Country-specific guidance Current

Setting a record retention schedule: the EU AML floor and GDPR minimisation

Two EU rules point in different directions on the same records; here's how they actually fit together.

The EU's anti-money laundering rules set a retention floor for due diligence evidence, while GDPR says not to keep personal data longer than necessary. This guide sets out how the two are meant to work together, not against each other. It is general information, not legal or compliance advice.

Action plan

1 Know the EU AML retention floor: 5 years, once it applies The clock runs from the end of the relationship or transaction, not from when the record was created.

The EU's Anti-Money Laundering Regulation requires obliged entities to retain customer due diligence documents, transaction records, and related evidence for a period of 5 years, commencing on the date of the termination of the business relationship, the carrying out of an occasional transaction, or a refusal to enter into a relationship or transaction. This specific EU-wide text becomes directly applicable from 10 July 2027; before that date, follow your member state's currently transposed retention rule.

  • Start the 5-year retention clock from the end of the relationship or transaction, not from record creation
  • Treat 10 July 2027 as the date this specific EU-wide floor becomes directly applicable
  • Confirm your currently applicable national retention rule until that date

Done when: A retention schedule consistent with the applicable 5-year AML floor is tracked per relationship or transaction

EUR-Lex: EU Anti-Money Laundering Regulation (EU) 2024/1624, Article 77
2 Delete personal data once the retention floor expires, unless properly extended The obligation doesn't stop at retaining for 5 years; it continues into actually deleting afterwards.

The Regulation states that, without prejudice to retention periods for data collected for the purposes of other EU legal acts or national law complying with GDPR, obliged entities shall delete personal data upon expiry of the 5-year period. A competent authority may require further retention on a case-by-case basis where necessary for preventing, detecting, investigating, or prosecuting money laundering or terrorist financing, but that further period must not exceed 5 years, and it isn't a default your firm can apply on its own.

  • Delete personal data once the applicable retention period expires, as a default practice
  • Only extend retention where a competent authority has actually required it, case by case
  • Don't treat an open-ended extension as available by default

Done when: Personal data is deleted on schedule once the retention floor expires, unless a competent authority has required further retention

3 Reconcile the AML floor with GDPR's storage limitation principle These two rules aren't in conflict; the AML floor is what makes the retention 'necessary' under GDPR for that purpose.

GDPR requires personal data to be kept in a form permitting identification of the data subject for no longer than is necessary for the purposes for which it is processed. Where the EU AML framework sets a specific retention floor for due diligence evidence, that floor is the necessary period for that AML purpose; the GDPR principle then requires you to actually delete the data once that floor expires, and to avoid retaining the same records for longer under a different, unstated purpose.

  • Treat the AML retention floor as defining what's 'necessary' for that specific AML purpose under GDPR
  • Don't keep AML evidence beyond its floor for a purpose you haven't actually defined and documented
  • Review retained records against both the AML floor and GDPR's necessity test, not just one of them

Done when: The firm's retention schedule reflects the applicable AML floor and is actively enforced against GDPR's storage limitation principle, not left to run indefinitely

See GDPR data controller obligations for client personal data