilience asks whether the service supports an important business service, what happens if it fails and whether exit plans are credible.

Running these reviews separately can create duplicated effort and regulatory blind spots. A supplier may pass a data protection assessment but fail to meet operational resilience expectations. Another may offer strong functionality but have weak deletion controls, access management or transfer transparency.

The answer is integrated supplier governance. This means one intake process, one risk classification, one evidence pack and the right specialist sign-off at each stage.

The FCA and ICO’s March 2026 joint statement on vulnerability-related data makes a similar point. Data protection law does not prevent firms from delivering good outcomes under the Consumer Duty, but firms must still meet their data protection obligations. One regulatory regime should not become an excuse for failing another.

Independence Does Not Mean Isolation

Closer coordination should not compromise the independence of the Data Protection Officer.

Article 38 UK GDPR requires that a DPO is not instructed on how to perform their tasks and is not placed in a conflict of interest. However, independence of judgement is not the same as isolation from the process.

A DPO can remain independent while being involved early in retention design, supplier assessment, model governance, data protection impact assessments and data mapping.

In fact, late-stage review can weaken effective oversight. By the time a system is configured, data has been collected or a supplier has been appointed, the commercial decision may already be difficult to change.

The same applies to financial crime teams. Data protection should not be seen as a paper exercise that slows down effective controls. Good minimisation, access control and retention practices can make financial crime information more accurate, better governed and easier to evidence.

Emerging Technology

Privacy-enhancing technologies may eventually help firms reduce the tension between financial crime detection and data minimisation.

These are technologies designed to gain insight from data while reducing unnecessary exposure of the underlying information. Examples include federated learning, secure multi-party computation, fully homomorphic encryption and differentially private synthetic data.

They could be valuable for anti-money laundering and fraud detection, where suspicious patterns are often easier to identify across wider datasets. Developments such as Singapore’s COSMIC platform also show the direction of travel towards more controlled, purpose-specific information sharing.

However, these technologies should be treated as emerging developments rather than immediate compliance fixes. Many remain difficult to deploy at scale due to cost, technical complexity, immature supplier tooling, performance limitations and evolving regulatory expectations.

They also do not remove the need for strong governance. A firm using privacy-enhancing technology would still need a clear lawful basis, a documented assessment of necessity and proportionality, appropriate retention rules, supplier controls and security assurance.

What Good Practice Looks Like

Firms that manage this tension well tend to do five things.

  1. Maintain one reliable data inventory. A single data inventory should support both Article 30 records of processing and financial services governance records. Separate teams should not maintain inconsistent versions of the same information.
  2. Build retention schedules together. The DPO, MLRO, legal, operations and records teams should agree the legal basis, retention period and deletion point for each record category.
  3. Apply risk-based collection. Enhanced data gathering should be linked to documented risk triggers, not habit, fear or supplier defaults.
  4. Join up supplier governance. Data protection, financial crime, information security and operational resilience reviews should work through one coordinated process.
  5. Involve data protection early. Data protection should be part of model governance, transaction monitoring design and customer decision-making from the beginning. Automated or analytics-led controls should be explainable, proportionate and supported by clear data lineage.

One Operating Model, Not Two Separate Rulebooks

The firms best placed to manage this challenge recognise the overlap and deliberately design governance that works across both regimes.

The answer is not to prioritise data protection over financial crime regulation, or vice versa. It is to build an operating model that supports proportionate collection, lawful retention, controlled sharing, resilient outsourcing and evidence that can stand up to scrutiny.

For firms under pressure to detect financial crime, protect customers and minimise personal data, that joined-up approach is essential.

This article provides general information and is not legal advice.