Record retention under the AMLR: five years, then deletion, and the data-protection balance
The AMLR sets a five-year retention period for customer due diligence and transaction records and requires deletion afterwards. How to reconcile it with GDPR, litigation holds and the reporting template.
Record keeping is where AML law and data-protection law meet most directly. The AMLR requires obliged entities to retain the documents and information obtained in customer due diligence and the records of transactions for five years after the end of the business relationship or the occasional transaction, and to delete them when the period ends, unless a longer period is justified and allowed by national law.
What must be kept
- The customer due diligence file: identity documents or references to them, beneficial-ownership information, the purpose and nature of the relationship, the risk assessment and its updates, the screening results.
- Transaction records sufficient to reconstruct individual transactions.
- The internal analysis behind reports to the FIU, and the reports themselves.
- Evidence of the measures taken: approvals, reviews, training.
Five years, then deletion
The five-year period is a maximum by default, not a minimum to exceed at will. Member States may allow a further period of up to five years where necessary for the prevention, detection or investigation of money laundering, on a case-by-case basis. Beyond that, personal data must be deleted. Institutions that keep everything indefinitely will breach the AMLR and the GDPR at the same time.
The data-protection balance
The AMLR provides the legal basis for processing personal data for AML purposes and restricts its use for other purposes. It also limits the data subject's right of access where disclosure would prejudice an investigation, with safeguards. Data protection impact assessments remain required for high-risk processing such as transaction monitoring and screening.
Practical tensions
Litigation holds and regulatory investigations that require longer retention; group systems that cannot delete per customer; and the new reporting template, which needs structured data that older files do not contain.
What to do now
- Define the retention clock per record type and the trigger (end of relationship, transaction date).
- Build or verify the deletion capability in core systems and archives.
- Document the exceptions process for longer retention with the legal basis.
The dashboard tracks record keeping under Data, technology & detection; the readiness tracker has a Record Retention block.